CertiK flags suspicious $2.19 million transfer tied to deprecated Aztec Connect

CertiK flags suspicious $2.19 million transfer tied to deprecated Aztec Connect

BlockSec said attackers drained roughly $2.15 million from deprecated Aztec Connect contracts by exploiting a proof-validation flaw that Aztec Labs said cannot be paused or upgraded because control was renounced years ago.

ETH
DAI
AAVE

Fact Check
CertiK's own alert confirms detection of a ~$2.19M suspicious drain from Aztec's Router contract (the CertiK flag and amount). Aztec Labs confirmed investigating a potential exploit of deprecated/retired Aztec Connect (~$2.1M), matching the Aztec Foundation portion of the claim. The RollupProcessorV3 proof-validation flaw and seven affected assets are corroborated by the Our Crypto Talk report and search snippets referencing BlockSec/Phalcon's analysis. The only element not directly retrieved from a primary BlockSec Phalcon post is the exact '$2.15 million' figure, but its substance (proof-validation flaw in RollupProcessorV3 across seven assets) is independently confirmed, so the claim is well supported overall.
    Reference123
Summary

Attackers drained roughly $2.15 million from deprecated Aztec Connect contracts on Ethereum, with BlockSec identifying losses of about 909 ETH, 270,000 DAI and 167 wstETH tied to a proof-validation flaw in legacy RollupProcessorV3 infrastructure. Aztec Labs said Aztec Connect was deprecated three years ago and that it holds no admin keys or control over the system, leaving it unable to pause or upgrade the contracts. The Aztec Foundation said the incident is unrelated to the AZTEC ERC-20 token smart contracts or the current Aztec network, which is focused on private smart contracts. Security researchers said the bug stemmed from incomplete validation at the boundary between the verified transaction set and Layer 1 settlement, allowing manipulated withdrawals from an immutable legacy bridge that once used zero-knowledge proofs to connect users with DeFi protocols such as Aave and Lido.

Terms & Concepts
  • zero-knowledge proofs: Cryptographic proofs that allow transactions or computations to be verified without revealing the underlying details.
  • Layer 1 settlement: The process of finalizing transactions on the base blockchain rather than on a secondary scaling system.
  • immutable legacy bridge: An older cross-chain or rollup-linked contract system that remains onchain and cannot be changed after deployment.