Hacker mints $5M in ZK tokens after compromising ZKsync admin account


A hacker compromised a ZKsync admin account on April 15, minting $5 million value of unclaimed airdrop tokens, according to an announcement from the official ZKsync X account. The assault was described as remoted, with no person funds affected.

Following an investigation, ZKsync detailed the incident on April 15, disclosing that the compromised account had administrative management over three airdrop distribution contracts. The attacker exploited a operate known as sweepUnclaimed() to mint 111 million unclaimed ZK tokens, rising the overall token provide by 0.45%. As of the most recent replace, the attacker nonetheless held management of many of the stolen funds.

01963afd 01e0 72ce 9ec5 443ca16d9e9e

Supply: ZKsync

ZKsync is coordinating restoration efforts with the Security Alliance (SEAL). In keeping with the protocol, its governance and token contracts are unaffected. The corporate acknowledged that no additional exploits are potential through the “sweepUnclaimed()” vector.

ZKsync is an Ethereum layer-2 protocol that processes main-layer transactions in batches utilizing a expertise known as zero-knowledge rollups. The ZKsync Period platform has $57.3 million in whole worth locked as of April 15, according to DefiLlama. ZKsync had been within the means of airdropping 17.5% of its token provide to ecosystem contributors.

Associated: DeFi platform KiloEx offers $750K bounty to hacker

ZK token drops 7% in 24-hour buying and selling 

ZKsync’s token, ZK (ZK), noticed risky worth motion within the wake of the hack and the venture’s public disclosure on X. Round 1:00 pm UTC, the token had dropped 16%, falling to $0.040 earlier than rebounding to $0.047 on the time of writing. Regardless of the bounce, ZK stays down 7% over the previous 24 hours.

Total, $2 billion has been lost to crypto hacks within the first quarter of 2025 alone, simply $300 million less than the overall misplaced in 2024.

Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis