Stop overpaying - start transferring money with Ogvio. Sign up, invite friends & grab Rewards now! 🎁
ZKsync Hit by Admin Hack, Attacker Mints 111 Million Extra Tokens
Key Takeaways
- A ZKsync admin account was hacked, which allowed the attacker to mint $5 million in unclaimed ZK tokens;
- The exploit targeted airdrop contracts but didn’t impact user wallets or main systems;
- ZKsync is working with SEAL to recover the stolen tokens and prevent future abuse.
A ZKsync admin account was compromised on April 15, which allowed an attacker to mint about $5 million worth of unclaimed ZK tokens.
The breach was confirmed through ZKsync’s official account on X, which stated that this was an isolated event and no user wallets were affected.
ZKsync is a tool built on Ethereum
Did you know?
Subscribe - We publish new crypto explainer videos every week!
What is Staking Crypto? (Rewards & Risks Explained SIMPLY)
According to an updated post on X, the attacker used access to three airdrop-related contracts and triggered a feature called "sweepUnclaimed()". This function was meant to handle leftover tokens from the ongoing airdrop.
The attacker created 111 million extra ZK tokens, which increased the total supply by around 0.45%. Most of those tokens still remain in the attacker’s wallet.
ZKsync says its main contracts, including those controlling token rules and community governance, were not affected. The platform has also said that the exploited method cannot be used again.
To address the situation, ZKsync is working with a cybersecurity group called the Security Alliance (SEAL) to try to recover the stolen funds.
KiloEX, a decentralized exchange (DEX), recently paused all trading after a $7.5 million security breach. How did the attacker pull it off? Read the full story.