header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Aztec Network Suffers Attack, Loses Over $2.15 Million, Root Cause Linked to ZK Proof-L1 Settlement Mismatch

BlockBeats News, June 15th, according to BlockSec Phalcon (@Phalcon_xyz) analysis, Aztec Network's RollupProcessorV3 contract was attacked, resulting in a loss of over $2.15 million. The root cause was that numRealTxs was not correctly bound to the transaction set enforced by the ZK proof, causing a discrepancy between the proof verification path and the L1 settlement logic's interpretation of the transaction list.


The attacker exploited this vulnerability to move real deposits to slots not processed by the settlement logic, bypassing the decreasePendingDepositBalance() function, creating unsecured private balances out of thin air, and then extracting them through the normal settlement process, involving a total of seven assets.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish