Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

Attackers drained more than $2.2 million from a deprecated Aztec bridge contract, marking the second exploit targeting Aztec-related legacy infrastructure in less than a week.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 18, 2026
in Security & Hacks
0 0
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A legacy component of Aztec’s ecosystem suffered another security incident on June 18, with attackers draining approximately $2.2 million in crypto assets from the protocol’s Private Rollup Bridge. The latest breach comes only days after a separate exploit targeted Aztec Connect’s deprecated infrastructure, raising fresh concerns about dormant smart contracts that continue to hold assets long after a project has migrated to newer systems. Blockchain security firm SlowMist flagged suspicious transactions linked to the attack and estimated losses at approximately 1,158 ETH, 150,000 DAI, and 0.4696 renBTC, with the stolen assets valued at roughly $2.2 million.

🚨SlowMist TI Alert🚨@aztecnetwork has been exploited again.

💸 Loss: 1,158 ETH+150,000 DAI+0.4696 renBTC (~$2,209,704.23 USD)

🔍 Root Cause: The `RollupProcessor.escapeHatch()` function (`0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba`) lacks access control: no `onlyOwner`, no…

— SlowMist (@SlowMist_Team) June 18, 2026

The attacker targeted the RollupProcessor contract (0x737901…a2ba) by exploiting weaknesses in its emergency escapeHatch() withdrawal mechanism. The function lacked several authorization safeguards, including ownership restrictions, rollup-provider validation, and signature verification. Under certain conditions, the contract accepted an escape-hatch proof without sufficiently verifying whether the withdrawal request was legitimately authorized.

The exploit involved the contract’s interaction with the TurboVerifier contract (0x48cb7b…8ce8). When the rollup size was set to zero, the verification process accepted an escape-hatch proof and relied on public withdrawal inputs supplied by the caller. Because ownership and withdrawal balances were not independently validated, the attacker was able to execute an unauthorized withdrawal from the RollupProcessor contract.

Wallet address
Wallet address

On-chain data shows the attacker used the wallet 0x6952d9…e97f, which received initial funding from HitBTC before the exploit was carried out. The attacker subsequently withdrew approximately 1,158 ETH along with 150,000 DAI and 0.4696 renBTC from the vulnerable contract. At the time of writing, no major laundering activity had been publicly reported. Security firm PeckShield also identified the suspicious activity and estimated losses at roughly $2.16 million.

The incident follows another exploit disclosed on June 14 that drained roughly $2.19 million from Aztec Connect’s deprecated RollupProcessor infrastructure. Researchers linked that attack to weaknesses in legacy transaction verification logic that allowed attackers to create and withdraw unbacked balances from retired Aztec infrastructure. The two incidents have collectively resulted in more than $4 million in losses across Aztec-related legacy systems within a single week.

The market reaction to the latest exploit has remained relatively muted. The affected contracts were part of Aztec’s deprecated infrastructure rather than its active privacy-focused Layer 2 network, limiting broader ecosystem concerns. Available data indicates the legacy Aztec Connect infrastructure held roughly $2.2 million in remaining value before the latest drain, leaving little recoverable value in the affected contracts after the attack.

Despite two exploits targeting Aztec-related legacy systems within a week, there has been no evidence of a significant market-wide reaction tied directly to the incidents. The market has largely treated both breaches as issues affecting deprecated infrastructure rather than the active Aztec ecosystem. Earlier reports following the June 14 exploit also indicated that investor attention remained focused on the current network rather than the retired bridge contracts.

Aztec Labs has previously stated that deprecated Aztec infrastructure operates through immutable smart contracts that cannot be paused, upgraded, or modified by the team. The company has also emphasized that the incidents do not affect the current Aztec Network, its privacy-focused Layer 2 operations, or assets associated with the active ecosystem.

