Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

Attackers drained more than $2.2 million from a deprecated Aztec bridge contract, marking the second exploit targeting Aztec-related legacy infrastructure in less than a week.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 18, 2026
in Security & Hacks
0 0
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A legacy component of Aztec’s ecosystem suffered another security incident on June 18, with attackers draining approximately $2.2 million in crypto assets from the protocol’s Private Rollup Bridge. The latest breach comes only days after a separate exploit targeted Aztec Connect’s deprecated infrastructure, raising fresh concerns about dormant smart contracts that continue to hold assets long after a project has migrated to newer systems. Blockchain security firm SlowMist flagged suspicious transactions linked to the attack and estimated losses at approximately 1,158 ETH, 150,000 DAI, and 0.4696 renBTC, with the stolen assets valued at roughly $2.2 million.

🚨SlowMist TI Alert🚨@aztecnetwork has been exploited again.

💸 Loss: 1,158 ETH+150,000 DAI+0.4696 renBTC (~$2,209,704.23 USD)

🔍 Root Cause: The `RollupProcessor.escapeHatch()` function (`0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba`) lacks access control: no `onlyOwner`, no…

— SlowMist (@SlowMist_Team) June 18, 2026

The attacker targeted the RollupProcessor contract (0x737901…a2ba) by exploiting weaknesses in its emergency escapeHatch() withdrawal mechanism. The function lacked several authorization safeguards, including ownership restrictions, rollup-provider validation, and signature verification. Under certain conditions, the contract accepted an escape-hatch proof without sufficiently verifying whether the withdrawal request was legitimately authorized.

The exploit involved the contract’s interaction with the TurboVerifier contract (0x48cb7b…8ce8). When the rollup size was set to zero, the verification process accepted an escape-hatch proof and relied on public withdrawal inputs supplied by the caller. Because ownership and withdrawal balances were not independently validated, the attacker was able to execute an unauthorized withdrawal from the RollupProcessor contract.

Wallet address
Wallet address

On-chain data shows the attacker used the wallet 0x6952d9…e97f, which received initial funding from HitBTC before the exploit was carried out. The attacker subsequently withdrew approximately 1,158 ETH along with 150,000 DAI and 0.4696 renBTC from the vulnerable contract. At the time of writing, no major laundering activity had been publicly reported. Security firm PeckShield also identified the suspicious activity and estimated losses at roughly $2.16 million.

The incident follows another exploit disclosed on June 14 that drained roughly $2.19 million from Aztec Connect’s deprecated RollupProcessor infrastructure. Researchers linked that attack to weaknesses in legacy transaction verification logic that allowed attackers to create and withdraw unbacked balances from retired Aztec infrastructure. The two incidents have collectively resulted in more than $4 million in losses across Aztec-related legacy systems within a single week.

The market reaction to the latest exploit has remained relatively muted. The affected contracts were part of Aztec’s deprecated infrastructure rather than its active privacy-focused Layer 2 network, limiting broader ecosystem concerns. Available data indicates the legacy Aztec Connect infrastructure held roughly $2.2 million in remaining value before the latest drain, leaving little recoverable value in the affected contracts after the attack.

Despite two exploits targeting Aztec-related legacy systems within a week, there has been no evidence of a significant market-wide reaction tied directly to the incidents. The market has largely treated both breaches as issues affecting deprecated infrastructure rather than the active Aztec ecosystem. Earlier reports following the June 14 exploit also indicated that investor attention remained focused on the current network rather than the retired bridge contracts.

Aztec Labs has previously stated that deprecated Aztec infrastructure operates through immutable smart contracts that cannot be paused, upgraded, or modified by the team. The company has also emphasized that the incidents do not affect the current Aztec Network, its privacy-focused Layer 2 operations, or assets associated with the active ecosystem.

The latest exploit highlights an increasingly common challenge across decentralized finance. While projects often migrate users to newer architectures, older contracts can remain permanently accessible on-chain. If residual assets remain locked within those systems, attackers may continue searching for overlooked vulnerabilities years after a protocol has been retired.

Similar concerns have emerged elsewhere in the crypto sector. Last month, RetoSwap suspended trading after a second exploit in the Haveno protocol exposed weaknesses in its transaction handling process, forcing the platform to halt activity while developers worked on security fixes.

The back-to-back Aztec incidents also underscore the risks posed by so-called “zombie contracts.” These are deprecated smart contracts that remain live despite no longer serving an active role within a protocol.

Legacy infrastructure has increasingly become a target for attackers. Earlier this month, Thetanuts Finance suffered a $2.1 million exploit linked to a flaw in an older Ethereum vault system, highlighting how vulnerabilities can persist even after projects transition to newer architectures.

Security researchers have repeatedly warned that dormant systems can become attractive targets when they continue holding funds or retain withdrawal functionality long after users have migrated elsewhere. As DeFi protocols mature, safely winding down legacy infrastructure is becoming as important as securing newly deployed code.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol
Security & Hacks

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

by Saravana Kumar Mahendran
June 17, 2026

RetoSwap, a leading privacy-focused peer-to-peer decentralized exchange for trading Monero (XMR) against fiat and other cryptocurrencies over Tor, has temporarily...

Read moreDetails
Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

June 16, 2026
Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

June 16, 2026
Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

June 15, 2026 - Updated on June 16, 2026
Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

June 13, 2026
Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

June 11, 2026
Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

June 10, 2026
Next Post
STABLECON USA 2026 LAUNCHES

STABLECON USA 2026 LAUNCHES, WITH FIRST KEYNOTE SPEAKERS ANNOUNCED

Recommended

  • All
  • News
Tether to Wind Down Alloy and aUSDT as It Shifts Focus to XAUT and Core Products

Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform

June 18, 2026
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026
CZ Donates $2 Million to Prison Professors for U.S. Prison Education Programs

Binance founder CZ Donates $2 Million to Prison Professors for U.S. Prison Education Programs

June 18, 2026
EarnOS Secures $18.5 Million to Expand Verified Engagement Platform

EarnOS Secures $18.5 Million to Expand Verified Engagement Platform

June 18, 2026
Tether to Wind Down Alloy and aUSDT as It Shifts Focus to XAUT and Core Products

Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform

June 18, 2026
Architecting Indonesia’s Sovereign & Scalable AI Future: Inside the $10.9 Billion Tech Shift

Architecting Indonesia’s Sovereign & Scalable AI Future: Inside the $10.9 Billion Tech Shift.

June 18, 2026
STABLECON USA 2026 LAUNCHES

STABLECON USA 2026 LAUNCHES, WITH FIRST KEYNOTE SPEAKERS ANNOUNCED

June 18, 2026
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform
  • Architecting Indonesia’s Sovereign & Scalable AI Future: Inside the $10.9 Billion Tech Shift.
  • STABLECON USA 2026 LAUNCHES, WITH FIRST KEYNOTE SPEAKERS ANNOUNCED

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.