23 Mar 2025

light mode

Ethereum RWA Platform Zoth Hacked Again: $8.85M Stolen In Proxy Exploit

Ethereum RWA Platform Zoth Hacked Again: $8.85M Stolen In Proxy Exploit

The Zoth platform, built on Ethereum and focused on RWA tokenization, has once again been exploited. $8.85 million was drained off — the second major incident in less than 30 days.

On this page

For the second time in a month, Ethereum-based platform Zoth — known for tokenizing real-world assets — has fallen victim to a devastating exploit.

This time, a private key leak allowed the attacker to siphon off $8.85 million, using a carefully manipulated proxy contract.

Cybersecurity experts caution that more Zoth contracts may be at risk.

As detailed by Cyvers, the breach occurred on March 21, 2025. A rogue address upgraded the proxy and altered the implementation contract — ultimately transferring assets into the attacker’s possession.

Hackers made off with $8.85 million in USD0++ stablecoins, later swapping the funds for 4,223 ETH — worth approximately $8.3 million — and transferring the tokens to another address.

Zoth stated it is working with cybersecurity partners to investigate the breach and assess the scope of the loss.

According to findings from Cyvers and PeckShield, the attack was likely enabled by leaked private keys granting admin access.

This is the second successful attack on Zoth in just a month, raising serious concerns about the project’s smart contract management practices.

Check this out: Crypto Heist 101: How Hackers Steal Millions in Crypto

Zoth’s second major breach in a month can be traced to a vulnerability in its proxy contract — a widely used DeFi structure that separates contract logic from storage, allowing upgrades without changing the contract address.

The downside? It places immense trust in admin-level access and private key security.

In this case, the attacker updated the proxy to point to a malicious contract, giving themselves direct access to locked assets.

As Cyvers’ Hakan Unal explained, the attacker likely exploited a leaked private key or an internal permissions flaw. PeckShield reinforced the point: when the admin key is compromised, the entire contract’s logic becomes controllable.

Cyvers noted that Zoth maintains several proxy contracts, one of which currently safeguards $12.28 million in USYC. If administrative keys were reused, the potential exposure significantly exceeds the $8.85 million already extracted.

The absence of real-time surveillance and privilege escalation alerts was cited as a key vulnerability. Experts believe that automated admin-level monitoring could have offered an early warning — potentially averting the breach.

More insights: What is a proxy, and what is it used for?

March 6 Exploit: How Zoth First Got Breached

On March 6, Zoth experienced its first breach — a $285,000 exploit tied to its liquidity pool.

According to Solidity Scan, a flaw in the ZeUSD token contract allowed an attacker to generate uncollateralized tokens. The breach stemmed from a logic error that let them circumvent the rules meant to guarantee financial backing — a quiet flaw that would later echo louder.

Although the financial damage in March was limited, the recurrence of attacks suggests an underlying weakness in Zoth’s security governance. The close timing between the two breaches is particularly troubling for stakeholders.

Zoth has not issued a statement regarding any link between the incidents. Nonetheless, growing scrutiny within the digital asset space is now focused on the operational resilience of this RWA platform.

Read on: RWA Market Insights: Key Trends for 2025

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Metaplanet Appoints Eric Trump as Strategic Advisor Amid Bitcoin Adoption

Metaplanet Appoints Eric Trump as Strategic Advisor Amid Bitcoin Adoption

Metaplanet has named Eric Trump as the first member of its Strategic Advisory Board. The decision aims to strengthen the Japanese company’s presence in the Bitcoin economy and elevate its public brand.

Vlad Vovk
ZachXBT Uncovers Hyperliquid Whale Behind $20M in Illicit Crypto Profits 

ZachXBT Uncovers Hyperliquid Whale Behind $20M in Illicit Crypto Profits 

Blockchain investigator ZachXBT shared an analysis of the alleged identity of a Hyperliquid whale who profited around $20 million through illicit trading activity.

Anahit Avetisyan
US SEC Rules Out Securities Status for Proof-of-Work Mining

US SEC Rules Out Securities Status for Proof-of-Work Mining

According to an official clarification, the SEC has ruled that Proof-of-Work mining processes are exempt from securities oversight.

