Exploit of the outdated Aztec contract: hacker withdraws over $2 million — a lesson for the entire industry

The analytical service Cryptalist has recorded another incident that highlights the critical importance of auditing and timely withdrawal of funds from outdated protocols. An attacker successfully targeted the non-upgradable smart contract of the Aztec Connect platform, withdrawing approximately $2.1 million in cryptocurrency.
This concerns the Aztec Connect solution for private transactions, which was officially discontinued by the development team back in 2023. Despite the service being halted, a significant amount of liquidity remained locked in its infrastructure. The attack was carried out through a vulnerability in the RollupProcessorV3 contract, which essentially served as a "smart" bridge to Ethereum.
How the Attack Worked and What Was Stolen
Security experts from BlockSec and CertiK responded promptly to the incident. Their analysis revealed that the root cause was a mismatch between the logic of transaction verification and their actual settlement on the Ethereum base layer. The hacker managed to create fictitious, unbacked balances within the contract, after which they legitimately withdrew real assets. In other words, the contract accepted proofs that did not correspond to the state of the first-layer network.
According to monitoring data, the attack was carried out across seven different assets. The stolen items include: 909 ETH, 270,000 DAI, 167 wstETH, as well as a number of other tokens. It is important to emphasize that the current Aztec Network project and user funds within it were not affected — the vulnerability only impacted the old, non-upgradable version of the contract.
Team's Position and Key Takeaway
The developers at Aztec Labs stated that they do not have administrative keys to the outdated system and, therefore, cannot pause or update it. This is a classic dilemma of "immutable" contracts: the lack of control by the team protects against censorship but leaves the protocol completely defenseless against discovered vulnerabilities. Aztec Connect was launched in 2022 as a DeFi bridge, and its support ceased in March 2023 when the team shifted focus to developing the L2 solution Ignition Chain.
Cryptalist Expert Opinion: This incident is not just a story about hacking outdated code. It is a direct signal to the market. If you hold assets in "dead" or "frozen" protocols, you are taking on unjustified risk. Teams should more actively encourage users to withdraw funds from deprecated contracts, and users should respond promptly to such notifications. In the world of DeFi, "immutability" is a double-edged sword, and this case once again proves that old infrastructure becomes an attractive target for hackers who wait years for the right moment.