ZKsync Hack
What happened
On April 13, 2025, an attacker using a compromised admin key minted 111,881,122 unclaimed ZK tokens from three June 2024 airdrop Merkle-distributor contracts on ZKsync Era, worth about $5 million at the initial transaction. The incident was detected and disclosed on April 15; it was isolated to the airdrop distributors, leaving the ZKsync protocol, core ZK token contract and user funds safe. ZKsync's transparency filing reports a 90% return under a 10% safe-harbor bounty.
A compromised private key controlled a 1-of-1 admin multisig for three airdrop Merkle distributors. The operational failure was leaving that privileged key active after the claim window rather than migrating it to the intended multisig/governance controls; the exact method by which the key was compromised remains unknown.
How it happened
- The attacker obtained the private key for the admin account controlling three post-airdrop ZK Merkle distributors.
- That account was a 1-of-1 multisig that had not been migrated to the intended stronger control, so the attacker could call the privileged
sweepUnclaimed()function. - The call minted 111,881,122 remaining unclaimed ZK tokens; the attacker swapped about 67.2 million ZK for roughly 1,116 ETH before containment.
- Matter Labs temporarily filtered transactions and the ZKsync Security Council offered a 10% bounty for return of 90% of the funds. The attacker returned the funds under that arrangement, and no further tokens could be minted because the distributors' capped allocations were exhausted.
Protocol details
Evidence
Proof of concept
1 availableSources
- report @WuBlockchain incident report x.com
- report @zksync incident report x.com
- report @zksync incident report x.com
- report Incident Report: Compromised admin key to unclaimed airdrop tokens zksync.io
- transaction Transaction explorer.zksync.io
- analysis Website reference community.venus.io
- analysis DeFiLlama defillama.com
- analysis ZKsync Token Transparency Filing blockworks.com
- analysis ZKsync discloses $5 million attack from compromised airdrop admin account, triggering 20% price drop theblock.co
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.