ZKsync: The leaked key does not control other contracts and has limited impact. Transaction filtering will remain effective until the event is resolved

PANews
PANews|Apr 21, 2025 15:27
ZKsync releases update on investigation progress, mitigation measures, and follow-up actions regarding last week's security incident: The investigation shows that the incident was triggered by a leaked airdrop administrator key and only affected three specific Merkle distribution contracts in the June 2024 ZK token issuance. As the total supply of each distribution contract has already been minted, it is not possible to mint additional ZK tokens or further utilize them through this method. The leaked key does not control other contracts, and only unclaimed airdrop tokens can be minted after the claim window expires. The ZKsync protocol, ZK token contract, governance contract, time lock, and active token plan cap minters are not affected and will not be affected in the future. About 70% of the utilized assets are still in ZKsync Era, including approximately 45 million ZKs and 1021 ETH. As the current only sorter on the Era chain, Matter Labs implements transaction filtering on affected accounts. Although Matter Labs is typically unable to address every potential event of a smart contract, after consultation with the ZKsync Association, this special measure has been taken due to protocol governance involved in unauthorized minting of ZK tokens. Currently, ZKsync is being upgraded to Phase 1 and promoting decentralized sorting, while Era is still running as Phase 0 rollup, making this measure feasible. It should be noted that the ZKsync governance body and security committee may replace the sorter and remove filters at any time. Transaction filtering will continue until the event is resolved. The investigation is still ongoing and efforts are being made to recover funds. After the incident is completely resolved, a detailed report will be released. Previously, ZKsync stated that attackers illegally minted approximately 111 million ZK tokens from three airdrop contracts, accounting for about 0.45% of the total supply.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads