Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Aztec Network’s RollupProcessor Exploited for $2.21 Million 

This exploit follows closely on the heels of a separate ~$2.19 million attack days earlier on its deprecated Aztec Connect RollupProcessorV3 contract, which was compromised via a ZK-rollup settlement boundary bypass.

Written By Gopal Solanky
Published 2026-06-18·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Aztec Network’s RollupProcessor Exploited for $2.21 Million
Show AI Summary
The Aztec Network exploit highlights broader vulnerabilities in zero-knowledge proof verification and access control within ZK-rollup architectures.
Recurring security breaches in Aztec Network underscore long-term risks associated with immutable smart contracts holding residual funds.
The incident marks the second significant DeFi exploit disclosed by SlowMist in a short timeframe, emphasizing the need for enhanced security measures.

Blockchain security firm SlowMist has disclosed a significant exploit targeting Aztec Network’s RollupProcessor contract, resulting in the theft of approximately 1,158 ETH, 150,000 DAI, and 0.4696 renBTC—totaling around $2.21 million USD. 

The attack exploited the escapeHatch() function in the RollupProcessor contract at address 0x7379…2a2ba. According to SlowMist’s analysis, this function lacked essential access controls, such as an onlyOwner modifier, rollup provider authorization, or signature verification. 

🚨SlowMist TI Alert🚨@aztecnetwork has been exploited again.

💸 Loss: 1,158 ETH+150,000 DAI+0.4696 renBTC (~$2,209,704.23 USD)

🔍 Root Cause: The `RollupProcessor.escapeHatch()` function (`0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba`) lacks access control: no `onlyOwner`, no…

— SlowMist (@SlowMist_Team) June 18, 2026

The TurboVerifier contract at 0x48cb…e8ce8 accepted escape hatch proofs even when rollupSize was set to zero. Consequently, the processDepositsAndWithdrawals() function trusted spoofed proofData public inputs—including publicOutput, outputOwner, and assetId—without validating actual fund ownership or withdrawal balances.

This vulnerability enabled the attacker’s externally owned account (0x6952…8e97f) to execute unauthorized withdrawals, including a direct drain of 1,158 ETH in a single transaction.

Source: Etherscan

Aztec confirms incident involving deprecated product

Following the disclosure, Aztec Labs confirmed it was investigating a potential exploit affecting a deprecated Aztec Payments product launched in 2021. The team said approximately $2 million was transferred from the immutable smart contract, adding that the affected product is a Stage 2 rollup that was sunset in 2022.

Aztec Labs emphasized that it holds no administrative keys or control over the deprecated system, meaning the contract cannot be paused or upgraded. The company also clarified that the latest exploit is separate from the June 14, 2026 attack targeting the deprecated Aztec Connect product and said additional updates will be shared as the investigation progresses.

We are investigating a potential exploit affecting a deprecated Aztec payments product from 2021. ~$2m was transferred from the immutable smart contract in transaction:https://t.co/FS4JoNnfiJ

The deprecated product is an immutable stage 2 rollup that was sunset in 2022.…

— Aztec Labs (@AztecLabs_) June 18, 2026

The incident highlights persistent risks in zero-knowledge proof verification and access control mechanisms within ZK-rollup architectures, even in active components of the protocol.

Aztec Network, a leading privacy-focused Ethereum ZK-rollup, has faced recent scrutiny. This exploit follows closely on the heels of a separate ~$2.19 million attack days earlier on its deprecated Aztec Connect RollupProcessorV3 contract, which was compromised via a ZK-rollup settlement boundary bypass. While the current network remains distinct, the repeated incidents underscore the long-tail risks associated with immutable smart contracts holding residual funds.

This Aztec breach represents the second DeFi exploit disclosed by SlowMist in hours. The first involved LittleBoyPlus being drained on BNB Smart Chain, where a flaw in the LBPHashrate._update() function allowed unauthorized token minting and a subsequent drain of roughly 377,642 USDT (~610 BNB) through PancakeSwap liquidity imbalances. 

The events serve as a stark reminder for DeFi projects to prioritize rigorous audits, robust authorization logic, and ongoing monitoring of both active and legacy contracts to safeguard user assets in an evolving threat landscape.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Coinbase Stock Prediction: Can COIN Defy August’s Losing Streak?
July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave
Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave
DeFi Kingdoms to Shut Down DFK Chain on August 28, Begins Avalanche Migration
DeFi Kingdoms to Shut Down DFK Chain on August 28, Begins Avalanche Migration
AAVE Drops 7% as Selling Pressure Pushes Token Below $90
AAVE Drops 7% as Selling Pressure Pushes Token Below $90

Find Us on Socials

You may also like

Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M

Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M 

Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

Bitcoin’s Invisible Risk: Coldcard Mk3 Firmware Bug Leaves BTC Wallet Seeds Exposed, $38M Drained 

Bitcoin’s Invisible Risk: Coldcard Mk3 Firmware Bug Leaves BTC Wallet Seeds Exposed, $38M Drained 

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information