{"investigation":{"slug":"zoth-zeusd","entity_name":"Zoth ZeUSD","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Zoth is a Dubai-based real-world asset (RWA) restaking protocol and the issuer of ZeUSD, a CDP-style stablecoin backed by tokenized fixed-income assets including U.S. T-Bills and ETFs. In March 2025, the protocol suffered two separate security incidents within three weeks: a $285,000 logic-flaw exploit on March 1 and a critical $8.4–8.85 million admin key compromise on March 21, the latter resulting in the theft of 8.85 million USD0++ tokens. The stolen funds remain largely unrecovered as of mid-2025, with Zoth offering a $500,000 bounty and engaging Crystal Blockchain BV for forensic investigation.","sections":[{"content":"Zoth suffered two exploits in March 2025, making it one of the first RWA-focused protocols to experience repeated security breaches within a single month. The first incident occurred on March 1, 2025, coinciding with the protocol's public launch date. The second, far more severe incident occurred on March 21, 2025, and resulted in the loss of approximately $8.4–8.85 million. Together the two incidents represent a total loss exceeding $8.7 million. Security firm Cyvers Alerts was the first to publicly identify the second breach. The Lazarus attribution tag has been applied by at least one threat intelligence source (Whitestream, April 2025), though no authoritative public attribution to a specific threat actor has been confirmed.","heading":"Security Incidents Overview","sources":[{"url":"https://decrypt.co/311077/ethereum-defi-platform-zoth-hit-by-8-85-million-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://rekt.news/zoth-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://lazarus.day/incidents/zoth","name":"lazarus.day","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 1, 2025, an attacker exploited a logic flaw in the LTV (Loan-to-Value) validation inside Zoth's mintWithStable() function. The attacker manipulated a Uniswap V3 liquidity pool to engineer a price distortion during a collateral swap. As a result, the system incorrectly recorded 330,979 collateral tokens as deposited when only 7,669 were actually received. Because the LTV check used the inflated on-chain value, the attacker was able to mint ZeUSD against uncollateralized positions, resulting in a net theft of approximately $285,000. The exploit transaction was recorded on-chain at hash 0xc3f70057e261af554c6acf6a372389899f0c2d7d1ebd27311e39525dee88fb39. This incident was analyzed in detail by Verichains.","heading":"First Exploit — March 1, 2025 ($285,000 LTV Logic Flaw)","sources":[{"url":"https://blog.verichains.io/p/anatomy-of-a-hack-how-a-simple-logic","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://research.blockscope.co/zoth-vault-breach","name":"research.blockscope.co","type":"other","credibility":3},{"url":"https://protos.com/rwa-platform-zoth-suffers-second-hack-this-month-loses-8-4m/","name":"protos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Three weeks after the first incident, on March 21, 2025, Zoth suffered a far more severe attack stemming from the compromise of its deployer wallet (0x3604582f56565d7060d73829ffb9ebd579218dca). At 8:46 UTC, the attacker executed the upgradeToAndCall function on the USD0PPSubVaultUpgradeable proxy contract (upgrade transaction hash: 0xb2335f7bf58abbcaa006d0a2bed7db2c64a5dabed56fb1759260adc012c49abe), installing a malicious implementation contract (0xc89d7894341e13d5067d003af5346b257d861f56). One minute later at 8:47 UTC, 8,851,750.3737 USD0++ tokens were drained (transaction hash: 0x33bf669d125d11c432ac9b52b9d56161101c072fd8b0ac2aa390f5760fb50ca4). The stolen USD0++ was swapped to DAI via CowSwap at 9:01 UTC, then converted to approximately 4,222.89 ETH and distributed across at least five attacker-controlled wallets. The primary exploit address was 0x3b33c5Cd948Be5863b72cB3D6e9C0b36E67d01E5. The method by which the deployer private key was obtained has not been publicly confirmed by Zoth; security researchers note that phishing or social engineering are typical vectors for such compromises. The protocol relied on a single externally-owned account rather than a multi-sig or MPC wallet for proxy upgrade authority, a design flaw identified by both Halborn and Blockscope as the root cause.","heading":"Second Exploit — March 21, 2025 ($8.4M–$8.85M Admin Key