zkSync Airdrop Eligibility, Distribution, and Smart Contract Breach
Summary
The document explains the zkSync token airdrop, including its stated allocation, eligibility signals, snapshot date, and claim period. Eligibility was tied to activity on zkSync Era or Lite, such as interacting with contracts, using paymasters, trading tokens, providing liquidity, or holding a specified NFT. It also describes claiming through a portal and delegating voting power as part of the process.
The article then recounts an April 2025 breach in which a compromised administrator key was reportedly used to mint unclaimed tokens through an airdrop contract function. It says the incident was isolated from user funds and the main protocol, while the token price temporarily fell. These details highlight operational risks in token distribution contracts and privileged key management. The account offers no audit or forensic material, so the reported attack mechanism and market response should be treated as claims in the document rather than independently established findings.
Key ideas
- Airdrop eligibility was based on several forms of past activity across zkSync networks and applications.
- The claim process included wallet verification, a transaction, and optional governance delegation.
- The document reports that a compromised administrator key enabled unauthorized minting from the airdrop contracts.
- It says the breach did not affect user funds or the main protocol.
- The incident illustrates the security risks of privileged keys and token distribution contracts.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.