ZKsync – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 24 Apr 2025 10:23:50 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 ZKsync – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hacker Takes Bounty Deal, Returns $5.7 Million to ZKsync After Token Heist https://earlybirdsinvest.com/hacker-takes-bounty-deal-returns-5-7-million-to-zksync-after-token-heist/ https://earlybirdsinvest.com/hacker-takes-bounty-deal-returns-5-7-million-to-zksync-after-token-heist/#respond Thu, 24 Apr 2025 10:23:49 +0000 https://earlybirdsinvest.com/hacker-takes-bounty-deal-returns-5-7-million-to-zksync-after-token-heist/

ZKsync, a Layer-2 scaling protocol on Ethereum, has successfully recovered approximately $5 million worth of crypto after the person behind the attack agreed to keep 10% as a reward and return the rest.

The security incident happened on April 15, which targeted a contract used for distributing tokens.

To resolve the situation, ZKsync offered a “safe harbor” option—no legal consequences if the stolen funds were returned within 72 hours. The hacker responded by sending back around $5.7 million in three separate transactions on April 23.

What is Shiba Inu Coin? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Two of those transactions were made on the ZKsync Era network. One included $2.47 million in ZKsync tokens, while the other carried $1.83 million in ETH
ETH


$1,744.56

. A third transfer of 776 ETH, worth about $1.4 million, was sent to a separate Ethereum wallet controlled by the project’s Security Council.

According to blockchain records, the first return took place at 2:39 PM UTC, and the final transfer was made just 13 minutes later—all within the agreed timeframe.

The ZKsync Association shared the update on X, saying, “We’re pleased to share that the hacker has cooperated and returned the funds within the safe harbor deadline”.

Additionally, ZKsync plans to release a full report explaining how the attack happened, what went wrong, and what steps will be taken to improve security.

On April 21, Bybit CEO Ben Zhou shared new details on X about the February digital asset theft linked to North Korea’s Lazarus Group. What did he say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hacker-takes-bounty-deal-returns-5-7-million-to-zksync-after-token-heist/feed/ 0 32554
ZKsync Hit by Admin Hack, Attacker Mints 111 Million Extra Tokens https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/ https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/#respond Fri, 18 Apr 2025 04:16:36 +0000 https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/

A ZKsync admin account was compromised on April 15, which allowed an attacker to mint about $5 million worth of unclaimed ZK tokens.

The breach was confirmed through ZKsync’s official account on X, which stated that this was an isolated event and no user wallets were affected.

ZKsync is a tool built on Ethereum
ETH


$1,579.64

that helps speed up transactions by grouping them together and confirming them at once. The platform had been running an airdrop to give out 17.5% of its total ZK token supply to supporters of the project.

What Are Oracles in Crypto? (Beginner Friendly Animation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

According to an updated post on X, the attacker used access to three airdrop-related contracts and triggered a feature called “sweepUnclaimed()”. This function was meant to handle leftover tokens from the ongoing airdrop.

The attacker created 111 million extra ZK tokens, which increased the total supply by around 0.45%. Most of those tokens still remain in the attacker’s wallet.

ZKsync says its main contracts, including those controlling token rules and community governance, were not affected. The platform has also said that the exploited method cannot be used again.

To address the situation, ZKsync is working with a cybersecurity group called the Security Alliance (SEAL) to try to recover the stolen funds.

KiloEX, a decentralized exchange (DEX), recently paused all trading after a $7.5 million security breach. How did the attacker pull it off? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/feed/ 0 31422
ZKsync Reveals Hack on Airdrop Tokens, Attacker Mints $5M Worth of Unclaimed ZK https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/ https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/#respond Thu, 17 Apr 2025 06:38:49 +0000 https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/

A security incident has shaken the ZKsync layer-2 network: on April 15, a compromised admin account led to the minting of roughly $5 million worth of unclaimed airdrop tokens. Although user funds remain untouched, the event highlights how leftover airdrop allocations can become a target for bad actors if not properly secured.

Unclaimed Airdrop Tokens Targeted

ZKsync originally airdropped 3.6 billion ZK tokens in June 2024 to reward early adopters of ZKsync Era and ZKsync Lite. Despite this extensive distribution, millions of tokens—amounting to nearly $5 million—remained unclaimed. These tokens resided in three smart contracts overseen by an admin account, which was compromised.

According to ZKsync’s statement, the attacker called a function named sweepUnclaimed() on the airdrop contract, thereby minting 111 million ZK tokens. This move effectively boosted the circulating supply by around 0.45% of a total fixed supply of 21 billion tokens.

The function existed to allow recovery of unclaimed tokens after the claim period but was gated behind admin-only access—an access point that was exploited once the admin key was compromised.

While $5 million is relatively modest compared to the broader crypto space, any unauthorized minting raises concerns about contract security and leftover token handling.

Scope of the Incident

ZKsync emphasizes that this hack was isolated to the airdrop contract and did not affect user wallets or the main ZK token contract. The governance framework and protocol itself remain intact, with no vulnerabilities reported beyond the compromised admin key. Additionally, ZKsync has assured the public that no further exploits are possible through the sweepUnclaimed() function, as the attacker has already taken all mintable tokens.

Still, the situation has reignited debate about contract design and admin key security. Best practices—such as using multisig wallets for critical admin functions, implementing time-locked operations, or designing contracts with immutable parameters—might have mitigated or prevented the breach.

Nevertheless, the incident sparked price volatility. At one point on April 15, ZK’s value had slid 16% to $0.040, though it later rebounded to around $0.047. Still, the token remains down approximately 7% over the past 24 hours, reflecting ongoing market wariness following the hack’s disclosure.

History of the Airdrop

ZKsync’s airdrop in 2024 was significant, allocating a considerable supply of tokens as a reward for ecosystem participants. Users who contributed to ZKsync Era and ZKsync Lite received varying amounts of ZK based on their activity, but a portion stayed unclaimed. These unclaimed tokens ended up centralized under three distribution contracts, ultimately making them a high-value prize for anyone who managed to breach the admin account’s security.

Response and Recovery Efforts

In a move to protect against further damage, ZKsync has enlisted the help of the Security Alliance (SEAL). The attacker’s wallet—containing most of the newly minted tokens—remains closely monitored, and ZKsync has publicly requested that the individual reach out to negotiate the return of funds. If that fails, the company could seek legal channels to address the theft.

ZKsync stresses that the rest of its architecture—including governance mechanisms, bridging components, and token supplies—remains secure. The protocol also claims that leftover vulnerabilities from the compromised admin key have been neutralized and that no additional user-facing security measures are needed at this time.

Looking Forward

While the hack did not involve user deposits or core protocol infrastructure, it raises questions about how leftover airdrop tokens are stored and secured. Distributing tokens to community members can be an effective way to reward early participation, but unclaimed portions may become a single point of failure if they are controlled by one privileged account.

ZKsync’s quick response and transparent communication have helped contain the issue. However, it remains to be seen whether the attacker will willingly return the stolen tokens. As the network continues to grow—it currently has $57.3 million in total value locked, according to DefiLlama—users and developers alike will watch closely to see what additional security measures ZKsync implements to prevent future admin key compromises.

]]>
https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/feed/ 0 31258