Market Cap: $2.6263T -0.35%
Volume(24h): $70.1241B 67.88%
  • Market Cap: $2.6263T -0.35%
  • Volume(24h): $70.1241B 67.88%
  • Fear & Greed Index:
  • Market Cap: $2.6263T -0.35%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$78114.682709 USD

-0.18%

ethereum
ethereum

$2439.257493 USD

-0.81%

tether
tether

$0.999910 USD

0.00%

bnb
bnb

$686.888465 USD

-1.01%

xrp
xrp

$1.365967 USD

-2.45%

usd-coin
usd-coin

$1.000000 USD

0.00%

solana
solana

$102.847391 USD

-2.33%

tron
tron

$0.337155 USD

-1.01%

hyperliquid
hyperliquid

$80.961478 USD

-2.73%

zcash
zcash

$825.231867 USD

-1.40%

dogecoin
dogecoin

$0.082727 USD

-2.62%

monero
monero

$518.349059 USD

9.26%

unus-sed-leo
unus-sed-leo

$9.659832 USD

-0.52%

chainlink
chainlink

$11.274973 USD

-1.42%

cardano
cardano

$0.195707 USD

-3.10%

Cryptocurrency News Articles

ZKsync Suffers Major Security Breach, Resulting in the Unauthorized Mint of 111 Million Tokens

Apr 16, 2025 at 04:02 pm

Ethereum layer-2 protocol ZKsync experienced a major security breach on April 15, 2025, resulting in the unauthorized minting of 111 million ZK tokens

ZKsync Suffers Major Security Breach, Resulting in the Unauthorized Mint of 111 Million Tokens

The crypto world was hit with a major security breach on April 15, 2025, as a primary admin key for Ethereum layer-2 protocol ZKsync was compromised, leading to the unauthorized minting of 111 million ZK tokens, valued at approximately $5 million.

According to DeFi researcher Harun and blockchain security firm SEAL 911, the exploit involved a privileged function, sweepUnclaimed(), within the airdrop smart contract. This function was designed to collect unclaimed tokens after the airdrop period ended. However, the compromised admin account manipulated it to mint and transfer tokens directly to the attacker’s wallet.

While the sum represents only about 0.45% of the total ZK token supply, the implications for smart contract governance and user trust are substantial.

The incident triggered immediate alarm among users and investors in the ZKsync ecosystem. As explained by Unchained Capital, the exploit did not stem from a vulnerability in the protocol itself, but rather from the elevated privileges assigned to the admin wallet. This aligns with a broader industry concern—centralized control and the critical need for multi-signature protections in sensitive contract functions.

Announcing the incident, ZKsync stated that the unauthorized minting was confined to the airdrop distribution contract and did not affect user funds, the core ZKsync protocol, or the token contract itself.

“The development team is working on implementing corrective measures to prevent similar incidents in the future,” the company added.

To support its investigation, ZKsync is collaborating with SEAL 911, a well-known blockchain security response team, and multiple centralized exchanges to trace the attacker’s steps on-chain and potentially recover the stolen funds by freezing or intercepting suspicious activity.

Moreover, ZKsync is offering the attacker an opportunity to return the funds and avoid further legal consequences.

Following the incident, the ZK token experienced significant volatility, plummeting nearly 19% before partially recovering. As of the latest trading sessions on Monday morning, the token is valued around $0.047.

With more information expected to be released, the token price is likely to continue fluctuating as confidence in the project is gradually restored.

The breach has also sparked a broader conversation about the role of admin keys, centralized authority in decentralized systems, and the transparency of contract permissions. Community members and developers are calling for stricter governance standards, including open-source audits, decentralized multisig setups, and time-locked function calls.

ZKsync has pledged to release a complete post-mortem once its internal investigation is complete. For now, the incident serves as a cautionary tale about the complexities and trade-offs of deploying smart contracts with such elevated administrative privileges.

Original source:financefeeds

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 01, 2026