icon
icon
icon
icon
🏷️$300 Off
🏷️$300 Off

News /

Articles /

ZKsync Suffers $5 Million Token Theft in Airdrop Contract Exploit

Coin WorldWednesday, Apr 16, 2025 9:27 am ET
1min read

ZKsync, an Ethereum Layer-2 scaling solution, has disclosed a security breach resulting in the theft of $5 million in unclaimed airdrop tokens. The incident occurred when an administrative wallet managing the airdrop contracts was compromised. This isolated attack has raised concerns about the security of token distribution within the zk-rollup market, especially given the project's past criticisms for unequal token allocation and inadequate Sybil protection during last year’s 21 billion token airdrop.

On April 15, ZKsync announced that an unauthorized user exploited a privileged function in the airdrop distribution contracts. The attacker used the ‘sweepUnclaimed()’ function to mint approximately 111 million unclaimed ZK tokens, valued at around $5 million. This action significantly increased the circulating supply by 0.45%. According to ZKsync’s official statement, the exploit was due to the misuse of the ‘sweepUnclaimed()’ function, which had access to unallocated tokens from the ongoing airdrop initiative.

ZKsync confirmed that the attacker called the sweepUnclaimed() function that minted approximately 111 million unclaimed ZK tokens from the airdrop contracts. The team reassured the community that the breach was isolated to the airdrop distribution contracts only, and all the funds that could be minted have been minted. No further exploits via this method are possible. ZKsync underlined that the attack did not affect any user cash or fundamental smart contracts, and that necessary security measures are being taken, as well as a complete investigation into the issue to assess it and prevent future weaknesses.

Additional examination by security researchers revealed that the vulnerability was facilitated by weak controls around privileged functions. Critics emphasized the compromised admin wallet’s absence of comprehensive multisignature (multisig) security, which if addressed beforehand may have minimized or completely averted the breach. ZKsync is collaborating with the Security alliance (SEAL) on recovery work, confirming that its token contracts and governance are not impacted, and no other exploits are feasible through the “sweepUnclaimed()” vector. The overall value of Ethereum’s layer-2 protocol based on zero-knowledge rollups is now locked onto the ZKsync Era platform, worth $57.3 million. On April 15, the company was airdropping 17.5% of its token supply to members of the ecosystem.

This event highlights the significance of strong security measures in DeFi platforms. As the ecosystem evolves, securing the integrity of administrative controls is critical to preserving user trust and protecting assets. The ZKsync hack serves as a sharp reminder of the vulnerabilities that can exist in smart contract systems, particularly those involving administrative responsibilities. As DeFi platforms grow and attract more users, extensive security audits and strong governance procedures become increasingly important.

Comments

Add a public comment...
Post
User avatar and name identifying the post author
UpbeatBase7935
04/16
ZKsync's got some serious housecleaning to do. Time to tighten those multisig wallets and prevent next breach.
0
Reply
User avatar and name identifying the post author
joethemaker22
04/16
ZKsync's airdrop fiasco serves as a cautionary tale. Always double-check those smart contracts, folks. 🚀
0
Reply
User avatar and name identifying the post author
Shakyhedgehog
04/16
@joethemaker22 alright
0
Reply
User avatar and name identifying the post author
Didntlikedefaultname
04/16
ZKsync airdrop exploit = $5M minted outta thin air
0
Reply
User avatar and name identifying the post author
bnabin51
04/16
Rollup security is a big deal, folks. Don't sleep.
0
Reply
User avatar and name identifying the post author
RamBamBooey
04/16
$5M heist is wild, but glad it was just airdrop tokens. Imagine if they hit the $TSLA of zk-rollups!
0
Reply
User avatar and name identifying the post author
FluidMarzipan1444
04/16
@RamBamBooey Imagine if it hit $ETH!
0
Reply
User avatar and name identifying the post author
lies_are_comforting
04/16
ZKsync better buckle up on security, one breach could tank the whole zk-rollup market. 🚀
0
Reply
User avatar and name identifying the post author
stydolph
04/16
Airdrops should learn from $AAPL's secure distribution strategies. No free lunches in crypto, it seems.
0
Reply
User avatar and name identifying the post author
EconomySoltani
04/16
ZKsync’s admin wallet was a hot mess, leading to a $5 million heist. No multisig, no problem—just a big security fail. Let’s hope they lock it down better next time before they’re the punchline of the next DeFi joke.
0
Reply
User avatar and name identifying the post author
JSOAN321
04/16
Holding $ZKS? Time to reevaluate risk tolerance, maybe?
0
Reply
User avatar and name identifying the post author
acg7
04/16
ZKsync's got work to do on trust issues 😅
0
Reply
User avatar and name identifying the post author
Shot_Ride_1145
04/16
@acg7 ZKsync needs to step up.
0
Reply
User avatar and name identifying the post author
user74729582
04/16
@acg7 True, ZKsync gotta earn back trust.
0
Reply
User avatar and name identifying the post author
Alert-Reveal5217
04/16
Multisig would've saved ZKsync from this headache
0
Reply
User avatar and name identifying the post author
pimppapy
04/16
@Alert-Reveal5217 True, multisig would've helped.
0
Reply
User avatar and name identifying the post author
Brett-_-_
04/16
OMG!Those $META whale-sized options block were screaming danger! � Closed positions just in time profiting more than $191
0
Reply
Disclaimer: The news articles available on this platform are generated in whole or in part by artificial intelligence and may not have been reviewed or fact checked by human editors. While we make reasonable efforts to ensure the quality and accuracy of the content, we make no representations or warranties, express or implied, as to the truthfulness, reliability, completeness, or timeliness of any information provided. It is your sole responsibility to independently verify any facts, statements, or claims prior to acting upon them. Ainvest Fintech Inc expressly disclaims all liability for any loss, damage, or harm arising from the use of or reliance on AI-generated content, including but not limited to direct, indirect, incidental, or consequential damages.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App