A guide for zkSync users on how not to fall victim to a scam!

CryptAm
7 min readApr 29, 2023

--

Hey! Helping out in zkSync chats I have seen many users write “I followed a link and got all my funds stolen, help me out etc”, and as many already realise in such a case funds are lost forever, so I decided to write a quick guide on basic things just for beginners!
If you are an experienced user you are unlikely to find anything new to learn, but I encourage you to read the full article and become an active member by adding or correcting my article based on your own experience. This way each of us can keep users of the zkSync community safe from losing their money!

Given the increased interest of users in zkSync, a lot of scamming around the project has intensified, and what’s more, there are already a lot of different schemes, which we will now take apart with you!

  1. Social media.

Social media is the most common way of scamming. Just log into your Twitter account and there will already be a lot of scam posts about various token airdrops, etc.
I’ll go ahead and make it clear right away that the project has NO TOKENS!

Discord is also a favourite place for scammers, who spam various fake giveaways into private messages without end.
Some monitor who is helping in the chat room as a volunteer and create an identical profile, messaging the person needing help with an offer of “help” while posing as an admin/moderator/volunteer/team member.

The flagged users are scammers.

As an added, there is another situation in which a scammer created a separate channel in zkSync Discord and tagged the user, then invited him to chat in private messages. As a result, the user lost a large amount of their funds:

The team reacted immediately and now users cannot create separate branches on the server, but I hope this situation shows you the tricks scammers are capable of!

Tips:

First of all, I should point out that this spam (both on Twitter and Discord) is persistent and difficult to get rid of, for example by disabling the ability to write you private messages in Discord.

The advice here is simple: we ignore ALL intrusive messages!

It is IMPORTANT to remember that the team/admins/moderators and anyone else involved in the project will NEVER write to you first, let alone with any suggestions!

  • You can use this Discord channel for questions and communication!
  • You can write here for help!
  • If you find any type of scam, you will report it to this channel!
    Note: if possible, please include the scammer’s Username (example: cryptam#6678)

And in general, if using Discord is difficult for you, you can check out all the channels here to help you navigate more easily!

As far as Twitter is concerned, the project does not have any secondary accounts. There is only the main one: https://twitter.com/zksync
Also note that the zkSync Twitter account has a gold badge:

Anything else that positions itself as a project/team is a SCAM!

This also applies to any other social network, such a scam scheme will be present everywhere, so do not let your guard down, and at the slightest doubt immediately write to the above zkSync Discord channels to check with the moderators on the plausibility of these accounts.

Also, only follow the official project sources, which you can find here, to make sure the links you follow are not scam!

2. Scam websites and projects.

You’ve probably guessed by now that this category is very closely related to social media! Today there are simply a huge number of fraudulent sites, equivalent to the number of scam social networking accounts giving out “Airdrop to users”, offering various NFTs, etc., and if a user clicks on these sites and connects their wallet to the site, ALL their funds disappear instantly.

It’s also worth remembering that zkSync is open to absolutely everyone, which means that anyone right now can create their own project on zkSync Era Mainnet and use it to their advantage, attracting users in various ways and acting on their scam motives!

But don’t think of every project as a scam now! We just do research all new projects and decide whether or not we should take part in them!

Given the fact that absolutely anyone can deploy their project without much trouble today, the zkSync team’s position is based on recommending that these projects be researched independently. In other words, the team, even if it marks any project on Twitter, DOES NOT undertake to solve the problems of these projects in case of various circumstances! The team is only responsible for the operation of the network!

Therefore, I personally recommend that you do your own research on ecosystem projects and use the time-tested ones and be as careful as possible with projects that have just come out in zkSync.
Note: if you don’t have any experience in project research, I recommend that you don’t use projects that have just come out.

Interpret zkSync as one big platform where many different projects are being developed and built.
At the time of writing, ~50 projects are already available on the Era network, and this number is growing at an unimaginable rate!

3. Zealy(Crew3).

Also on the well-known Zealy platform (old name Crew3) there are sometimes scammers who “giveaway tokens” to their users for completing easy tasks:

But as you already know, the project has NO TOKEN, and the only channels where you will see plausible information about token output are:

But I hasten to point out straight away that the token will most likely not be released until 2024, based on what the team says, which means that any information about the token from left-wing sources is SCAM!

You can join the official Zealy project via this link!
There’s also a separate channel on Discord!

Note: Zealy zkSync has been created for educational purposes only!
There you will be able to complete the “Scam Detective” tasks, thus improving your security skills!

To summarise, I would like to emphasise one main point for you — the Discord project is the foundation of security for you:

  • there you can ask any question and get an instant answer;
  • there you can see all the official links so that you can clearly understand whether they are reliable or not;
  • there you can chat about ecosystem projects to get a better understanding of them;
  • and with Discord, you’ll be the first to know all the project’s news.

A prime example is the recent situation in which the team announced that “The zkSync Twitter account has been compromised.
Fortunately, nothing horrible happened, and in such a situation, by periodically communicating and reading the announcements on Discord you would have been informed by now!

Read more about the incident here!

This example clearly shows us that even if you see news about a giveaway or a suspicious link you’d better wait a while to see if the given giveaway/link is really from the zkSync team, because the issue of social network account security is in no way dependent on the team, but directly depends on the vulnerability of the given social network!

Also, at the end of this article, I would like to stress once again that I STRONGLY recommend using only official links that you can find on the project’s Discord! Recommendations of third-party sources (users, sites, social networks) we ignore! At the very least, if you are confused, feel free to write any of your questions on Discord!

That’s all for now, I hope you found this article useful! I also hope to update it with hints/tips from community members!
Thank you very much for reading!

Official links of the zkSync project:

Twitter | Discord | Reddit | Youtube | Telegram Announce | Telegram Support | Medium

--

--