According to Odaily, the leading lending platform on the Starknet chain, zkLend, recently experienced a security breach resulting in the loss of nearly ten million dollars in assets. The analysis by SlowMist indicates that the attack exploited a specific mechanism within flash loans, manipulating the value of accumulators in the empty market. This allowed the attacker to exploit a rounding vulnerability during withdrawals to gain more assets than expected.
Experts recommend that project developers design a secure and logical model for flash loans, considering the impact on the calculation of deposit certificate tokens. Implementing a safe rounding mechanism in mathematical operations is advised to prevent precision loss. Additionally, it is crucial to enhance auditing and security testing for core business logic involving deposits and withdrawals to prevent similar incidents in the future.