Back to Home

Hackers attacked Aztec for the second time in a week: $2.16 million loss

In a week, hackers twice attacked outdated smart contracts of the Aztec privacy protocol, stealing over $4.3 million. The incidents affected Aztec Connect and Private Rollup Bridge, which were deactivated in 2022-2023 but still held assets. The exploits demonstrate a fundamental problem of contract immutability and inability to update, creating risks for the entire DeFi industry.

Aztec hack: repeated attack on outdated privacy protocol
Advertisement 728x90

Hackers Attack Aztec's Deprecated Product for the Second Time in a Week

The privacy protocol Aztec suffered an exploit worth approximately $2.16 million targeting a deprecated payment product. The attack, linked to a validation vulnerability, occurred four days after a similar $2.1 million hack, raising concerns about the security of outdated but still-used smart contracts.


Brief Analysis: What's Really Happening

At first glance, what happened to Aztec is just another DeFi protocol hack—there have been over 30 in 2026, with total stolen funds exceeding $600 million. However, the double attack on deprecated contracts that still hold assets reveals a systemic problem threatening not only Aztec but the entire philosophy of decentralization. This is about "legacy risks"—time bombs embedded in the architecture of early DeFi protocols that their creators, striving for maximum decentralization, made ungovernable and immune to patches but not to attacks.

Google AdInline article slot

Between June 14 and June 17, 2026, hackers stole over $4.3 million from Aztec by attacking two different but equally defenseless smart contracts that were deactivated back in 2022 and 2023. The first hack affected Aztec Connect, the second—Private Rollup Bridge. Although the Aztec foundation rushed to assure the market that the current network and AZTEC token were unaffected, the token price still dropped about 1.6%, showing that investor confidence is shaken and they do not distinguish between the project's "old" and "new" infrastructure.

Timeline and Context

The first incident occurred on June 14, 2026, when an attacker found a vulnerability in the Aztec Connect contract, which was officially shut down in March 2023. It was a classic attack on a mismatch in the zero-knowledge proof verification process. The proof verification system processed transactions in batches of 32, while the on-chain settlement code processed only the number of transactions declared in the batch. The hacker exploited this mismatch to create 14 fake batches and withdraw about 909 ETH, 270,513 DAI, and other assets including wstETH, totaling approximately $2.19 million. The next day, June 15, the same technique was used to withdraw another $88,000 from remaining positions on DeFi bridges.

Google AdInline article slot

However, the most alarming was the second incident, occurring just three days later—on June 17. This time, the target was Private Rollup Bridge, an old bridge launched in 2021 and shut down in 2022. The exploit was related to the emergency withdrawal function escapeHatch() in the RollupProcessor contract. This function was designed for emergency withdrawals in case of main process failure, but it turned out to lack critical authorization checks, including signature verification. The hacker exploited the vulnerability by setting the rollupSize parameter to 0, causing the validator to accept a fake proof and withdraw 1,158 ETH, 150,000 DAI, and 0.46 renBTC worth about $2.16 million.

Thus, the attacks differed in technique and targeted different contracts, but they shared one fundamental problem: both contracts were immutable, and the Aztec team had no administrative keys to stop or upgrade them.

Who Wins and Who Loses

Google AdInline article slot

In this situation, there are both obvious and implicit losers, as well as those who may benefit from others' misfortune.

Losers: Users and asset holders. The direct loss of $4.3 million is funds of real users who, for some reason, did not withdraw their assets from deprecated contracts despite the Aztec team warning about it since 2024. These people didn't just lose money—they lost it in a system designed as a security guarantor.

Losers: Aztec's reputation and the private zk-rollup segment. Although the hack technically did not affect the current Aztec network, it is a serious blow to trust in the entire project and the technology as a whole. Investors start asking: "If developers can't protect old contracts, how will they protect new ones?" Risky assets like AZTEC show increased volatility in response to such news.

