Aztec Network loses over $4 million in three days to 2 subsequent hacks – CoinJournal

Aztec Network loses over  million in three days to 2 subsequent hacks – CoinJournal

  • Legacy Aztec Network contracts had been drained of over $4M in three days.
  • Assaults exploited flaws in zero-knowledge proof verification logic.
  • The core Aztec community and AZTEC token weren’t affected by the exploits.

Aztec’s legacy infrastructure has come below a coordinated wave of assaults, resulting in losses that crossed $4 million inside simply three days.

The exploits focused deprecated good contracts that had already been shut down years earlier however nonetheless held on-chain liquidity.

Regardless of being labelled as inactive and immutable, the contracts remained accessible to attackers who exploited weaknesses in zero-knowledge proof verification logic.

Whereas the assaults didn’t have an effect on the present Aztec community or its AZTEC token, they uncovered long-standing dangers tied to retired DeFi techniques that live on on Ethereum with out lively upkeep or improve paths.

First breach: Aztec Join drained of $2.1 million

The primary incident occurred on June 14, when attackers exploited the Aztec Join protocol, a deprecated privacy-focused bridge that had been formally shut down after its retirement part.

The contract was already thought of inactive, but it nonetheless contained residual funds.

The attacker managed to empty roughly $2.1 million in digital property, together with round 909 ETH, 270,000 DAI, and 167 wstETH, alongside different smaller holdings.

The exploit was linked to flaws in the best way rollup proof verification was dealt with, permitting invalid or manipulated proofs to be accepted as legit.

What made the state of affairs extra crucial was the character of the contract itself.

Aztec Join was described as immutable, which means it couldn’t be paused or patched as soon as deployed.

Although customers had beforehand been inspired to withdraw funds earlier than shutdown, the remaining stability turned a simple goal for exploitation years later.

Safety groups reviewing the incident pointed to a breakdown within the relationship between zero-knowledge proof validation and on-chain settlement logic.

In easy phrases, the system accepted proofs that didn’t accurately match the underlying transaction state, permitting the attacker to set off unauthorised withdrawals.

Second assault: Personal Rollup Bridge exploited for $2.15 million

Simply three days later, a second exploit hit one other legacy system generally known as the Personal Rollup Bridge.

This contract was additionally a part of Aztec’s older infrastructure and had been deprecated following the transition away from earlier rollup designs.

On this case, attackers drained roughly 1,158 ETH, valued at near $2.15 million on the time of the incident.

The tactic used was totally different in execution however comparable in technical root trigger.

As an alternative of straight manipulating withdrawals by way of fundamental proof mismatch, the attacker leveraged a weak “escape hatch” mechanism embedded within the bridge design.

By submitting a specifically crafted zero-knowledge proof, the attacker was in a position to set off the contract’s exit logic.

The system incorrectly validated the proof and launched funds with out correct verification of the underlying state transitions.

This allowed the attacker to extract liquidity in a single coordinated sequence.

Like the sooner exploit, this breach didn’t contain personal key compromise or reentrancy vulnerabilities.

As an alternative, it highlighted deeper points in how proof validation was structured in legacy rollup techniques, notably when contracts stay completely lively on-chain after being formally sundown.

Response from Aztec and safety corporations

Following each incidents, Aztec Labs and the Aztec Basis confirmed that the affected techniques had been deprecated merchandise with no connection to the present Aztec community or AZTEC token ecosystem.

They emphasised that neither contract may very well be upgraded, paused, or managed, as each had been designed to be immutable at deployment.

Safety agency CertiK Alert additionally flagged the Personal Rollup Bridge exploit, figuring out the attacker’s handle and confirming the motion of funds tied to a particular Ethereum transaction.

Their evaluation aligned with different evaluations, suggesting that the vulnerability stemmed from flaws in zero-knowledge proof verification somewhat than standard good contract bugs.

Aztec representatives additionally clarified that the Personal Rollup Bridge and Aztec Join incidents had been separate occasions, regardless that they occurred inside a brief timeframe and shared comparable technical weaknesses.

