$SOL Outdated contract on the Aztec network was hacked for $2 million
On June 18, a hacker exploited an unused smart contract in the _2 network
#Aztec . Preliminary estimates indicate the damage amounts to around $2.15 million.
Analysts from Certik were the first to notice the incident, followed by confirmation from the Aztec Labs development team.
The vulnerability was found in the outdated payment product Aztec Payments, which was shut down in 2022. The incident did not affect users or assets in the current network of the project.
According to researchers, the hacker took advantage of a flaw in the proof-checking logic of the smart contract PrivateRollupBridge. The attacker spent 0.134
$ETH (~$230) to execute the attack.
In total, they managed to withdraw 1158
$ETH , 150,000 DAI, and 0.47
#renBTC . Overall, they managed to withdraw 1158
#ETH , 150,000 DAI, and 0.47
#renBTC .
For Aztec, this isn't the first security incident in the past few days. On June 14, unknown parties drained another outdated router contract for nearly $2.19 million.
Representatives from Aztec Labs noted that they do not hold administrative keys and do not control the system. Because of this, the team cannot freeze contracts or release updates to prevent attacks.