T
iTokenly

Aztec 2.0 Rollup Bridge hack — June 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 17, 2026
Target typeCross-chain bridge
Loss$2,200,000Published estimates range $2,150,000 to $2,200,000Price at time of incident
MethodContract logic errorA soundness flaw in the escape-hatch withdrawal path of the deprecated Aztec 2.0 RollupProcessor. Per Aztec Labs, the contract never checked that the Merkle root used to validate ownership matched the root used for settlement, so a caller could prove ownership against a fabricated ledger while presenting the genuine ledger on L1. DARKNAVY describes the same path as the escape hatch accepting a proof for another user's claim with the final output owner replaced by an attacker-controlled address, with the bridge executing the encoded L1 withdrawal on verifier success alone.
ChainsEthereum
OutcomeUnresolved

What happened

On 17 June 2026 at 18:34 UTC an attacker drained the Ethereum L1 contract of Aztec's original 2.0 rollup, a privacy system Aztec Labs deprecated in April 2024 after a year of notice, at which point it revoked all administrative roles and renounced upgrade authority on-chain. The contract remained immutable and still custodied user deposits, retrievable only through an escape-hatch withdrawal path. Aztec Labs attributes the loss to a soundness flaw in the escape-hatch verifier: the deployed circuit accepted a withdrawal that was not backed by any real deposit. Its account is that the contract never verified that two Merkle roots, one used to validate ownership and one used for settlement, matched, so an attacker could prove ownership against a fabricated ledger while presenting the genuine ledger on L1. The independent research group DARKNAVY describes the same path in different terms: the escape hatch accepted a proof for a victim's note with the final output owner replaced by an attacker-controlled address, and the bridge acted on the withdrawal encoded in the proof data on the strength of verifier success alone. Aztec Labs puts the total at approximately $2.2 million, comprising about 1,158 ETH (roughly $2.04 million), 150,000 DAI and 0.47 renBTC. It describes the renBTC leg as an upper bound of about $7,000 and notes that renBTC is a deprecated, depegged asset whose real value is likely far lower. DARKNAVY valued the same 1,158 ETH at about $2.15 million, so the gap between the published totals of roughly $2.15 million and $2.2 million is mainly a difference in the ETH price applied, not a difference in whether the DAI and renBTC legs are counted. The drained contract is the RollupProcessor, and DARKNAVY identifies the attacker address. The main drain ran about 37 minutes from initial funding to the final asset movement. A copycat swept a residual 0.76 ETH the following morning. Aztec Labs said it was working with its incident response provider, Groom Lake, to block the funds across exchanges. No reimbursement has been announced. This incident is distinct from the Aztec Connect drain of 14–15 June 2026, a separate deprecated Aztec contract of similar size. The two must not be merged.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba
  • 0x6952d9246e9afe8b887b2877225163436f78e97f

Sources

  1. Aztec LabsPrimary · retrieved 2026-08-01
  2. Aztec LabsPrimary · retrieved 2026-08-01
  3. DARKNAVYSecondary · retrieved 2026-08-01

Official post-mortem: https://aztec-labs.com/blog/aztec-2-incident

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Aztec 2.0 Rollup Bridge hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aztec-2-rollup-bridge
https://itokenly.com/hacks/aztec-2-rollup-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.