An exploit on the $ZORA claim contract for 0xProject's allocation - $128K have been stolen


8 recorded changes
Want your article here?
Promote with Leviathan News

8 recorded changes
Want your article here?
Promote with Leviathan NewsAn attacker drained roughly $128,000 worth of ZORA tokens by abusing how the ZORA airdrop claim contract interacted with 0x Protocol’s infrastructure, specifically the 0x Settler contract, rather than by exploiting a low-level bug in either protocol. Zora’s community airdrop had assigned a token allocation meant for the 0x ecosystem to the 0x Settler contract address, which is a permissionless execution contract that anyone can call, instead of assigning it to a controlled 0x-owned address. On April 24, 2025, an attacker used Settler’s execute() function to trigger Zora’s claim logic and redirect the full ZORA allocation to their own address, then swapped and bridged the proceeds, ultimately extracting about $128,000 in assets. Security firm Blockaid initially flagged the incident as an exploit on the ZORA claim contract for 0x’s allocation and quantified the loss at around $128,000 in ZORA. Post-incident analysis by Blockaid and Three Sigma emphasized that no smart contract was technically “hacked”: both the ZORA claim contract and 0x Settler behaved according to their code, but Zora’s decision to allocate tokens to a permissionless contract created an opening for what is being framed as a “composability attack”. The case has become a reference example of how complex interactions between otherwise secure, permissionless DeFi components can introduce emergent risks in token airdrop design and onchain distribution mechanisms.
AI-generated background, compiled from web sources — not editorial content.

𝕏/@chainlink ·

𝕏/@coinage_media ·

finance.yahoo ·

youtu.be ·

CoinTelegraph ·

𝕏/@traders_insight ·

𝕏/@chainlink ·

𝕏/@coinage_media ·

finance.yahoo ·

youtu.be ·

CoinTelegraph ·

𝕏/@traders_insight ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?