Aztec’s Legacy Bridge Exploited for $2.15M in Second Deprecated Product Hack

3 hour ago 6 sources neutral

Key takeaways:

  • Deprecated immutable contracts on Ethereum pose lingering security risks, as Aztec exploits show.
  • Repeated breaches may create negative sentiment and short-term selling pressure on AZTEC token.
  • Investors should monitor sunsetted DeFi infrastructure for similar vulnerabilities and attack patterns.

Privacy-oriented Ethereum scaling project Aztec has suffered its second major exploit in less than a week, with an attacker draining approximately $2.15 million from a deprecated Private Rollup Bridge contract. The incident follows a separate $2.1 million breach of the also-retired Aztec Connect earlier this month, intensifying scrutiny of immutable smart contracts left on-chain after projects shut down.

Blockchain data shows three suspicious transactions moving roughly 1,158 ETH, 150,000 DAI, and 0.47 renBTC from the bridge contract. Security researcher Cos (@evilcos) and blockchain security firm PeckShield traced the attack to an abuse of the RollupProcessor’s “Escape Hatch” mechanism — a safety feature intended to let users submit rollup proofs during outages. The attacker allegedly crafted proofs with manipulated public output values that the verifier accepted, releasing assets directly from custodial reserves. Stolen funds were later routed to wallets connected to exchange HitBTC.

The Aztec Foundation and Aztec Labs quickly issued statements distancing the current network from the incident. They stressed that the affected product was an immutable Stage 2 rollup deprecated in 2022, with no admin keys or upgrade controls, and that it has “no links” to any smart contracts associated with the active Aztec network or the AZTEC ERC‑20 token. Both entities are investigating and will provide further updates.

The event reignites concerns about the safety of deprecated DeFi infrastructure. While the financial damage is modest compared to historic bridge exploits, the repeated targeting of legacy contracts — even after official discontinuation — undermines confidence and highlights the lingering risks posed by immutable code that remains live on Ethereum. Analysts warn that trust becomes a critical casualty when multiple incidents strike a single ecosystem in rapid succession.

Previously on the topic:
Jun 15, 2026, 12:08 p.m.
Aztec Connect Exploit Drains $2.1M from Deprecated Ethereum Bridge
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.