Kucoin Aztec Connect Router Exploit Drains $2.19 Million from Deprecated Ethereum Contracts
Article Content
- •Over $2.19 million was drained from the deprecated Aztec Connect Router contract.
- •The exploit involved manipulating proof data in the smart contract validation process.
- •The attacker used Tornado Cash to obscure the origin of funds before the exploit.
A recent exploit drained approximately $2.19 million from the deprecated Aztec Connect Router contract on Ethereum. The attacker, using wallet address 0x0f18d8b44a740272f0be4d08338d2b165b7edd17, exploited a flaw in the smart contract's handling of proof data. Despite the protocol being shut down three years ago, over $2 million in assets remained locked in the immutable contracts. The exploit involved manipulating the _proofData payload, allowing unauthorized token transfers. CertiK flagged the suspicious transaction on June 14, 2026, prompting Aztec Labs to confirm the situation. The assets drained included 909 ETH and 270,000 DAI. The attack highlights vulnerabilities in legacy smart contracts that remain exploitable even after deprecation. Aztec Labs has stated they are monitoring the situation and the attacker's wallet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Aztec Network in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…