Hacker Returns Stolen $5M to ZKsync After Bounty Agreement
Key Takeaways: ZKsync has recovered $5 million worth of stolen tokens after offering a bounty. Within a 72-hour deadline, the hacker agreed to return 90% of the assets. User funds and core protocol infrastructure are una...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- ZKsync has recovered $5 million worth of stolen tokens after offering a bounty.
- Within a 72-hour deadline, the hacker agreed to return 90% of the assets.
- User funds and core protocol infrastructure are unaffected.
ZKsync has managed to recover around $5 million worth of stolen ZK tokens after the protocol reached a quick agreement with the exploiter. Within ZKsync’s 72-hour “safe harbor” window, the hacker accepted a 10% bounty in return for returning 90% of the stolen assets.
The exploit, which was found on April 15, involved an admin key that was related to the platform’s airdrop distribution contracts. The exploiter was able to mint approximately 111 million unclaimed ZK tokens, circumventing fair distribution methods. ZKsync promptly assured users that there was never any risk of losing their funds, and that it had no effect on the core functionalities of the ZKsync protocol.
ZKsync Delivers Firm On-Chain Ultimatum to HackerInstead of directly involving law enforcement, the team provided a route to redemption for the attacker through an on-chain message. The note described a bounty deal: give back most of the stolen tokens and keep 10% of the value — no legal repercussions.
The plan included specific conditions:
- 44.6 million ZK tokens were supposed to be sent to a target ZKsync Era address.
- 1,021.3 ETH was intended for an address on the ZKsync Era network and 766 ETH an address on Ethereum Layer 1.
Transactions sent to these addresses were exempt from transaction filtering, meaning they would be accepted even if they originated from wallets associated with the exploit. The hacker complied with all specific requests within the time frame, leading ZKsync to publicly confirm that the incident was effectively and completely closed.
ZKsync’s DeFi Crisis Response Ends with a Collaborative ResolutionThe swift resolution stands in contrast to the prolonged legal battles often seen in decentralized finance. ZKsync’s on-chain negotiation, undergirded by the security community at large on the Ethereum base layer, resulted in cooperation on the part of the hacker and a never-needed potential legal escalation.
They also gave thanks to other contributors such as @_SEAL_Org, @PatrickAlphaC, and @pcaversaccio for their involvement in coordinating the recovery process. The Security Council said the returned assets are in custody now while the Security Council awaits decisions by ZKsync’s governance community regarding the use of these resources.
The attacker, under the terms of the agreement, will not face any further legal or punitive action, as long as the returned funds remain intact and unused. Moreover, the hacker is required to maintain full accountability for the returned assets, ensuring that no further malicious actions are taken with the stolen funds, and reinforcing a sense of responsibility in the process.
More News: Bybit CEO Confirms 27.6% of Hacked Funds Still Untraceable Despite Recovery Efforts
The post Hacker Returns Stolen $5M to ZKsync After Bounty Agreement appeared first on CryptoNinjas.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoNinjasRelated market context
Bitget freezes XRP withdrawals as 27M stolen tokens move
Bitget’s XRP withdrawal route was still disabled on Sept. 26, even as the exchange set Oct. 2 at 08:00 UTC for the last phase of i...
Bitget hacker moves $83 million in stolen XRP that Ripple cannot freeze
Two wallets have been almost emptied and a third is being drained, with about $75 million remaining across the five original holdi...
THORChain under fire after Bitget hack funds routed through protocol
Bitget CEO Gracy Chen urges THORChain to block attacker wallets after a $387.5 million hack, reviving the censorship versus neutra...
SEC clears regulatory hurdle as crypto token buybacks hit record $638 million
Crypto projects spent about $638 million with token buybacks through late August 2026, according to Allium Labs data. That is alre...
XRP News: Bitget Hacker Moves 54M XRP, Putting Fresh Selling Pressure
The attacker behind Bitget’s $388 million news driver has moved about 54 million stolen XRP out of three of the five wallets that...
Bitget hacker withdraws $1.23M from Binance, funnels funds to attacker-controlled wallet
The Bitget hack highlights vulnerabilities in crypto exchanges, prompting urgent calls for enhanced security measures and internat...