Aztec probes $2M exploit of deprecated payments contract

Aztec is investigating a roughly $2 million loss after an attacker exploited a live legacy smart contract tied to a deprecated payments product.

Aztec is investigating an exploit that removed about $2 million from a payments product the team had marked as deprecated. The breach was detected earlier this week after abnormal on-chain activity flagged the transfer of funds to external addresses.

On-chain records show the attacker triggered a vulnerability in an older smart contract that remained active on the network. Assets were moved through multiple wallets and intermediaries after the initial withdrawal.

Aztec's engineering team immediately froze related backend services and disabled interfaces that interact with the deprecated contract to stop further transfers. The protocol began tracing the stolen funds and notified major custodial platforms and blockchain analytics providers to monitor movements. Coordination is under way with relevant law enforcement agencies to assist recovery efforts.

Aztec confirmed the amount taken is approximately $2 million and opened an internal investigation to determine the exploit vector and the full scope of the loss. The company plans to publish a technical post-mortem once the review is complete and will outline the sequence of events, the vulnerability exploited and remedial actions.

The targeted payments product was created to enable private transfers using Aztec’s cryptographic tools but was later deprecated in favor of newer components. Deprecation meant the product stopped receiving updates and was no longer recommended for users, while its smart contract remained live on-chain and callable.

Smart contracts left active after deprecation can be at risk if they retain privileged functions or fallback code paths. To reduce such risks, developers can add on-chain disable mechanisms or migrate remaining balances before removing interfaces that interact with legacy contracts. Aztec said it will review its deprecation and upgrade procedures as part of the investigation.

A spokesperson for Aztec said, “We are investigating the exploit and taking steps to secure our systems. We will share a full timeline and technical post-mortem once our review is complete.” The project advised users to avoid interacting with addresses linked to the deprecated payments product and to follow official channels for updates. At this stage there is no announced compensation or recovery plan for affected users.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author