![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
以太坊第2层协议ZKSYNC在2025年4月15日经历了严重的安全漏洞,导致未经授权的1100万个ZK令牌
The crypto world was hit with a major security breach on April 15, 2025, as a primary admin key for Ethereum layer-2 protocol ZKsync was compromised, leading to the unauthorized minting of 111 million ZK tokens, valued at approximately $5 million.
加密货币世界在2025年4月15日受到重大安全漏洞的袭击,作为以太坊2层协议ZKSYNC的主要管理员密钥,导致未经授权的铸造造成了1.11亿个ZK代币,价值约500万美元。
According to DeFi researcher Harun and blockchain security firm SEAL 911, the exploit involved a privileged function, sweepUnclaimed(), within the airdrop smart contract. This function was designed to collect unclaimed tokens after the airdrop period ended. However, the compromised admin account manipulated it to mint and transfer tokens directly to the attacker’s wallet.
根据Defi研究人员Harun和区块链安全公司SEAL 911的说法,该漏洞涉及在Airdrop Smart合同中的特权功能,即SweepunClaimed()。该功能旨在在空调期结束后收集无人认领的令牌。但是,受损的管理员帐户将其操纵以直接转移到攻击者的钱包中。
While the sum represents only about 0.45% of the total ZK token supply, the implications for smart contract governance and user trust are substantial.
虽然该总和仅占ZK代币供应总额的0.45%,但对智能合同治理和用户信任的影响很大。
The incident triggered immediate alarm among users and investors in the ZKsync ecosystem. As explained by Unchained Capital, the exploit did not stem from a vulnerability in the protocol itself, but rather from the elevated privileges assigned to the admin wallet. This aligns with a broader industry concern—centralized control and the critical need for multi-signature protections in sensitive contract functions.
该事件引发了ZKSYNC生态系统中用户和投资者之间的立即警报。正如Unchained Capital所解释的那样,利用并非源于协议本身的脆弱性,而是源于分配给管理员钱包的提升特权。这符合更广泛的行业关注 - 中央控制和对敏感合同功能中多签名保护的关键需求。
Announcing the incident, ZKsync stated that the unauthorized minting was confined to the airdrop distribution contract and did not affect user funds, the core ZKsync protocol, or the token contract itself.
ZKSYNC宣布事件表示,未经授权的铸造仅限于Airdrop发行合同,不影响用户资金,核心ZKSYNC协议或代币合同本身。
“The development team is working on implementing corrective measures to prevent similar incidents in the future,” the company added.
该公司补充说:“开发团队正在努力采取纠正措施,以防止将来的类似事件。”
To support its investigation, ZKsync is collaborating with SEAL 911, a well-known blockchain security response team, and multiple centralized exchanges to trace the attacker’s steps on-chain and potentially recover the stolen funds by freezing or intercepting suspicious activity.
为了支持其调查,ZKSYNC正在与SEAL 911,一个著名的区块链安全响应团队以及多次集中式交易所合作,以追踪攻击者在链上的步骤,并有可能通过冷冻或拦截可疑活动来恢复被盗的资金。
Moreover, ZKsync is offering the attacker an opportunity to return the funds and avoid further legal consequences.
此外,ZKSYNC为攻击者提供了归还资金并避免进一步法律后果的机会。
Following the incident, the ZK token experienced significant volatility, plummeting nearly 19% before partially recovering. As of the latest trading sessions on Monday morning, the token is valued around $0.047.
事件发生后,ZK令牌经历了明显的波动性,在部分恢复之前下降了近19%。截至周一上午的最新交易课程,该令牌的价值约为0.047美元。
With more information expected to be released, the token price is likely to continue fluctuating as confidence in the project is gradually restored.
随着预计将发布更多信息,随着对项目的信心逐渐恢复,令牌价格可能会继续波动。
The breach has also sparked a broader conversation about the role of admin keys, centralized authority in decentralized systems, and the transparency of contract permissions. Community members and developers are calling for stricter governance standards, including open-source audits, decentralized multisig setups, and time-locked function calls.
违规行为还激发了有关管理员钥匙的作用,集中权威在分散系统中的作用以及合同许可的透明度的更广泛的对话。社区成员和开发人员呼吁更严格的治理标准,包括开源审核,分散的Multisig设置和时间锁定的功能调用。
ZKsync has pledged to release a complete post-mortem once its internal investigation is complete. For now, the incident serves as a cautionary tale about the complexities and trade-offs of deploying smart contracts with such elevated administrative privileges.
一旦完成内部调查,ZKSYNC已承诺发布完整的验尸。目前,该事件是一个警告性的故事,讲述了以这种高度行政特权部署智能合约的复杂性和权衡。
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 1945年,富兰克林·德拉诺·罗斯福第四枚金牌
- 2025-04-18 06:10:13
- 在这种贵金属中仅有的10个例子之一,它将突出该公司即将举行的2025年夏季全球展示拍卖。
-
- 现在购买7种最佳山寨币(2023年4月更新)
- 2025-04-18 06:10:13
- 随着加密货币的成熟和全球采用的增长,重点正在从炒作转向真正的效用。
-
- 项目11提供了1个BTC,用于破解比特币的公钥,从而提高了量词后威胁讨论的最前沿
- 2025-04-18 06:05:13
- 项目11再次提出了一个问题,即在量子计算时代,有弹性比特币的加密基础是如何的。
-
-
- 随着加密市场的恢复,资本旋转回到大批山寨币和早期智能游戏
- 2025-04-18 06:00:12
- 随着加密货币市场从去年的放缓中恢复过来,资本正在恢复到大量的山寨币和早期智能比赛中。
-
- Web3 AI($ WAI) - 适合您的AI加密工具
- 2025-04-18 06:00:12
- 如果您正在寻找购买最不仅仅是缓慢增长的最佳加密硬币,web3 AI($ wai)是一个值得退房的人。
-
- XRP的市场价值大幅提高可以增强全球金融稳定
- 2025-04-18 05:55:12
- 金融教育者和财富导师琳达·琼斯(Linda Jones)表示,XRP的市场价值大幅提高可以增强全球金融稳定性。
-
-