Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
    SpaceX IPO: Kraken, Bybit, Coinbase, & Binance Lead the Crypto Rush
    Crypto’s Biggest Hypocrite Arthur Hayes Shills Tokens Then Dumps on His Followers
    Crypto’s Biggest Hypocrite: Arthur Hayes Shills Tokens Then Dumps on His Followers
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

SlowMist Details Root Cause of $2.19M Aztec Connect Exploit

The analysis identifies a mismatch between ZK proof commitments and L1 settlement verification that enabled forged deposits without corresponding asset backing.

Written By:
Shubham Soni

Last updated: 1 hour ago
Published 1 hour ago
Share
SlowMist Details Root Cause of $2.19M Aztec Connect Exploit
Show AI Summary
Users face financial losses due to the $2.19 million exploit of Aztec Connect’s contract
The incident exposes a critical design risk for ZK-rollups, potentially enabling attackers to withdraw unbacked assets
Legacy user assets remain vulnerable as the deprecated contract remains on-chain, posing ongoing security risks

Blockchain security firm SlowMist has published a technical analysis of the $2.19 million exploit targeting Aztec Connect’s deprecated RollupProcessor contract, concluding that the attack stemmed from a flaw in how Layer 1 settlement logic handled transactions committed by the protocol’s zero-knowledge proofs.

According to the report, the attacker exploited a mismatch between the contract’s settlement boundary and the public inputs committed by the ZK proof, creating a discrepancy between Layer 1 and Layer 2 accounting that enabled the withdrawal of assets without corresponding deposits.

✍️ Technical Analysis Published: Analysis of the $2.19M Asset Theft from Aztec Connect

A deprecated Aztec Connect RollupProcessor contract was exploited through a settlement boundary bypass vulnerability, enabling attackers to create an L1/L2 state discrepancy and drain… pic.twitter.com/w6SkUQXkhm

— SlowMist (@SlowMist_Team) June 15, 2026

The incident highlights a critical design risk for ZK-rollups: if Layer 1 settlement checks do not fully align with the data committed by zero-knowledge proofs, attackers may create inconsistent L1 and L2 states and withdraw unbacked assets.

Settlement boundary mismatch enabled the exploit

The exploit targeted the deprecated Rollup Processor contract, which has remained on-chain since Aztec Connect was retired in March 2024 because it continues to custody legacy user assets.

SlowMist found that the contract’s settlement loop processed transactions based on the numRealTxs parameter, while the accompanying ZK proof committed to a larger set of decoded public input slots. The difference between those two values created a gap that attackers could manipulate.

According to the report, the forged transactions were included in the ZK proof and accepted into the Layer 2 state but were never examined during Layer 1 settlement verification. As a result, the protocol recorded deposits on Layer 2 without deducting assets from the Layer 1 liquidity pool.

Exploit created divergent L1 and L2 states

SlowMist described the vulnerability as a settlement boundary bypass, where the same calldata was interpreted differently by two separate verification paths. The ZK proof committed to 32 public input slots, while the Layer 1 settlement contract processed only the first slot based on the attacker-controlled numRealTxs value. This inconsistency allowed forged deposits in the remaining slots to be accepted by the rollup while remaining invisible to Layer 1 validation.

The report notes that the protocol’s security model relied on both the smart contract and the ZK circuit, enforcing the same assumptions. Once the circuit failed to constrain the unused slots, the Layer 1 contract lacked independent checks to detect the manipulated values.

Attack executed in a single atomic transaction

According to SlowMist, the exploit was carried out through 14 consecutive processRollup() calls executed within a single atomic transaction.

The first seven rollups allegedly created unsupported balances on Layer 2 by inserting forged deposits into the unverified slots. The following seven rollups withdrew those balances as legitimate assets from the Layer 1 pool. The attacker ultimately drained approximately $2.19 million, including ETH, DAI, wstETH, LUSD, yvDAI, yvWETH, and yvLUSD, from the RollupProcessor contract.

SlowMist’s on-chain investigation found that the stolen assets were routed through an intermediate attack contract before being transferred to the attacker’s externally owned wallet (EOA). As of June 15, the security firm said all of the stolen assets remained in that wallet and had not yet been moved or laundered.

Lessons for rollup developers

SlowMist concluded that rollup protocols should ensure the scope of Layer 1 settlement verification exactly matches the public inputs committed by zero-knowledge proofs.

The firm also recommended comprehensive external audits focused on Layer 1 and Layer 2 state consistency, calldata decoding logic, and independent verification of ZK public inputs. For deprecated smart contracts that continue to hold user funds, SlowMist advised projects to migrate or remove legacy assets to reduce long-term security exposure.

Recent exploits highlight risks in legacy smart contracts

The Aztec Connect incident follows several recent crypto exploits involving both legacy infrastructure and compromised administrative controls. On June 10, Solana-based decentralized exchange Raydium disclosed that attackers exploited a validation flaw in its deprecated AMM V3 program to drain approximately $1.34 million from five inactive liquidity pools that had remained on-chain since the protocol was phased out in 2021. Raydium said no current users or active programs were affected.

Separately, Humanity Protocol disclosed that a June 8–9 attack involving compromised private keys and bridge administration controls resulted in the theft or unauthorized minting of approximately 447 million H tokens across Ethereum and BNB Smart Chain. The project said attackers gained control of multiple bridge-related administrative contracts, allowing them to drain existing tokens and mint new ones. 

Together, the incidents underscore how dormant smart contracts and compromised administrative privileges continue to be major attack vectors across the crypto ecosystem.

Also Read: XRP Jumps 10% Ahead of June FOMC Meeting As OI Rises to $2.7B

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:BlockchainCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Crypto Market Today ZEC, XRP Lead as $526M Shorts Get Wiped
Crypto Market Today: ZEC, XRP Lead as $526M Shorts Get Wiped
$2.1M Exploit Hits Thetanuts Inside the Latest DeFi Flash Loan
$2.1M Exploit Hits Thetanuts: Inside the Latest DeFi Flash Loan
Why Is Zcash (ZEC) Price Up Today?
Why Is Zcash (ZEC) Price Up Today?
How Indian Authorities Traced a ₹64.55 Cr Coinbase Phishing Scam
How Indian Authorities Traced a ₹64.55 Cr Coinbase Phishing Scam
248K Affected India's ED Cracks Down on Alleged ₹500 Crore Crypto MLM
248K Affected: India’s ED Cracks Down on Alleged ₹500 Crore Crypto MLM

Find Us on Socials

You may also like

Kraken Rolls Out CFTC-Regulated Perpetual Futures to US Clients

Kraken Rolls Out CFTC-Regulated Perpetual Futures to US Clients

Crypto's Dark Side: Arichain Shuts Down Amid "We Are Scammers" Confession

Crypto’s Dark Side: Arichain Shuts Down With “We Are Scammers” Confession

UK Investment Scam Losses Hit £221M as AI Fuels Crypto Fraud

UK Investment Scam Losses Hit £221M as AI Fuels Crypto Fraud

Inside Polymarket’s Record $2.34 Billion FIFA World Cup 2026 Betting Frenzy

Inside Polymarket’s Record $2.34 Billion FIFA World Cup 2026 Betting Frenzy

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information