Indirect losers: The entire DeFi industry. These hacks occur against a worrying trend: according to DefiLlama, in the first half of June 2026 alone, DeFi protocol losses exceeded $43 million. Incidents with Aztec, Thetanuts Finance, and other projects create a narrative of "DeFi as the Wild West," which could push regulators toward even stricter actions. This is particularly untimely given the MiCA deadline.

Winners: Competing projects and insurance protocols. Projects like zkSync, StarkNet, or Polygon, which offer more manageable and upgradeable solutions, can use this situation as an argument for their architecture. Meanwhile, DeFi insurance protocols (e.g., Nexus Mutual) may see increased demand for their policies as the market recognizes new risks.

Winners: Specialized blockchain security firms. Every new hack means contracts for firms like PeckShield, SlowMist, and BlockSec, which conduct investigations and audits. They become critical for the survival of the entire ecosystem.

What the Media Isn't Saying

Superficial articles focus on the hack facts and damage amounts but miss several fundamental aspects with deeper implications.

Insight #1: Immutability as the "Achilles' heel" of decentralization. When Satoshi Nakamoto created Bitcoin, the idea of immutable code was a cornerstone of trust. However, for complex DeFi protocols, immutability becomes a curse. Projects renounce ownership to prove decentralization but end up creating "digital ruins"—contracts that no one can fix. Blockchain analyst Blockful aptly noted: "Old contracts become open targets for hackers, and when protocols disclaim responsibility for their maintenance, they become even more attractive targets." Aztec took this step in April 2024 to allow users to withdraw funds independently without team involvement. This decision now looks like a costly mistake.

Insight #2: Technical default is not the only problem. The second hack was possible due to a vulnerability in the "escape hatch" mechanism. This is not just a code bug; it's a fundamental architectural flaw that could only be detected and fixed with active control. In effect, the Aztec team created a "backdoor" in the system, then handed over the keys—and didn't check if the door was locked. This was not just a proof verification failure; it was a failure in designing the system's economic security.

Insight #3: A signal to the market: How much can we trust "old" and "proven" protocols? The market is used to thinking that the longer a smart contract runs and the more funds it has processed, the safer it is. The series of Aztec hacks proves the opposite: over time, deprecated contracts become more vulnerable, not less, because they do not adapt to new attack methods, and their source code becomes a subject of intense study by hackers. SlowMist analysts have already warned that old contracts containing assets are turning into a permanent "time bomb."

Forecast: Next 30 Days and 90 Days

30-day forecast (July 2026): Panic among holders of "forgotten" assets. July 2026 will see a "cleanup" of old contracts. Users who haven't yet withdrawn funds from deactivated protocols (not just Aztec but others) will start mass withdrawals, fearing similar attacks. This will create additional pressure on the market, not so much on prices but on liquidity of secondary assets. Additionally, we will see increased activity from audit firms offering "emergency audits" of old contracts.

90-day forecast (September 2026): Regulatory response and paradigm shift. Given the overall context of tightening regulation in the EU (MiCA) and the US, such incidents will become "food" for legislators. Requirements may emerge for protocols not just to deactivate but to "freeze" or destroy old contracts, or to provide insurance coverage for funds left in them. The market will react with increased capitalization of projects offering manageable upgradeable smart contracts and decreased interest in radically decentralized but ungovernable protocols.

Editorial Forecast

In the next 24–72 hours, we expect continued downward pressure on the AZTEC token, which has already lost 1.6% after the hack news. The key support level is $0.015; if broken, a correction to $0.014 is possible. Confidence level is medium, as the main risk to the forecast is that Aztec Labs or the foundation may announce a compensation program for affected users, which could temporarily stabilize the price. However, fundamentally, trust in the project is undermined, and without positive news about mainnet development, token recovery in the short term is unlikely. This is the editorial opinion, not an investment recommendation.

— Editorial Team

Advertisement 728x90

Read Next

Partner News