A hacker compromised a ZKsync admin account on April 15, minting $5 million worth of unclaimed airdrop tokens, according to a statement from the official ZKsync X account. The attack was described as isolated, with no user funds affected.

Following an investigation, ZKsync detailed the incident on April 15, disclosing that the compromised account had administrative control over three airdrop distribution contracts. The attacker exploited a function called sweepUnclaimed() to mint 111 million unclaimed ZK tokens, increasing the total token supply by 0.45%. As of the latest update, the attacker still held control of most of the stolen funds.

Source: ZKsync

ZKsync is coordinating recovery efforts with the Security Alliance (SEAL). According to the protocol, its governance and token contracts are unaffected. The company stated that no further exploits are possible

Read More at https://cointelegraph.com/news/zksync-hacker-steals-5m-airdrop-tokens?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound