Loading...
[Aztec Network Suffers $2.15 Million Loss Due to Attack, Root Cause Linked to Mismatch Between ZK Proof and L1 Settlement] According to BlockSec Phalcon analysis, the RollupProcessorV3 contract of Aztec Network was attacked, resulting in a loss exceeding $2.15 million. The root cause lies in the failure to effectively bind numRealTxs to the transaction set enforced by the ZK proof, leading to a discrepancy between the proof verification path and the L1 settlement logic's interpretation of the transaction list. Exploiting this vulnerability, the attacker moved real deposits to slots not processed by the settlement logic, bypassed the decreasePendingDepositBalance() function, and created unsecured private balances out of thin air, which were then extracted through the normal settlement process. A total of seven assets were involved.