mt logoMyToken
ETH Gas
EN

Aztec Network suffered over $2.15 million in losses due to an attack stemming from a mismatch between ZK proofs and L1 settlement boundaries.

2026-06-15 05:18:04
Shareshare
According to an analysis by BlockSec Phalcon (@Phalcon_xyz), Aztec Network's RollupProcessorV3 contract was attacked, resulting in losses exceeding $2.15 million. The root cause lies in the fact that numRealTxs was not effectively bound to the transaction set enforced by ZK proofs, causing a discrepancy between the proof verification path and the L1 settlement logic's interpretation of the transaction list. Attackers exploited this vulnerability to move real deposits to slots not processed by the settlement logic, bypassing the decreasePendingDepositBalance() function, creating unsecured private balances out of thin air, and then withdrawing them through the normal settlement process. This involved seven different assets.
Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup