Crypto news

15.06.2026
17:04

A hacker withdrew $2.1 million from the dead protocol Aztec Connect: a lesson in smart contract security

On June 14, an incident occurred that once again reminded the market of the critical importance of auditing even "dead" protocols. An attacker managed to withdraw over $2.1 million from the smart contracts of the Aztec Connect platform, which was officially shut down three years ago.

A transaction analysis conducted by security specialists revealed a vulnerability in the proof verification mechanism. The key issue was that the verification function in the smart contract only checked the initial part of the provided data, leaving token transfer instructions without proper oversight. This allowed the attacker to substitute the withdrawal logic and redirect liquidity to their wallet.

The Aztec Labs team confirmed the hack but emphasized that they have neither administrative keys nor the ability to stop or update the contracts. "We do not control this system and cannot influence what is happening," the developers stated, adding that the incident does not affect the current AZTEC token (ERC-20) or the active smart contracts of the Aztec network.

This case is a stark illustration of how DeFi's legacy can become a "silent time bomb." Protocols that have been abandoned but whose contracts remain on the blockchain represent an ideal target for hackers seeking old, unpatched vulnerabilities.

Notably, the Aztec Connect hack occurred just days after the attack on Raydium (RAY), where attackers withdrew about $1.3 million from five unused liquidity pools on the Solana network. According to aggregators, the total damage from hacks since the beginning of June has already exceeded $43.93 million, indicating a worrying trend: hackers are increasingly hunting for "dormant" assets.

Analyst's opinion: This incident is a harsh reminder for all projects: deactivating the user interface does not mean deactivating risks. Any smart contract ever deployed on the network remains a perpetual target. Teams must either include self-destruct mechanisms for contracts upon closure or conduct a final audit with forced withdrawal of all funds. Otherwise, we will see more and more such attacks on DeFi "ghosts."