Compromise)","sources":[{"url":"https://research.blockscope.co/zoth-vault-breach","name":"research.blockscope.co","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/zoth-hack-analysis-80ba3ac5076b","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/rwa-restaking-protocol-zoth-suffers-security-breach/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/zoth-exploit-admin-leak-causes-8m-losses","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the March 21 exploit, Zoth froze approximately 73% of its total value locked to limit further damage. The protocol engaged Crystal Blockchain BV, a blockchain analytics firm, to lead a forensic investigation and asset tracing effort. Zoth and security partner Securr jointly offered a $500,000 bounty (equal to 10% of recovered funds) for information leading to the identification of the attacker or recovery of stolen assets. As of mid-2025, there is no confirmed public report of funds being recovered or the attacker being identified. In August 2025, Zoth announced a $15 million strategic token commitment from Bolts Capital, framed as support for protocol recovery and ZeUSD relaunch. Zoth also published a recovery and compensation plan including stable asset reimbursement for principal losses and vested $ZOTH tokens from ecosystem reserves. User retention was reported internally at above 80% during the recovery period. The protocol's current TVL on DeFiLlama stands at approximately $2.2 million as of mid-2025, a significant decline from the $27 million TVL reported during the February 2025 beta phase.","heading":"Protocol Response and Recovery Efforts","sources":[{"url":"https://www.prnewswire.com/news-releases/zoths-next-chapter-advancing-secure-scalable-rwa-infrastructure-302450470.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://cryptotvplus.com/2025/03/rwa-restaking-protocol-zoth-offers-500k-bounty-after-8-4m-hack/","name":"cryptotvplus.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/blockchain/zoth-engages-crystal-blockchain-bv-for-asset-recovery-post-theft-coincu/","name":"bitcoinethereumnews.com","type":"other","credibility":3},{"url":"https://medium.com/@zoth.io/zoth-secures-15m-strategic-commitment-from-bolts-capital-to-power-the-future-of-real-world-assets-262ba4577404","name":"medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/zoth","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Zoth was founded in 2023 and is headquartered in Dubai, UAE. The founders are Pritam Dutta (CEO) and Koushik Bhargav (CTO), who previously built a fintech venture with a reported $300 million AUM at AB InBev. The protocol describes itself as a stablecoin neobank and RWA restaking layer targeting institutional and retail users globally. Zoth raised $2.5 million in a seed round in April 2024 with participation from Borderless Capital, Mindfulness Capital, YAP Capital, SingularityDAO, and Wormhole. A subsequent $4 million strategic round in August 2024 included Ripple among its backers. Total disclosed external funding prior to the March 2025 incidents was approximately $6.5–6.7 million. The protocol received a smart contract audit from Hacken in December 2024 covering its ZeUSD contracts, though this audit predated the admin key compromise, which was an operational security failure rather than a smart contract vulnerability.","heading":"Protocol Background and Team","sources":[{"url":"https://www.rootdata.com/Projects/detail/Zoth?k=MTEzMDM%3D","name":"rootdata.com","type":"other","credibility":3},{"url":"https://www.finsmes.com/2024/04/zoth-raises-2-5m-in-funding.html","name":"finsmes.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/zoth-4m-funding-strategy/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://hacken.io/audits/zoth/sca-zoth-zeusd-contracts-dec2024/","name":"hacken.io","type":"other","credibility":3},{"url":"https://www.cryptonite.ae/global/zoth-protocol-hack-8-85m-uae-defi-2025","name":"cryptonite.ae","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers from Halborn, SolidityScan, Verichains, and Blockscope each published post-incident analyses. The consensus finding is that the March 21 exploit was not a smart contract vulnerability but an operational security failure: the protocol used a single private key to control upgradeability of a proxy contract holding tens of millions of dollars in user funds. Halborn noted that many failed access attempts went undetected prior to the successful exploit, indicating the absence of adequate monitoring. Recommended industry-standard mitigations — multi-signature wallets, MPC custody, and timelocks on proxy upgrades — were not in place at the time of the breach. The March 1 LTV logic flaw was a code-level vulnerability that the December 2024 Hacken audit apparently did not surface, though the full scope of that audit's coverage has not been publicly clarified. Post-breach, Zoth stated it implemented AI-driven real-time monitoring, independent smart contract audits, and a public bug bounty program.","heading":"Smart Contract and Operational Security Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/zoth-hack-analysis-80ba3ac5076b","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/anatomy-of-a-hack-how-a-simple-logic","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://research.blockscope.co/zoth-vault-breach","name":"research.blockscope.