Aztec Connect’s smart contract has reportedly lost $2.1 million after an attacker took advantage of a verification flaw in the privacy bridge that was shut downAztec Connect’s smart contract has reportedly lost $2.1 million after an attacker took advantage of a verification flaw in the privacy bridge that was shut down

Aztec Connect exploit drains $2.1M from deprecated zk-rollup bridge on Ethereum

2026/06/15 19:26
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Aztec Connect’s smart contract has reportedly lost $2.1 million after an attacker took advantage of a verification flaw in the privacy bridge that was shut down three years ago. This attack also comes with a twist, as the flaw sits beyond anyone’s ability to patch per the Aztec Labs team.

The stolen funds included approximately 909 ETH, 270,000 DAI, and 167 wstETH, according to blockchain security firm BlockSec, which flagged the suspicious transaction through its Phalcon monitoring system. 

Before it was deprecated by Aztec Labs in March 2023, Aztec Connect was a zk-rollup bridge that let users interact with DeFi protocols like Aave and Lido while shielding transaction details through zero-knowledge proofs. Aztec Labs stopped running its sequencer by March 2024.

The AZTEC token is up more than 5% as of the time of Cryptoplitan’s report.

What was the flaw that enabled the attacker to exploit Aztec Connect? 

The flaw was due to a mismatch involving the boundary between the verified transaction set and L1 settlement processing per BlockSec Phalcon’s analysis on X.

According to security firm CertiK, the flaw was an incomplete validation of submitted proof data.

 One contract function checked only the beginning of the proof while token transfer instructions embedded elsewhere went unverified, and this was what allowed the attacker to manipulate withdrawals.

What is Aztec Labs’ response to the exploit?

Aztec Labs confirmed it was investigating but said it has no mechanism to intervene. “Aztec Connect was deprecated 3 years ago. Aztec Labs holds no admin keys or control over the system; it cannot be paused or upgraded by us,” the team wrote on X.

In a separate statement, the Aztec Foundation posted on X, stating that the foundation stressed that the incident has no connection to any smart contracts tied to the AZTEC ERC-20 token or the current Aztec network, which focuses on private smart contracts. 

“Aztec Connect was deprecated 3 years ago and Aztec Labs retains no controls over the system,” Aztec Foundation wrote.

When Aztec Labs wound down the bridge, it renounced admin keys to the contracts given the fact that it was a privacy-focused protocol. However, the tradeoff is that once the keys are gone, nobody can deploy a fix when a vulnerability surfaces.

What is the cost of the exploit?

Aztec Connect contracts held about $2.15 million in total value locked before the attack, according to DefiLlama data, and those were the funds that the exploiter was able to access.

Aztec Labs draws line with deprecated Aztec Connect product after $2.1M exploitExploiters removed the $2.15 million that was sitting in Aztec Connect. Source: DefiLlama

The funds were unmonitored, and the team did nothing about them, as any assets left inside them depend entirely on the original code’s integrity. 

Aztec Connect’s exploit also brings to the fore the recurring risk for users who leave their funds in legacy contracts after a project migrates.

June exploits continue to mount

It is already halfway into the month of June, and with exploits picking up, crypto protocols do not seem to catch a break. May was also punctuated with various exploits, and recently deprecated platforms are seeing increased attacks

Cryptopolitan has previously reported on exploits hitting Gnosis Pay and TesseraDAO in the first days of June, with TesseraDAO alone losing $2.5 million in a mint-and-dump attack on BNB Chain. 

Per DeFiLlama data, June exploits have already reached approximately $43.93 million in cumulative losses as of mid-month.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

시장 기회
Aztec 로고
Aztec 가격(AZTEC)
$0.01648
$0.01648$0.01648
-7.15%
USD
Aztec (AZTEC) 실시간 가격 차트

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel