SlowMist releases a technical analysis report on the Aztec Connect approximately $2.19 million asset theft incident. The report points out that the attacker exploited a settlement boundary bypass vulnerability in the deprecated Aztec Connect RollupProcessor contract, causing a mismatch between L1 and L2 states, and stole assets from the protocol. The vulnerability stems from the inconsistent verification logic between numRealTxs and decoded_slots, allowing forged deposits to pass ZK proof verification but failing to be correctly recognized by the L1 settlement layer.

AZTEC1.91%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned