ZKLend Hacker Falls Victim to Phishing, Loses Stolen DeFi Millions

ZKLend Hacker Claims to Have Lost Stolen ETH to Phishing Scam in Bizarre Crypto Crime Twist

  • A Hacker who stole 3,600 ETH from ZKLend claims to have lost 2,930 ETH to a fake Tornado Cash phishing website.
  • The original theft occurred on February 11, 2025, but the hacker only revealed the subsequent loss of funds on March 31.
  • Skeptics question whether this is an elaborate scheme, with some suggesting the hacker may own the phishing website or that the message was an April Fool’s prank.

In an unusual twist of crypto crime, the hacker who stole millions from decentralized finance project ZKLend claims to have subsequently lost those funds to another scam. On February 11, 2025, ZKLend lost approximately 3,600 ether (ETH) in a hack, with the perpetrator later claiming those funds were stolen through a phishing website impersonating Tornado Cash.

- Advertisement -

The bizarre saga continued on March 31 when the hacker, identified as "Fake_Phishing927538," communicated with ZKLend’s token deployer account through an on-chain message. "I tried to move funds to tornado [cash] but I used a phishing website and all the funds have been lost," the hacker wrote, adding, "I am devastated. I am terribly sorry for all the havoc and losses caused."

Following the initial theft, ZKLend administrators had pleaded with the hacker to return the funds and offered a $500,000 bounty, but received no response until the March 31 message. According to the hacker’s statement, 2,930 ETH was lost to operators of the fake Tornado Cash website, a popular crypto mixing service used to obscure transaction trails.

Questions About the Hacker’s Claims

The timing and circumstances have raised significant skepticism throughout the crypto community. Some observers questioned why there was a lengthy delay between the February 18 theft and the March 31 message if the hacker genuinely intended to return funds. Others speculated that the proximity to April 1 might indicate the message was a cruel April Fool’s joke at the expense of users who lost their investments.

A more sinister theory proposed by some community members suggests potential cooperation between the original hacker and the phishing site operators, creating an elaborate scheme to launder the stolen funds while constructing a cover story.

ZKLend’s Response to the Situation

- Advertisement -

ZKLend has stated that "At this stage, security teams do not have conclusive evidence that the phishing website and the exploiter are connected." The protocol continues to monitor the situation, noting "significant movements of funds from the exploiter’s controlled wallet addresses."

Despite the ongoing saga, ZKLend’s homepage still displays logos from prominent backers including Delphi Digital, CMS Holdings, Starkware, and GBV, presenting itself as "supported by trusted institutions" even as investigations into both thefts continue.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

Stay in the Loop

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

    1 Email per day. Unsubscribe at any time.

    - Advertisement -

    Latest News

    Block Adds 108 BTC in Q2, Bitcoin Holdings Now Worth $1.15B

    Block added 108 Bitcoin (BTC) to its holdings in the second quarter of 2025,...

    Mystery Creator Nets $5M Launching Hundreds of Memecoins Daily

    One memecoin creator has launched hundreds of tokens daily since January.The creator has made...

    Tornado Cash Co-Founder Roman Storm Guilty on Money Transmitting Charge

    Roman Storm, co-founder of crypto mixing tool Tornado Cash, was found guilty of operating...

    Predictors Bet on Bitcoin Surge, Vitalik’s Linea Mention, ETH Push

    Prediction markets show most participants expect Bitcoin to reach $125,000 before dropping to $105,000. A...

    SocGholish Malware Leveraging TDS for Sophisticated Web Attacks

    Attackers use Traffic Distribution Systems to spread the SocGholish Malware through compromised websites. SocGholish operates...

    Must Read

    Sushiswap vs Uniswap, What are the differences between these dex?

    It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...