Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

CFTC AI tools now review crypto applications as staff falls by more than 20%

May 3, 2026

HaloGrow Analyzed: Why Is Halo Grow Hair Growth Spray Trending In The United States?

May 3, 2026

Quantra Partners with SumPlus to Push Forward AI-Led RWA Infrastructure

May 3, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Gaming»ZKsync Reveals Hack on Airdrop Tokens, Attacker Mints $5M Worth of Unclaimed ZK
Gaming

ZKsync Reveals Hack on Airdrop Tokens, Attacker Mints $5M Worth of Unclaimed ZK

April 17, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A security incident has shaken the ZKsync layer-2 network: on April 15, a compromised admin account led to the minting of roughly $5 million worth of unclaimed airdrop tokens. Although user funds remain untouched, the event highlights how leftover airdrop allocations can become a target for bad actors if not properly secured.

Unclaimed Airdrop Tokens Targeted

ZKsync originally airdropped 3.6 billion ZK tokens in June 2024 to reward early adopters of ZKsync Era and ZKsync Lite. Despite this extensive distribution, millions of tokens—amounting to nearly $5 million—remained unclaimed. These tokens resided in three smart contracts overseen by an admin account, which was compromised.

According to ZKsync’s statement, the attacker called a function named sweepUnclaimed() on the airdrop contract, thereby minting 111 million ZK tokens. This move effectively boosted the circulating supply by around 0.45% of a total fixed supply of 21 billion tokens.

The function existed to allow recovery of unclaimed tokens after the claim period but was gated behind admin-only access—an access point that was exploited once the admin key was compromised.

While $5 million is relatively modest compared to the broader crypto space, any unauthorized minting raises concerns about contract security and leftover token handling.

Scope of the Incident

ZKsync emphasizes that this hack was isolated to the airdrop contract and did not affect user wallets or the main ZK token contract. The governance framework and protocol itself remain intact, with no vulnerabilities reported beyond the compromised admin key. Additionally, ZKsync has assured the public that no further exploits are possible through the sweepUnclaimed() function, as the attacker has already taken all mintable tokens.

See also  A brief history of nonfungible tokens

Still, the situation has reignited debate about contract design and admin key security. Best practices—such as using multisig wallets for critical admin functions, implementing time-locked operations, or designing contracts with immutable parameters—might have mitigated or prevented the breach.

Nevertheless, the incident sparked price volatility. At one point on April 15, ZK’s value had slid 16% to $0.040, though it later rebounded to around $0.047. Still, the token remains down approximately 7% over the past 24 hours, reflecting ongoing market wariness following the hack’s disclosure.

History of the Airdrop

ZKsync’s airdrop in 2024 was significant, allocating a considerable supply of tokens as a reward for ecosystem participants. Users who contributed to ZKsync Era and ZKsync Lite received varying amounts of ZK based on their activity, but a portion stayed unclaimed. These unclaimed tokens ended up centralized under three distribution contracts, ultimately making them a high-value prize for anyone who managed to breach the admin account’s security.

Response and Recovery Efforts

In a move to protect against further damage, ZKsync has enlisted the help of the Security Alliance (SEAL). The attacker’s wallet—containing most of the newly minted tokens—remains closely monitored, and ZKsync has publicly requested that the individual reach out to negotiate the return of funds. If that fails, the company could seek legal channels to address the theft.

ZKsync stresses that the rest of its architecture—including governance mechanisms, bridging components, and token supplies—remains secure. The protocol also claims that leftover vulnerabilities from the compromised admin key have been neutralized and that no additional user-facing security measures are needed at this time.

See also  Space Nation Game to Feature AI-Created Personalized Narratives

Looking Forward

While the hack did not involve user deposits or core protocol infrastructure, it raises questions about how leftover airdrop tokens are stored and secured. Distributing tokens to community members can be an effective way to reward early participation, but unclaimed portions may become a single point of failure if they are controlled by one privileged account.

ZKsync’s quick response and transparent communication have helped contain the issue. However, it remains to be seen whether the attacker will willingly return the stolen tokens. As the network continues to grow—it currently has $57.3 million in total value locked, according to DefiLlama—users and developers alike will watch closely to see what additional security measures ZKsync implements to prevent future admin key compromises.

Source link

Airdrop Attacker Hack mints Reveals Tokens Unclaimed Worth zkSync
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Major ONDO investor moves 89.3 mln tokens – But price barely reacts

May 1, 2026

Invisible NFTs Explained: Hidden Metadata, Secret NFTs & Reveal Mechanics

May 1, 2026

North Korea Hit Twice And Snagged 76% Of 2026 Hack Value

April 30, 2026

Analyst Calls Local Bitcoin Top, Reveals Why The Price Is Headed Below $60,000

April 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

New SRBMiner-Multi 2.3.7 With Dynex (DNX) and Zilliqa (ZIL) Dual-Mining on Nvidia

October 5, 2023

BNB Futures OI Surges as Funding Rate Slumps to Long-Term Low

July 17, 2023

Billion-Dollar Bank Charges Massive Overdraft Fee After $10,000 Vanishes From Veteran’s Account in Mysterious Hack: Report

February 10, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

CFTC AI tools now review crypto applications as staff falls by more than 20%

May 3, 2026

HaloGrow Analyzed: Why Is Halo Grow Hair Growth Spray Trending In The United States?

May 3, 2026

Quantra Partners with SumPlus to Push Forward AI-Led RWA Infrastructure

May 3, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$78,398.000.20%
  • ethereumEthereum(ETH)$2,311.950.36%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.390.06%
  • binancecoinBNB(BNB)$617.810.35%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$83.85-0.07%
  • tronTRON(TRX)$0.3379572.05%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.71%
  • dogecoinDogecoin(DOGE)$0.1078250.09%