Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

Attackers drained more than $2.2 million from a deprecated Aztec bridge contract, marking the second exploit targeting Aztec-related legacy infrastructure in less than a week.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 18, 2026
in Security & Hacks
0 0
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A legacy component of Aztec’s ecosystem suffered another security incident on June 18, with attackers draining approximately $2.2 million in crypto assets from the protocol’s Private Rollup Bridge. The latest breach comes only days after a separate exploit targeted Aztec Connect’s deprecated infrastructure, raising fresh concerns about dormant smart contracts that continue to hold assets long after a project has migrated to newer systems. Blockchain security firm SlowMist flagged suspicious transactions linked to the attack and estimated losses at approximately 1,158 ETH, 150,000 DAI, and 0.4696 renBTC, with the stolen assets valued at roughly $2.2 million.

🚨SlowMist TI Alert🚨@aztecnetwork has been exploited again.

💸 Loss: 1,158 ETH+150,000 DAI+0.4696 renBTC (~$2,209,704.23 USD)

🔍 Root Cause: The `RollupProcessor.escapeHatch()` function (`0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba`) lacks access control: no `onlyOwner`, no…

— SlowMist (@SlowMist_Team) June 18, 2026

The attacker targeted the RollupProcessor contract (0x737901…a2ba) by exploiting weaknesses in its emergency escapeHatch() withdrawal mechanism. The function lacked several authorization safeguards, including ownership restrictions, rollup-provider validation, and signature verification. Under certain conditions, the contract accepted an escape-hatch proof without sufficiently verifying whether the withdrawal request was legitimately authorized.

The exploit involved the contract’s interaction with the TurboVerifier contract (0x48cb7b…8ce8). When the rollup size was set to zero, the verification process accepted an escape-hatch proof and relied on public withdrawal inputs supplied by the caller. Because ownership and withdrawal balances were not independently validated, the attacker was able to execute an unauthorized withdrawal from the RollupProcessor contract.

Wallet address
Wallet address

On-chain data shows the attacker used the wallet 0x6952d9…e97f, which received initial funding from HitBTC before the exploit was carried out. The attacker subsequently withdrew approximately 1,158 ETH along with 150,000 DAI and 0.4696 renBTC from the vulnerable contract. At the time of writing, no major laundering activity had been publicly reported. Security firm PeckShield also identified the suspicious activity and estimated losses at roughly $2.16 million.

The incident follows another exploit disclosed on June 14 that drained roughly $2.19 million from Aztec Connect’s deprecated RollupProcessor infrastructure. Researchers linked that attack to weaknesses in legacy transaction verification logic that allowed attackers to create and withdraw unbacked balances from retired Aztec infrastructure. The two incidents have collectively resulted in more than $4 million in losses across Aztec-related legacy systems within a single week.

Related Story

Hacked SpaceXAI and Starlink Accounts Promote SCATMAN Token Before 73.7 ETH Sales

Hacked SpaceXAI and Starlink Accounts Promote SCATMAN Token Before 73.7 ETH Sales

July 13, 2026
Suspected Hedera DeFi Hack Moves $5.8 Million to Ethereum

Bonzo Lend Oracle Exploit Triggers Cross-Chain Fund Transfers on Hedera

July 11, 2026

The market reaction to the latest exploit has remained relatively muted. The affected contracts were part of Aztec’s deprecated infrastructure rather than its active privacy-focused Layer 2 network, limiting broader ecosystem concerns. Available data indicates the legacy Aztec Connect infrastructure held roughly $2.2 million in remaining value before the latest drain, leaving little recoverable value in the affected contracts after the attack.

Despite two exploits targeting Aztec-related legacy systems within a week, there has been no evidence of a significant market-wide reaction tied directly to the incidents. The market has largely treated both breaches as issues affecting deprecated infrastructure rather than the active Aztec ecosystem. Earlier reports following the June 14 exploit also indicated that investor attention remained focused on the current network rather than the retired bridge contracts.

Aztec Labs has previously stated that deprecated Aztec infrastructure operates through immutable smart contracts that cannot be paused, upgraded, or modified by the team. The company has also emphasized that the incidents do not affect the current Aztec Network, its privacy-focused Layer 2 operations, or assets associated with the active ecosystem.

The latest exploit highlights an increasingly common challenge across decentralized finance. While projects often migrate users to newer architectures, older contracts can remain permanently accessible on-chain. If residual assets remain locked within those systems, attackers may continue searching for overlooked vulnerabilities years after a protocol has been retired.

