ZKsync airdrop exploit triggers $5M token theft as community cries foul

Source Cryptopolitan

Ethereum layer 2 protocol ZKsync has confirmed that approximately $5 million worth of airdropped tokens were stolen following the compromise of an administrator account, sparking concerns over the security of token distribution processes within the rapidly evolving zk-rollup space.

The stolen funds were the “remaining unclaimed tokens from the ZKsync airdrop,” the project wrote on X before saying that “necessary security measures are being taken.”

The firm said the incident was isolated, initiated using a compromised key, and limited to the ZK Token airdrop contract. While the hack could only reach the airdrop reserve, it resulted in a fast sell-off that led to a dramatic price drop of the token. Since the incident was announced, the ZK token has fallen 15%.

After the attack, ZKsync noted that it was taking safety measures to address the issue. The company said on X that it had begun an internal investigation.

Admin account breach triggers unauthorized minting of 111M ZK tokens

In a recent update, ZKsync disclosed that the admin account overseeing three airdrop distribution contracts had been compromised. The affected wallet address has been identified as 0x842822c797049269A3c29464221995C56da5587D.

According to the X post, the attacker called the sweepUnclaimed() function that minted approximately 111 million unclaimed ZK tokens from the airdrop contracts. 

The incident was limited solely to the airdrop distribution contracts, and all tokens that could be minted through the compromised method have already been minted. ZKsync confirmed that no additional exploits of this nature are possible.

The company continued to say that the ZKsync protocol, ZK token contract, all three governance contracts, and all active Token Program capped minters have not been and will not be affected by the incident. ZKsync says the attacker still holds the majority of funds on this account.

The attacker has been urged to contact security@zksync.io to discuss the potential return of the stolen funds to avoid legal consequences.

Community erupts, accuses ZKsync of mismanagement 

The incident has sparked outrage among community members who were expecting to receive a portion of the ZKsync airdrop—a major milestone for the zk-rollup project, which aims to scale Ethereum with low-cost, high-speed transactions.

“The same tokens you all couldn’t give the community…A good way to exit, though.. no need for this English, just sell and move on,” one user replied to the company’s X post.

Another user accused ZKsync of selling and just trying to play it off. One user identified as @TheBrownGentYT asked why this never happens with their salaries but only with funds allocated for users and the community. The user continued to say that everyone knew what had happened.

The ZKsync team has requested patience from the affected parties as they coordinate the recovery efforts with Security Alliance and exchanges.

Cryptopolitan Academy: Tired of market swings? Learn how DeFi can help you build steady passive income. Register Now

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold price loses momentum on profit-taking The Gold price (XAU/USD) holds steady on Friday after retreating from an all-time high of $3,358 as investors book profits during a long Easter weekend.
Author  FXStreet
16 hours ago
The Gold price (XAU/USD) holds steady on Friday after retreating from an all-time high of $3,358 as investors book profits during a long Easter weekend.
placeholder
Ethereum Price Fights for Momentum—Traders Watch Key ResistanceEthereum price started a fresh decline below the $1,620 zone. ETH is now consolidating and might attempt to recover above the $1,620 resistance. Ethereum started a fresh decline below the $1,620 and
Author  NewsBTC
16 hours ago
Ethereum price started a fresh decline below the $1,620 zone. ETH is now consolidating and might attempt to recover above the $1,620 resistance. Ethereum started a fresh decline below the $1,620 and
placeholder
XRP Price Weakens—Further Losses on The Table?XRP price started a fresh decline below the $2.120 zone. The price is now consolidating above $2.00 and remains at risk of more losses below $2.00. XRP price started a fresh decline below the $2.150
Author  NewsBTC
16 hours ago
XRP price started a fresh decline below the $2.120 zone. The price is now consolidating above $2.00 and remains at risk of more losses below $2.00. XRP price started a fresh decline below the $2.150
placeholder
WTI drifts higher to near $63.50 on trade deal hopes, fresh Iran sanctionsWest Texas Intermediate (WTI), the US crude oil benchmark, is trading around $63.50 during the Asian session on Friday. The WTI price edges higher to a two-week high amid hopes for a trade deal between the United States and the European Union and fresh US sanctions on Iran.
Author  FXStreet
16 hours ago
West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $63.50 during the Asian session on Friday. The WTI price edges higher to a two-week high amid hopes for a trade deal between the United States and the European Union and fresh US sanctions on Iran.
placeholder
Dogecoin (DOGE) Under Pressure—Bearish Setup Could Trigger Sell-OffDogecoin started a fresh decline from the $0.1680 zone against the US Dollar. DOGE is consolidating and might extend losses below the $0.150 support. DOGE price started a fresh decline below the
Author  NewsBTC
16 hours ago
Dogecoin started a fresh decline from the $0.1680 zone against the US Dollar. DOGE is consolidating and might extend losses below the $0.150 support. DOGE price started a fresh decline below the
goTop
quote