Deprecated Aztec Connect Contract Exploited for $2.19M, SlowMist Says

A deprecated smart contract linked to Aztec Connect was exploited for approximately $2.19 million, according to blockchain security firm SlowMist. The incident underscores the residual risks posed by inactive or sunset decentralized finance (DeFi) infrastructure that may continue to hold funds or permissions.

Exploit overview

SlowMist reported that an attacker targeted a deprecated component associated with Aztec Connect, draining roughly $2.19 million in digital assets. The affected contract was no longer actively maintained, highlighting how legacy DeFi code can remain vulnerable after services are discontinued.

Further technical specifics about the vulnerability and the attacker’s on-chain movements were not immediately available.

Background on Aztec Connect

Aztec Connect was a privacy-focused system built on Ethereum that allowed users to interact with DeFi protocols using zero-knowledge proofs. The service was deprecated in 2023 as the Aztec team shifted focus to developing its next-generation privacy infrastructure. As with many discontinued protocols, some legacy contracts may persist on-chain even after support ends.

Lingering risks in deprecated DeFi infrastructure

Security incidents involving obsolete smart contracts have become a recurring challenge in DeFi. Deprecated contracts can retain upgrade paths, token approvals, or custodial balances that are overlooked once a project sunsets a product. Industry security practices increasingly emphasize:

  • Proactively sweeping residual funds from legacy contracts.
  • Revoking permissions and approvals tied to discontinued systems.
  • Implementing kill switches or deactivation mechanisms where possible.
  • Communicating clear offboarding timelines and withdrawal guidance to users.

The reported Aztec Connect exploit adds to a growing body of cases illustrating the importance of thorough end-of-life planning and on-chain risk mitigation when deprecating DeFi services.

×