Aztec suffers second exploit in four days, with attackers draining $2.2M from a deprecated payments product.
Security & Exploits ·
Aztec is investigating a second exploit in four days, with attackers draining $2.2 million from a deprecated payments product. The incident targeted a stage 2 rollup payments system that was sunset in 2022, meaning Aztec Labs no longer maintains administrative control over the affected contract.
The timing underscores mounting pressure on the protocol after a prior breach within the same four-day window. Because the vulnerable product had already been deprecated and deactivated years earlier, the attack vector exploited legacy infrastructure rather than active systems. The exact mechanics of how attackers accessed and drained funds from the offline payments layer remain under investigation.
It is not yet clear whether the two exploits share a common vulnerability or whether one attacker or group was responsible for both incidents. The implications for Aztec's broader ecosystem and the status of any user recovery efforts have not been disclosed.