Incident case file
Sign in to watchAztec Connect ZK-Rollup Settlement Boundary Exploit — RollupProcessorV3
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x0F18D8b44a740272f0be4d08338d2b165b7EdD17 (funded via Tornado Cash)
Timeline: On June 14, 2026 at approximately 12:16-12:20 UTC, an attacker deployed a sequence of helper contracts on Ethereum, detected by Blockaid's onchain monitoring about 6 minutes before the exploit. At 12:26 UTC, the attacker executed transaction 0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1, calling processRollup() 14 times (rollupId 13277-13290) within a single atomic transaction, draining 909 ETH, 270,513 DAI, 167.89 wstETH and various Yearn vault tokens (yvDAI, yvWETH, LUSD, yvLUSD) — approximately $2.19M total. The root cause was a mismatch between the ZK proof system, which validates batches in fixed groups of 32 transaction slots, and the L1 settlement code, which only processes the first numRealTxs declared 'real' transactions — leaving a verification gap exploitable to credit internal balances without matching deposits. CertiK Alert and AMLBotHQ issued the first public alerts within minutes; Aztec Labs confirmed the exploit the same day, clarifying that Aztec Connect was deprecated three years earlier and that the team holds no admin keys over the immutable contract. BlockSec Phalcon published a comparative technical analysis on June 17, 2026, classifying the bug as a 'public input binding issue' — the same general class later identified in the unrelated June 17 Aztec Private Rollup Bridge exploit. A second, smaller exploit (~$88K) hit the same contract on June 15, 2026 (~04:00 UTC) via a freshly funded wallet, targeting residual wrapped DeFi bridge positions; this continuation is documented only in Blockaid's June 16, 2026 post-mortem blog. As the contract is immutable and Aztec Labs renounced all admin authority in April 2024, no patch, pause, or fund recovery is technically possible. 0% of funds have been recovered.
Sources and coverage
- Articlekucoin.comhttps://www.kucoin.com/news/flash/aztec-connect-hacked-for-2-19m-via-zk-rollup-vulnerability
- Articleblockaid.iohttps://www.blockaid.io/blog/219m-drained-on-aztec-how-blockaid-flagged-an-exploit-before-it-happened
- Articlex.comhttps://x.com/AztecLabs_
- Articlex.comhttps://x.com/aztecFND/status/2067511967237939636
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)