On the eve of April Fool’s Day, there was a comical event that will be discussed in the crypto community for a long time to come

Scammer became a victim: steal $10 million worth of crypto and be left with nothing

21.04.2025

612

4 min

The classic story of the DeFi protocol hack ended unexpectedly for everyone. The developers of the project were left without liquidity, but the hacker was not able to get unfairly “earned” funds either. GetBlock AML Research has analyzed one of the most unusual situations in the crypto world over the past couple of years.

It started as usual

On February 11, a clever hacker conducted an attack on the zkLend project. He managed to manipulate a smart contract to receive cryptocurrency without collateral. The full chronology and description of the hack can be found on the blog of the protocol’s developers. In the end, the attacker withdrew:

  • 2 213,6 ETH
  • 1 553 069,4 USDC
  • 7 426 029,9 STRK
  • 518 225,7 USDT

Total: $9,6 million at the time of the hack.

After the successful attack, the hacker began moving funds through various cross-chain bridges (StarkGate, Orbiter, Layerswap, and rhino.fi), then converted the assets to ETH and concentrated them into a single storage address for later laundering.

The zkLend team sent a message to the hacker in hopes that he would return the stolen assets. As usual in such situations, the developers allowed the hacker to keep 10% of the stolen funds. But days and weeks passed, and the hacker remained silent.

Addressing the hacker on zkLend’s X page

The best part

The culmination of this story took place on the eve of April Fool’s Day, which only adds to the comical nature of this situation. After the stolen cryptocurrency was “settled down” — the hacker moved 2930 ETH to a new address: 0xD89B7236f4eA38a2AfC1d614Dc3De08A190f1Ff5.

Next, the attacker decided to act according to the classic method, to launder ETH through the Tornado Cash mixer. With the help of this protocol, the cryptocurrency passes through hundreds of addresses in a chaotic manner. This is done to interrupt the chain of asset movement and make it impossible to track them on the blockchain.

At this stage, something went wrong and instead of the original Tornado Cash mixer, the hacker used a phishing link that led to a fake project address (tornadoeth[.]cash). At this point, the hacker lost the funds he had previously stolen from the zkLend project. And the scammer, who got them, did not miss the opportunity to inform his “colleague” about this situation.

Communication between two attackers on the Ethereum blockchain

After the loser hacker lost his cryptocurrency, he suddenly felt “very sorry” and reported it to zkLend developers. All of the hacker’s messages were sent on the Ethereum blockchain, so the reminder of this story will stay with us for a long time.

The hacker’s “repentance

Moral

Despite the comical nature of the situation, there is much to learn from it. For example, when interacting with assets (any assets, not just cryptocurrency), you should always check incoming and outgoing data: addresses, links, senders, recipients, etc. To exclude the possibility of a common mistake or manipulation. And this should always be done. Even knowledge of Solidity (a language for developing smart contracts on Ethereum), skills of auditing smart contracts, detecting bugs, and writing exploits will not save you. The hacker who was the subject of this article was not spared from losses.

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy