{"id":107153,"date":"2023-07-26T12:09:00","date_gmt":"2023-07-26T12:09:00","guid":{"rendered":"https:\/\/fr.cryptonews.com\/?p=120664"},"modified":"2023-07-26T15:28:07","modified_gmt":"2023-07-26T15:28:07","slug":"era-lend-protocole-zksync-pirate-34-millions-dollars","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/","title":{"rendered":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars"},"content":{"rendered":"<p style=\"text-align:justify;\"><img decoding=\"async\" src=\"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg\" alt=\"\" srcset=\"https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_1260_630.jpg 1260w, https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_1200_600.jpg 1200w, https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_900_450.jpg 900w, https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_720_360.jpg 720w, https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_600_300.jpg 600w, https:\/\/cimg.co\/news\/120664\/320106\/responsive-images\/eralend-hack___media_library_original_300_150.jpg 300w\" sizes=\"100vw\" width=\"1260\" class=\"content-img\">Le protocole de pr&ecirc;t <strong>Era Lend<\/strong>, bas&eacute; sur le layer 2 d&#8217;Ethereum, zkSync, a &eacute;t&eacute; pirat&eacute; ce mardi 26 juillet. Le hacker a utilis&eacute; une faille dans le code du projet et est reparti avec la modique somme de <strong>3,4 millions de dollars<\/strong> &agrave; en croire la soci&eacute;t&eacute; de s&eacute;curit&eacute;\/audit blockchain <a href=\"https:\/\/twitter.com\/BlockSecTeam?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1683824959452504065%7Ctwgr%5Ec42cc6f2028955871a4e7f857fbf491f3bcd6b27%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fcryptonaute.fr%2Fhack-3-4-millions-protocole-pret-zksync%2F\">BlockSec<\/a>.&nbsp;<\/p><h2 style=\"text-align:justify;\">Une attaque au niveau du contrat intelligent&nbsp;<\/h2><span class=\"replacer\"><\/span><p style=\"text-align:justify;\">Avant de rentrer dans les d&eacute;tails techniques de l&#8217;attaque perp&eacute;tr&eacute;e hier, rappelons que le protocole de pr&ecirc;t<strong> Era Lend est un fork du projet Synswap<\/strong>, les deux entit&eacute;s ayant donc du code en commun et par cons&eacute;quent des failles similaires.&nbsp;<\/p><p style=\"text-align:justify;\">L&#8217;attaque a eu lieu au niveau du<strong> smart contract<\/strong> (contrat intelligent) sur lequel tourne Era Lend et plus pr&eacute;cis&eacute;ment <strong>au niveau d&#8217;un oracle de prix<\/strong>. Selon plusieurs obesrvateurs, et notamment la soci&eacute;t&eacute; d&#8217;audit <a href=\"https:\/\/cryptonews.com\/fr\/guides\/blockchain\/\">blockchain<\/a> BlockSec ou encore la soci&eacute;t&eacute; de s&eacute;curit&eacute; Certik, il s&#8217;agirait d&#8217;une <strong>attaque de r&eacute;entrance en lecture seule<\/strong>.&nbsp;<\/p><figure class=\"media\"><oembed url=\"https:\/\/twitter.com\/BlockSecTeam\/status\/1683824959452504065\"><\/oembed><\/figure><p style=\"text-align:justify;\">Il s&#8217;agit d&#8217;une attaque sur un <a href=\"https:\/\/cryptonews.com\/fr\/guides\/blockchain\/\">contrat intelligent<\/a> dans lequel un attaquant peut <strong>appeler une fonction du contrat plusieurs fois<\/strong> avant que la fonction ne soit termin&eacute;e. Cela peut &ecirc;tre fait en appelant la fonction &agrave; partir d&#8217;une autre fonction qui est elle-m&ecirc;me appel&eacute;e par la fonction vuln&eacute;rable.<\/p><p style=\"text-align:justify;\">L&#8217;attaquant peut alors <strong>utiliser la fonction vuln&eacute;rable pour modifier des donn&eacute;es dans le contrat intelligent <\/strong>avant que la fonction ne soit termin&eacute;e, ce qui peut entra&icirc;ner une perte de fonds ou d&#8217;autres dommages.<\/p><p style=\"text-align:justify;\">Sur Twitter, l&#8217;observateur blockchain Spreek explique qu&#8217;avec &#8220;les jetons LP Syncswap, on peut burn, puis rappeler les jetons avant que la fonction &#8220;update_reserves&#8221; ne soit ex&eacute;cut&eacute;. L&#8217;oracle utilise donc <strong>une valeur de r&eacute;serve incorrecte pour calculer le prix<\/strong>, ce qui a pour effet de <strong>gonfler le prix de l&#8217;oracle<\/strong>&#8220;.&nbsp;<\/p><p style=\"text-align:justify;\">Selon EraLend, l&#8217;attaquant a ensuite utilis&eacute; des ponts et diff&eacute;rents portefeuilles afin de disperser son butin sur<strong> 3 <\/strong><a href=\"https:\/\/cryptonews.com\/fr\/guides\/blockchain\/\"><strong>blockchains<\/strong><\/a><strong> diff&eacute;rentes et 8 adresses au total<\/strong>.<\/p><p style=\"text-align:justify;\">Le mode op&eacute;ratoire a rapidement &eacute;t&eacute; identifi&eacute;, les experts alertant donc sur cette <strong>faille dans le contrat intelligent<\/strong> et appelant &agrave; la vigilance de tous les <strong>protocoles construits sur Syncswap<\/strong>.