Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Aztec Connect Loses $2.1 Million in Exploit Three Years After Shutdown
00

Aztec Connect Loses $2.1 Million in Exploit Three Years After Shutdown

Jun 15, 2026

An attacker drained $2.1 million from Aztec Connect, a privacy bridge deprecated three years ago, by exploiting a flaw in its proof verification logic. Aztec Labs, the developer, confirmed it has no admin keys or control over the immutable smart contract and cannot intervene. The incident highlights the persistent security risks of abandoned DeFi infrastructure, where funds can remain vulnerable long after a project ceases active support.

Aztec Connect exploit

  • ▪The stolen funds included approximately 909 ETH, 270,000 DAI, and 167 wrapped staked Ether (wstETH)
  • ▪Blockchain security firms CertiK and BlockSec flagged the suspicious transaction
  • ▪An attacker exploited a flaw in an Aztec Connect smart contract on June 14, draining approximately $2.1 million
  • ▪Prior to the attack, the exploited Aztec Connect contracts held about $2.15 million in total value locked
  • ▪The exploit was caused by incomplete validation of submitted proof data, where a contract function only checked the beginning of the proof

Deprecated contract risks

  • ▪The exploit is part of a wider trend in June, with total losses from crypto exploits reaching approximately $43.93 million by mid-month
  • ▪The incident highlights the risk that old DeFi smart contracts can remain live and attackable long after a product is shut down
  • ▪The exploited Aztec Connect platform had been deprecated three years prior to the incident
  • ▪Aztec Connect was a zk-rollup privacy bridge that Aztec Labs deprecated in March 2023

Immutability trade-offs

  • ▪Aztec Labs confirmed it holds no admin keys or control over the Aztec Connect system and cannot pause or upgrade it
  • ▪The situation illustrates a core DeFi trade-off: upgradeable contracts pose governance risks, while immutable contracts pose response risks
  • ▪When Aztec Labs wound down the bridge, it renounced the admin keys, a common practice for privacy-focused protocols
  • ▪The contract's immutability, often considered a security feature, prevented developers from patching the vulnerability after it was discovered

Protocol shutdown practices

  • ▪A responsible shutdown of a DeFi protocol should include repeated user warnings, post-shutdown monitoring, and clear risk communication
  • ▪The Aztec Foundation stated the exploit does not affect the AZTEC ERC-20 token or any smart contracts on the current Aztec network

User security guidance

  • ▪If a protocol's front-end is shut down, the underlying smart contracts may still hold funds and remain at risk
  • ▪Users are advised not to leave funds in deprecated contracts and to withdraw assets when a protocol announces a shutdown

3 sources

Beincrypto
Attacker Drains $2.1 Million From Aztec Connect 3 Years After Its Shutdown
View source article
Bitcoinist
Aztec Connect Exploit Shows Why Old DeFi Contracts Can Still Be Dangerous
View source article
Cryptopolitan
Aztec Labs draws line with deprecated Aztec Connect product after $2.1M exploit - Cryptopolitan
View source article

Story comments

Loading comments…

Related entities

Blockchain Security

Related Projects

Aztec

Topics

DeFiPrivacy coinsDeFi securityCrypto hacks