Aztec Network Suffers Attack, Loses Over $2.15 Million, Root Cause Linked to ZK Proof-L1 Settlement Mismatch
BlockBeats News, June 15th, according to BlockSec Phalcon (@Phalcon_xyz) analysis, Aztec Network's RollupProcessorV3 contract was attacked, resulting in a loss of over $2.15 million. The root cause was that numRealTxs was not correctly bound to the transaction set enforced by the ZK proof, causing a discrepancy between the proof verification path and the L1 settlement logic's interpretation of the transaction list.
The attacker exploited this vulnerability to move real deposits to slots not processed by the settlement logic, bypassing the decreasePendingDepositBalance() function, creating unsecured private balances out of thin air, and then extracting them through the normal settlement process, involving a total of seven assets.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Nikkei May Decline Amid Concerns About Energy Costs -- Market Talk
Costco Wholesale Nearly Doubles Kirkland Motor Oil Price, Caps Purchases at Two Weekly
Liquidity Unconcerned? The Federal Reserve Hits 'Pause' Again, Ceasing Reserve Management Bond Purchases Until Mid-October
The Federal Reserve announced on Monday that it will not conduct short-term Treasury bond purchases for reserve management purposes in the next phase for the second consecutive month, indicating that policymakers are satisfied with the level of bank reserves in the financial system.

NAB says Australia August consumer spending rises 1.1% as fuel costs jump 12%
