ZKSwap Hack
What happened
On 9 July 2025 an attacker drained about $5 million from ZKSwap's Layer 1 bridge on Ethereum, part of the ZKBase project, by abusing its emergency withdrawal feature, Exodus Mode. In Exodus Mode users withdraw directly from the bridge by proving that their balance was in the last L2 state. But the bridge's verifyExitProof() function began with return true, so it accepted any claimed balance without checking the proof. Blockaid reports that the last block verified on the bridge dated from 2 February 2025.
The attacker's main address was 0x0a652decf9caca373e2b50607ecb7b069d71a7ba, and the exploit contract 0x2D3103c8Fdd9d9411E24f555fdad6B22F29F613A was deployed at 14:12:35 UTC. The first withdrawal followed about 13 minutes later, taking tokens under 15 different token IDs before the funds were split across several addresses. No recovery has been reported.
How it happened
- The attacker called
triggerExodusIfNeeded, switching the bridge into Exodus Mode, where users can exit without the operator. - Through an exploit contract, the attacker called
exit()with made-up balances and fake proofs.verifyExitProof()returnedtruewithout verifying them. - OpenZeppelin notes that the
exitedmapping also failed to stop repeat claims, so the attacker reused the trick across many token IDs. - With the bridge crediting these balances, the attacker ran the normal
withdraw()flow to pull about $5 million in tokens out, then moved them to several addresses.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.