ZKSwap Hack

Reported loss $5.0M
Ethereum
Forged Proof

What happened

On 9 July 2025 an attacker drained about $5 million from ZKSwap's Layer 1 bridge on Ethereum, part of the ZKBase project, by abusing its emergency withdrawal feature, Exodus Mode. In Exodus Mode users withdraw directly from the bridge by proving that their balance was in the last L2 state. But the bridge's verifyExitProof() function began with return true, so it accepted any claimed balance without checking the proof. Blockaid reports that the last block verified on the bridge dated from 2 February 2025.

The attacker's main address was 0x0a652decf9caca373e2b50607ecb7b069d71a7ba, and the exploit contract 0x2D3103c8Fdd9d9411E24f555fdad6B22F29F613A was deployed at 14:12:35 UTC. The first withdrawal followed about 13 minutes later, taking tokens under 15 different token IDs before the funds were split across several addresses. No recovery has been reported.

How it happened

  1. The attacker called triggerExodusIfNeeded, switching the bridge into Exodus Mode, where users can exit without the operator.
  2. Through an exploit contract, the attacker called exit() with made-up balances and fake proofs. verifyExitProof() returned true without verifying them.
  3. OpenZeppelin notes that the exited mapping also failed to stop repeat claims, so the attacker reused the trick across many token IDs.
  4. With the bridge crediting these balances, the attacker ran the normal withdraw() flow to pull about $5 million in tokens out, then moved them to several addresses.

Protocol details

Classification Bridge & Cross-Chain
Protocol Type Chain
Category Bridge Hack
Implementation language Solidity
Protocol links @ZKSwapOfficial

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.