zksync crypto scam

The debut of the crypto ZK, the new governance token of the ZKsync ecosystem, was not all roses and flowers: in the midst of one of the most anticipated airdrops in history, there were also many cases of scam.

First among all on X who, falsely impersonating the ZKsync team, invited to click on malicious dapp links resulting in the draining of users’ wallets.

There have been various complaints from users and protocols about a poorly decentralized launch, which benefited only a few.

All the details below.

ZK crypto listing: the token of ZKsync is inaugurated in the midst of a wave of scam 

The launch of the much-anticipated token of the ZKsync blockchain, namely ZK, was not free from the fictitious presence of crypto scam on the X platform.

Usually, when a new resource is launched in the crypto sector with a lot of enthusiasm, scammers thrive to try to attract naive or distracted users with the aim of robbing them with phishing, malware, and malicious dApp links.

After the announcement of the checker for the airdrop of ZK on Tuesday, June 11, the number of scams began to multiply, with several X accounts falsely impersonating the ZKsync team, waiting for some bull to pluck.

In particular, from that day, the Web3 security company Blockaid recorded a dramatic increase in the volume of malicious dApps targeting ZKsync, up to a 5-fold increase on the day of the crypto listing.

In this regard, the CEO of Blockaid  Ido Ben-Natan explained in a recent interview how these scams are set up and how they lead to the draining of users’ wallets, emphasizing that:

“The scams we are witnessing are impersonation scams: malicious dApps that use the ZK brand to trick users into signing malicious transactions. These malicious dApps use draining SDKs to mitigate detection and reach users”

Often this kind of scams use X profiles with a significant number of followers, with the same nickname/photo as the official ZKsync account, and with a similar “@”, in order to resemble the real entity as much as possible.

Generally then, they comment under the posts of real accounts (such as that of ZKsync) with posts increasingly crafted to perfection and with malicious links in plain sight, exploiting the potential inattention of users who might be deceived.

The same ZKNation, the governance section of the project, has admitted the high number of scams and the presence of individuals posing as insiders.

The attackers have taken advantage, and are still taking advantage of the FOMO for the launch of ZK, attracting users to malicious dApps.

Correction from the team: the addresses exist on the developer list, which is changing dynamically as devs are binding addresses.

They do not belong to ZKsync. Google them, you'll see.

Apologies to all. Intern needs to sleep.

Full details are coming. https://t.co/7ySrTqAjWE

— ZK Nation (@TheZKNation) June 12, 2024

Throughout all this, shortly before the launch, the ZKsync team observed a high load of requests and inefficient performance in some remote procedure call (RPC) services, contributing to creating confusion amidst the proliferation of scams.

The RPC are elements of the architecture of a blockchain that communicate with the nodes and execute the network operations requested by the users.

The team at the time of the inauguration of the crypto ZK, explained that the entire staff was working to increase the RPC capabilities, inviting to “stay tuned for updates.

Now the congestion seems to have passed.

(1/2) The network is currently under high load. Some RPC services may experience degraded performance.

Teams are working to increase RPC capacities.

Stay tuned for updates.

— ZKsync (∎, ∆) (@zksync) June 17, 2024

A very discussed launch: ZKsync receives many criticisms from the community

Along with scams and technical issues, the listing of the ZK crypto on all the largest first-tier exchanges such as Binance, Bybit and Bitget was accompanied by a shitstorm of criticism from some of the same users/protocols of the ZKsync ecosystem, more precisely from those who received the airdrop.

Bringing here some examples we can mention the memecoin zkPEPE, which despite being natively developed on ZKsync and despite including the acronym “zk” in its own ticker, decided to rebrand to “ArbPEPE” and migrate to the Arbitrum chain after discovering it had not received any tokens as an incentive.

It is clear that this is a passive attitude towards the crypto environment and totally inadequate for the context.

📢 ZKPEPE is moving from @zkSync to @arbitrum and will airdrop to all $ZKPEPE and $ARB holders!

ZKPEPE was launched in Nov 2023 during a market downturn. Many #zkSync users were reluctant to pay gas fees, leading to decreased activity in the zkSync eco. To encourage continued… pic.twitter.com/bvredSc4fy

— ArbPEPE (💙,🧡) | Airdrop Soon (@arbpepereal) June 14, 2024

Another protocol that complained about the airdrop distribution being a little “fairby the ZKsync team is the lending platform ZeroLend, which in a post on X explained how it was unfair not to reward a dapp that represents a cornerstone in the TVL of the chain. 

La ZKNation ha commentato dicendo di apprezzare il feedback, seppur negativo, ricordando però che ZeroLend ha scelto il competitor Linea per lanciare la propria crypto “ZERO” e dunque non dovrebbe lamentarsi se non è stata ricompensata con un’allocazione da airdrop.

On June 11th, 2024, @zkSync / @TheZKNation revealed the list of protocols eligible for developer incentives. ZeroLend, the largest lending protocol and the second-largest dApp at the time of the snapshot was omitted from this list.



ZeroLend’s contribution to zkSync Era from… pic.twitter.com/GBESPMktgv

— ZeroLend (@zerolendxyz) June 17, 2024

Many other users have shouted SCAM, using the hashtag #zkscam,  highlighting a token distribution that favored insiders and the team at the expense of the community. 

Even in this case, we are talking about simple “whims” advanced solely and exclusively by those who have not received any ZK tokens, as they were probably identified as sybil and because they are not very active and have little balance on the ZKsync chain.

Always be careful to understand the motivations that drive an individual to criticize a crypto project: many users were indeed satisfied with the airdrop, in these circumstances it is statistically impossible to please everyone.

🚨 SCAM ALERT 🚨$ZK token was distributed to insiders and team wallets. There's presumably a money laundering scheme involved, DYOR before interacting with the token!

See the proofs below, find more by searching #zkscamhttps://t.co/3z9IPgtlighttps://t.co/rJgEHr5PXb pic.twitter.com/lbGk711Uou

— 0xNobler (@CryptoNobler) June 15, 2024

A much more concrete problem, for which it would be appropriate to find an adequate solution, is the excessive centralization reached by the DEX Syncswap in the governance of ZKsync, having obtained delegations for about 25% of the ZK available on the market.

A possible solution is to invite users who have indicated Syncswap as the subject for the formal decisions of the project, to re-delegate their vote to themselves or to other cryptographic entities.

🚨 URGENT 🚨

It has come to our attention that @syncswap now controls 25% of the delegation pool, which is EXTREMELY alarming. @syncswap has been untrustworthy from the very beginning. They have consistently aimed to see other projects decline just to boost their success.… https://t.co/weARiiDCWv pic.twitter.com/uxQxFIHU1Z

— It's me, Zorro (∎, ∆) (@zkzorro) June 17, 2024

In the meantime ZK loses about 23% since the launch, with over 40% of the wallets holding the airdrop having already sold all their crypto stocks (data from Nansen), opening up a possible scenario of price recovery in the coming days.