A compromised admin account linked to ZKsync’s airdrop contracts minted $5 million worth of ZK tokens, exploiting unclaimed allocations. The breach, confined to distribution contracts, did not affect user funds or protocol security. Recovery efforts are underway, with the team urging the attacker to negotiate.
- Exploiter minted 111M ZK tokens (~$5M) via compromised admin key, swapping $3.5M to ETH.
- ZKsync confirms no protocol/user fund risks; breach limited to airdrop distribution contracts.
- ZK token fell 8.6% post-exploit, down 90% since launch amid broader L2 market corrections.
📎 Related coverage from: cryptoslate.com
