Aztec's older version of its privacy bridge has been attacked again, with approximately $2.16 million stolen.
Coinpedia
06-18 18:20
Ai Focus
Aztec's legacy privacy bridge suffered another attack, resulting in approximately $2.16 million in losses. The team stated that the current network and AZTEC tokens are unaffected.
Helpful
No.Help

Aztec's discontinued old bridging product has been attacked again, resulting in the transfer of approximately $2.16 million in assets. This is the second time in a week that the team has come under scrutiny due to a vulnerability in a legacy product. Aztec Labs stated that the affected product was the Private Rollup Bridge, which was launched in 2021 and shut down in 2022, and is not directly related to the current Aztec network or the AZTEC token.

The stolen assets include ETH and DAI.

Blockchain security firm SlowMist claims the attackers targeted Aztec's older version of Private Rollup Bridge. Although the product is no longer in use, the related contracts, being immutable, remain on the blockchain and can still be invoked.

SlowMist disclosed that the transferred assets included approximately 1,158 ETH, 150,000 DAI, and 0.47 renBTC. Based on the prices at the time, the total loss was approximately $2.16 million.

Following the news, the AZTEC token fell by about 1.6%, with the price dropping to around $0.016.

The vulnerability lies in the emergency withdrawal function.

SlowMist researchers stated that the problem lies in the bridging contract's escape hatch emergency withdrawal function. This function was originally intended for fund withdrawals in exceptional circumstances, but the contract failed to perform the necessary security checks.

The investigation revealed that the contract failed to adequately verify withdrawal requests and directly trusted certain transaction data without independently verifying the ownership of funds. Attackers could therefore submit seemingly valid evidence, but with tampered withdrawal information, to induce the contract to release assets that should not have been approved.

It was also disclosed that the wallet that carried out the attack had received approximately 0.134 ETH from HitBTC as initial funds before the operation.

Aztec states that its live network and tokens are unaffected.

Aztec Labs stated that the affected infrastructure is unrelated to the current Aztec network, existing smart contracts, and the AZTEC token. The team explained that this older bridging product was shut down four years ago and was a non-upgradeable, non-pauseable Stage 2 rollup architecture.

Since the contract itself is immutable, the team is currently unable to suspend, upgrade, or directly intervene in the relevant system, nor does it hold management authority over the infrastructure.

Just days earlier, Aztec's discontinued Aztec Connect product was also found to have been attacked, resulting in losses exceeding $2.15 million. These two incidents, occurring in quick succession, demonstrate that legacy contracts, even when discontinued, can still pose ongoing security risks.

Tip
$0
Like
0
Save
0
Views 307
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Aztec Network suffers another attack within three days, with approximately $2.21 million stolen.
Aztec Network was attacked for the second time in three days, with approximately $2.21 million in digital assets stolen. The issue points to a lack of access control and verification in the emergency withdrawal mechanism.
AMBCrypto
·2026-06-18 21:21:06
813
Aztec Network's overpass was exploited, resulting in a loss of approximately $2.16 million.
Aztec Network's Private Rollup Bridge was exploited, with on-chain data showing a loss of approximately $2.16 million, involving ETH, DAI, and renBTC.
U.Today
·2026-06-18 20:21:15
912
Aztec suffered its second attack in a week, resulting in losses of approximately $2.15 million.
Aztec suffered its second attack in a week, with old payment product contracts being exploited by forged rollup credentials, resulting in a loss of approximately $2.15 million.
Coinpaper
·2026-06-18 21:31:06
389
Aztec's old contract suffered two attacks within three days, resulting in losses exceeding $4 million.
Aztec's two deactivated old contracts were attacked twice within three days, resulting in a total loss of over $4 million. The current network and AZTEC tokens are unaffected.
CoinJournal
·2026-06-18 20:30:00
451
Allbirds, after transforming into an AI company, has changed its name to Smartbird, and a new CEO has begun assembling a team.
Allbirds has spun off its footwear business and renamed it Smartbird. The new CEO says he will build a team from scratch to focus on AI infrastructure services that emphasize data sovereignty.
TechCrunch
·2026-06-19 21:02:20
724