ZKsync hack — April 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 15, 2025 |
| Target type | Blockchain or validator set |
| Loss | $5,000,000Price at time of incident |
| Method | Private key compromiseAn attacker in possession of the private key to a 1/1 multisig admin address (0x842822c797049269A3c29464221995C56da5587D) called sweepUnclaimed() on three ZK token Merkle distributor contracts left over from the June 2024 airdrop, minting 111,881,122 unclaimed ZK tokens to an address they controlled. ZKsync said the key had been generated by a former contributor and that it found no evidence of malicious intent by that person; how the key was obtained has not been disclosed. |
| Chains | Other, Ethereum |
| Outcome | Settled as bug bounty |
What happened
On 13 April 2025 at 12:32 UTC an attacker holding a compromised administrative key called sweepUnclaimed() on three Merkle distributor contracts left over from ZKsync's June 2024 ZK token airdrop, minting 111,881,122 ZK tokens to an address they controlled. ZKsync's own incident report values the mint at approximately $5 million at the moment of the transaction. The key belonged to a 1/1 multisig, which retained the right to sweep tokens airdrop recipients had never claimed. ZKsync said the investigation found that the key had been generated by a former contributor and that no evidence of malicious intent on that person's part was found; it has not said how the key was obtained. Between 13 and 15 April the attacker swapped about 67.2 million ZK for ETH and moved roughly 1,116 ETH to Ethereum mainnet. Matter Labs engineers established the scope on the morning of 15 April and the incident was disclosed the same day. ZKsync stated that the ZKsync protocol, the ZK token contract, the three governance contracts and all active capped minters were unaffected and that no user funds were ever at risk, the loss falling on unclaimed airdrop supply. The ZK token fell 8.6% over the following 24 hours. On 21 April at 15:03 UTC the ZKsync Security Council posted an on-chain safe-harbour offer: return 90% of the proceeds within 72 hours and keep 10%. The attacker accepted and returned 90% on 23 April at 14:39 UTC. The recovered assets are held by the Security Council pending a governance decision. The attacker has not been identified.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0x842822c797049269A3c29464221995C56da5587D
Sources
- ZKsyncPrimary · retrieved 2026-08-01
- CryptoSlateSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
Official post-mortem: https://www.zksync.io/blog/incident-report-compromised-admin-key
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "ZKsync hack — April 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/zksynchttps://itokenly.com/hacks/zksyncPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.