ZKsync Urgent Alert: Hackers Post False SEC Probe to Crash ZK Token

Crypto community members were met with an urgent alert early on May 13 when the official X accounts for the Ethereum layer 2 network ZKsync and its developer, Matter Labs, were compromised. This significant crypto hack involved attackers posting misleading information, including a fabricated claim about a U.S. regulatory investigation, in what appeared to be a deliberate effort to manipulate the market.
The ZKsync and Matter Labs X Account Breach
The compromise of the ZKsync and Matter Labs X accounts occurred simultaneously, leading to the dissemination of false and potentially harmful messages. Users were quickly warned by other ZKsync-related accounts and community members not to interact with the compromised profiles, as they were sharing links to a fake airdrop, indicative of a phishing scam attempt.
The attackers posted a false statement asserting that ZKsync was under investigation by the U.S. Securities and Exchange Commission (SEC) and that the Treasury Department might impose sanctions. This was swiftly debunked by Matter Labs communications head, Lynnette Nolan, who confirmed the post was “not legit” and that both accounts were back under team control.
Commenting on the incident, Harrison Leggio, co-founder of crypto startup g8keep, humorously noted the hackers’ approach: “Shoutout to the zksync hackers. Instead of dropping a token and stealing a few bucks they decided to scare the living shit out of onchain degens.”
False SEC Probe Claims Aimed at ZK Token Price
The primary goal behind the false claims, particularly the fabricated SEC probe, seemed to be market manipulation. By spreading fear and uncertainty regarding regulatory action, the attackers likely intended to cause a sharp decline in the price of the platform’s native asset, the ZK token.
While the SEC has indeed investigated various crypto companies in the past, and some firms have chosen to disclose such probes publicly, the claim made via the hacked ZKsync account was entirely false. This tactic highlights the vulnerability of even prominent crypto projects to social media manipulation.
Following the hack announcement and the spread of the false information, the ZK token experienced a price drop. According to CoinGecko data, the token fell around 2% in the hour following the X account breach. Over the last 24 hours, ZK was down approximately 6.4%, trading around 7 cents, cooling off from a recent rally.
Previous Incidents: Another Crypto Hack
This social media compromise is not the first security incident impacting ZKsync-controlled platforms recently. It follows another crypto hack that occurred just a month prior, on April 15.
In the April incident, an attacker breached the admin account of ZKsync’s airdrop distribution contract. Using this access, the attacker minted 111 million unclaimed ZK tokens, valued at roughly $5 million at the time. This exploit took place during the platform’s distribution of 17.5% of the total ZK supply to ecosystem participants.
Fortunately, the outcome of the April hack was less severe than it could have been. The attacker later returned 90% of the stolen tokens, agreeing to keep 10% as a bounty, effectively acting as a white-hat security researcher.
Response and Investigation
Matter Labs confirmed they are investigating how the X accounts were breached. Initial assessments suggest the compromise may have occurred via “compromised delegated accounts,” which grant limited posting access to an X account without requiring full login credentials.
These incidents underscore the ongoing security challenges faced by crypto projects, ranging from smart contract vulnerabilities to social media account compromises. Maintaining robust security practices across all platforms is crucial for protecting both the project’s assets and its community from scams and manipulation attempts targeting the ZK token and other assets.
Summary
The recent crypto hack targeting the ZKsync and Matter Labs X accounts served as a stark reminder of the digital risks in the crypto space. Attackers posted false information, including a fabricated SEC probe claim, seemingly to trigger panic and lower the ZK token price. While the accounts were quickly recovered and the claims debunked, the incident caused temporary market impact and highlighted vulnerabilities. Coupled with a previous airdrop contract exploit, these events emphasize the critical need for continuous security vigilance by projects like ZKsync and Matter Labs to protect their platforms and users.