Aztec Connect, a previously used decentralized finance platform, suffered an exploit resulting in the loss of approximately $2.1 million in cryptocurrency. The incident occurred on Sunday when an attacker leveraged a vulnerability in the platform's verification function within its immutable smart contract.
According to crypto security firm BlockSec, the attacker exploited a discrepancy between how Aztec Connect verified transactions and how they were settled on the Ethereum blockchain. This allowed the attacker to create unbacked balances by manipulating the contract's interpretation of transaction lists, which could then be withdrawn. The attacker reportedly executed this seven times across different assets.
The stolen assets included 909 Ether (ETH), 270,000 Dai (DAI), and 167 wrapped staked ETH, among other cryptocurrencies. Aztec Labs confirmed the exploit and stated that it did not impact users or assets on the current Aztec Network. The team also noted that they do not hold admin keys for the deprecated system, which became fully immutable after its deprecation in March 2023.
This exploit is the latest in a series of security breaches in the DeFi space, with over $44 million stolen in June alone from at least 12 other exploits. The incident serves as a reminder that older, abandoned DeFi contracts can remain vulnerable to attacks years after their initial deployment.