Market Cap: $2.6437T 0.10%
Volume(24h): $40.0551B -59.47%
  • Market Cap: $2.6437T 0.10%
  • Volume(24h): $40.0551B -59.47%
  • Fear & Greed Index:
  • Market Cap: $2.6437T 0.10%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$77146.398531 USD

-0.23%

ethereum
ethereum

$2514.088317 USD

-0.37%

tether
tether

$0.999674 USD

0.00%

bnb
bnb

$722.500739 USD

-1.34%

xrp
xrp

$1.361192 USD

-0.23%

usd-coin
usd-coin

$0.999776 USD

-0.01%

solana
solana

$101.320251 USD

-0.42%

tron
tron

$0.339801 USD

0.16%

hyperliquid
hyperliquid

$78.899137 USD

-0.02%

zcash
zcash

$1141.149289 USD

-0.18%

dogecoin
dogecoin

$0.084480 USD

-0.05%

monero
monero

$530.834712 USD

-1.66%

chainlink
chainlink

$11.453705 USD

-0.73%

unus-sed-leo
unus-sed-leo

$9.056535 USD

-0.61%

cardano
cardano

$0.207439 USD

-0.31%

Cryptocurrency News Articles

ZKsync Returns Nearly $5.7 Million in Stolen Tokens After Accepting a 10% Bounty

Apr 25, 2025 at 10:22 am

returned nearly $5.7 million in stolen tokens after accepting a 10% bounty. The vulnerability came from a compromised administrative address that allowed the attacker to call the sweepUnclaimed() function in the contract

ZKsync Returns Nearly $5.7 Million in Stolen Tokens After Accepting a 10% Bounty

Cybercriminals stole nearly $5.7 million worth of ZK tokens from ZKsync on April 20, prompting the protocol to offer a 10% bounty and threaten legal action if the tokens weren't returned within 72 hours. In response, the attacker returned the stolen tokens and accepted the bounty, returning the tokens within the 72-hour window.

The vulnerability came from a compromised administrative address that allowed the attacker to call the sweepUnclaimed() function in the contract, enabling them to mint approximately 111 million unclaimed ZK tokens.

The attacker transferred the stolen tokens on April 23 in three transactions, including about $2.47 million in ZK tokens and $1.83 million in ETH to the ZKsync Security Council’s address on the ZKsync Era blockchain. An additional 776 ETH, worth around $1.4 million, was sent to their Ethereum address.

The return occurred within a 72-hour window offered by ZKsync, which promised no legal consequences and a 10% bounty in exchange for the safe return of the stolen tokens.

According to CertiK, $1.67 billion was lost in the first quarter due to hacks, scams, and exploits, with Ethereum-based projects accounting for most losses—nearly $1.54 billion across 98 incidents. Immunefi reported $1.6 billion in stolen funds just in January and February. Private key compromises led to $142.3 million in losses over 15 incidents in Q1. Recovery rates have dropped significantly, with only 0.38% of stolen crypto being recovered this quarter, down from 42% in the previous one.

Original source:yahoo

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 14, 2026