icon
icon
icon
icon
$300 Off
$300 Off

News /

Articles /

ZKsync Loses $5M in Hack, Unclaimed Tokens Stolen

Coin WorldWednesday, Apr 16, 2025 3:32 am ET
1min read

ZKsync, an Ethereum Layer-2 scaling protocol, has confirmed that a hacker exploited a compromised administrator wallet to steal approximately $5 million worth of ZK tokens. The breach specifically targeted unclaimed tokens from the June 2024 airdrop distribution contracts.

The attack was executed by an individual who gained control of the private key associated with the admin account for three airdrop distribution contracts. Using this key, the attacker called a function named sweepUnclaimed() to mint around 111 million unclaimed ZK tokens, which were then transferred to the attacker’s wallet, 0xb102…d6a8. This wallet currently holds the majority of the stolen tokens.

ZKsync has assured users that the incident is isolated to the airdrop distribution contracts and that the ZKsync protocol, ZK token contract, governance, and capped minting contracts remain secure. The team emphasized that all user funds are safe and have never been at risk.

In response to the breach, ZKsync is actively coordinating with the Security Alliance and several crypto exchanges to track the attacker’s movements and freeze the stolen assets. The protocol has also extended an invitation to the attacker to contact their security team directly to negotiate a return of the stolen tokens and avoid legal consequences. A full post-incident report is expected to be released later in the day.

This incident highlights the ongoing challenges in the crypto space regarding security and the potential vulnerabilities in smart contract administration. As the investigation continues, ZKsync is taking proactive measures to recover the stolen funds and ensure the safety of its users' assets.

Comments

Add a public comment...
Post
User avatar and name identifying the post author
CALAND951
04/16
$ZK holders on edge now. Will they recover the stolen tokens or nah? Only time will tell.
0
Reply
User avatar and name identifying the post author
rvnmsn
04/16
Hacking for fun and profit. This attacker's wallet's got 111M reasons to smile. 😎
0
Reply
User avatar and name identifying the post author
EX-FFguy
04/16
ZKsync got hacked, $5M gone. But they're playing it cool, inviting the hacker for a chat. Smart move or just desperation? 🤔
0
Reply
User avatar and name identifying the post author
mayorolivia
04/16
@EX-FFguy Smart move, IMO.
0
Reply
User avatar and name identifying the post author
howtospellsisyphus
04/16
ZKsync better have a solid plan B, or this could be a major bag holder situation.
0
Reply
User avatar and name identifying the post author
gnygren3773
04/16
Holding some $ZK, but keeping it tight. This hack's a reminder to always secure those private keys.
0
Reply
User avatar and name identifying the post author
Excellent-Win-4625
04/16
Airdrops can be risky. ZKsync's learning the hard way that security should never be compromised.
0
Reply
User avatar and name identifying the post author
kenton143
04/16
@Excellent-Win-4625 True, airdrops can be risky.
0
Reply
User avatar and name identifying the post author
Miguel_Legacy
04/16
ZKsync's quick response gives me 🤔 confidence in their recovery plan.
0
Reply
User avatar and name identifying the post author
rareinvoices
04/16
@Miguel_Legacy True, ZKsync moved quick.
0
Reply
User avatar and name identifying the post author
EL-Vinci93
04/16
Hackers always seem one step ahead. ZKsync needs to tighten up their security real quick.
0
Reply
User avatar and name identifying the post author
sniper459
04/16
Smart contract admin vulnerabilities are a real issue. ZKsync's quick response might just save their reputation.
0
Reply
User avatar and name identifying the post author
Luka77GOATic
04/16
ZKsync's got some serious 'plainin' to do. Hope they can track down that attacker and get the bags back.
0
Reply
User avatar and name identifying the post author
CarterUdy02
04/16
@Luka77GOATic K boss
0
Reply
User avatar and name identifying the post author
mattko
04/16
ZKsync's got the right attitude, working with exchanges and the Security Alliance. Collaboration is key in these situations.
0
Reply
User avatar and name identifying the post author
WellWe11Well
04/16
ZKsync's response seems solid. Tracking the attacker's moves and offering a deal. Let's see if it pays off. 🚀
0
Reply
User avatar and name identifying the post author
Zurkarak
04/16
Smart contract admin vulnerabilities are a real issue, folks.
0
Reply
User avatar and name identifying the post author
InjuryIll2998
04/16
The crypto world needs better security measures. ZKsync's situation serves as a wake-up call for all of us.
0
Reply
User avatar and name identifying the post author
istockusername
04/16
$5M hack, yet ZKsync stays calm and coordinates. Respect.
0
Reply
User avatar and name identifying the post author
TheOSU87
04/16
@istockusername Makes sense
0
Reply
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App