← Back to KHAO

Ethereum · CertiK ·

Aztec Connect’s abandoned smart contract exploited for $2 million three years after shutdown

2 min read

Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.

◎ Multiple-sources

Aztec Connect’s abandoned smart contract exploited for $2M three years after shutdown.

A deprecated zk-rollup bridge on Ethereum lost roughly 909 ETH, 270,000 DAI, and 167 wstETH after an attacker found a flaw in verification logic no one could patch.

Key facts

Summary

The haul included approximately 909 ETH, 270,000 DAI, and 167 wstETH, along with other ERC-20 tokens. Here’s the thing: nobody could have stopped it. Aztec Connect launched in 2022 as a zk-rollup bridge designed to bring privacy to DeFi interactions on Ethereum. The root cause of the exploit was a mismatch between the contract’s verification and settlement logic.

#Ethereum #CertiK