Zoth Hack Analysis.webp

Incident Summary

On March 21, 2025, at 08:47:35 AM UTC, the Zoth protocol suffered an exploit due to a compromise of its deployer wallet, which led to the unauthorized upgrade of a proxy contract to a malicious implementation.

This allowed the attacker to withdraw approximately $8.4 million USD0++ tokens, which were quickly swapped for DAI and later converted into ETH.

The attack appears to have been planned weeks in advance, with all associated accounts being funded via ChangeNOW.

Timeline of Events

Initial Funding & Preparation

Execution of the Exploit

Failed Pre-Exploit Attempt

Root Cause Analysis

The exploit was made possible due to a compromise of the deployer wallet, which had admin privileges over the proxy contract.

The attacker gained access to this Externally Owned Account (EOA) and used it to execute an upgrade to a malicious implementation contract, granting them complete control over funds.

Key Findings