Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

Attackers drained more than $2.2 million from a deprecated Aztec bridge contract, marking the second exploit targeting Aztec-related legacy infrastructure in less than a week.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 18, 2026
in Security & Hacks
0 0
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A legacy component of Aztec’s ecosystem suffered another security incident on June 18, with attackers draining approximately $2.2 million in crypto assets from the protocol’s Private Rollup Bridge. The latest breach comes only days after a separate exploit targeted Aztec Connect’s deprecated infrastructure, raising fresh concerns about dormant smart contracts that continue to hold assets long after a project has migrated to newer systems. Blockchain security firm SlowMist flagged suspicious transactions linked to the attack and estimated losses at approximately 1,158 ETH, 150,000 DAI, and 0.4696 renBTC, with the stolen assets valued at roughly $2.2 million.

🚨SlowMist TI Alert🚨@aztecnetwork has been exploited again.

💸 Loss: 1,158 ETH+150,000 DAI+0.4696 renBTC (~$2,209,704.23 USD)

🔍 Root Cause: The `RollupProcessor.escapeHatch()` function (`0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba`) lacks access control: no `onlyOwner`, no…

— SlowMist (@SlowMist_Team) June 18, 2026

The attacker targeted the RollupProcessor contract (0x737901…a2ba) by exploiting weaknesses in its emergency escapeHatch() withdrawal mechanism. The function lacked several authorization safeguards, including ownership restrictions, rollup-provider validation, and signature verification. Under certain conditions, the contract accepted an escape-hatch proof without sufficiently verifying whether the withdrawal request was legitimately authorized.

The exploit involved the contract’s interaction with the TurboVerifier contract (0x48cb7b…8ce8). When the rollup size was set to zero, the verification process accepted an escape-hatch proof and relied on public withdrawal inputs supplied by the caller. Because ownership and withdrawal balances were not independently validated, the attacker was able to execute an unauthorized withdrawal from the RollupProcessor contract.

Wallet address
Wallet address

On-chain data shows the attacker used the wallet 0x6952d9…e97f, which received initial funding from HitBTC before the exploit was carried out. The attacker subsequently withdrew approximately 1,158 ETH along with 150,000 DAI and 0.4696 renBTC from the vulnerable contract. At the time of writing, no major laundering activity had been publicly reported. Security firm PeckShield also identified the suspicious activity and estimated losses at roughly $2.16 million.

The incident follows another exploit disclosed on June 14 that drained roughly $2.19 million from Aztec Connect’s deprecated RollupProcessor infrastructure. Researchers linked that attack to weaknesses in legacy transaction verification logic that allowed attackers to create and withdraw unbacked balances from retired Aztec infrastructure. The two incidents have collectively resulted in more than $4 million in losses across Aztec-related legacy systems within a single week.

The market reaction to the latest exploit has remained relatively muted. The affected contracts were part of Aztec’s deprecated infrastructure rather than its active privacy-focused Layer 2 network, limiting broader ecosystem concerns. Available data indicates the legacy Aztec Connect infrastructure held roughly $2.2 million in remaining value before the latest drain, leaving little recoverable value in the affected contracts after the attack.

Despite two exploits targeting Aztec-related legacy systems within a week, there has been no evidence of a significant market-wide reaction tied directly to the incidents. The market has largely treated both breaches as issues affecting deprecated infrastructure rather than the active Aztec ecosystem. Earlier reports following the June 14 exploit also indicated that investor attention remained focused on the current network rather than the retired bridge contracts.

Aztec Labs has previously stated that deprecated Aztec infrastructure operates through immutable smart contracts that cannot be paused, upgraded, or modified by the team. The company has also emphasized that the incidents do not affect the current Aztec Network, its privacy-focused Layer 2 operations, or assets associated with the active ecosystem.

The latest exploit highlights an increasingly common challenge across decentralized finance. While projects often migrate users to newer architectures, older contracts can remain permanently accessible on-chain. If residual assets remain locked within those systems, attackers may continue searching for overlooked vulnerabilities years after a protocol has been retired.

Similar concerns have emerged elsewhere in the crypto sector. Last month, RetoSwap suspended trading after a second exploit in the Haveno protocol exposed weaknesses in its transaction handling process, forcing the platform to halt activity while developers worked on security fixes.

The back-to-back Aztec incidents also underscore the risks posed by so-called “zombie contracts.” These are deprecated smart contracts that remain live despite no longer serving an active role within a protocol.

Legacy infrastructure has increasingly become a target for attackers. Earlier this month, Thetanuts Finance suffered a $2.1 million exploit linked to a flaw in an older Ethereum vault system, highlighting how vulnerabilities can persist even after projects transition to newer architectures.

Security researchers have repeatedly warned that dormant systems can become attractive targets when they continue holding funds or retain withdrawal functionality long after users have migrated elsewhere. As DeFi protocols mature, safely winding down legacy infrastructure is becoming as important as securing newly deployed code.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
Security & Hacks

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days

by Saravana Kumar Mahendran
August 31, 2026

More Markets, a lending protocol built on Flow EVM, lost about $9.3 million on Sunday after an attacker used a...

Read moreDetails
Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

August 29, 2026
Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

August 29, 2026
Sandbox’s $1 trillion in phantom SAND is still frozen. The real bridge hack cost under $700,000.

Sandbox’s $1 Trillion Phantom SAND Frozen as Real Hack Cost Hits $700K

August 28, 2026
Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

August 27, 2026
Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

August 25, 2026
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026
Next Post
Tether to Wind Down Alloy and aUSDT as It Shifts Focus to XAUT and Core Products

Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Recommended

  • All
  • Crypto News Today

Sam Bankman-Fried Asks Supreme Court to Overturn Fraud Conviction

September 13, 2026

Bitcoin Suisse Reported to Cut Up to 60 Swiss Jobs in Overhaul

September 13, 2026

ESMA Reminds Firms of Binary Option Rules as Prediction Markets Grow

September 13, 2026

Clearpool Plans XRPL Expansion With CPOOL Token Migration

September 13, 2026

Maharashtra Explores Tokenized Funding for India’s Power Grid

September 13, 2026

Bank-Issued Stablecoins Can Earn DeFi Yield, But Holders Bear the Risk

September 13, 2026

SEC’s Tokenized Stock Approach Targets the Register, Not the Token

September 13, 2026

US Regulators Revisit Bank Third-Party Risk Rules as Crypto Custody Grows

September 13, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • White House Adviser’s Financial Disclosure Shows Coinbase Stock Holding
  • Sam Bankman-Fried Asks Supreme Court to Overturn Fraud Conviction
  • Bitcoin Suisse Reported to Cut Up to 60 Swiss Jobs in Overhaul

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • Uncategorized
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.