Dmytro Psevdonimenko
BitMEX and KuCoin Face South Korean Sanctions Over Unlicensed Operations

BitMEX and KuCoin Face South Korean Sanctions Over Unlicensed Operations

As South Korea intensifies its oversight of digital assets, regulators are preparing sanctions against unregistered foreign exchanges lacking VASP certification.

Anton Kryshtal
WhiteBIT’s Rise: How Volodymyr Nosov Built Europe’s Largest Crypto Exchange

WhiteBIT’s Rise: How Volodymyr Nosov Built Europe’s Largest Crypto Exchange

The crypto market is ruthless. It demands determination, total commitment, and leaves little room for mistakes. But some don’t just follow the rules—they set them. One of those people is Volodymyr Nosov, the founder and CEO of WhiteBIT.

Ivan Dikalenko
How Jeremy Allaire Built Circle and Made USDC a Stablecoin Giant

How Jeremy Allaire Built Circle and Made USDC a Stablecoin Giant

On a Friday evening in March 2023, panic gripped the crypto market. USDC, a so-called reliable stablecoin, temporarily lost its dollar peg, dropping below $1.

Ivan Dikalenko
Top Crypto Tweets of the Week: Ripple Case Ended, Solana Ad Debates, & More

Top Crypto Tweets of the Week: Ripple Case Ended, Solana Ad Debates, & More

The long-awaited end of the US SEC vs. Ripple lawsuit, Solana’s controversial ad and the SEC’s crypto roundtable were among the top trending topics on X today.

Anahit Avetisyan
What is a Hash Function and Why It’s Essential?

What is a Hash Function and Why It’s Essential?

Learn what a hash function is, how it works, and why it’s vital for data integrity, security, and performance in modern computing and blockchain technology.

The Coinomist
How Many Confirmations for Bitcoin Transactions and Why It Matters

How Many Confirmations for Bitcoin Transactions and Why It Matters

Learn what Bitcoin confirmations are, how many are required for different transactions, and why they matter for security and fraud prevention in the blockchain.

The Coinomist
What is a Check Digit? A Full Explanation

What is a Check Digit? A Full Explanation

Discover what a check digit is, how it’s calculated, and why it matters for data verification. Learn how algorithms like Luhn ensure data integrity across various industries.

The Coinomist
When Was Ethereum Created and How It Transformed Blockchain?

When Was Ethereum Created and How It Transformed Blockchain?

Explore Ethereum’s origins and evolution. Learn how Vitalik Buterin’s vision reshaped blockchain technology, sparking innovations like smart contracts, DeFi, and NFTs.

The Coinomist
How Many Sats in a Bitcoin? Everything You Need to Know

How Many Sats in a Bitcoin? Everything You Need to Know

Learn how many satoshis (sats) make up one Bitcoin and why this divisibility matters. Understand the role of sats in facilitating microtransactions and enhancing Bitcoin’s usability.

The Coinomist
OnyxCoin (XCN): Why This Layer-3 Blockchain Is Gaining Investor Attention

OnyxCoin (XCN): Why This Layer-3 Blockchain Is Gaining Investor Attention

OnyxCoin isn’t just a crypto project—it’s an infrastructure built for the digital age, offering scalable, secure, and low-cost transactions for a globalized economy.

Vlad Vovk
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

There’s been a lot of talk about possible changes to crypto tax policies in the U.S. One of the more controversial ideas floating around is “Trump no tax on crypto.” As Trump adopts a more crypto-friendly stance, major rumors have surfaced that he’s considering a 0% tax on crypto gains.

Anahit Avetisyan
MORE
Surf, Sun & Satoshis: Inside El Zonte, the Bitcoin Beach Town

Surf, Sun & Satoshis: Inside El Zonte, the Bitcoin Beach Town

El Zonte, a scenic coastal town in El Salvador, was once known as a surfer’s paradise. However, with Bitcoin now functioning as everyday currency, the town has earned a new identity as Bitcoin Beach.

The Coinomist
Hidden Gem or Overhyped? Exploring El Salvador Like a Local

Hidden Gem or Overhyped? Exploring El Salvador Like a Local

Your ultimate El Salvador travel guide to a country where BTC is legal tender and cryptocurrency is transforming the way locals live and transact.

The Coinomist
MORE