Zoth, an Ethereum-based real-world asset platform, has suffered an $8.85 million exploit after attackers gained unauthorized access to a private key.

The breach marks the second major security incident for Zoth in a month, highlighting ongoing vulnerabilities in DeFi protocols.

The attacker reportedly compromised the protocol’s deployer wallet, allowing them to upgrade the “USD0PPSubVaultUpgradeable” proxy contract to a contract under their control. 

https://twitter.com/CyversAlerts/status/1903021017460600885?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Etweet

This maneuver helped them to withdraw $8.4 million in Zoth’s USD0++ stablecoin, which was quickly swapped for 8.3 million DAI and moved to an external address.

In response, Zoth has placed its website in maintenance mode and is working with security partners to assess the damage and prevent further exploits.

Source: Zoth.io

Proxy contract hack

Proxy contracts, widely used in DeFi for upgradability, introduce a risk when private keys securing them are compromised. The unauthorized upgrade in Zoth’s case demonstrates how attackers can manipulate contract logic to reroute funds without resistance. 

This breach follows a March 6 exploit in which Zoth lost $285,000 due to a liquidity pool vulnerability. Repeated security failures raise concerns about the platform’s risk management and could invite regulatory scrutiny. 



Read the full article here

Share.

Leave A Reply

Your road to financial

freedom starts here

With our platform as your starting point, you can confidently navigate the path to financial independence and embrace a brighter future.

Registered address:

First Floor, SVG Teachers Credit Union Uptown Building, Kingstown, St. Vincent and the Grenadines

CFDs are complex instruments and have a high risk of loss due to leverage and are not recommended for the general public. Before trading, consider your level of experience, relevant knowledge, and investment objectives and seek financial advice. Vittaverse does not accept clients from OFAC sanctioned jurisdictions. Also, read our legal documents and make sure you fully understand the risks involved before making any trading decision