zERC20 suffers exploit on Polygon, 3.35 million JPYC drained
Privacy-focused token transfer protocol zERC20 reported an exploit on its Polygon-based zJPYC token, resulting in the unauthorized minting of 9.96 million tokens and the subsequent drainage of 3.35 million JPYC. The attacker leveraged a known vulnerability in the Nova cryptographic proof system combined with a configuration error that enabled a batch withdrawal function that should have been disabled. The stolen funds were converted to POL and moved across chains via the LI.FI protocol. zERC20 stated that the issue was specific to the deployment settings of zJPYC on Polygon and Kaia, and the protocol has committed to fully compensating affected users and implementing post-deployment audits.
Summaries are written by AI from the original article. Not investment advice.