Kucoin
Aztec Connect Router Exploit Drains $2.19 Million from Deprecated Ethereum Contracts
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A recent exploit drained approximately $2.19 million from the deprecated Aztec Connect Router contract on Ethereum. The attacker, using wallet address 0x0f18d8b44a740272f0be4d08338d2b165b7edd17, exploited a flaw in the smart contract's handling of proof data. Despite the protocol being shut down three years ago, over $2 million in assets remained locked in the immutable contracts. The exploit involved manipulating the _proofData payload, allowing unauthorized token transfers. CertiK flagged the suspicious transaction on June 14, 2026, prompting Aztec Labs to confirm the situation. The assets drained included 909 ETH and 270,000 DAI. The attack highlights vulnerabilities in legacy smart contracts that remain exploitable even after deprecation. Aztec Labs has stated they are monitoring the situation and the attacker's wallet.
Key Points: • Over $2.19 million was drained from the deprecated Aztec Connect Router contract. • The exploit involved manipulating proof data in the smart contract validation process. • The attacker used Tornado Cash to obscure the origin of funds before the exploit.