Hacker mints $5M in ZK tokens after compromising ZKsync admin account
A hacker compromised a ZKsync admin account on April 15, minting $5 million worth of unclaimed airdrop tokens, according to a statement from the official ZKsync X account. The attack was described as isolated, with no us...
A hacker compromised a ZKsync admin account on April 15, minting $5 million worth of unclaimed airdrop tokens, according to a statement from the official ZKsync X account. The attack was described as isolated, with no user funds affected.
Following an investigation, ZKsync detailed the incident on April 15, disclosing that the compromised account had administrative control over three airdrop distribution contracts. The attacker exploited a function called sweepUnclaimed() to mint 111 million unclaimed ZK tokens, increasing the total token supply by 0.45%. As of the latest update, the attacker still held control of most of the stolen funds.
Source: ZKsync
ZKsync is coordinating recovery efforts with the Security Alliance (SEAL). According to the protocol, its governance and token contracts are unaffected. The company stated that no further exploits are possible via the “sweepUnclaimed()” vector.
ZKsync is an Ethereum layer-2 protocol that processes main-layer transactions in batches using a technology called zero-knowledge rollups. The ZKsync Era platform has $57.3 million in total value locked as of April 15, according to DefiLlama. ZKsync had been in the process of airdropping 17.5% of its token supply to ecosystem participants.
Related: DeFi platform KiloEx offers $750K bounty to hacker
ZK token drops 7% in 24-hour tradingZKsync’s token, ZK (ZK), saw volatile price action in the wake of the hack and the project’s public disclosure on X. Around 1:00 pm UTC, the token had dropped 16%, falling to $0.040 before rebounding to $0.047 at the time of writing. Despite the bounce, ZK remains down 7% over the past 24 hours.
Overall, $2 billion has been lost to crypto hacks in the first quarter of 2025 alone, just $300 million less than the total lost in 2024.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis
Original source
Read on CointelegraphRelated market context
Carlo Ancelotti takes responsibility for Brazil’s 1-1 draw with Morocco as crypto fan tokens enter the World Cup spotlight
Ancelotti's debut highlights challenges of foreign leadership in Brazil, while FIFA's blockchain ventures could reshape fan engage...
Morocco stuns Brazil at 2026 World Cup as crypto fan tokens and betting platforms watch closely
Morocco's victory over Brazil could influence crypto fan token values and betting markets, highlighting sports' evolving financial...
2026 World Cup language ban sparks controversy as crypto fan tokens face their own inclusion test
The language ban highlights challenges in global inclusivity, impacting both media dynamics and crypto's promise of borderless fan...
Kraken’s FIFA World Cup deal and rising fan tokens signal crypto’s deepening sports play
Crypto's integration into major sports events like the FIFA World Cup highlights its growing influence and potential for mainstrea...
Carlo Ancelotti confident Brazil can compete with any team as crypto fan tokens heat up ahead of World Cup opener
Ancelotti's leadership and Brazil's strong squad could boost fan token interest, impacting crypto markets and enhancing digital fa...
SpaceX’s IPO exposes the first crack in tokenized stocks – fragmented ownership and allocation
SpaceX priced its IPO at $135 per share on June 11, raised $75 billion in the largest public offering in history, and opened on Na...