{"id":662932,"date":"2025-04-16T00:55:13","date_gmt":"2025-04-15T21:55:13","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hacker-mints-5m-in-zk-tokens-after-compromising-zksync-admin-account\/"},"modified":"2025-04-16T00:55:13","modified_gmt":"2025-04-15T21:55:13","slug":"hacker-mints-5m-in-zk-tokens-after-compromising-zksync-admin-account","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hacker-mints-5m-in-zk-tokens-after-compromising-zksync-admin-account\/","title":{"rendered":"Hacker mints $5M in ZK tokens after compromising ZKsync admin account"},"content":{"rendered":"<p style=\"float:right;margin:0 0 10px 15px;width:240px\">\n                        <img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDQvMDE5NjNiMDktMTYzNi03NDE2LWI2YWQtMzBmOGYwNDk1NzQ1.jpg\" class=\"type:primaryImage\">\n                    <\/p>\n<p>The attacker exploited an admin account tied to ZKsync\u2019s airdrop contracts, minting 111 million unclaimed tokens worth $5 million.<\/p>\n<p><p>A hacker compromised a ZKsync admin account on April 15, minting $5 million worth of unclaimed airdrop tokens, <a rel=\"nofollow\" target=\"_blank\" data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/zksync\/status\/1912141160744632737\" rel=\"null\" target=\"null\" title=\"null\">according<\/a> to a statement from the official ZKsync X account. The attack was described as isolated, with no user funds affected.<\/p>\n<p>Following an investigation, ZKsync <a rel=\"nofollow\" target=\"_blank\" data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/zksync\/status\/1912165357642473488\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/zksync\/status\/1912165357642473488\">detailed<\/a> the incident on April 15, disclosing that the compromised account had administrative control over three airdrop distribution contracts. The attacker exploited a function called sweepUnclaimed() to mint 111 million unclaimed ZK tokens, increasing the total token supply by 0.45%. As of the latest update, the attacker still held control of most of the stolen funds.<\/p>\n<p><em>Source: <\/em><a rel=\"nofollow\" target=\"_blank\" data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/zksync\/status\/1912141160744632737\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/zksync\/status\/1912141160744632737\"><em>ZKsync<\/em><\/a><\/p>\n<p>Read more<\/p>\n<\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMN63nwsw68G3Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/category\/general\/\" target=\"_blank\" >General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/zksync-hacker-steals-5m-airdrop-tokens?utm_source=rss_feed&#038;utm_medium=feed&#038;utm_campaign=rss_partner_inbound\" target=\"_blank\" >Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The attacker exploited an admin account tied to ZKsync\u2019s airdrop contracts, minting 111 million unclaimed tokens worth $5 million. A hacker compromised a ZKsync admin account on April 15, minting $5 million worth of unclaimed airdrop tokens, according to a statement from the official ZKsync X account. The attack was described as isolated, with no&#8230;<\/p>\n","protected":false},"author":1,"featured_media":662933,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1200\/https:\/\/s3.cointelegraph.com\/uploads\/2025-04\/01963b09-1636-7416-b6ad-30f8f0495745","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74894,74882,74892,137593],"class_list":["post-662932","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain","tag-hacks","tag-tokens","tag-zk-rollup"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/662932","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=662932"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/662932\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/662933"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=662932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=662932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=662932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}