
Aztec Labs said it is investigating a second exploit in four days affecting retired Aztec infrastructure, while BlockSec linked the latest drain to a separate validation flaw in an old immutable rollup.
Aztec Labs is investigating an exploit of a deprecated Aztec payments product that drained about $2.15 million in crypto assets, marking the second attack on retired Aztec infrastructure in four days. PeckShield estimated the latest exploit took 1,158 ETH, 150,000 DAI and about 0.47 renBTC, while BlockSec said the incident appears related to the June 14 Aztec exploit but struck a different pool through a separate entry point. BlockSec attributed the drain to a validation flaw that let an attacker withdraw funds while still passing onchain verification checks, adding that it was not the same bug as the earlier incident even though both involved circuit public input binding issues and a similar execution trace. Aztec Labs said it would provide further updates, and the Aztec Foundation said the affected product was an immutable stage 2 rollup deprecated four years ago with no link to the current network or the AZTEC ERC20 token.