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the March 21 exploit, the $8.4 million in stolen USD0++ tokens was converted to DAI via CowSwap and then to ETH across multiple hops. At least five attacker-controlled wallet addresses have been identified by on-chain researchers. The main exploiter address (0x3b33c5Cd948Be5863b72cB3D6e9C0b36E67d01E5) distributed funds to secondary addresses including 0x7b0cd0D83565aDbB57585d0265b7D15d6D9f60cf (holding approximately 3,233 ETH post-attack) and 0x6ce41f95fc5514a3e8f74c5c500ef1b8a68e2316 (approximately 1,014 ETH). Total ETH held across attacker wallets was approximately 4,222.89 ETH. At least one threat intelligence source (Whitestream, published April 13, 2025 via lazarus.day) tagged the incident with a Lazarus Group attribution, but this has not been independently corroborated by major blockchain analytics firms or law enforcement as of the available record.","heading":"On-Chain Fund Tracing","sources":[{"url":"https://research.blockscope.co/zoth-vault-breach","name":"research.blockscope.co","type":"other","credibility":3},{"url":"https://lazarus.day/incidents/zoth","name":"lazarus.day","type":"other","credibility":3},{"url":"https://rekt.news/zoth-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023","event":"Zoth protocol founded in Dubai by Pritam Dutta and Koushik Bhargav","source":"","date_original":"2023-01-01"},{"date":"2024-04-10","event":"Zoth raises $2.5M seed round led by Borderless Capital and others including Wormhole and SingularityDAO","source":""},{"date":"2024-08-06","event":"Zoth raises $4M strategic funding round with Ripple among backers","source":""},{"date":"2024-09-18","event":"Zoth Atlas introduces ZeUSD as a permissionless fixed-income RWA gateway","source":""},{"date":"2024-12","event":"Hacken publishes smart contract audit of Zoth ZeUSD contracts","source":"","date_original":"2024-12-01"},{"date":"2025-01-27","event":"Zoth announces first-ever RWA restaking layer with ZeUSD pre-deposit campaign","source":""},{"date":"2025-02","event":"ZeUSD enters beta phase, reaching over $27M TVL within six weeks","source":"","date_original":"2025-02-01"},{"date":"2025-03","event":"ZeUSD opens to public; first exploit occurs on the same day — $285,000 stolen via LTV logic flaw in mintWithStable() function exploiting Uniswap V3 price manipulation","source":"","date_original":"2025-03-01"},{"date":"2025-03-21","event":"Second exploit: attacker compromises Zoth deployer wallet (0x3604582f...218dca), upgrades USD0PPSubVaultUpgradeable proxy to malicious contract, drains 8,851,750 USD0++ tokens (~$8.4–8.85M). Funds converted to DAI then ETH across five wallets","source":""},{"date":"2025-03-22","event":"Zoth freezes 73% of TVL, engages Crystal Blockchain BV for investigation, and offers $500,000 recovery bounty (10% of recovered funds)","source":""},{"date":"2025-04-13","event":"Whitestream threat intelligence report tags the March 21 exploit with a Lazarus Group attribution indicator (via lazarus.day)","source":""},{"date":"2025-08","event":"Zoth secures $15M strategic token commitment from Bolts Capital to fund protocol recovery and ZeUSD relaunch","source":"","date_original":"2025-08-01"}],"sources_used":[{"url":"https://decrypt.co/311077/ethereum-defi-platform-zoth-hit-by-8-85-million-hack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260421003644/https://decrypt.co/311077/ethereum-defi-platform-zoth-hit-by-8-85-million-hack","credibility":3,"archive_timestamp":"2026-04-21T00:36:44+00:00"},{"url":"https://rekt.news/zoth-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260415160231/https://rekt.news/zoth-rekt","credibility":3,"archive_timestamp":"2026-04-15T16:02:31+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260606004333/https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025","credibility":3,"archive_timestamp":"2026-06-06T00:43:33+00:00"},{"url":"https://