A hacker has returned nearly $5 million worth of stolen cryptocurrency to ZKsync after accepting a 10% bounty under a safe harbor agreement. The incident, which involved a compromised airdrop contract, has been resolved, marking a rare success in the often tumultuous world of crypto security.
Key Takeaways
-
The hacker returned approximately $5 million in stolen assets after accepting a 10% bounty.
-
The exploit occurred on April 15, 2025, due to a compromised admin key.
-
ZKsync's Security Council now holds the recovered tokens, with governance to decide their fate.
-
The incident highlights ongoing security challenges in the cryptocurrency sector.
Overview Of The Incident
On April 15, 2025, ZKsync, a layer-2 blockchain protocol, experienced a significant security breach when a hacker exploited a compromised admin key. This breach allowed the attacker to mint approximately 111 million ZK tokens from unclaimed airdrop reserves, valued at around $5 million. Fortunately, the core protocol systems and user funds remained unaffected, ensuring that the broader ZKsync ecosystem was not compromised.
In response to the hack, ZKsync issued a message on April 21, offering the hacker a deal: return 90% of the stolen funds and keep 10% as a bounty. This approach aimed to incentivize the return of the assets without legal repercussions. The hacker accepted the offer and returned the funds within the stipulated 72-hour safe harbor period, which is a common practice in security incidents to encourage cooperation.
Recovery Process
The recovery of the stolen funds was executed in several transactions:
-
Total Recovered Amount: Approximately $5.7 million, exceeding the initial $5 million due to market fluctuations.
-
Breakdown of Recovered Assets:
-
ZK Tokens: 44.6 million ZK tokens
-
Ethereum (ETH): Nearly 1,800 ETH
-
-
Transfer Details:
-
The hacker made two transfers on the ZKsync Era blockchain and one on the Ethereum network, all within the 72-hour window.
-
Implications For The Crypto Sector
This incident underscores the ongoing security challenges faced by cryptocurrency platforms. Despite the successful recovery of funds, the event adds to the alarming statistics of crypto losses, with over $1.67 billion reported in the first quarter of 2025 alone. The ZKsync case is a notable exception in a landscape where many hacks go unresolved.
ZKsync has assured its users that all funds remain safe and that the core protocol and governance structures were not at risk during the exploit. The Security Council will now determine the next steps regarding the recovered assets, and a final investigation report is expected to be published soon.
Conclusion
The ZKsync incident serves as a reminder of the vulnerabilities that exist within the cryptocurrency ecosystem. While the return of the stolen funds is a positive outcome, it highlights the need for robust security measures and proactive responses to potential threats. As the crypto industry continues to evolve, the lessons learned from such incidents will be crucial in shaping future security protocols and governance strategies.
Sources
-
ZKsync Recovers $5M After Hacker Accepts Bounty, Cryptonews.
-
ZKSync recovers stolen funds after hacker accepts bounty, Crypto News.
-
ZKsync Hacker Accepts Bounty, Returns Nearly $5M in Stolen Crypto, Decrypt.
-
ZKsync recovers $5M of stolen tokens after hacker accepts bounty offer, Cointelegraph.
-
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
-