Aztec 2.0 Rollup Bridge hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 17, 2026 |
| Target type | Cross-chain bridge |
| Loss | $2,200,000Published estimates range $2,150,000 to $2,200,000Price at time of incident |
| Method | Contract logic errorA soundness flaw in the escape-hatch withdrawal path of the deprecated Aztec 2.0 RollupProcessor. Per Aztec Labs, the contract never checked that the Merkle root used to validate ownership matched the root used for settlement, so a caller could prove ownership against a fabricated ledger while presenting the genuine ledger on L1. DARKNAVY describes the same path as the escape hatch accepting a proof for another user's claim with the final output owner replaced by an attacker-controlled address, with the bridge executing the encoded L1 withdrawal on verifier success alone. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 17 June 2026 at 18:34 UTC an attacker drained the Ethereum L1 contract of Aztec's original 2.0 rollup, a privacy system Aztec Labs deprecated in April 2024 after a year of notice, at which point it revoked all administrative roles and renounced upgrade authority on-chain. The contract remained immutable and still custodied user deposits, retrievable only through an escape-hatch withdrawal path. Aztec Labs attributes the loss to a soundness flaw in the escape-hatch verifier: the deployed circuit accepted a withdrawal that was not backed by any real deposit. Its account is that the contract never verified that two Merkle roots, one used to validate ownership and one used for settlement, matched, so an attacker could prove ownership against a fabricated ledger while presenting the genuine ledger on L1. The independent research group DARKNAVY describes the same path in different terms: the escape hatch accepted a proof for a victim's note with the final output owner replaced by an attacker-controlled address, and the bridge acted on the withdrawal encoded in the proof data on the strength of verifier success alone. Aztec Labs puts the total at approximately $2.2 million, comprising about 1,158 ETH (roughly $2.04 million), 150,000 DAI and 0.47 renBTC. It describes the renBTC leg as an upper bound of about $7,000 and notes that renBTC is a deprecated, depegged asset whose real value is likely far lower. DARKNAVY valued the same 1,158 ETH at about $2.15 million, so the gap between the published totals of roughly $2.15 million and $2.2 million is mainly a difference in the ETH price applied, not a difference in whether the DAI and renBTC legs are counted. The drained contract is the RollupProcessor, and DARKNAVY identifies the attacker address. The main drain ran about 37 minutes from initial funding to the final asset movement. A copycat swept a residual 0.76 ETH the following morning. Aztec Labs said it was working with its incident response provider, Groom Lake, to block the funds across exchanges. No reimbursement has been announced. This incident is distinct from the Aztec Connect drain of 14–15 June 2026, a separate deprecated Aztec contract of similar size. The two must not be merged.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba
- 0x6952d9246e9afe8b887b2877225163436f78e97f
Sources
- Aztec LabsPrimary · retrieved 2026-08-01
- Aztec LabsPrimary · retrieved 2026-08-01
- DARKNAVYSecondary · retrieved 2026-08-01
Official post-mortem: https://aztec-labs.com/blog/aztec-2-incident
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Aztec 2.0 Rollup Bridge hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aztec-2-rollup-bridgehttps://itokenly.com/hacks/aztec-2-rollup-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.