A Dormant Threat: Hacker Drains $2.1 Million from Long-Closed Aztec Connect Protocol
On June 14, I detected suspicious activity related to the Aztec Connect protocol. An attacker, exploiting a critical vulnerability in the proof verification mechanism, managed to withdraw over $2.1 million from the smart contracts of a long-dormant project.
Blockchain security specialists quickly identified the anomalous transaction and brought it to the community's attention. Analysis revealed that the root of the problem lies in an incomplete verification of the provided proofs. One of the contract's functions only checked the initial portion of the data, leaving the token transfer instructions embedded in another segment without proper oversight. This flaw allowed the attacker to manipulate the withdrawal mechanism and misappropriate approximately $2.19 million.
The Aztec Foundation confirmed receiving information about the incident. In an official statement, the developers emphasized that the situation does not affect the AZTEC token (ERC-20 standard) or the smart contracts of the active Aztec network. A key point I want to highlight: Aztec Connect was shut down and ceased operations three years ago. Aztec Labs no longer manages this protocol, does not possess administrative keys, and is effectively unable to intervene.
"Aztec Labs does not have admin keys and does not gain control over the system. We cannot pause or update it," the development team stated.
This hack is not an isolated incident but part of a worrying trend. Just a few days earlier, hackers withdrew approximately $1.3 million from five outdated liquidity pools on the Solana network (Raydium). According to DeFi aggregators, the total damage from such attacks since the beginning of June has already exceeded $43.93 million.
Cryptalist Analysis: This incident is a stark reminder of the "dormant" risks in DeFi. Closed or abandoned protocols are digital time bombs. Their code remains on the blockchain forever, and as we see, vulnerabilities do not expire. For users, this is a signal: even if a project has ceased to exist, your funds stuck in its contracts may be at risk. The market must develop mechanisms for "burying" or forcibly withdrawing liquidity from such "dead" protocols.