Aztec Network lost over $4.3 million in two separate exploits within a week, targeting its deprecated infrastructure. On June 17, attackers drained ~$2.16M from the Private Rollup Bridge, days after a ~$2.2M hack of Aztec Connect. Both incidents exploited flaws in zero-knowledge proof logic in immutable contracts that could not be patched. Aztec Labs confirmed the current network and AZTEC token are unaffected by the attacks.
Aztec Connect exploit details
- ▪A follow-up attack on June 15, 2026, used the same vulnerability on Aztec Connect to steal an additional $88,000
- ▪The Aztec Connect protocol was a privacy-preserving zk-rollup that was launched in 2022 and deprecated in 2023
- ▪On June 14, 2026, an attacker exploited the deprecated Aztec Connect protocol, draining between $2.1 million and $2.2 million
- ▪The stolen assets from Aztec Connect included approximately 909 ETH, over 270,000 DAI, and 167 wstETH
Private Rollup Bridge attack
- ▪The wallet used in the Private Rollup Bridge attack was initially funded with 0.134 ETH from the crypto exchange HitBTC
- ▪On June 17, 2026, an attacker drained approximately $2.16 million from Aztec's deprecated Private Rollup Bridge
- ▪The assets stolen from the Private Rollup Bridge included 1,158 ETH, 150,000 DAI, and 0.47 renBTC
Zero-knowledge proof vulnerabilities
- ▪The Private Rollup Bridge attack exploited a vulnerable "escape hatch" function, which was designed as an emergency withdrawal tool
- ▪The Aztec Connect exploit involved a flaw where the proof verification system and on-chain settlement code interpreted transaction batches differently
- ▪Security firm BlockSec attributed both exploits to "public input binding issues" in the zero-knowledge proof verification logic
- ▪The attacker tricked the escape hatch by submitting a manipulated proof, causing the contract to release funds without proper ownership verification
Immutable legacy contract risks
- ▪The incidents are part of a growing trend of attacks targeting old, abandoned DeFi smart contracts that still contain funds
- ▪Although the products were officially shut down years ago, the smart contracts remained active on-chain and still held residual user funds
- ▪The exploited smart contracts were "immutable," meaning they could not be paused, upgraded, or patched by developers after being deployed
- ▪In April 2024, Aztec Labs renounced administrative control over Aztec Connect, which prevented the team from deploying any potential fixes
Aztec Foundation official response
- ▪Aztec Labs and the Aztec Foundation stated the exploits have no connection to the current Aztec network or the AZTEC ERC20 token
- ▪Aztec Labs confirmed it no longer holds administrative control over the affected infrastructure due to the contracts' immutable design
- ▪Following the news of the second exploit, the price of the AZTEC token declined by approximately 1.6%
- ▪The exploited Private Rollup Bridge was a product launched in 2021 and officially shut down in 2022
Story comments
Loading comments…