Aztec Network Suffers Attack, Loses Over $2.15 Million, Root Cause Linked to ZK Proof-L1 Settlement Mismatch
BlockBeats News, June 15th, according to BlockSec Phalcon (@Phalcon_xyz) analysis, Aztec Network's RollupProcessorV3 contract was attacked, resulting in a loss of over $2.15 million. The root cause was that numRealTxs was not correctly bound to the transaction set enforced by the ZK proof, causing a discrepancy between the proof verification path and the L1 settlement logic's interpretation of the transaction list.
The attacker exploited this vulnerability to move real deposits to slots not processed by the settlement logic, bypassing the decreasePendingDepositBalance() function, creating unsecured private balances out of thin air, and then extracting them through the normal settlement process, involving a total of seven assets.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Federal Reserve officials: Not enough progress seen in reducing inflation
Data: ETH Falls Below $2550
Moody’s gives Sky Protocol B3 rating as institutional interest in USDS grows

Brent crude oil falls to $104 per barrel, down 0.2% in 24 hours.

