HomeSecurity OperationsHacker steals $5M in ZK tokens by compromising ZKsync admin account —...

Hacker steals $5M in ZK tokens by compromising ZKsync admin account — TradingView News

Published on

spot_img

A recent hack on the ZKsync platform has left the company reeling, as a hacker managed to compromise an admin account and mint $5 million worth of unclaimed airdrop tokens. The incident, which occurred on April 15, was deemed isolated, with no user funds impacted, according to a statement from ZKsync X.

After conducting an investigation, ZKsync revealed that the compromised account had administrative control over three airdrop distribution contracts. The hacker exploited a function called sweepUnclaimed() to mint 111 million unclaimed ZK tokens, resulting in a 0.45% increase in the total token supply. As of the latest update, the attacker still retains control over most of the stolen funds.

The company is now working with the Security Alliance (SEAL) to coordinate recovery efforts. Fortunately, ZKsync stated that its governance and token contracts remain unaffected, and no further exploits are possible using the “sweepUnclaimed()” vector.

ZKsync is known for being an Ethereum layer-2 protocol that processes main-layer transactions in batches through zero-knowledge rollups technology. As of April 15, the ZKsync Era platform has $57.3 million in total value locked, as reported by DefiLlama. The platform had been in the midst of airdropping 17.5% of its token supply to various ecosystem participants prior to the hack.

Following the security breach, ZKsync’s native token, ZK (ZK), experienced significant price fluctuations. The token dropped by 16% to $0.040 at around 1:00 pm UTC, before rebounding to $0.047 at the time of writing. Despite the recovery, ZK remains down 7% in the past 24 hours, showcasing the impact of the hack on investor sentiment.

This incident adds to the growing trend of crypto-related hacks in recent years. In the first quarter of 2025 alone, $2 billion has been lost to such malicious activities, almost reaching the total amount lost in 2024. These incidents highlight the ongoing challenges faced by the crypto industry in terms of security and the protection of user funds.

In conclusion, the ZKsync hack serves as a stark reminder of the vulnerabilities present in the crypto space and the importance of robust security measures to safeguard users’ assets. As the industry continues to evolve and expand, addressing these security concerns will be crucial to building trust and ensuring long-term sustainability.

Source link

Latest articles

Concerns over Trump’s Push for AI in Classrooms: What Safeguards are in Place?

President Donald Trump's initiative to introduce artificial intelligence (AI) in K-12 schools across the...

Anatomy of a Data Breach: And What to Do If It Happens to You [Virtual Event]

A recent virtual event titled "Anatomy of a Data Breach: And what to do...

As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware

Dell, a major player in the server industry, has reassured its customers that their...

Protecting Yourself and Your Business from Cybercrime in PNG

Cybercrime has become a growing concern in Papua New Guinea, with scammers, hackers, and...

More like this

Concerns over Trump’s Push for AI in Classrooms: What Safeguards are in Place?

President Donald Trump's initiative to introduce artificial intelligence (AI) in K-12 schools across the...

Anatomy of a Data Breach: And What to Do If It Happens to You [Virtual Event]

A recent virtual event titled "Anatomy of a Data Breach: And what to do...

As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware

Dell, a major player in the server industry, has reassured its customers that their...