The latest exploit highlights an increasingly common challenge across decentralized finance. While projects often migrate users to newer architectures, older contracts can remain permanently accessible on-chain. If residual assets remain locked within those systems, attackers may continue searching for overlooked vulnerabilities years after a protocol has been retired.

Similar concerns have emerged elsewhere in the crypto sector. Last month, RetoSwap suspended trading after a second exploit in the Haveno protocol exposed weaknesses in its transaction handling process, forcing the platform to halt activity while developers worked on security fixes.

The back-to-back Aztec incidents also underscore the risks posed by so-called “zombie contracts.” These are deprecated smart contracts that remain live despite no longer serving an active role within a protocol.

Legacy infrastructure has increasingly become a target for attackers. Earlier this month, Thetanuts Finance suffered a $2.1 million exploit linked to a flaw in an older Ethereum vault system, highlighting how vulnerabilities can persist even after projects transition to newer architectures.

Security researchers have repeatedly warned that dormant systems can become attractive targets when they continue holding funds or retain withdrawal functionality long after users have migrated elsewhere. As DeFi protocols mature, safely winding down legacy infrastructure is becoming as important as securing newly deployed code.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges
Security & Hacks

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

by Saravana Kumar Mahendran
August 1, 2026

Crypto lost roughly $198.8 million across 34 disclosed hacks in July, plus one incident with an undisclosed amount (35 total)....

Read moreDetails
Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

July 31, 2026
Drift Protocol Hacker Moves $44M in ETH to Tornado Cash After Three Months

Drift Exploiter Moves $44M in ETH Through Tornado Cash After Three Months of Inactivity

July 24, 2026
Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Unauthorized Memecoin

Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Fake VLAD Token

July 24, 2026
Three Crypto Exploits Drain Over $35.5 Million in Hours as Verus, AFX, and B² Are Hit

Multiple Bridge Exploits Drain $35 Million Across Bitcoin and Ethereum Networks

July 23, 2026
VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

July 23, 2026
SecondFi Shuts Down Following $2.6 Million ADA Security Breach

SecondFi Shuts Down Following $2.6 Million ADA Security Breach

July 22, 2026
Next Post
Tether to Wind Down Alloy and aUSDT as It Shifts Focus to XAUT and Core Products

Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Recommended

  • All
  • Crypto News Today

Trump Media Launches Truth API for Wall Street Traders Despite Objections

August 1, 2026
XRPL's Next Upgrade Resubmits Two Amendments That Failed Security Review

XRPL’s Next Upgrade Resubmits Two Amendments That Failed Security Review

August 1, 2026
Hyperliquid Opens HIP-4 Prediction Markets to Testnet Developers at a Fraction of Its Mainnet Price Tag

Hyperliquid Opens HIP-4 Prediction Markets to Testnet Developers at a Fraction of Its Mainnet Price Tag

August 1, 2026
July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

August 1, 2026
Pump.fun Laid Off Staff Two Months Before Tokens Vested

Pump.fun Laid Off Staff Two Months Before Tokens Vested

August 1, 2026
Michael Saylor, Strategy Back Digital Asset Market Clarity Act

Michael Saylor, Strategy Back Digital Asset Market Clarity Act

August 1, 2026
Crypto Token Unlocks in August 2026: YZY, PROVE and KAITO Lead More Than $323 Million in Scheduled Releases

Crypto Token Unlocks in August 2026: YZY, PROVE and KAITO Lead More Than $323 Million in Scheduled Releases

August 1, 2026
Tether Posts $1.5B Q2 Profit, But Its Reserve Buffer Shrank by Nearly Half

Tether Posts $1.5B Q2 Profit, But Its Reserve Buffer Shrank by Nearly Half

August 1, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Trump Media Sends Another 2,628 Bitcoin to Crypto.com, Its Third Such Move in Nine Months
  • Trump Media Launches Truth API for Wall Street Traders Despite Objections
  • XRPL’s Next Upgrade Resubmits Two Amendments That Failed Security Review

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.