fwiw, presumably because of the exploit, ZKsync Era has added an unverified "TransactionFilterer" contract that can censor forced transactions from L1, without any onchain approval from the Security Council. This is one of the main reason ZKsync Era is currently not Stage 1
Update: further investigation has confirmed yesterdayโs findings that the compromise was contained to the airdrop distribution contracts and no additional ZK tokens can be minted from this contract.
User funds are secure and were never at risk. The ZKsync protocol, ZK token contract, all three governance contracts, and all active Token Program capped minters are not impacted by this incident.
The investigation and recovery efforts are on-going. We will share material updates as we have them, and will have a comprehensive incident report to share with the community once the investigation is fully completed.