Aztec Connect RollupProcessor exploited for $2.19M through forged proof verification bypass in escape-hatch withdrawal function.
Security & Exploits ·
On June 14, 2026, approximately $2.19M in user deposits were withdrawn from the Aztec Connect RollupProcessor through a proof verification exploit. The affected contract, operating in escape-hatch mode since Aztec Connect's deprecation in 2023, held user-escrowed Layer 1 assets pending withdrawal. A fresh attacker EOA executed the drain in a single transaction, extracting 909 ETH, 167.9 wstETH, 270.5K DAI, 9.27K LUSD, and yield-bearing token variants.
The attack bypassed verification in the escape-hatch processRollup function by forging a proof that satisfied the Verifier28x32 contract, allowing unauthorized asset extraction. The attacker deployed a helper contract and routed the transaction through multiple intermediate contracts before withdrawing funds to their own address. The token composition and single-transaction drain pattern are inconsistent with a legitimate depositor recovery.
Since Aztec Connect operates in read-only escape-hatch status, no administrative authority could have authorized such a withdrawal, indicating a pure logic or cryptographic vulnerability in proof validation. The full scope of affected users and any recovery mechanisms remain undisclosed.