ZkSync-Based DEX Merlin Drained of $1.8M During Public Token Sale Despite ‘Audit’
The project garnered hype among Crypto Twitter users for its attractive yield offered on deposits.

New zkSync-based decentralized exchange Merlin was seemingly exploited for over $1.8 million Wednesday morning during a public sale of its mage (MAGE) tokens.
Exploiters drained some $850,000 worth of USD coin (USDC) from Merlin along with some more relatively illiquid tokens. As such, blockchain data suggested that an entity with control of the liquidity pool was able to drain the funds easily – meaning this was not a complex or sophisticated exploit.
The attack occurred despite Merlin touting an audit conducted by blockchain security firm CertiK. “No Critical Findings,” the audit concluded, as CertiK’s website data shows.
Merlin was offering its MAGE tokens in a public sale to investors in a three-day event without any hard cap. “$MAGE will begin trading at $45, with a $850K market value. The total amount raised will determine the final price of tokens for all users,” developers said Tuesday.
Merlin developers did not issue any statement regarding the funds drain on Wednesday at press time.
On-chain data provided by Arkham Intelligence reveals that $1.82 million in total had been stolen, with the funds being bridged back to the Ethereum network before being converted to ether.
UPDATE (April 26, 14:33 UTC): Updates total amount stolen, adds details that hacker bridged funds to Ethereum.
UPDATE (April 26, 16:37 UTC): Adds information about CertK's Twitter response to the loss of funds, including plans for compensation.
UPDATE (April 27, 10:29 UTC): Removes Certik's Twitter response from end of story after company deletes tweet.
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
Більше для вас
Tassat Wins U.S. Patent for 'Yield-in-Transit' Onchain Settlement Tech

The IP covers intraday, block-by-block interest accrual during 24/7 settlement and underpins Lynq, an institutional network Tassat co-launched in July.
Що варто знати:
- The patent covers on-chain 'yield-in-transit' interest accrual and distribution during settlement.
- Tassat said the tech powers Lynq, which it billed as an institutional network offering integrated, interest-bearing settlement.
- The company argued that continuous yield during collateral and reserve operations could improve how market makers, custodians and stablecoin issuers deploy capital.










