Summary
Zoth is a Dubai-based real-world asset (RWA) restaking protocol and the issuer of ZeUSD, a CDP-style stablecoin backed by tokenized fixed-income assets including U.S. T-Bills and ETFs. In March 2025, the protocol suffered two separate security incidents within three weeks: a $285,000 logic-flaw exploit on March 1 and a critical $8.4–8.85 million admin key compromise on March 21, the latter resulting in the theft of 8.85 million USD0++ tokens. The stolen funds remain largely unrecovered as of mid-2025, with Zoth offering a $500,000 bounty and engaging Crystal Blockchain BV for forensic investigation.
Connected Entities
1 entities- + 2 more
Timeline(12 events)
2023-01-01
Zoth protocol founded in Dubai by Pritam Dutta and Koushik Bhargav
2024-04-10
Zoth raises $2.5M seed round led by Borderless Capital and others including Wormhole and SingularityDAO
2024-08-06
Zoth raises $4M strategic funding round with Ripple among backers
2024-09-18
Zoth Atlas introduces ZeUSD as a permissionless fixed-income RWA gateway
2024-12-01
Hacken publishes smart contract audit of Zoth ZeUSD contracts
2025-01-27
Zoth announces first-ever RWA restaking layer with ZeUSD pre-deposit campaign
2025-02-01
ZeUSD enters beta phase, reaching over $27M TVL within six weeks
2025-03-01
ZeUSD opens to public; first exploit occurs on the same day — $285,000 stolen via LTV logic flaw in mintWithStable() function exploiting Uniswap V3 price manipulation
2025-03-21
Second exploit: attacker compromises Zoth deployer wallet (0x3604582f...218dca), upgrades USD0PPSubVaultUpgradeable proxy to malicious contract, drains 8,851,750 USD0++ tokens (~$8.4–8.85M). Funds converted to DAI then ETH across five wallets
2025-03-22
Zoth freezes 73% of TVL, engages Crystal Blockchain BV for investigation, and offers $500,000 recovery bounty (10% of recovered funds)
2025-04-13
Whitestream threat intelligence report tags the March 21 exploit with a Lazarus Group attribution indicator (via lazarus.day)
2025-08-01
Zoth secures $15M strategic token commitment from Bolts Capital to fund protocol recovery and ZeUSD relaunch
Decision Log
- hash: 7uRpHj1puSsZp8DgBtqso7RP7NtRZtAu8CGwE14FHurC
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:25 AM
last updated: 5/28/2026, 1:44:30 AM
avoid.net — verified advice for a post-truth world