Aztec's legacy Private Rollup Bridge exploited, $2.16 million assets drained.

SlowMist said the vulnerability was specifically tied to the legacy RollupProcessor escape hatch function at address 0x7379…2a2ba, which reportedly lacked critical access controls such as an onlyOwner restriction, rollup-provider authorization, or signature verification.
SlowMist reported that the TurboVerifier contract (0x48cb…e8ce) would accept escape-hatch proofs even when rollupSize was set to zero, and that processDepositsAndWithdrawals trusted spoofed public inputs (including publicOutput, outputOwner, and assetId) without verifying real fund ownership/withdrawal balances—enabling an EOA to drain funds.
Coinpedia reported that the exploit wallet (x73790…42a2ba) was initially funded with only 0.134 ETH from exchange HitBTC before executing the attack.
Coinpedia provided specific market context: after the exploit was reported, AZTEC fell about 1.6%, trading near $0.0160.
A hacker drained roughly $2.15 million from Aztec's legacy Private Rollup Bridge on June 17, stealing 1,158 ETH, 150,000 DAI, and a small amount of renBTC. Coinpaper reported the attack came less than a week after a separate exploit took $2.19 million from another retired Aztec contract, bringing the combined loss to more than $4.3 million in under seven days.
Aztec confirmed the breach but stressed that the hit product was deprecated in 2022 and is entirely separate from its live network. "The product was deprecated 4 years ago and Aztec Labs retains no controls over the system," the team said, according to MEXC News.
The attacker started with almost nothing. Coinpedia reported that the exploit wallet was funded with just 0.134 ETH — worth roughly $250 to $300 — sourced from a HitBTC exchange deposit address. From that tiny seed, the hacker executed three transactions against the old bridge contract and walked away with millions.
Security firm SlowMist was among the first to flag the suspicious activity on June 18. Its founder publicly identified the attacker's primary wallet as 0x6952d9…e97f, according to Namecoinnews. The speed and low cost of the attack underscored how little effort modern hackers need when a vulnerable contract sits unguarded on-chain.
The weakness lived inside a function called `escapeHatch()` inside the old RollupProcessor contract at address 0x7379…2a2ba. Coinlaw reported that SlowMist found the function had no access controls at all — no owner restriction, no rollup-provider check, and no signature verification. Anyone could call it.
The problem went deeper. A linked contract called TurboVerifier would accept escape-hatch proofs even when the rollup size was set to zero. The system also trusted fake public inputs — things like who owned the funds and which asset was being withdrawn — without checking if those claims were real. That let an outside wallet drain the bridge's entire balance, according to Bloomingbit.
Aztec's back-to-back losses are part of a wider pattern in June 2026. MEXC News noted that Raydium lost $1.3 million from deprecated liquidity pools on June 10, and Thetanuts Finance lost $2.1 million from a legacy vault on June 15. Each case involved old, immutable contracts that teams could no longer patch or pause.
Risk platform Blockful warned that DeFi is entering a new era where "old contracts continue to be bug bounties available to any hackers." The core problem is immutability. When a team renounces its admin keys — a move seen as good for decentralization — it also loses the ability to freeze funds or fix bugs in an emergency, according to Coinpaper.
Markets reacted quickly to the news. Coinpedia reported the AZTEC token fell about 1.6%, trading near $0.0160 after the exploit surfaced. MEXC News put the drop closer to 2.5%, with the price touching $0.0158. Either way, the move was modest given the size of the theft and the back-to-back headlines.
Aztec insisted the current network and its token architecture are safe. The team said the compromised bridge was an "immutable stage 2 rollup that was sunset in 2022" and that Aztec Labs holds no admin keys to stop or reverse what happened. For users who left funds in Aztec's early products, that message offers little comfort — the stolen funds cannot be recovered.
Publishers
13
Articles
4
Reach
17