← Radar

Incident case file

Sign in to watch

Aztec Connect ZK-Rollup Settlement Boundary Exploit — RollupProcessorV3

Incident date June 14, 2026

1 views

ClosedEthereum L1Smart contract exploit — ZK-rollup settlement boundary bypassCluster: AZC-ETH-2026-06

Estimated loss

$2.2M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 0x0F18D8b44a740272f0be4d08338d2b165b7EdD17 (funded via Tornado Cash)

Funds moved to: 909 ETH + 270,513 DAI + 167.89 wstETH + Yearn vault tokens (yvDAI/yvWETH/LUSD/yvLUSD), ~$2.19M total, drained via tx 0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1. Funds moved through helper contract 0x06f585F74e0DA633Ae813A0f23Fb9900B61d0fcD; no further cash-out path publicly disclosed. 0% recovered — contract is immutable, admin authority renounced April 2024.
Victim contract: RollupProcessorV3 proxy 0xFF1F2B4ADb9dF6FC8eAFecDcbF96A2B351680455 (Aztec Connect, deprecated since March 2023). Helper contract deployed by attacker: 0x06f585F74e0DA633Ae813A0f23Fb9900B61d0fcD. 14 processRollup() calls (rollupId 13277-13290) executed atomically in one transaction. NOTE: a second, smaller continuation exploit (~$88K, rollupId 13291-13304) hit the same contract on June 15, 2026 targeting residual wrapped Aave/Compound/Euler positions — documented only by Blocka

Timeline: On June 14, 2026 at approximately 12:16-12:20 UTC, an attacker deployed a sequence of helper contracts on Ethereum, detected by Blockaid's onchain monitoring about 6 minutes before the exploit. At 12:26 UTC, the attacker executed transaction 0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1, calling processRollup() 14 times (rollupId 13277-13290) within a single atomic transaction, draining 909 ETH, 270,513 DAI, 167.89 wstETH and various Yearn vault tokens (yvDAI, yvWETH, LUSD, yvLUSD) — approximately $2.19M total. The root cause was a mismatch between the ZK proof system, which validates batches in fixed groups of 32 transaction slots, and the L1 settlement code, which only processes the first numRealTxs declared 'real' transactions — leaving a verification gap exploitable to credit internal balances without matching deposits. CertiK Alert and AMLBotHQ issued the first public alerts within minutes; Aztec Labs confirmed the exploit the same day, clarifying that Aztec Connect was deprecated three years earlier and that the team holds no admin keys over the immutable contract. BlockSec Phalcon published a comparative technical analysis on June 17, 2026, classifying the bug as a 'public input binding issue' — the same general class later identified in the unrelated June 17 Aztec Private Rollup Bridge exploit. A second, smaller exploit (~$88K) hit the same contract on June 15, 2026 (~04:00 UTC) via a freshly funded wallet, targeting residual wrapped DeFi bridge positions; this continuation is documented only in Blockaid's June 16, 2026 post-mortem blog. As the contract is immutable and Aztec Labs renounced all admin authority in April 2024, no patch, pause, or fund recovery is technically possible. 0% of funds have been recovered.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)