
BlockSec said attackers drained roughly $2.15 million from deprecated Aztec Connect contracts by exploiting a proof-validation flaw that Aztec Labs said cannot be paused or upgraded because control was renounced years ago.
Attackers drained roughly $2.15 million from deprecated Aztec Connect contracts on Ethereum, with BlockSec identifying losses of about 909 ETH, 270,000 DAI and 167 wstETH tied to a proof-validation flaw in legacy RollupProcessorV3 infrastructure. Aztec Labs said Aztec Connect was deprecated three years ago and that it holds no admin keys or control over the system, leaving it unable to pause or upgrade the contracts. The Aztec Foundation said the incident is unrelated to the AZTEC ERC-20 token smart contracts or the current Aztec network, which is focused on private smart contracts. Security researchers said the bug stemmed from incomplete validation at the boundary between the verified transaction set and Layer 1 settlement, allowing manipulated withdrawals from an immutable legacy bridge that once used zero-knowledge proofs to connect users with DeFi protocols such as Aave and Lido.