Market Cap: $2.6666T 0.350%
Volume(24h): $63.8399B -21.110%
  • Market Cap: $2.6666T 0.350%
  • Volume(24h): $63.8399B -21.110%
  • Fear & Greed Index:
  • Market Cap: $2.6666T 0.350%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$83957.564405 USD

0.11%

ethereum
ethereum

$1585.920614 USD

-0.82%

tether
tether

$0.999948 USD

0.01%

xrp
xrp

$2.072262 USD

-0.73%

bnb
bnb

$582.425941 USD

-0.18%

solana
solana

$130.764273 USD

2.87%

usd-coin
usd-coin

$0.999932 USD

-0.01%

tron
tron

$0.244935 USD

-3.03%

dogecoin
dogecoin

$0.155322 USD

-0.28%

cardano
cardano

$0.613597 USD

-0.35%

unus-sed-leo
unus-sed-leo

$9.435609 USD

0.74%

chainlink
chainlink

$12.391354 USD

0.22%

avalanche
avalanche

$18.974844 USD

-0.16%

toncoin
toncoin

$2.921269 USD

0.65%

stellar
stellar

$0.235516 USD

-0.75%

Cryptocurrency News Articles

ZKsync Suffers Major Security Breach, Resulting in the Unauthorized Mint of 111 Million Tokens

Apr 16, 2025 at 04:02 pm

Ethereum layer-2 protocol ZKsync experienced a major security breach on April 15, 2025, resulting in the unauthorized minting of 111 million ZK tokens

ZKsync Suffers Major Security Breach, Resulting in the Unauthorized Mint of 111 Million Tokens

The crypto world was hit with a major security breach on April 15, 2025, as a primary admin key for Ethereum layer-2 protocol ZKsync was compromised, leading to the unauthorized minting of 111 million ZK tokens, valued at approximately $5 million.

According to DeFi researcher Harun and blockchain security firm SEAL 911, the exploit involved a privileged function, sweepUnclaimed(), within the airdrop smart contract. This function was designed to collect unclaimed tokens after the airdrop period ended. However, the compromised admin account manipulated it to mint and transfer tokens directly to the attacker’s wallet.

While the sum represents only about 0.45% of the total ZK token supply, the implications for smart contract governance and user trust are substantial.

The incident triggered immediate alarm among users and investors in the ZKsync ecosystem. As explained by Unchained Capital, the exploit did not stem from a vulnerability in the protocol itself, but rather from the elevated privileges assigned to the admin wallet. This aligns with a broader industry concern—centralized control and the critical need for multi-signature protections in sensitive contract functions.

Announcing the incident, ZKsync stated that the unauthorized minting was confined to the airdrop distribution contract and did not affect user funds, the core ZKsync protocol, or the token contract itself.

“The development team is working on implementing corrective measures to prevent similar incidents in the future,” the company added.

To support its investigation, ZKsync is collaborating with SEAL 911, a well-known blockchain security response team, and multiple centralized exchanges to trace the attacker’s steps on-chain and potentially recover the stolen funds by freezing or intercepting suspicious activity.

Moreover, ZKsync is offering the attacker an opportunity to return the funds and avoid further legal consequences.

Following the incident, the ZK token experienced significant volatility, plummeting nearly 19% before partially recovering. As of the latest trading sessions on Monday morning, the token is valued around $0.047.

With more information expected to be released, the token price is likely to continue fluctuating as confidence in the project is gradually restored.

The breach has also sparked a broader conversation about the role of admin keys, centralized authority in decentralized systems, and the transparency of contract permissions. Community members and developers are calling for stricter governance standards, including open-source audits, decentralized multisig setups, and time-locked function calls.

ZKsync has pledged to release a complete post-mortem once its internal investigation is complete. For now, the incident serves as a cautionary tale about the complexities and trade-offs of deploying smart contracts with such elevated administrative privileges.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Apr 18, 2025