Forgotten protocol attacked: hacker withdraws $2.1 million from closed Aztec Connect
On June 14, an attack occurred on the Aztec Connect protocol, which had been shut down three years ago. The attacker managed to withdraw over $2.1 million by exploiting a critical vulnerability in the proof verification mechanism.
Blockchain security specialists detected a suspicious transaction and promptly alerted the community. It turned out that the root of the problem lies in an incomplete verification of the provided data. One of the smart contract functions only checked the initial part of the proof, while the token transfer instructions embedded in another part of the data remained without proper oversight. This architectural flaw allowed the attacker to manipulate the withdrawal mechanism and steal approximately $2.19 million.
Developer Response and Current Situation
The Aztec Foundation confirmed receiving a notification about the potential exploit. The team emphasized that the incident does not affect the AZTEC token (ERC-20 standard) or the active smart contracts of the Aztec mainnet. The key point here is the developers' complete helplessness in the face of the attack. Aztec Labs stated that they no longer manage the Aztec Connect protocol, as it was shut down three years ago.
"Aztec Labs does not have administrative keys and does not have control over the system. We cannot pause or update it," the developers reported.
The company confirmed that it is conducting an investigation but is no longer able to influence the situation. This hack is a stark example of how "dormant" or abandoned protocols become easy targets. The incident occurred just a few days after the exploit on Raydium (RAY), where hackers withdrew about $1.3 million from five outdated liquidity pools on the Solana (SOL) network. According to DeFiLlama data, total losses from hacks since the beginning of June have already exceeded $43.93 million.
Expert opinion: The attack on Aztec Connect is a wake-up call for the entire industry. Protocols that have been "frozen" or have ceased active development remain part of the blockchain. Their code, lacking support and updates, becomes a ticking time bomb. Investors and users should be extremely cautious when interacting with any legacy contracts, even if they seem "dead." Security does not tolerate negligence, especially regarding abandoned assets.