The Shezmu protocol was hacked on September 20, 2024, in two isolated incidents involving shezUSD and shezETH at 07:21:59 PM UTC and 10:55:47 UTC. Two different exploiter addresses collectively stole 509.34 ETH and 9447 DAI worth nearly $1.25 million during the time of the exploit. Shezmu is an Ethereum lending platform where users can borrow against their NFTs and yield-bearing assets (vaults). First, users deposit the collateral asset into a qualifying vault contract and receive shares. Later, the vault shares are used to borrow shezUSD (or shezETH). The vulnerability lies in the collateral contract (0x6412…924), where anyone can mint the collateral out of thin air. As collateral could be minted in large quantities (infinite mint bug), it could be deposited in the ERC20 vault (0x5924…e9c) and used to borrow shezETH / shezUSD against it. Thus draining the protocol’s shezETH and shezUSD liquidity pool.