ZKsync disclosed on April 15, 2025 that an attacker had compromised an administrative account connected to its airdrop infrastructure and taken control of ZK tokens the project valued at approximately $5 million.
The Ethereum layer-two project said the incident was confined to its token-airdrop contracts. Its event-day statements said the ZKsync protocol and ZK token contract were secure, user funds were not at risk and the affected tokens were the remaining unclaimed allocation from the project’s 2024 airdrop. ZKsync also said it was investigating with the Security Alliance and taking security measures.
Those were claims from the affected organizations during an active investigation, not an independent audit completed on April 15. Contemporaneous CoinDesk and The Block reports attributed the same scope and approximately $5 million estimate to ZKsync.
A privileged account became the attack surface
The incident mattered because it did not depend on defeating ZKsync’s zero-knowledge proofs or extracting deposits from the rollup. The attacker instead obtained privileged access associated with contracts created to distribute ZK tokens.
A later official investigation established that the unauthorized transaction occurred at 12:18 UTC on April 13, 2025. The compromised administrator invoked a function called `sweepUnclaimed()` across three Merkle-distributor contracts, minting 111,881,122 ZK tokens that had not been claimed during the original distribution period. The transaction is preserved in the ZKsync Era block explorer.
That distinction limits the technical scope but not the governance significance. An airdrop contract can sit outside a network’s core execution machinery while still retaining authority over economically meaningful token supply. The event demonstrated how a residual administrative permission could remain dangerous after the public-facing distribution had ended.
On April 15, ZKsync described the incident as isolated and said no further ZK could be minted through the affected path. The investigation was still developing, however, and the precise method used to obtain the administrative credential had not been established. The event-day record therefore supported confidence about the identified contracts more strongly than it supported any conclusion about who controlled the attacker address or how the key was compromised.
Disclosure followed community scrutiny
ZKsync’s later timeline recorded that community members had raised questions about unusual token movements on April 14. The issue was escalated to Matter Labs personnel early on April 15, and a joint investigation involving Matter Labs, the ZKsync Association and the ZKsync Foundation identified the affected distributor contracts that morning.
The first official public notice was posted at 13:49 UTC on April 15, followed by a second update at 15:25 UTC. That sequence is institutionally important: observable on-chain activity preceded the project’s public confirmation, illustrating both the value of open-ledger monitoring and the limits of relying exclusively on internal alerts.
No market-return calculation is included here. Contemporaneous publishers reported different percentage declines for ZK using different timestamps and price feeds, while the project’s approximately $5 million figure was a valuation at the initial unauthorized transaction rather than a guaranteed recovery value or a universal market price.
Later context: the configuration failure
ZKsync’s April 25 incident report attributed the compromise to a procedural failure that left the distributor administrator as a one-of-one multisignature account instead of transferring control to the intended governance structure. It said the distributor contracts had been assigned an insufficient risk classification and that related monitoring failed to alert correctly.
Those findings were not available when ZKsync first disclosed the incident on April 15. They clarify why a peripheral distribution system retained dangerous authority, but they must not be read as facts conclusively established in the initial announcement. The durable lesson from the April 15 record was narrower: protocol security depended not only on cryptographic validity, but also on the lifecycle management of privileged keys and contracts surrounding the protocol.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

