Post
Replies
This incident also highlights the risks of centralized administrator privileges in an originally decentralized system. Strong account access control is as important as smart contract security itself. The security of administrator keys will also seriously affect the security of crypto projects and should not be discussed separately.
Technologies such as ZK verification have always been touted as having better security than optimistic proofs, and were once considered the final technical form of Ethereum L2, which is Endgame. However, although the token theft did not involve the core project tokens, the protection measures for the airdrop distribution contract are too weak, as if the walls of an advanced high-tech building are still filled with straw used to build houses in ancient times.
When faced with the community's question of why it did not foresee this attack as one of the leaders in the ZK field, the founder of ZKsync responded shamelessly that it was impossible to foresee a black swan. The theft of permission account keys is the most common attack method for blockchain projects, just like the phishing that users face every day. ZKsync did not strengthen protection security measures in advance and defined everything as a black swan, which also reflects the team's weak security awareness.
ZKsync is heading towards Endgame. This is not the perfect ending after the superhero defeats the boss in the movie, but the black screen ending in the game where the player is killed because of being too bad. But before being completely killed, I hope ZKsync can save the investors who are stuck.