This article is compiled and organized by BlockWeeks
ZKsync and LayerZero Airdrop Launches, Sybil Controversy Follows
The ZK token and LayerZero's ZRO token opened for claiming successively this week. On Monday, ZK-based L2 protocol ZKsync opened ZK token claims to eligible airdrop recipients. The development team behind ZKsync, Matter Labs, announced the airdrop criteria and tokenomics of the ZK token last week; the token will be used for future governance of the protocol.
The total supply of ZK is 21 billion tokens, of which 66.6% is allocated to the "community" and the rest to the "team and investors." At launch, 17.5% of the total supply will be distributed via a one-time airdrop to eligible users and contributors of the ZKsync protocol. The airdrop allocation is based on usage and calculated using "value scaling"—that is, based on the time-weighted average amount of capital contributed to the ecosystem (value held in wallets or locked in DeFi protocols). Nearly 700,000 addresses were eligible for the airdrop.
On Thursday morning, the ZRO token of LayerZero, an omnichain interoperability protocol, opened for claiming. According to the announcement blog, the ZRO supply is fixed at 1 billion tokens, of which 38.3% is allocated to the "community," 32.2% to "strategic partners," 25.5% to "core contributors," and the remaining 4% is repurchased and staked to the community. At launch, 8.5% of the ZRO supply is available for eligible participants to claim, totaling nearly 1.3 million wallets. ZRO airdrop claimants must pay 10 cents per ZRO to claim; the LayerZero team calls this a new claim mechanism called "Proof-of-Donation," which will donate up to approximately $18.5 million to the Protocol Guild to fund core development of Ethereum and its ecosystem.
Prior to this, expectations for the ZKsync and LayerZero airdrops had led to a large amount of Sybil activity on both protocols—individuals creating multiple addresses and frequently conducting low-value economic activity to obtain multiple airdrops. Matter Labs founder and CEO Alex Gluchowski said last week that the airdrop was designed in a way that "naturally prioritizes humans, putting real people first." Last month, the LayerZero team offered potential Sybil users the opportunity to self-report in exchange for 15% of their intended allocation.
As of press time, ZK is trading at about $0.20, corresponding to an FDV of about $4.2 billion; ZRO is trading at about $3.35, with an FDV of about $3.3 billion.
These two of the most anticipated airdrops in crypto have left many airdrop farmers both delighted and frustrated. ZKsync has been one of the most popular L2s by active addresses and transactions, leading all other L2s such as Arbitrum and Base in the first quarter of this year. Some of the activity was driven by LayerZero—as an omnichain protocol, LayerZero's farming activity has spread to ZKsync and multiple L1s and L2s (including Ethereum, Arbitrum, Base, Polygon, BNB Chain, and Avalanche). After the airdrop snapshot, activity on both ZKsync and LayerZero has declined.
When the airdrop details for ZK and ZRO were announced, many of the protocols' "real users" complained about being disqualified for not meeting the criteria. Satisfying everyone is extremely difficult; on the other hand, projects find it hard to attract usage without airdrop expectations, and this in turn attracts Sybil attackers. The development teams behind both protocols made thoughtful efforts to address Sybils: ZKsync's airdrop eligibility included conditions based on the amount of risk capital committed, while the LayerZero team gave Sybils the opportunity to self-report.
The main goal of most airdrops (aside from decentralized governance) should be to cultivate a strong community by sustainably rewarding users and contributors. Token incentives are a core component of the web3 growth playbook and can attract product builders and users. As the first round of airdrop events comes to a close, the ZKsync and LayerZero teams will increasingly rely on technological innovation to drive "real" user activity in the future.
CertiK's Aggressive White-Hat Hacking Behavior
Leading blockchain security firm CertiK discovered a critical vulnerability in Kraken's deposit system. Kraken's chief security officer revealed that nearly $3 million was exploited from Kraken's treasury—the flaw allowed users to deposit funds without completing the deposit process. This UX vulnerability credited trading accounts before the deposited assets were cleared by Kraken. According to CertiK, "a large amount of fabricated cryptocurrency (worth over $1 million) could be withdrawn from the account and converted into valid cryptocurrency." CertiK noted that no alerts were triggered during its testing phase, making the vulnerability undetectable by Kraken's internal security systems.
