CryptoReal
CASE FILE — Apr 27, 2023

zkSync's First Rug Pull Reopens the Debate Over Paid Audits

Roughly $1.8 million vanished from Merlin, a decentralized exchange built on the newly launched zkSync L2, in what looks like a straightforward rug pull.

The project was three days into a "Liquidity Generation Event" tied to the launch of its MAGE token when the incident occurred. A community member first flagged suspicious activity, and PeckShield subsequently amplified the warning. Merlin then confirmed the exploit and urged users to revoke contract permissions.

This Merlin should not be confused with Merlin Labs, the BSC lending project that landed on the rekt leaderboard three separate times during the Spring 2021 exploit wave (see the first, second, and third incidents). Notably, this Merlin had cleared its second audit from CertiK just two days prior to the attack.

On the surface, this reads like a familiar rug-pull story. What makes it noteworthy is the argument it has reignited over the reliability of certain audit practices.

Per analysis credited to BeosinAlert, the mechanism was simple: liquidity pools that users were funding as part of the MAGE sale were drained outright. This was possible because the pools had granted maximum token approvals to a "Feeto" address at deployment. Whoever controlled that address was able to empty the pools of all deposited assets and route them toward ETH.

Merlin's own post-mortem pins responsibility on its back-end development team, going as far as linking to the developers' GitHub profiles and stating that Serbian authorities have been notified.

The drained funds landed in a single address on zkSync: 0x2744d62a1e9ab975f4d77fe52e16206464ea79b7. From there, they were bridged back to Ethereum, converted to ETH, and dispersed to additional wallets. Beosin's complete write-up contains further address-level detail.

This marks the first reported security incident on zkSync, the zero-knowledge Ethereum rollup that went live on mainnet in March 2023 — and it didn't take long for someone to target the fledgling network. Earlier that same month, zkSync's own Twitter account had already survived a close call after being targeted in what looked like a phishing attempt.

As new ecosystems attract capital and attention, opportunists tend to follow close behind, and rushed, low-effort launches make easy targets for both rug-pullers and hackers hunting for weak code.

An audit from a credible security firm is normally treated as a reassuring signal for prospective depositors. But the Merlin case raises the question of what "credible" really means when a firm's logo shows up on project after project that ends up rekt.

The same day this newly-audited project was drained, CertiK's founder publicly touted the sheer volume of low-cost audits the firm performs. Given how many CertiK-reviewed protocols have wound up compromised, the firm's value proposition is increasingly being questioned.

To be fair, CertiK's original audit had flagged the centralization risk, noting:

We advise the client to carefully manage the privileged account's private key to avoid any potential risks of being hacked. In general, we strongly recommend centralized privileges or roles in the protocol be improved via a decentralized mechanism or smart-contract-based accounts with enhanced security practices, e.g., multisignature wallets.

Despite this, CertiK marked the finding as "Resolved" once the Merlin team said it would adopt a multisig. Whether or not depositors read the fine print, many clearly proceeded without weighing what that unresolved trust assumption meant for their funds.

Adding to the pressure, allegations have surfaced that the contract contained a deliberate backdoor. CertiK is now floating the idea of a "community compensation plan" to offset user losses.

The broader lesson: a rushed audit shouldn't be mistaken for a guarantee, particularly for protocols handling millions in user deposits — and users bear some responsibility for evaluating risk themselves. Rug-pullers will keep doing what rug-pullers do.

Plenty of protocols carry centralization risks that could enable a rug pull, yet these warnings are routinely brushed aside by yield-chasers and airdrop hunters eager to ape in. The question of where accountability ultimately falls remains open.

MerlinRugpullzksync
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.