Crypto界消息,据BlockSec Phalcon分析,Aztec Network的RollupProcessorV3合约遭到攻击,损失超过2.15M美元。根本原因在于numRealTxs未有效绑定至zk证明所强制执行的交易集,导致证明验证路径与L1结算逻辑对交易列表的解释出现偏差。攻击者利用该漏洞将真实存款移至未被结算逻辑处理的槽位,绕过decreasePendingDepositBalance()函数,凭空创建无担保私人余额后通过正常结算流程提取,共涉及七种资产。

AZTEC4.53%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • 2
  • Share
Comment
Add a comment
Add a comment
StillHereAfterTheRugPull
· 2h ago
After reviewing the vulnerability details, the attacker moves the deposits to the "ghost slot" and then withdraws normally. This approach is quite clever; can the audit team think of this method?
View OriginalReply0
MildlyRugged
· 2h ago
Synchronizing the state between zk circuits and L1 contracts is truly an eternal challenge. This time, Aztec stumbled over the binding of numRealTxs, and the complexity of privacy Rollups has once again taught everyone a lesson.
View OriginalReply0
SlippageSiren
· 2h ago
2.15 million dollars for a lesson, the privacy track still needs a few more years of polishing.
View OriginalReply0
GlassDomeObservatory
· 2h ago
numRealTxs is not tightly bound, indicating that proof verification and settlement are speaking past each other, a classic cross-layer semantic bias.
View OriginalReply0
  • Pinned