ZKsync Hack

Reported loss $5.0M
zkSync Era
Private Key Compromised (Unknown Method)

What happened

On April 13, 2025, an attacker using a compromised admin key minted 111,881,122 unclaimed ZK tokens from three June 2024 airdrop Merkle-distributor contracts on ZKsync Era, worth about $5 million at the initial transaction. The incident was detected and disclosed on April 15; it was isolated to the airdrop distributors, leaving the ZKsync protocol, core ZK token contract and user funds safe. ZKsync's transparency filing reports a 90% return under a 10% safe-harbor bounty.

Technical root cause

A compromised private key controlled a 1-of-1 admin multisig for three airdrop Merkle distributors. The operational failure was leaving that privileged key active after the claim window rather than migrating it to the intended multisig/governance controls; the exact method by which the key was compromised remains unknown.

How it happened

  1. The attacker obtained the private key for the admin account controlling three post-airdrop ZK Merkle distributors.
  2. That account was a 1-of-1 multisig that had not been migrated to the intended stronger control, so the attacker could call the privileged sweepUnclaimed() function.
  3. The call minted 111,881,122 remaining unclaimed ZK tokens; the attacker swapped about 67.2 million ZK for roughly 1,116 ETH before containment.
  4. Matter Labs temporarily filtered transactions and the ZKsync Security Council offered a 10% bounty for return of 90% of the funds. The attacker returned the funds under that arrangement, and no further tokens could be minted because the distributors' capped allocations were exhausted.

Protocol details

Classification Infrastructure / Other / Key Compromise
Protocol Type Exploit/Access control
Implementation language Vyper
Protocol links Website @zksync

Market Context at Time of Hack

Token Price at Hack $0.0488
Market Cap at Hack $179.4M
Reported loss / token market cap 2.79%
Token Categories
Privacy Zero Knowledge Proofs Ethereum Ecosystem Layer 2 Rollups Governance Blockchain Capital Portfolio a16z Portfolio

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.