🚨 Approximately 2.1 million dollars in ETH, DAI, and wstETH have been drained from obsolete $ETH smart contracts. 🕵️‍♂️ The loophole exploited was in a privacy🚨 Approximately 2.1 million dollars in ETH, DAI, and wstETH have been drained from obsolete $ETH smart contracts. 🕵️‍♂️ The loophole exploited was in a privacy

2.1 million dollars drained from obsolete Aztec Connect contracts! What does this reveal about DeFi security?

2026/06/15 21:21
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A security breach targeting Aztec Connect smart contracts has led to the drainage of digital assets valued at approximately 2.1 million dollars. According to on-chain security firm BlockSec, the attacker managed to seize 909 ETH, 270,000 DAI, and 167 wstETH. The incident is especially notable due to the vulnerability residing in a privacy bridge that had been out of service for three years, and, according to statements from Aztec Labs, there is now no mechanism in place to intervene within the system.

How was the old bridge exploited?

Prior to being decommissioned in March 2023, Aztec Connect operated as a zk rollup bridge, enabling users to interact with decentralized finance platforms such as Aave and Lido. By March 2024, Aztec Labs had completely shut down its own sequencer infrastructure. Aztec is known for focusing on smart contracts that prioritize user privacy.

Mini glossary: A zk rollup is a scaling solution that batches many transactions off-chain and submits a summary to the main chain. Zero knowledge proofs are cryptographic methods that let a transaction be verified as legitimate without disclosing its details.

Analysis by BlockSec’s Phalcon platform indicates the flaw stemmed from a mismatch between the batch of validated transactions and the L1 consensus process. Security firm CertiK noted that the issue was linked to an incomplete verification of proof data. In essence, a contract function only checked the initial part of the proof, leaving token transfer instructions in another segment unverified. This allowed the attacker to manipulate the withdrawal process and extract funds.

Aztec Labs and foundation respond

Aztec Labs confirmed they are investigating the incident but reiterated their inability to intervene directly. In a separate statement, the Aztec Foundation stressed that the breach does not affect the AZTEC ERC 20 token or any contracts tied to the current Aztec network, explaining that today’s network focuses solely on privacy-centric smart contracts.

When Aztec Labs discontinued the bridge, it relinquished all administrative control as part of its commitment to privacy. However, this decision has now proven problematic, as it leaves no option to patch security flaws discovered later on.

Financial losses and greater implications

Data from DeFiLlama put the total value locked in Aztec Connect contracts at around 2.15 million dollars before the attack, suggesting that nearly all locked funds were compromised in the exploit.

Asset Amount
ETH 909
DAI 270,000
wstETH 167
Total value locked Approximately 2.15 million dollars

The report highlights that the remaining assets in the contracts at the time of the attack were not actively monitored. This reopens the debate around the risks of leaving funds in outdated contracts, where security entirely depends on the original code base, even if the project has since moved forward.

As of mid June, total losses from similar exploits in the crypto ecosystem have reached 43.93 million dollars. Earlier in the month, Gnosis Pay and TesseraDAO faced comparable breaches, with TesseraDAO losing 2.5 million dollars on the BNB Chain. These incidents underline that discontinued platforms remain attractive targets for attackers.

The post 2.1 million dollars drained from obsolete Aztec Connect contracts! What does this reveal about DeFi security? appeared first on COINTURK NEWS.

Market Opportunity
Ethereum Logo
Ethereum Price(ETH)
$1,828.04
$1,828.04$1,828.04
-0.93%
USD
Ethereum (ETH) Live Price Chart

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel