A vulnerability in an abandoned Aztec smart contract led to the theft of $2.1 million.
The incident affected the outdated Aztec Connect smart contract, which was decommissioned back in 2023. The attacker exploited a mismatch in the transaction verification logic, allowing them to artificially create unbacked balances and withdraw funds totaling approximately $2.1 million.
The attack was carried out across seven assets. According to data from CertiK analysts, the stolen assets included 909 ETH, 270,000 DAI, 167 wstETH, and several other cryptocurrencies. BlockSec experts linked the vulnerability to discrepancies between transaction verification and their actual settlement on Ethereum — the contract credited value without proper validation on the L1 blockchain.
Aztec Labs developers emphasized that they do not hold administrative keys and do not control system updates, so they cannot suspend its operation or fix the vulnerability. Nevertheless, the team assured that the project's current network and user funds were not affected.
As a reminder, Aztec Connect was launched in 2022 as a DeFi bridge for private transactions. In March 2023, its support was discontinued, and resources were redirected to the development of the Aztec Network. In November 2025, the project launched the L2 protocol Ignition Chain, positioning it as "the first fully decentralized second-layer solution."
Analyst's opinion: This incident is a stark example of the risks associated with "dead" smart contracts. Despite the cessation of support, funds in such contracts often remain locked and vulnerable. It serves as a reminder of the need to timely withdraw liquidity from outdated protocols and strengthen security audits during their deactivation phase.