Aztec's Retired Contracts Are Drained Twice in Four Days for $4.4 Million

Two sets of contracts that Aztec deprecated more than two years ago have been drained in the space of four days. A retired verifier for Aztec 2.0's escape hatch lost about $2.2 million between Wednesday and Thursday, according to figures logged by PeckShield. The deprecated Aztec Connect rollup had lost $2.19 million over the previous weekend. Both were deprecated in April 2024 and sit outside Aztec Labs' control. The combined loss is a little under $4.4 million.
What an escape hatch is, and why it still had money in it
A rollup is a network that executes transactions away from Ethereum and posts the results back to it, so Ethereum holds the funds and the rollup holds the activity. An escape hatch is a fallback that lets users withdraw from a rollup directly on Ethereum if the operator disappears. It exists precisely so funds are never stranded. The trade-off is that the contract must accept withdrawals on its own, which means the verifier that checks them has to be correct forever. Aztec's 2.0 verifier was retired when the project moved on, but the funds that users never withdrew stayed reachable through it. Whoever found the way in did not need the operator's cooperation. That is the design working as intended, pointed the wrong way.
The earlier incident hit Aztec Connect, the privacy bridge Aztec ran before its current network. Some users never took their funds out after it was wound down. PeckShield's log puts the loss at $2.19 million across 14 and 15 June. Nothing in the available reporting links the two events beyond the obvious: same project, same abandoned surface, four days apart. Whether the same party was behind both is not established. The dollar figures are PeckShield's; no second tally was available to compare them against, and they may move.
A month of old code failing
The Aztec losses are small next to Humanity Protocol's drain on 9 June, where the figure was disputed between $31 million and $36 million, and next to the roughly $10 million minted through Syscoin's bridge two days before that. The pattern is different, though. Those were live systems. Aztec's were retired, unmaintained and no longer anyone's responsibility. Deprecated does not mean empty.
The same week, the opposite direction
The contrast with the rest of the month is sharp. Starknet put STRK20, a new privacy standard for ordinary tokens, live on its mainnet on 9 June, with encrypted notes stored in contract storage and a shielded transfer costing about four STRK. Aztec was the project that made private transfers on Ethereum a working product first; what drained this week was the generation of that work it had already abandoned. The live systems failing this month failed on their own bugs. The retired ones failed because nobody was left to watch them.
Nothing left to patch
There is no fix to ship. The contracts are immutable, the team that wrote them has moved on, and the remaining balances are whatever users have not yet claimed. No statement from Aztec Labs on the second incident appeared in the reporting available on Thursday. The practical lesson is older than either exploit. Funds left in a retired protocol belong to whoever reads the code next. For Aztec the sum is $4.4 million and counting; for the users who left it there, it is a reminder that a migration announcement is not a withdrawal.
Read also: Secret Network's Axelar Bridge Hit by a $4.67M Infinite Mint