HomeCrypto News StoriesRumoursZKsync Recovers Millions After Bounty Agreement—Was the Breach Planned?

ZKsync Recovers Millions After Bounty Agreement—Was the Breach Planned?

Date:

  • ZKsync recovers $5.7M after hacker returns funds under bounty deal.  
  • Breach exploited airdrop function via compromised admin key, affecting 3 contracts.  
  • Incident highlights rising crypto hacks, with Q1 2025 losses hitting $ 1.63B.

ZKsync gained back over $5.7 million in stolen tokens as a result of an attack targeting their airdrop allocation protocol. The breach, which occurred on April 15, involved a breached administrative password that enabled the unauthorized production of roughly 111 million ZK tokens, then valued at $5 million.

The attacker agreed to repay 90% of the stolen cash for a 10% reward. The agreement was reached within the protocol’s designated 72-hour “safe harbor” window, raising questions about the planning and intent behind the breach.

On April 21, the ZKsync Association publicly offered a bounty deal to the attacker, allowing them to retain 10% of the stolen funds if 90% were returned voluntarily within three days. On April 23, blockchain info revealed that the attacker had sent back roughly $5.7m in the three transactions.

These included $2.47m in ZK tokens and $1.83m in ETH on the ZKsync Era network, and 776 ETH worth nearly $1.4m were transferred to the Security Council’s Ethereum address. The transfers were executed within 15 minutes. This quick compliance, coupled with the precision of the exploit, has prompted discussions within the crypto security community about whether the breach was opportunistic or strategically planned.

Vulnerability Exploited in Airdrop Function

The attack took advantage of a weak spot in the codepack contract’s function called sweepUnclaimed(), which is used to claim tokens without an owner. Thus, when the attacker received the admin document, he could mint new ZK tokens out of the unclaimed reserve fund for participants of an airdrop. These tokens were transferred through Ethereum and the zk-sync layer 2 solution.

Based on the revelations from the ZKsync team, only three contracts associated with the airdrop were affected. Core protocol systems, the decentralised governance mechanisms relating to the project and affiliates, and user funds were not impacted. Moreover, Matter Labs, the company behind ZKsync, said that more tokens cannot be created because of caps in the distribution smart contracts.

Emergency Measures and Governance Oversight

Reacting to the event, Matter Labs introduced interim transaction filtering on the ZKsync Era network. This aimed to block addresses linked to the exploit, a step made possible because the network is still in its Stage 0 governance phase.

However, these filters are not permanent and can be removed by future governance decisions. The stated assets have been returned to the ZKsync Security Council for safekeeping. Based on community governance procedures, the way in which the returned funds will be utilized or further distributed will be decided. Additionally, ZKsync emphasized in an official update that “all user funds are safe and have never been at risk,” reiterating that the core ZK token contract and protocol remained secure throughout the incident.

Breach Adds to Record-Setting Quarter for Hacks

The ZKsync event added to the rising number of cryptocurrency attacks in 2025. Immunefi, a blockchain security company, indicated that Q1 2025 was the worst quarter of hacks, with losses of $1.63 billion and 39 attacks.
Two exchanges, Phemex, which lost $69.1M, and Bybit, which lost $1.46 billion, were major hits. Two threats were attributed to the North Korean Lazarus Group, which emerged as the biggest threat in the first quarter, with over 94% loss.

You May Also Like

Missouri Set to Become First State to Eliminate Capital Gains Tax

Missouri’s bill exempts capital gains from taxes, aiming to attract crypto investments.The tax exemption might cost the state over $430 million in the first year.Lawmakers hope the reform will...

Here’s Why Solana (SOL) Could Be Set For A Massive Surge

Robinhood may soon bring Wall Street to the blockchain for its EU users, with plans to introduce tokenized versions of U.S. stocks.This way, instead of having to buy equities...

Astar Network Unveils Tokenomics 3.0 with Fixed Supply and Fee Burn

Astar shifts to fixed supply Tokenomics 3.0, capping ASTR at 10.5B and using exponential decay to gradually reduce emissions.50% of Astar network fees will be burned permanently, adding long-term...

Coinbase Users Duped in $45M Scam—Is Your Wallet Next?

Over $45M was stolen from Coinbase users in one week through impersonation scams.Scam kits mimicking Coinbase tools are sold on Telegram, enabling widespread fraud.ZachXBT estimates $300M in yearly losses...
Peter Mwangi
Peter Mwangi
Peter Mwangi is a skilled crypto writer and expert in blockchain technology, digital assets, and decentralized finance. He has a talent for translating complex concepts into engaging informative content. With a deep understanding of the industry, Peter delivers accurate analysis that appeals to beginners and seasoned enthusiasts.

Subscribe To Our Weekly Picks!

- Join over 76,000+ subscribers

- Weekly picks delivered to your email

- It's free to subscribe!

Latest Altcoin News

SPONSORED ADVERTISEMENTspot_img

Latest News Stories

Wellgistics Bets $50M on XRP to Revolutionize Healthcare Pay

Wellgistics Health will use a $50M credit line to integrate XRP for faster, low-cost...

Senators Probe Trump-Binance Ties—Demand Answers from Treasury, DOJ

Democratic senators pressed Treasury and Justice to probe Trump family's financial links with Binance.A...

SEC Ends Legal Battle With Ripple in $50 Million Settlement

Ripple and the SEC agreed to settle their XRP lawsuit with $50 million payment...

Missouri Set to Become First State to Eliminate Capital Gains Tax

Missouri’s bill exempts capital gains from taxes, aiming to attract crypto investments.The tax exemption...

Celebrity Liability in FTX Collapse—Did They Really Know the Risks?

A Florida judge dismissed most claims against celebrities like Tom Brady and Stephen Curry,...