On June 14, more than $2.1M was withdrawn from Aztec Connect. The attacker exploited a flaw in the logic of cryptographic proof verification.
The suspicious transaction was noticed by CertiK specialists, who reported it on X.
$2.1M Withdrawn From Aztec Connect
According to CertiK, the problem may have been due to incomplete data verification. One of the smart contract functions only checked the beginning of the proof. As a result, token transfer instructions located in another part of the data could pass without full verification.
This likely allowed the attacker to substitute data during the withdrawal and take about $2.19M.
The Aztec Foundation confirmed that they received a report of a possible exploit in Aztec Connect. The team separately emphasized that the attack did not affect the AZTEC token of the ERC-20 standard or the smart contracts of the current Aztec network.
The foundation reminded that Aztec Connect stopped operating three years ago. Since then, Aztec Labs has no longer controlled the system.
The team has already started an investigation, but they cannot intervene in the operation of the old protocol.
“Aztec Labs has no admin keys or control over the system. We cannot pause or update it,” the statement said.
The attack occurred just a few days after the Raydium (RAY) hack. At that time, hackers withdrew about $1.3M from five old liquidity pools on the Solana (SOL) network.
According to DeFiLlama, in June alone, crypto projects have already lost about $43.93M due to hacks and exploits.