An attacker drained $2.1 million from Aztec Connect, a privacy bridge deprecated three years ago, by exploiting a flaw in its proof verification logic. Aztec Labs, the developer, confirmed it has no admin keys or control over the immutable smart contract and cannot intervene. The incident highlights the persistent security risks of abandoned DeFi infrastructure, where funds can remain vulnerable long after a project ceases active support.
Story comments
Loading comments…