TheCryptoNews.eu
Featured

Aztec Network loses over $4 million in three days to two subsequent hacks

Aztec Network loses over $4 million in three days to two subsequent hacks
Aztec Network loses over $4 million in two exploits
  • Legacy Aztec Network contracts had been drained of over $4M in three days.
  • Assaults exploited flaws in zero-recordsdata proof verification common sense.
  • The core Aztec network and AZTEC token weren’t stricken by the exploits.

Aztec’s legacy infrastructure has attain below a coordinated wave of attacks, ensuing in losses that crossed $4 million within appropriate three days.

The exploits centered deprecated neat contracts that had already been shut down years earlier but clean held on-chain liquidity.

Despite being labelled as inactive and immutable, the contracts remained accessible to attackers who exploited weaknesses in zero-recordsdata proof verification common sense.

While the attacks did not have an effect on the most modern Aztec network or its AZTEC token, they uncovered lengthy-standing dangers tied to retired DeFi systems that continue to exist on Ethereum with out active maintenance or upgrade paths.

First breach: Aztec Connect drained of $2.1 million

The first incident took place on June 14, when attackers exploited the Aztec Connect protocol, a deprecated privateness-focused bridge that had been officially shut down after its retirement section.

The contract changed into as soon as already regarded as as inactive, but it clean contained residual funds.

The attacker managed to empty approximately $2.1 million in digital property, alongside with round 909 ETH, 270,000 DAI, and 167 wstETH, alongside other smaller holdings.

The exploit changed into as soon as linked to flaws within the technique rollup proof verification changed into as soon as handled, allowing invalid or manipulated proofs to be authorized as official.

What made the scenario extra severe changed into as soon as the persona of the contract itself.

Aztec Connect changed into as soon as described as immutable, which technique it may perhaps per chance perhaps not be paused or patched as soon as deployed.

Even supposing customers had previously been inspired to withdraw funds earlier than shutdown, the final steadiness became a easy plan for exploitation years later.

Safety teams reviewing the incident pointed to a breakdown within the connection between zero-recordsdata proof validation and on-chain settlement common sense.

In easy terms, the system authorized proofs that didn’t wisely match the underlying transaction snarl, allowing the attacker to home off unauthorised withdrawals.

2nd attack: Non-public Rollup Bridge exploited for $2.15 million

Ultimate three days later, a second exploit hit one other legacy system is called the Non-public Rollup Bridge.

This contract changed into as soon as also section of Aztec’s older infrastructure and had been deprecated following the transition far from earlier rollup designs.

In this case, attackers drained roughly 1,158 ETH, valued at discontinuance to $2.15 million on the time of the incident.

The design historical changed into as soon as a quantity of in execution but same in technical root reason.

As a substitute of straight manipulating withdrawals thru total proof mismatch, the attacker leveraged a susceptible “spoil out hatch” mechanism embedded within the bridge occupy.

By submitting a specially crafted zero-recordsdata proof, the attacker changed into as soon as ready to home off the contract’s exit common sense.

The system incorrectly validated the proof and launched funds with out correct verification of the underlying snarl transitions.

This allowed the attacker to extract liquidity in a single coordinated sequence.

Admire the earlier exploit, this breach didn’t involve non-public key compromise or reentrancy vulnerabilities.

As a substitute, it highlighted deeper components in how proof validation changed into as soon as structured in legacy rollup systems, particularly when contracts remain permanently active on-chain after being officially sunset.

Response from Aztec and safety companies

Following both incidents, Aztec Labs and the Aztec Foundation confirmed that the affected systems had been deprecated merchandise with out a connection to the most modern Aztec network or AZTEC token ecosystem.

The Aztec Foundation changed into as soon as made attentive to a doubtless exploit focusing on a deprecated product which took place on June 17, 2026. There are no hyperlinks between this product and any neat contracts linked to the most modern network or the AZTEC ERC20 token.

The product changed into as soon as deprecated 4 years… https://t.co/kANaIuw8HF

— Aztec Foundation (@aztecFND) June 18, 2026

They emphasised that neither contract is prone to be upgraded, paused, or managed, as both had been designed to be immutable at deployment.

Safety company CertiK Alert also flagged the Non-public Rollup Bridge exploit, identifying the attacker’s address and confirming the motion of funds tied to a selected Ethereum transaction.

Their diagnosis aligned with other experiences, suggesting that the vulnerability stemmed from flaws in zero-recordsdata proof verification as adverse to historical neat contract bugs.

Aztec representatives also clarified that the Non-public Rollup Bridge and Aztec Connect incidents had been separate events, even if they took place within a brief timeframe and shared same technical weaknesses.


Piece this article

Categories

Tags

Learn Extra

Related posts

Vitalik argues that proof-of-stake is a ‘resolution’ to Ethereum’s environmental woes

The Crypto News

SEC sues Binance and CZ for breaking US Securities Rules

The Crypto News

Bitcoin provide held by long-term holders hits all-time excessive — Be taught

The Crypto News

Leave a Comment

Or Login with

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More