ZKsync (ZK), an Ethereum layer-2 scaling solution, reported on Tuesday that its admin wallet had been compromised. The hacker then minted 111 million unclaimed ZK tokens worth $5 million. The ZK token price dipped nearly 19% and closed at a 5% loss that day.
ZKsync, an Ethereum layer-2 scaling solution using zero-knowledge proofs, reported a security breach on Tuesday. The attacker exploited an admin wallet and took control of $5 million worth of ZK tokens—the remaining unclaimed tokens from the ZKsync airdrop.
“The attacker called the sweepUnclaimed() function that minted approximately 111 million unclaimed ZK tokens from the airdrop contracts,” said ZKsync on its X post.
The post continued: “This incident is contained to the airdrop distribution contracts only, and all the funds that could be minted have been minted. No further exploits via this method are possible.”
This security breach has inflated the amount of tokens in circulation by 0.45% of the total token supply. The ZK token price dipped nearly 19% and closed at a 5% loss that day. At the time of writing on Wednesday, it is recovering slightly, trading at around $0.047.
ZK chart. Source: CoinGecko