Supply hyperlink

bitcoin
Bitcoin (BTC) $ 60,179.00 0.01%
ethereum
Ethereum (ETH) $ 1,575.99 0.43%
tether
Tether (USDT) $ 0.998544 0.00%
bnb
BNB (BNB) $ 557.59 1.61%
usd-coin
USDC (USDC) $ 0.99974 0.01%
xrp
XRP (XRP) $ 1.05 0.41%
solana
Solana (SOL) $ 70.83 1.26%
tron
TRON (TRX) $ 0.321845 0.60%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04 1.52%
staked-ether
Lido Staked Ether (STETH) $ 2,265.05 3.46%
hyperliquid
Hyperliquid (HYPE) $ 61.98 2.70%
dogecoin
Dogecoin (DOGE) $ 0.074472 1.48%
usds
USDS (USDS) $ 0.999627 0.02%
rain
Rain (RAIN) $ 0.015605 0.34%
leo-token
LEO Token (LEO) $ 9.41 1.07%
zcash
Zcash (ZEC) $ 400.34 4.18%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67 3.22%
canton-network
Canton (CC) $ 0.15323 0.74%
stellar
Stellar (XLM) $ 0.174308 0.19%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00 3.12%
monero
Monero (XMR) $ 312.88 2.66%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762 0.02%
whitebit
WhiteBIT Coin (WBT) $ 48.05 0.74%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93 3.47%
chainlink
Chainlink (LINK) $ 7.30 0.81%
cardano
Cardano (ADA) $ 0.145447 1.77%
lab
LAB (LAB) $ 17.04 14.02%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31 3.39%
usd1-wlfi
USD1 (USD1) $ 0.99909 0.02%
susds
sUSDS (SUSDS) $ 1.08 0.16%
dai
Dai (DAI) $ 0.999679 0.01%
ethena-usde
Ethena USDe (USDE) $ 0.998085 0.00%
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.57 1.09%
bitcoin-cash
Bitcoin Cash (BCH) $ 197.26 0.50%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00 3.12%
litecoin
Litecoin (LTC) $ 42.13 0.05%
hedera-hashgraph
Hedera (HBAR) $ 0.071546 0.83%
hashnote-usyc
Circle USYC (USYC) $ 1.13 0.00%
weth
WETH (WETH) $ 2,268.37 3.40%
global-dollar
Global Dollar (USDG) $ 0.999772 0.01%
avalanche-2
Avalanche (AVAX) $ 6.41 2.57%
sui
Sui (SUI) $ 0.684368 2.97%
usdt0
USDT0 (USDT0) $ 0.998824 0.03%
paypal-usd
PayPal USD (PYUSD) $ 0.999649 0.02%
crypto-com-chain
Cronos (CRO) $ 0.054696 0.23%
tether-gold
Tether Gold (XAUT) $ 4,067.66 0.04%
shiba-inu
Shiba Inu (SHIB) $ 0.000004 0.91%
near
NEAR Protocol (NEAR) $ 1.91 5.48%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
ondo-us-dollar-yield
Ondo US Dollar Yield (USDY) $ 1.14 0.26%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.22 0.04%
bittensor
Bittensor (TAO) $ 209.31 1.46%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.058128 0.49%
pax-gold
PAX Gold (PAXG) $ 4,072.25 0.07%
uniswap
Uniswap (UNI) $ 2.92 0.64%
aster-2
Aster (ASTER) $ 0.621458 0.74%
okb
OKB (OKB) $ 79.07 3.43%
ripple-usd
Ripple USD (RLUSD) $ 1.00 0.03%
worldcoin-wld
Worldcoin (WLD) $ 0.439356 5.87%
htx-dao
HTX DAO (HTX) $ 0.000002 0.14%
ondo-finance
Ondo (ONDO) $ 0.310124 2.17%
little-pepe-5
Little Pepe (LILPEPE) $ 2.16 99,999.99%
aave
Aave (AAVE) $ 94.91 1.94%
syrupusdc
syrupUSDC (SYRUPUSDC) $ 1.15 0.04%
mantle
Mantle (MNT) $ 0.436226 0.58%
falcon-finance
Falcon USD (USDF) $ 0.994776 0.17%
pi-network
Pi Network (PI) $ 0.129178 0.87%
usdd
USDD (USDD) $ 0.99867 0.13%
polkadot
Polkadot (DOT) $ 0.810589 4.65%
bfusd
BFUSD (BFUSD) $ 0.998322 0.00%
internet-computer
Internet Computer (ICP) $ 2.15 1.81%
sky
Sky (SKY) $ 0.049692 0.43%
bitget-token
Bitget Token (BGB) $ 1.64 0.18%
morpho
Morpho (MORPHO) $ 1.73 2.41%
ethereum-classic
Ethereum Classic (ETC) $ 7.14 1.45%
dexe
DeXe (DEXE) $ 22.19 2.74%
united-stables
United Stables (U) $ 0.999708 0.01%
pepe
Pepe (PEPE) $ 0.000002 0.64%
blockchain-capital
Blockchain Capital (BCAP) $ 107.03 0.00%
jupiter-perpetuals-liquidity-provider-token
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00 2.64%
quant-network
Quant (QNT) $ 65.43 1.99%
memecore
MemeCore (M) $ 0.720351 1.36%
eutbl
Spiko EU T-Bills Money Market Fund (EUTBL) $ 1.20 0.02%
kucoin-shares
KuCoin (KCS) $ 6.79 0.07%
stable-2
​​Stable (STABLE) $ 0.037331 0.54%
jito-staked-sol
Jito Staked SOL (JITOSOL) $ 124.46 4.71%
janus-henderson-anemoy-treasury-fund
Janus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11 0.00%
usdgo
USDGO (USDGO) $ 0.999996 0.02%
kelp-dao-restaked-eth
Kelp DAO Restaked ETH (RSETH) $ 2,404.69 3.37%
render-token
Render (RENDER) $ 1.56 2.73%
cosmos
Cosmos Hub (ATOM) $ 1.57 0.92%
binance-peg-weth
Binance-Peg WETH (WETH) $ 2,262.26 3.62%
audiera
Audiera (BEAT) $ 2.72 4.00%
rocket-pool-eth
Rocket Pool ETH (RETH) $ 2,631.35 3.29%
algorand
Algorand (ALGO) $ 0.086997 3.05%
superstate-short-duration-us-government-securities-fund-ustb
Invesco Short Duration US Government Securities Fund (USTB) $ 11.13 0.00%
binance-bridged-usdc-bnb-smart-chain
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945 0.02%
kaspa
Kaspa (KAS) $ 0.027922 0.47%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.07097 0.07%
wbnb
Wrapped BNB (WBNB) $ 759.61 1.56%
Scroll to Top