The vulnerability was fixed within hours. But after the fix, Kraken investigated two other accounts associated with the CertiK researchers who exploited the vulnerability. Kraken demanded a full report of their activities and the return of funds. The researchers allegedly refused to return any funds until Kraken disclosed the potential severity of the vulnerability if they had not reported it. After further discussions between CertiK and Kraken, CertiK transferred the funds to an address controlled by Kraken.
Although white-hat hacking is extremely valuable to crypto projects and companies, there are no clear rules for white-hat hackers to follow. Typically, the reward for white-hat hackers depends on the severity of the discovered vulnerability to the business or project. CertiK's hacking behavior has therefore been questioned: one account exploited the vulnerability for only $4, while two other CertiK researchers went further and exploited nearly $3 million. Kraken's chief security officer believed that the $4 exploit was enough to take immediate action, implying that the decision to exploit an additional $3 million was unethical. In addition, CertiK tested and exploited Kraken's vulnerability across multiple accounts over five days without notifying Kraken, and its timeline also raised red flags. After some back and forth, CertiK ultimately returned all funds to Kraken's wallet.
Although CertiK's work deserves compensation, the researchers exceeded their authorized scope—testing the limits of the vulnerability without immediately notifying Kraken. White-hat hacking often involves gray areas, and other ethical hackers should learn from the Kraken-CertiK dispute: prioritize transparent communication for projects with severe vulnerabilities.
SEC Ends Investigation into Ethereum 2.0
On Tuesday, June 18, 2024, Ethereum software company Consensys announced that the U.S. Securities and Exchange Commission (SEC) has ended its investigation into "Ethereum 2.0." Background: In March 2023, SEC Enforcement Division Director Gurbir Grewal approved a formal investigation into individuals and entities involved in buying and selling ETH, named the "Ethereum 2.0" investigation in court documents. In addition to multiple subpoenas that year, Consensys also received a Wells Notice on April 10, 2024, indicating that the SEC intended to take enforcement action against the company for violations of securities laws related to its MetaMask Swap and MetaMask Staking products. Consensys subsequently sued the SEC in April.
SEC Chair Gary Gensler testified at a Senate Appropriations Committee hearing last week that S-1 approval is expected to occur sometime this summer. In light of this, it is logical for the SEC to formally abandon its investigation into securities law violations by individuals and entities involved in buying and selling ETH.
However, it is not entirely clear whether the SEC is reversing its position of treating staked ETH as a security, which is why Consensys is unwilling to withdraw its lawsuit until the SEC also states that the MetaMask Staking product does not violate securities laws. None of the spot ETH ETPs awaiting approval this summer offer staking yields. If commodity-based trust shares can stake ETH without violating securities laws, then broader staking activities promoted by exchanges, software companies, etc., can also be more confident in offering staking services to end users.
The SEC's sudden move makes predicting its future actions difficult. One factor that must be continuously watched is the upcoming U.S. presidential election. More than in any previous year, cryptocurrency has become an important ballot issue, enough for major presidential candidates such as former President Donald J. Trump to take clear positions and use it to win votes.
Ethereum Blob Fees Soar
Ethereum consensus layer (CL) blob fees spiked to a peak of 0.979256 ETH at block 20134272 (June 24, 2024, 16:56 UTC). At the time, this was equivalent to $3,450 per blob, and did not include the execution layer (EL) base fee and priority fee required to post the blob to Ethereum Layer 1. The reason for the rise in blob base fees remains unclear, although "blobscriptions" caused a similar disruption to the consensus layer blob fee market between March 27 and April 3, 2024.
The current surge in CL blob base fees has caused rollups to spend 51% more than the previous high during the early April blobscription frenzy. This puts enormous pressure on the profitability of rollup sequencers that must pay for blobs.






