Rounding error in collateralization check.
Attacker wallets funded and staged ahead of the smart contract bug exploit against ZkLend.
$9.5M drained from ZkLend on Ethereum via Smart Contract Bug.
PeckShield flagged the anomalous transactions and published an initial alert.
ZkLend paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$3.0M of $9.5M recovered (32%); the remainder is still unaccounted for.
Remaining funds monitored across chains with exchange partners notified.