Aztec Connect hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 14, 2026 |
| Target type | Cross-chain bridge |
| Loss | $2,270,000Published estimates range $2,190,000 to $2,270,000Price at time of incident |
| Method | Contract logic errorThe deprecated rollup contract's settlement loop processed transactions only up to a declared numRealTxs value, while the accompanying zero-knowledge validity proof committed to a larger set of decoded public-input slots. The contract never asserted that the side effects of the proof matched what the deposit-withdrawal system actually processed, so deposits placed in slots beyond the declared count were credited inside the rollup without ever being collected on Layer 1, creating unbacked balances that were then withdrawn. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 14 June 2026 an attacker drained approximately $2.19 million from the deprecated Aztec Connect rollup contracts on Ethereum. A second actor extracted roughly a further $88,000 the following day, bringing the total Aztec Labs accounts for to about $2.27 million.
Aztec Connect was a privacy-focused zk-rollup bridge launched in 2022 and discontinued as a product in March 2023. Aztec Labs renounced all administrative roles and upgrade authority over the contracts in April 2024 after a year of notice to users, leaving them immutable and unattended.
According to Aztec Labs' own incident report, the side effects of a given rollup proof were not asserted to be the same as those processed by the deposit-withdrawal system. SlowMist's analysis sets out the mechanism concretely: the settlement loop processed transactions up to a declared numRealTxs value while the validity proof committed to a larger set of decoded public-input slots. By placing deposits in slots beyond the declared count, the attacker had the rollup credit balances that Layer 1 never actually collected. The exploit ran fourteen consecutive processRollup() calls inside a single atomic transaction, seven creating the unbacked balances and seven withdrawing against them.
BlockSec's Phalcon system detected the transaction on 14 June. The assets taken included 909 ETH, 167.9 wstETH, 270,500 DAI, 9,270 LUSD and Yearn vault tokens; the follow-up attack took wrapped Aave and Compound positions. Funds moved through a purpose-built contract to a freshly created wallet.
Aztec Labs said it holds no control over the contracts and that the live Aztec Network and the AZTEC ERC-20 token were unaffected.
Sources
- Aztec LabsPrimary · retrieved 2026-08-01
- Aztec LabsPrimary · retrieved 2026-08-01
- The Crypto Times (reporting SlowMist analysis)Secondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://aztec-labs.com/blog/aztec-connect-incident
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Aztec Connect hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aztec-connecthttps://itokenly.com/hacks/aztec-connectPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.