← Radar

Incident case file

Sign in to watch

Aztec Private Rollup Bridge escapeHatch Exploit — Second Aztec Incident of the Week

Incident date June 17, 2026

1 views

ClosedEthereum L1 (deprecated Private Rollup Bridgesunset 2022)Smart contract exploit — escapeHatch access control flaw / public input binding issueCluster: APRB-ETH-2026-06

Estimated loss

$2.2M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 0x6952d9246e9aFE8B887B2877225163436F78E97F (funded with 0.134 ETH from HitBTC)

Funds moved to: 1,158 ETH + 150,000 DAI + 0.4696 renBTC (~$2,209,704.23) drained via tx 0xab306cd2184d23b6ba3e151b10b3b9a0b81f211cc16f4f3b0c79f0b17a59c2b5 at 18:34:47 UTC. 0% recovered — contract immutable, no upgrade authority.
Victim contract: RollupProcessor (Private Rollup Bridge) 0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba. TurboVerifier: 0x48cb7ba00d087541dc8e2b3738f80fdd1fee8ce8. This is a distinct contract from the RollupProcessorV3 exploited on June 14, 2026 (separate radar entry), though BlockSec classifies both as the same general 'public input binding issue' bug class.

Timeline: On June 17, 2026 at 18:34:47 UTC, attacker EOA 0x6952d9246e9aFE8B887B2877225163436F78E97F (funded by a 0.134 ETH deposit from HitBTC) exploited the escapeHatch() function of Aztec's deprecated Private Rollup Bridge (a payments product launched in 2021 and sunset in 2022). The escapeHatch function lacked access control: it accepted forged ZK proofs with specific proofId and publicOutput parameters during brief 'open' windows, allowing release of RollupProcessor-held funds without verifying ownership. The attacker drained 1,158 ETH, 150,000 DAI, and 0.4696 renBTC (approximately $2,209,704.23) via transaction 0xab306cd2184d23b6ba3e151b10b3b9a0b81f211cc16f4f3b0c79f0b17a59c2b5. Security researcher Vishal Singh (@thisvishalsingh) issued the first public alert the same day, explicitly noting this was a separate incident from the June 14 Aztec Connect drain. SlowMist founder Yu Xian (@evilcos) published a technical thread on June 18, 2026: 'during the brief windows the hatch was open, anyone could trick the escapeHatch function into releasing the RollupProcessor-held funds by setting specific proofId and publicOutput parameters.' BlockSec Phalcon confirmed: 'both Sunday's and Thursday's incidents, while not identical, were caused by public input binding issues.' Aztec Labs confirmed the exploit on June 18, 2026, clarifying the product was an immutable stage-2 rollup sunset in 2022 with no relation to the current Aztec network or AZTEC token. As the contract is immutable with no upgrade authority, 0% of funds have been recovered and none is technically possible.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)