CryptoReal
CASE FILE — Jun 12, 2025

A Compromised Admin Key Drains $500K From Zunami Protocol — Its Fourth Exploit Since 2023

Zunami Protocol lost roughly $500,000 in collateral on May 14th after control over its admin privileges ended up in the wrong hands. Rather than a technically sophisticated attack, the incident amounted to someone with elevated contract access invoking a single emergency function and moving the funds out.

There was no flash loan, no price manipulation, and no intricate smart-contract exploit involved. Whoever held admin rights simply called withdrawStuckToken() and emptied the vault.

More than three weeks later, the project still hasn't given a clear account of what happened, leaving the community to wonder whether this was a genuine compromise or something closer to an inside job.

01How the news broke

Zunami itself was first to disclose the incident, posting that the protocol had been hacked and that collateral backing zunUSD and zunETH had been stolen, with an investigation underway.

Roughly an hour afterward, Vladimir S. identified the compromise, pointing to an admin key breach as funds moved toward Tornado Cash.

PeckShield then verified the loss at $500,000 in zunUSD and zunETH collateral.

Tony Ke raised the obvious question of whether this reflected a compromised private key or deliberate action by an insider, while SuplabsYi noted the irony of a leaked private key rendering the protocol's audits meaningless.

Curve founder Michael Egorov summed up the core issue: "What is worse, admin key existed!"

02Mechanics of the exploit

No clever code and no precise timing were required — just a single transaction from whoever controlled the admin role.

On May 14th, an admin role was granted in this transaction, issued by the Zunami Protocol Deployer wallet (0xe9b2B067eE106A6E518fB0552F3296d22b82b32B).

Seven minutes after that grant, the protocol was exploited. The attacking address (0x051370419b871f7c05dee8f7134401530832e250) executed the drain transaction (0xd7ce50992b36acbc746a821a74e5600230cfe5b36cfc155841581e376f4c14d2).

According to Dedaub's trace of that transaction, the attacker called withdrawStuckToken() on Zunami's UsdtCrvUsdStakeDaoCurve strategy — a function ostensibly meant to recover stuck assets. In practice, it transferred 296,456 LP tokens, the collateral underlying zunUSD and zunETH, directly to the attacker. No cryptographic exploit was needed; the attacker simply had the authority to request the funds, and the contract complied.

03Warning signs that preceded the hack

The May collapse did not emerge without warning. For at least three months before the exploit, there were no new commits to the public GitHub repository, suggesting development had effectively stalled while user funds remained deposited in active strategies.

Total value locked had also been declining steadily for months as yield incentives dried up. A Discord community member noted that Curve gauge rewards had dropped to zero just before the exploit occurred — a detail that, in hindsight, lined up conveniently with the timing of the attack.

Sums referenced in this case file

The team's initial reaction on Discord to the loss of half a million dollars was simply "rekt lmfao." Three weeks on, the team has still not provided further updates.

04A pattern going back to 2023

This was not Zunami's first brush with disaster. In 2023 alone, the protocol suffered three separate incidents.

On January 26, 2023, a routine transfer of funds was sandwiched in the mempool, costing the protocol $49,000.

About a month later, attackers exploited price discrepancies between Zunami's pools using flash loans — minting ZLP tokens cheaply and redeeming them at inflated valuations across thirteen separate transactions. Zunami's own Medium post put the combined toll of these two incidents at $260,000, with LP pricing mechanics and strategy design exposed as the underlying weaknesses.

The largest blow came in August 2023: a $2.1 million price-manipulation attack that Rekt covered at the time. Flash loans were used to drain the zETH and UZD liquidity pools on Curve, causing depegs of 85% and 99% respectively. The attacker manipulated LP prices through token swaps and ultimately funneled 1,184 ETH to Tornado Cash.

Across those three 2023 incidents, Zunami lost a combined $2.36 million. The team pledged improved security and compensation at the time. Two years later, a fourth exploit has occurred — this time attributed to an admin key compromise rather than a code-level vulnerability.

05The team's response

Roughly two weeks after the exploit, Zunami CEO Kirill Kozlov ("Sterx") finally commented publicly, stating: "We're investigating the exploit and considering both scenarios: a compromised deployer or malicious intent by the key holder."

CTO Mikhail Zelenin, known on Discord as MioGreen, offered a more elaborate account: he said his laptop had been examined by Russian border police for several hours, and that the protocol's source code — stored without encryption — had been on the device. He said cloning of his hard drive during that search was his only remaining hypothesis for how the compromise occurred.

He also acknowledged that the protocol's strategies had never been transferred to DAO governance as previously promised, attributing this to burnout and lack of resources: "Because of the absence of investment in the protocol, I was the only developer… I made simple mistakes."

A separate controversy followed after a Russian-language article claimed the CTO owned a Ferrari. Zelenin denied it: "I never had any Ferrari. And I don't have any right now. Cyprus police will easily clarify it, because I am here in the residential permit."

The community remained unconvinced. One Discord member responded bluntly: "You're either a thief or completely incompetent and responsible for the protocol getting hacked three times."

06Community backlash

Zunami's Discord became a venting ground as users compared notes on the timeline. One member laid out the case: "No commits in 3 months, TVL dropping for months, domain expired, rug happened hours after Curve gauge incentives dropped to 0%."

When pressed, the team responded defensively rather than transparently: "You're making direct accusations, and I'd like to ask you to be more careful." The user pushed back: "I'm not making direct accusations, I'm literally saying 'if it turns out to be'—but yeah, there is a high likelihood here."

By June, patience had run out. A team moderator issued an ultimatum: "I live in Thailand. If the founder doesn't make progress on this soon, I'm prepared to file a report with the Thai police myself." The stated deadline, June 13th, has since passed without any update from the founder.

07Where things stand

Three weeks after the exploit, Zunami has issued no post-mortem, no compensation plan, and no resolution on whether the admin key was compromised by an outside actor or misused internally. Half a million dollars moved into Tornado Cash, and outside of ongoing scrutiny from Vladimir S., PeckShield, Tony Ke, and SuplabsYi, the incident largely faded from broader attention.

Given the abandoned repository, the declining TVL, the incentive cutoff timed just before the exploit, and a team whose first public reaction was dismissive, the circumstances invite skepticism regardless of whether the root cause turns out to be negligence or intent. Either way, users are left holding losses while the party controlling the admin key remains unidentified.

Admin PrivilegesZunami Protocol
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.