CertiK detected a $2.19M drain from Aztec Network's router contract via a suspicious Ethereum transaction.
Security & Exploits ·
Security firm CertiK flagged a suspicious Ethereum transaction that moved approximately $2.19M out of Aztec Network's router contract, with funds transferred to address 0x0f18d8b44a740272f0be4d08338d2b165b7edd17. CertiK identified what it characterized as an exploit in the underlying verification logic.
According to CertiK's analysis, the vulnerability stemmed from incomplete verification of proof data. The computeRootHashes() function validated only the beginning portion of submitted '_proofData', while the processDepositsAndWithdrawals() function that executed token transfers operated on parameters located in the middle of that data—creating a gap in the verification chain. The Aztec Foundation was notified of the potential exploit on June 14, 2026.
The incident affected deprecated infrastructure rather than active systems. The vulnerable contracts were deprecated three years prior, in 2023, and Aztec Labs no longer maintains control over them. The foundation emphasized that Aztec Connect carries no connection to the AZTEC ERC20 token or the current Aztec network, limiting the scope of the exploit to legacy code no longer in use.