Ethereum Layer-2 ZKsync Suffers Exploit As $5,000,000 in ZK Tokens Drained
Ethereum (ETH) Layer-2 scaling solution ZKsync (ZK) has suffered a significant exploit, resulting in the loss of $5 million worth of ZK tokens. The breach, which targeted the platform’s smart contract infrastructure, has been acknowledged by the protocol through a post to the social media platform X. “ZKsync security team has identified a compromised admin account that took control of ~$5M worth of ZK tokens – the remaining unclaimed tokens from the ZKsync airdrop. Necessary security measures are being taken. All user funds are safe and have never been at risk. The ZKsync protocol and ZK token contract remained secure, and no further ZK is at risk. This is an isolated incident caused by a compromised key and confined to the ZK Token airdrop contract. The investigation is ongoing, and a detailed update will be shared later today.” The attack, reportedly executed through a sophisticated vulnerability in ZKsync’s zero-knowledge proof mechan...