RWA Restaking Protocol Zoth Suffers $8.4M Exploit, Attacker Converts Funds to DAI

RWA Restaking Protocol Zoth Suffers $8.4M Exploit, Attacker Converts Funds to DAI

  • 21.03.2025 00:00
  • cryptonews.com
  • Keywords: DeFi, Exploit, Security Breach, Stablecoin

RWA restaking protocol Zoth suffered an $8.4M exploit as attackers drained funds and converted them into DAI. This incident highlights growing security concerns in crypto, following a record-breaking February 2025 with over $1.5B stolen.

Coinbase ReportsCoinbase ProductsCOINsentiment_neutral

Estimated market influence

Zoth

Negativesentiment_dissatisfied
Analyst rating: N/A

The company experienced a security breach resulting in the loss of $8.4 million.

Cyvers Alerts

Positivesentiment_satisfied
Analyst rating: N/A

Reported the incident, indicating a compromised deployer wallet as the root cause.

Borderless

Neutralsentiment_neutral
Analyst rating: N/A

Provided funding to Zoth.

Blockchain Founders Fund

Neutralsentiment_neutral
Analyst rating: N/A

Investor in Zoth.

Taisu Ventures

Neutralsentiment_neutral
Analyst rating: N/A

Investor in Zoth.

G20

Neutralsentiment_neutral
Analyst rating: N/A

Investor in Zoth.

Fat Cat Ventures

Neutralsentiment_neutral
Analyst rating: N/A

Investor in Zoth.

GemHead Capital

Neutralsentiment_neutral
Analyst rating: N/A

Investor in Zoth.

Coinbase

Coinbase

Neutralsentiment_neutral
Analyst rating: Buy

Angel investor in Zoth.

Hedera

Neutralsentiment_neutral
Analyst rating: N/A

Angel investor in Zoth.

Ripple

Neutralsentiment_neutral
Analyst rating: N/A

Provided a grant to Zoth.

Context

Analysis of RWA Restaking Protocol Zoth Exploit

Exploit Overview

  • Amount stolen: $8.4 million
  • Date of exploit: March 21, 2025
  • Protocol affected: Zoth restaking protocol
  • Attacker action: Converted funds to DAI and swapped into Ether
  • Immediate response: Zoth website taken offline for maintenance

Root Cause

  • Triggered by: Upgrade to proxy contract "USD0PPSubVaultUpgradeable"
  • Compromised wallet: Deployer wallet identified as the source of the breach
  • Attacker activity: Drained $8.4 million from USD0++ stablecoin

Immediate Actions Post-Hack

  • Zoth's response: Issued statement on X, acknowledging the breach and promising updates
  • Investigation status: Ongoing with no detailed report released yet
  • Community reaction: Vigilant monitoring of developments

Zoth’s Launch and Funding Details

  • Founders: Pritam Dutta and Koushik Bhargav
  • Launch date: January 2023
  • Funding amount: $4 million in August 2024
  • Investors: Borderless, Blockchain Founders Fund, Taisu Ventures, G20, Fat Cat Ventures, GemHead Capital, Coinbase angels, Hedera angels, Ripple’s XRPL Foundation
  • Protocol details: Backed by US Treasury Bills and corporate bonds

Market Context

  • Crypto security trend: February 2025 saw $1.5 billion stolen in four high-profile hacks
  • Notable attackers: Lazarus Group targeted multiple protocols, including Bybit ($1.46B), Ionic Money, zkLend, and Infini (Hong Kong)
  • Common vulnerabilities: Social engineering, smart contract flaws, compromised private keys

Competitive Landscape

  • DeFi sector risks: Highlighted by the growing number of security breaches
  • Industry implications: Emphasizes need for rigorous audits and proactive security measures
  • Investor concerns: Potential impact on confidence in DeFi protocols

Long-Term Implications

  • Reputation damage: Zoth faces credibility challenges post-breach
  • Regulatory focus: Likely increased scrutiny of DeFi security practices
  • Strategic considerations: Enhanced security protocols and user trust rebuilding efforts

Regulatory Concerns

  • Potential impact: Regulatory bodies may impose stricter guidelines on RWA protocols
  • Industry response: Calls for better compliance frameworks and transparency

Strategic Considerations

  • Investor due diligence: Greater focus on protocol security and audit history
  • Protocol upgrades: Need for thorough testing and vulnerability assessments
  • Community engagement: Importance of transparent communication during crises