ZKsync tokens worth $5M swiped in admin account breach

The team says an attacker minted unclaimed tokens from ZKsync’s 2024 airdrop

article-image

CryptoFX/Shutterstock and Adobe modified by Blockworks

share

This is a segment from The Drop newsletter. To read full editions, subscribe.


The Ethereum scaling-focused ZKsync team said one of their admin accounts was accessed and compromised, leading to the theft of over 100 million tokens.

The attacker swiped roughly 111 million ZK, or $5 million worth of the token, the ZKsync team said. This was the amount left unclaimed from the controversial ZK airdrop that took place in June last year.

The team said the incident is “isolated” and added that “all user funds are safe and have never been at risk.” 

ZKsync later identified a wallet address believed to be in the attacker’s possession and explained that the perpetrator had called a function in the airdrop contract that minted the unclaimed tokens. 

“The attacker called the sweepUnclaimed() function that minted approximately 111 million unclaimed ZK tokens from the aidrop [sic] contracts,” ZKsync’s X account said.

Loading Tweet..

That wallet also moved over 1,000 ETH two days ago onto Ethereum’s mainnet. Its first transaction is from three days ago. DeBank data shows that the wallet holds $3.7 million in ZK and ETH tokens on ZKsync’s chain and $1.76 million in ETH on Ethereum’s mainnet as of Wednesday morning, meaning that wallet has a net worth of over $5.5 million.

We don’t know yet how the account was breached, nor do we know the identity of the attacker. 

ZKsync co-inventor Alex Gluchowski wrote Tuesday morning: “We’re actively investigating this incident and will publish the full update once the investigation and recovery efforts are complete.”

Gluchowski also emphasized in a post: “No code was compromised — an operator key was compromised.”

Image: ZK token price in Pacific Time, showing a price plunge before the 6:49 am X post announcing the breach.

Some X users have accused the ZK breach of being an inside job (without showing evidence), while others have alleged that the ZK token is a scam in its entirety. Blockworks has reached out to ZKsync for comment, but did not receive a response by press time.

ZK’s price fell shortly after 6:30 am PT, right before the team’s first post about the breach at 6:49 am PT.

The token hit an all-time low of $0.041 on Tuesday.

By Wednesday morning, ZK’s price was up roughly 5% in the past 24 hours, but remains down 30% in the past month, per CoinGecko data.

Updated April 16, 2025 at 3:15 pm ET: Updated headline.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template (10).png

Research

Innovations on Aptos’ technical design through Raptr, Shardines, and Zaptos approach near-optimal latency and throughput by unlocking 100% utilization of network resources, with the capacity to settle 260k transactions per second with latencies less than 800ms. The original Move language was revamped with the launch of Move 2, supporting more expressivity in smart contract logic and a scalable ability to interact with high volume datasets. The ecosystem has benefitted from strong asset inflows, now hosting over $1.3B in stablecoins, $450M in bridged BTC, and $530M in RWAs. Activity in the Aptos ecosystem has grown notably over the past year, with monthly application revenue reaching ~$835k and monthly DEX volumes growing to over $5B, both at new all time highs.

article-image

Sam Altman sees our future through the World Orb

article-image

Few US politicians are this clearheaded about Bitcoin

article-image

Pump.fun seemed to kick off buybacks on Tuesday according to onchain analysis

article-image

Stablecoins are a new form of money, with an old kind of limit

article-image

Firedancer has yet to go fully live, but its progress has been “pretty impressive,” a dev said

article-image

House lawmakers support, criticize the GENIUS Act, CLARITY Act and the Anti-CBDC Surveillance Act in Monday hearing