{"id":23489,"date":"2025-04-24T05:01:34","date_gmt":"2025-04-24T05:01:34","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=23489"},"modified":"2025-04-24T05:01:34","modified_gmt":"2025-04-24T05:01:34","slug":"zksync-recovers-5m-of-stolen-tokens-after-hacker-accepts-bounty-offer","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=23489","title":{"rendered":"ZKsync recovers $5M of stolen tokens after hacker accepts bounty offer"},"content":{"rendered":"<div>\n<p style=\"float:right; margin:0 0 10px 15px; width:240px;\"><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDQvMDE5NjY1ODctYTRiMy03Yjk3LTlkYTEtN2M2NTAyZDRmYWFl.jpg\"><\/p>\n<\/p>\n<p style=\"float:right; margin:0 0 10px 15px; width:240px;\"><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDQvMDE5NjY1ODctYTRiMy03Yjk3LTlkYTEtN2M2NTAyZDRmYWFl.jpg\" alt=\"ZKsync recovers $5M of stolen tokens after hacker accepts bounty offer\"><\/p>\n<p>The ZKsync Association has confirmed the recovery of $5 million worth of stolen tokens from an April 15 ZKsync security incident involving its airdrop distribution contract.<\/p>\n<p>The hacker agreed to accept a 10% bounty and return 90% of the remaining stolen tokens, transferring the ZKsync Security Council almost $5.7 million across three transfers on April 23.<\/p>\n<p>\u201cWe\u2019re pleased to share that the hacker has cooperated and returned the funds within the safe harbor deadline,\u201d ZKsync Association <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/TheZKNation\/status\/1915110305790660939\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">posted<\/a> to X on April 23, which was later <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/zksync\/status\/1915111545417224572\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">reposted<\/a> by ZKsync\u2019s X account.<\/p>\n<p>Matter Labs, the company behind the ZKsync protocol, also <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/zksync\/status\/1915111545417224572\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">reposted<\/a> the news shared on X.<\/p>\n<p>The ZKsync X account previously confirmed that <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/zksync-hacker-steals-5m-airdrop-tokens\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">no user funds were compromised.<\/a><\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-04\/01966613-c5e7-7524-a44e-6e7abb85b72b\" title=\"\" alt=\"ZKsync recovers $5M of stolen tokens after hacker accepts bounty offer\"><figcaption style=\"text-align: center;\"><em>Source: <\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/TheZKNation\/status\/1915110305790660939\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\"><em>ZKsync Association<\/em><\/a><br \/><\/figcaption><\/figure>\n<p>The hacker <a data-ct-non-breakable=\"null\" href=\"https:\/\/explorer.zksync.io\/address\/0xfFB6126FF8401665081b771bB11cCD0e09f95D5A#transfers\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">sent<\/a> two transfers on the ZKsync Era blockchain, consisting of $2.47 million worth of ZKsync (<a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/zksync-price-index\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">ZK<\/a>) tokens and $1.83 million worth of Ether (<a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/ethereum-price\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">ETH<\/a>) to the ZKsync Security Council\u2019s ZKsync Era address.<\/p>\n<p>Another 776 ETH worth nearly $1.4 million was also sent to their security council\u2019s Ethereum address, Etherscan <a data-ct-non-breakable=\"null\" href=\"https:\/\/etherscan.io\/tx\/0xa344a0e759652246e51b1def91c8081b3527bdbbcab92128100f8fbc11c204df\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">data<\/a> shows.<\/p>\n<p>The first transfer was made on April 23 at 2:39:57 pm UTC on and the last transfer was made roughly 13 minutes later \u2014 all within the 72-hour window that ZK Sync had initially set.<\/p>\n<p>ZKsync Association said the company would publish a final report revealing more details from the security incident.<\/p>\n<h2>How the hack happened<\/h2>\n<p>The hacker breached <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/zksync-liquidity-program-ignite-sunset-march-17\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">ZKsync\u2019s admin account,<\/a> allowing them to exploit the airdrop distribution contract&#8217;s sweepUnclaimed() function to mint 111 million unclaimed ZK tokens, worth approximately $5 million at the time of the April 15 attack.<\/p>\n<p>The hack occurred while ZKsync was in the <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/zksync-token-airdrop-criticism-sybil-vulnerabilities\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">process of airdropping<\/a> 17.5% of ZK\u2019s token supply to ecosystem participants.<\/p>\n<p>The recovered amount \u2014 almost $5.7 million \u2014 exceeded the $5 million originally stolen due to a rise in the market value of the stolen tokens, with ZK and ETH increasing 16.6% and 8.8% respectively since the April 15 attack, <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.coingecko.com\/\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">according<\/a> to CoinGecko data.<\/p>\n<p>Despite the asset recovery, the ZK token failed to rise substantially on the news and is currently down 0.2% over the last 24 hours.<\/p>\n<p><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/zksync-2025-roadmap-scalable-blockchain-privacy-tech\" rel=\"null\" target=\"null\" text=\"null\" title=\"https:\/\/cointelegraph.com\/news\/zksync-2025-roadmap-scalable-blockchain-privacy-tech\">ZKsync Era<\/a> is an <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/explained\/block-size-and-scalability-explained\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">Ethereum layer 2<\/a> solution that uses zero-knowledge rollups to batch and process transactions offchain. It has nearly $59 million in total value locked on its chain and has over $2 billion in real-world assets onchain, <a data-ct-non-breakable=\"null\" href=\"https:\/\/defillama.com\/chain\/zkSync%20Era\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">according<\/a> to DefiLlama and <a data-ct-non-breakable=\"null\" href=\"https:\/\/app.rwa.xyz\/networks\" rel=\"nofollow noopener\" target=\"_blank\" text=\"null\" title=\"https:\/\/app.rwa.xyz\/networks\">RWA.xyz<\/a>.<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/magazine\/ethereum-maxis-should-become-assholes-to-win-tradfi-tokenization-race\/\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\"><em><strong>Ethereum maxis should become \u2018assholes\u2019 to win TradFi tokenization race<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\" label=\"Subscription Form: Markets Outlook\"><\/template>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The ZKsync Association has confirmed the recovery of $5 million worth of stolen tokens from an April 15 ZKsync security incident involving its airdrop distribution contract. The hacker agreed to accept a 10% bounty and return 90% of the remaining stolen tokens, transferring the ZKsync Security Council almost $5.7 million across three transfers on April [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-23489","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/23489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23489"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/23489\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}