TechFlow reports that on June 15, SlowMist released a technical analysis stating that the deprecated Aztec Connect RollupProcessor contract was exploited via a settlement boundary bypass vulnerability, resulting in the theft of approximately $2.19 million worth of assets from the protocol. The attacker leveraged a mismatch between numRealTxs and decoded_slots to forge deposits and induce inconsistency between L1 and L2 states, thereby bypassing L1 settlement validation and completing the fund transfer. The report also discloses the root cause of the vulnerability, on-chain fund flows, and the attack execution path.
Navigating Web3 tides with focused insights
Contribute An Article
Media Requests
Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / support@techflowpost.com ICP License: 琼ICP备2022009338号


