Attacker Drains $2.1 Million From Aztec Connect 3 Years After Its Shutdown
An attacker drained greater than $2.1 million from Aztec Connect on June 14 by exploiting a flaw within the platform’s proof verification logic.
Blockchain safety agency CertiK flagged the suspicious transaction on X (previously Twitter).
Aztec Connect Exploit Nets Attacker $2.1 Million
CertiK said the exploit appears to stem from incomplete validation of submitted proof knowledge. According to the safety agency, one contract operate verified solely the start of the proof, whereas token switch directions embedded elsewhere within the knowledge could not have been correctly checked. This probably allowed the attacker to control withdrawals and drain roughly $2.19 million.
Follow us on X to get the most recent information because it occurs
The Aztec Foundation said it was notified of a possible exploit involving Aztec Connect. The workforce careworn that the incident doesn’t have an effect on the AZTEC ERC-20 token or any smart contracts related to the present Aztec community.
The basis famous that Aztec Connect was deprecated three years in the past. Thus, Aztec Labs not has any management over the system.
Aztec Labs additionally confirmed an lively investigation. However, the workforce mentioned it has no approach to step in.
(*3*)
“Aztec Labs holds no admin keys or management over the system; it can’t be paused or upgraded by us,” the post learn.
The incident got here simply days after a separate exploit on Raydium (RAY). The incident resulted within the lack of roughly $1.3 million after attackers drained 5 legacy liquidity swimming pools on the Solana (SOL) community.
The assault provides to the rising checklist of exploits recorded this month, which have collectively resulted in losses of roughly $43.93 million, according to DeFiLlama.
Subscribe to our YouTube channel to observe leaders and journalists present knowledgeable insights
The put up Attacker Drains $2.1 Million From Aztec Connect 3 Years After Its Shutdown appeared first on BeInCrypto.