&nbsp;<\/p><h2 style=\"text-align:justify;\">EraLend souhaite r&eacute;cup&eacute;rer les fonds le plus rapidement possible&nbsp;<\/h2><span class=\"replacer\"><\/span><p style=\"text-align:justify;\">L&#8217;adresse utilis&eacute;e par le hacker a vite &eacute;t&eacute; rep&eacute;r&eacute;e, l&#8217;auteur de l&#8217;attaque ayant effectu&eacute; deux transactions frauduleuses. EraLend a d&#8217;ailleurs r&eacute;&eacute;valu&eacute; le montant du hack &agrave;<strong> 2,76 millions de dollars<\/strong>, celui-ci ne concernant que le pool USDC. Dans un thead twitter, le protocole d&eacute;clare :&nbsp;<\/p><blockquote><p style=\"text-align:justify;\">&#8220;Nous mobilisons <strong>toutes les ressources disponibles pour prot&eacute;ger notre pr&eacute;cieuse communaut&eacute;<\/strong> et nous accueillons avec plaisir toute aide de la part de la communaut&eacute;. Si vous pouvez nous aider, n&#8217;h&eacute;sitez pas &agrave; nous contacter. Nous vous tiendrons inform&eacute;s et vous remercions de votre soutien dans cette p&eacute;riode difficile&#8221;.<\/p><\/blockquote><p style=\"text-align:justify;\">Le protocole dit &eacute;galement travailler en &eacute;troite collaboration avec <strong>les autorit&eacute;s, les exchanges et des &eacute;quipes de s&eacute;curit&eacute; <\/strong><a href=\"https:\/\/cryptonews.com\/fr\/guides\/blockchain\/\"><strong>blockchain<\/strong><\/a><strong> <\/strong>pour tenter de r&eacute;cup&eacute;rer les fonds de ses 500k utilisateurs. En attendant un retour &agrave; la normale et pour emp&ecirc;cher tout d&eacute;g&acirc;t suppl&eacute;mentaire l&#8217;&eacute;quipe derri&egrave;re EraLend d&eacute;clare avoir &#8221; <strong>temporairement interrompu les emprunts, l&#8217;approvisionnement en USDC et l&#8217;approvisionnement en SyncSwap LP<\/strong>&#8220;.<\/p><p>Sources : <a href=\"https:\/\/twitter.com\/Era_Lend\/status\/1683897344046268416\">EraLend<\/a> , <a href=\"https:\/\/twitter.com\/BlockSecTeam\/status\/1683824959452504065\">BlockSec<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Le protocole de pr&ecirc;t Era Lend, bas&eacute; sur le layer 2 d&#8217;Ethereum, zkSync, a &eacute;t&eacute; pirat&eacute; ce mardi 26 juillet. Le hacker a utilis&eacute; une faille dans le code du projet et est reparti avec la modique somme de 3,4 millions de dollars &agrave; en croire la soci&eacute;t&eacute; de s&eacute;curit&eacute;\/audit blockchain BlockSec.&nbsp;Une attaque au niveau [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9,1],"tags":[],"editors":[2550],"sponsored_companies":[],"class_list":["post-107153","post","type-post","status-publish","format-standard","hentry","category-blockchain-news","category-news","editors-jurgen-hoffman"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars<\/title>\n<meta name=\"description\" content=\"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars\" \/>\n<meta property=\"og:description\" content=\"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-26T12:09:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-07-26T15:28:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars\" \/>\n<meta name=\"twitter:description\" content=\"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars","description":"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/","og_locale":"fr_FR","og_type":"article","og_title":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars","og_description":"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.","og_url":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/","og_site_name":"Cryptonews France","article_published_time":"2023-07-26T12:09:00+00:00","article_modified_time":"2023-07-26T15:28:07+00:00","og_image":[{"url":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars","twitter_description":"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.","twitter_image":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/"},"author":{"name":"giedrius","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/5d79e712f570715212460260f4f9cc0f"},"headline":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars","datePublished":"2023-07-26T12:09:00+00:00","dateModified":"2023-07-26T15:28:07+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/"},"wordCount":668,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg","articleSection":["Actualit\u00e9s Blockchain","News"],"inLanguage":"fr-FR","copyrightYear":"2023","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/","url":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/","name":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg","datePublished":"2023-07-26T12:09:00+00:00","dateModified":"2023-07-26T15:28:07+00:00","description":"Une faille dans le smart contract du protocole de pr\u00eat EraLend a permis \u00e0 un hacker de d\u00e9tourner 3,4 millions de dollars.","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#primaryimage","url":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg","contentUrl":"https:\/\/cimg.co\/news\/120664\/320106\/eralend-hack.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/era-lend-protocole-zksync-pirate-34-millions-dollars\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Era lend : le protocole de zkSync a \u00e9t\u00e9 pirat\u00e9 pour 3.4 millions de dollars"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/107153","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=107153"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/107153\/revisions"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=107153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=107153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=107153"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=107153"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=107153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}