An attacker drained approximately $2.2 million in assets from Aztec’s original, deprecated rollup contract on June 17, 2026 by exploiting an unsound verification key in an emergency withdrawal mechanism. Aztec said its current network and proof systems were separate and were not affected.
According to Aztec Labs’ incident report, the attacker submitted a withdrawal accepted by the escape-hatch verifier even though it was not backed by a real deposit. The withdrawals occurred across three transactions and emptied most of the assets remaining in the legacy contract.
The affected Aztec 2.0 rollup launched in 2021 and was deprecated in 2022. Aztec Labs said it had no admin keys or control over the immutable contract, so it could not pause the system or reverse the withdrawals.
A second actor reproduced the same technique about 14 hours later, on June 18, and removed the remaining 0.76 ETH. That second transaction was not another $2.1 million loss. The incident was also distinct from a June 15 exploit involving the deprecated Aztec Connect rollup.
Aztec estimated the June 17 loss at about $2.2 million at the time, while noting that renBTC was deprecated and depegged, making its realizable value uncertain. The event affected funds left in obsolete infrastructure, not assets on the live Aztec Network.

