ZKsync: Attackers illegally minted about 111 million ZK tokens from three airdrop contracts, accounting for about 0.45% of the total supply

Reprinted from panewslab
04/15/2025·7DPANews reported on April 15 that according to the official update of ZKsync, the investigation showed that the administrator address of the airdrop contract (0x8428…587D) was compromised. The attacker called the sweepUnclaimed() function to illegally mint about 111 million ZK tokens from three airdrop contracts, accounting for about 0.45% of the total supply. The incident is limited to airdrop distribution contracts, and the ZKsync protocol, its token contracts, governance contracts and authorized minting parties are not affected. Most of the funds are still in the attacker's address, and the team is coordinating with SEAL organizations and exchanges to track and encourage the attacker to return the funds.