Loading prices…
🩸BEARISH

Aztec Labs probes $2.2M exploit of deprecated rollup

The Aztec Foundation says the breached product is a four-year-old immutable stage 2 rollup with no ties to current network contracts or the AZTEC token — but a related validation flaw just drained…

Aztec Labs is investigating an estimated $2.165 million exploit of a deprecated Aztec payments product, with on-chain analyst PeckShield tallying the drained assets at roughly 1,158 ETH, 150,000 DAI, and 0.47 renBTC. The attacker originally funded the operation with 0.134 ETH sourced from HitBTC, then walked an immutable, four-year-old stage 2 rollup for the proceeds.

The Aztec Foundation stressed on X that the breached product is disconnected from any current-network smart contracts or the AZTEC ERC20 token — but the incident lands four days after a Sunday exploit of the Aztec Connect immutable contract drained roughly $2.1 million via what researchers called a similar validation weakness.

Why it matters

BlockSec researchers at Phalcon said the latest attack is related to, but distinct from, the June 14 incident: a circuit public input binding issue that let the attacker pass onchain verification while withdrawing assets, with a separate entry point and a different pool targeted. Both bugs trace to the same family of ZK-circuit verification flaws in the legacy stack — and both sit in code Aztec itself has flagged as deprecated, meaning there is no patch path without a redeployment. The Foundation's separation-of-concerns framing (current network vs. legacy product) protects the AZTEC token narrative but does nothing for the broader lesson: an immutable contract, by definition, remains exploitable as long as the original verification logic has a hole.

Market impact

The incident slots into one of the roughest stretches DeFi has seen in some time — more than 30 protocols hacked for over $600 million in the current cycle, paced by the $292 million Kelp DAO exploit. The Aztec Connect lineage has now lost close to $4.3 million across two events in a single week, and Aztec Labs has not yet named a remediation timeline, saying only that further updates will follow.

Related tokens
$ETH $AZTEC

Frequently asked questions

  1. Which Aztec product was exploited?

    A four-year-old, immutable stage 2 rollup used as a deprecated payments product. The Aztec Foundation said it has no link to current network contracts or the AZTEC ERC20 token.

  2. How much was drained and in which assets?

    PeckShield estimated roughly $2.165 million in total: about 1,158 ETH, 150,000 DAI, and 0.47 renBTC. The attacker funded the operation with 0.134 ETH routed from HitBTC.

  3. Is this exploit related to the Sunday Aztec Connect hack?

    BlockSec's Phalcon team said yes, at the family level. Both trace to ZK-circuit public-input binding issues that let the attacker pass onchain verification while withdrawing assets, though the entry points and targeted pools differ.

  4. Is the AZTEC token or current network at risk?

    The Aztec Foundation said no — the breached product is deprecated and disconnected from live network contracts and the AZTEC token. Legacy holders, however, remain exposed while the immutable contracts stand.

  5. Can Aztec Labs patch the exploited contract?

    No. The contract is immutable, meaning there is no upgrade path. The team has not announced a remediation timeline and said further updates will follow.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 46d ago
Open original →