lazarus.day/incidents/zoth","name":"lazarus.day","type":"other","archive_url":"http://web.archive.org/web/20260727201110/https://lazarus.day/incidents/zoth/","credibility":3,"archive_timestamp":"2026-07-27T20:11:10+00:00"},{"url":"https://blog.verichains.io/p/anatomy-of-a-hack-how-a-simple-logic","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260608060135/https://blog.verichains.io/p/anatomy-of-a-hack-how-a-simple-logic","credibility":3,"archive_timestamp":"2026-06-08T06:01:35+00:00"},{"url":"https://research.blockscope.co/zoth-vault-breach","name":"research.blockscope.co","type":"other","archive_url":"http://web.archive.org/web/20260422225852/https://research.blockscope.co/zoth-vault-breach","credibility":3,"archive_timestamp":"2026-04-22T22:58:52+00:00"},{"url":"https://protos.com/rwa-platform-zoth-suffers-second-hack-this-month-loses-8-4m/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260508121537/https://protos.com/rwa-platform-zoth-suffers-second-hack-this-month-loses-8-4m/","credibility":3,"archive_timestamp":"2026-05-08T12:15:37+00:00"},{"url":"https://blog.solidityscan.com/zoth-hack-analysis-80ba3ac5076b","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20250402074351/https://blog.solidityscan.com/zoth-hack-analysis-80ba3ac5076b","credibility":3,"archive_timestamp":"2025-04-02T07:43:51+00:00"},{"url":"https://cryptonews.com/news/rwa-restaking-protocol-zoth-suffers-security-breach/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/zoth-exploit-admin-leak-causes-8m-losses","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20251113134933/https://cointelegraph.com/news/zoth-exploit-admin-leak-causes-8m-losses","credibility":3,"archive_timestamp":"2025-11-13T13:49:33+00:00"},{"url":"https://www.prnewswire.com/news-releases/zoths-next-chapter-advancing-secure-scalable-rwa-infrastructure-302450470.html","name":"prnewswire.com","type":"other","archive_url":"http://web.archive.org/web/20260726110751/https://www.prnewswire.com/news-releases/zoths-next-chapter-advancing-secure-scalable-rwa-infrastructure-302450470.html","credibility":3,"archive_timestamp":"2026-07-26T11:07:51+00:00"},{"url":"https://cryptotvplus.com/2025/03/rwa-restaking-protocol-zoth-offers-500k-bounty-after-8-4m-hack/","name":"cryptotvplus.com","type":"other","archive_url":"http://web.archive.org/web/20260217151842/https://cryptotvplus.com/2025/03/rwa-restaking-protocol-zoth-offers-500k-bounty-after-8-4m-hack/","credibility":3,"archive_timestamp":"2026-02-17T15:18:42+00:00"},{"url":"https://bitcoinethereumnews.com/blockchain/zoth-engages-crystal-blockchain-bv-for-asset-recovery-post-theft-coincu/","name":"bitcoinethereumnews.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/@zoth.io/zoth-secures-15m-strategic-commitment-from-bolts-capital-to-power-the-future-of-real-world-assets-262ba4577404","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260412131929/https://medium.com/@zoth.io/zoth-secures-15m-strategic-commitment-from-bolts-capital-to-power-the-future-of-real-world-assets-262ba4577404","credibility":3,"archive_timestamp":"2026-04-12T13:19:29+00:00"},{"url":"https://defillama.com/protocol/zoth","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250907023808/https://defillama.com/protocol/zoth","credibility":3,"archive_timestamp":"2025-09-07T02:38:08+00:00"},{"url":"https://www.rootdata.com/Projects/detail/Zoth?k=MTEzMDM%3D","name":"rootdata.com","type":"other","archive_url":"http://web.archive.org/web/20251110132306/https://www.rootdata.com/Projects/detail/Zoth?k=MTEzMDM%3D","credibility":3,"archive_timestamp":"2025-11-10T13:23:06+00:00"},{"url":"https://www.finsmes.com/2024/04/zoth-raises-2-5m-in-funding.html","name":"finsmes.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/zoth-4m-funding-strategy/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20250921003001/https://cryptobriefing.com/zoth-4m-funding-strategy/","credibility":3,"archive_timestamp":"2025-09-21T00:30:01+00:00"},{"url":"https://hacken.io/audits/zoth/sca-zoth-zeusd-contracts-dec2024/","name":"hacken.io","type":"other","archive_url":null,"credibility":3,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.cryptonite.ae/global/zoth-protocol-hack-8-85m-uae-defi-2025","name":"cryptonite.ae","type":"other","archive_url":"http://web.archive.org/web/20251207124650/https://www.cryptonite.ae/global/zoth-protocol-hack-8-85m-uae-defi-2025","credibility":3,"archive_timestamp":"2025-12-07T12:46:50+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:25.011435+00:00","updated_at":"2026-08-29T23:26:12.882512+00:00"}}