VERDICT —OUT OF SCOPE
Root cause is phishing — victims signed malicious transactions or approvals off-protocol. Contract logic was not the failure surface; user-side wallet hygiene was. Pre-deployment audit cannot catch this class.
▰ METHOD
PHISHING
PHISHING
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
ZK Rollup Order Book DEX Protocol ZigZag tweeted, "Our Discord has been hacked, please note that there is no airdrop activity at ZigZag at this time, please do not click on phishing links. We are working to resolve this issue and will provide an update when control is regained." Attack method (per SlowMist): Account Compromise. Reported loss: -.
Sourced from
slowmist
Technical record
- chain
- —
- protocol
- ZigZag
- bug_class
- phishing
- date_occurred
- 2023-06-27
- loss_usd
- —
- source_id
- sm:zigzag::2023-06-27
Related — same bug class· phishing