Similar concerns have emerged elsewhere in the crypto sector. Last month, RetoSwap suspended trading after a second exploit in the Haveno protocol exposed weaknesses in its transaction handling process, forcing the platform to halt activity while developers worked on security fixes.

The back-to-back Aztec incidents also underscore the risks posed by so-called “zombie contracts.” These are deprecated smart contracts that remain live despite no longer serving an active role within a protocol.

Legacy infrastructure has increasingly become a target for attackers. Earlier this month, Thetanuts Finance suffered a $2.1 million exploit linked to a flaw in an older Ethereum vault system, highlighting how vulnerabilities can persist even after projects transition to newer architectures.

Security researchers have repeatedly warned that dormant systems can become attractive targets when they continue holding funds or retain withdrawal functionality long after users have migrated elsewhere. As DeFi protocols mature, safely winding down legacy infrastructure is becoming as important as securing newly deployed code.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

Hacked SpaceXAI and Starlink Accounts Promote SCATMAN Token Before 73.7 ETH Sales
Security & Hacks

Hacked SpaceXAI and Starlink Accounts Promote SCATMAN Token Before 73.7 ETH Sales

by Saravana Kumar Mahendran
July 13, 2026

Promotional content related to the SCATMAN token appeared on the @SpaceXAI and @Starlink X accounts in mid-July 2026. On-chain analytics...

Read moreDetails
Suspected Hedera DeFi Hack Moves $5.8 Million to Ethereum

Bonzo Lend Oracle Exploit Triggers Cross-Chain Fund Transfers on Hedera

July 11, 2026
CodexField on BNB Chain Faces Rug Pull Allegations

BNB Chain Project CodexField Faces Rug Pull Claims After Abnormal Fund Transfers

July 10, 2026
Hackers Target Injective Wallet Keys Through Compromised npm Package

Malicious Injective SDK Package Targets Private Keys and Seed Phrases

July 10, 2026
Ethereum User Loses Nearly $1 Million USDT in Phishing Token Approval Exploit

Phishing Approval Drains 999K USDT From Ethereum Wallet

July 9, 2026
Ctrl Wallet to Permanently Shut Down

Ctrl Wallet to Permanently Shut Down on August 3 After Cardano Security Exploit

July 7, 2026
Trader Loses $2M After ETH Swap to LIT Routes Through AVAIL Pool

Trader Loses $2M After ETH Swap to LIT Routes Through AVAIL Pool

July 7, 2026
Next Post
Tether to Wind Down Alloy and aUSDT as It Shifts Focus to XAUT and Core Products

Tether to Shut Down aUSDT as It Ends Support for Gold-Backed Platform

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Bitcoin Rodney Pleads Guilty as HyperFund Fraud Case Shifts Spotlight to Crypto Promoters

Recommended

  • All
  • News
Polymarket Partners With Blockchain.com to Roll Out Prediction Markets During World Cup Semifinals

Polymarket Partners With Blockchain.com to Roll Out Prediction Markets During World Cup Semifinals

July 14, 2026
UK Defers Capital Gains Tax on Crypto Lending and Liquidity Pools From 2027

UK Defers Capital Gains Tax on Crypto Lending and Liquidity Pools From 2027

July 14, 2026
South Korea Expands Blockchain Strategy With Tokenized Bond Pilot and Crypto Reforms

South Korea Expands Blockchain Strategy With Tokenized Bond Pilot and Crypto Reforms

July 14, 2026
Telegram t.me Domain Suspension Disrupts TON Ecosystem Access

Telegram t.me Domain Suspension Disrupts TON Ecosystem Access

July 14, 2026
Binance.US CEO Eyes 20% U.S. Crypto Market Share as Exchange Accelerates Comeback

Binance.US CEO Eyes 20% U.S. Crypto Market Share as Exchange Accelerates Comeback

July 14, 2026

US Government Transfers $288M in Bitcoin and Ether to Coinbase Prime From Multiple Seized Wallets

July 14, 2026
Bolivia Evaluates USDT Integration

Bolivia Evaluates USDT Integration Into National Payment System as Stablecoin Use Expands

July 13, 2026
BNB Plus to Exit Nasdaq as Shares Transition to OTCQB Trading

BNB Plus to Exit Nasdaq as Shares Transition to OTCQB Trading

July 13, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Tether Leads $7 Million Funding Round in Pact Labs to Bring USA₮ Into U.S. Payroll Infrastructure
  • Polymarket Partners With Blockchain.com to Roll Out Prediction Markets During World Cup Semifinals
  • UK Defers Capital Gains Tax on Crypto Lending and Liquidity Pools From 2027

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.