The old Aztec infrastructure has come under attack for the second time in a few days. The new incident affected not an active product, but an outdated contract that continued to hold assets on the blockchain.
According to SlowMist, the attacker withdrew about $2.15 million. The stolen funds included 1,158 ETH, 150,000 DAI, and a small amount of renBTC. The main takeaway from analysts is unpleasant for the entire industry: a closed product does not stop being a risk if there is still money left in its contracts.
The Hacker Tricked the Rollup Check
A preliminary analysis by SlowMist points to an error in the verification mechanism. The attacker used a false rollup proof, after which the contract accepted it as valid and released assets from reserves.
For a regular user, such an attack is almost invisible. A transaction goes through the network, the contract executes its built-in logic, and the funds are sent to the attacker’s address.
The problem is that the old system was still working as code, even though the product had long ceased to be part of the current infrastructure. It is in such places that errors can live for years, waiting for someone to find a way to exploit them.
Aztec Could Not Stop the Withdrawal of Funds
Aztec Labs confirmed the hack and reported that the funds were taken from an immutable smart contract of its old payment product. It was decommissioned back in 2022.
The team specifically emphasized that they did not have admin keys or a function to stop transactions. This means the developers could not quickly pause the contract or intervene after the attack began.
This situation shows the downside of immutability. A smart contract cannot be quietly changed, and this protects users from arbitrary actions by the team. But if there is a vulnerability in the code and assets remain, it can be impossible to stop the problem.
This Is Not the Same Hack as on Sunday
The new incident is different from the attack on Aztec Connect, which happened a few days earlier. At that time, about $2.1 million was also withdrawn from another old contract.
Aztec Connect was a private rollup that was closed in March 2023. After that, the team stopped deposits and switched to developing Aztec Network, the next version of its infrastructure.
But closing the product did not mean the risk disappeared completely. User assets remained in old contracts, and this is exactly what made them an attractive target.
Abandoned Infrastructure Becomes a Reward for Hackers
The Aztec case is not unique. Earlier in June, a similar story happened with Raydium, where about $1.3 million was withdrawn from outdated pools.
In all these cases, the problem is similar. The project develops new versions, removes old interfaces, and stops actively supporting the previous code. But the contract remains on the network, and with it, assets and possible bugs remain.
Blockful described such contracts as permanent “rewards” for hackers. If the team no longer monitors the old product and there is still money inside, attackers have a clear target.
Why Closing the Product Is Not Enough
In traditional software, an old system can be turned off. In blockchain, it is more complicated. A smart contract continues to exist if it is deployed on the network, and users or reserves are still connected to it.
Therefore, ending a product should include not only an announcement and stopping new deposits. Asset migration, user warnings, monitoring of balances, and a clear deadline for closing old withdrawal routes are needed.
If this is not done, the old contract turns into technical debt. The only difference is that this debt can hold real assets worth millions of dollars.
The Risk Is Especially High for Private Systems
Aztec worked with private transfers and rollup infrastructure. Such systems are more complex than regular DeFi contracts because they use proofs, special checks, and more complicated accounting logic.
The more complex the mechanism, the higher the chance that a non-trivial bug will remain. Especially if the product is no longer being developed and the team is focused on a new version.
This does not mean that private protocols are inherently unsafe. But for them, long-term audits, a plan for closing old systems, and control of assets remaining in outdated contracts are especially important.
Users Also Bear Part of the Risk
Many asset holders do not withdraw funds immediately after a product is closed. Sometimes the amount seems small, sometimes the user simply forgets about the old position, and sometimes they do not realize the contract is no longer supported.
For a hacker, this does not matter. If a total balance accumulates in the old system, it becomes a target. Even scattered user leftovers can add up to a significant amount.
Therefore, when closing a bridge, pool, or rollup, it is better not to leave funds “for later.” If the team offers migration or withdrawal, delaying it is risky.
SlowMist Advises Withdrawing Assets From Old Contracts
After the attacks, SlowMist recommended that protocols organize the transfer of funds from outdated contracts. This is especially important if the code cannot be updated or stopped.
This approach should become part of normal operational security. Projects need to think not only about launching new products but also about safely ending old ones.
For the industry, this is a painful but necessary lesson. Old contracts do not disappear from the blockchain on their own. If assets remain in them, they continue to be part of the attack surface.
What Is Next?
Aztec needs to explain which outdated contracts may still contain assets and what measures the team will offer users. After two attacks in a week, the market will expect not only a technical analysis but also a plan to reduce risk in the old infrastructure.
For other protocols, this is a warning. If a project closes a product but does not withdraw assets from contracts, it leaves hackers with an open opportunity to look for bugs.
The main takeaway is simple. The Aztec hack shows that an outdated contract can be more dangerous than a new product. It is checked less, monitored worse, and often considered a closed chapter. But as long as it holds funds, it is not an archive but an active target for attack.
Read More: Upbit Listing Caused Sharp Price Swings for Nine Altcoins at Once