Morning Edition · Friday, August 28, 2026Published at 1:39 AM EDT · New York
Core contributors found the defect on July 27 through internal artificial-intelligence-assisted auditing and say they cannot determine whether anyone exploited it first.

Aztec, a privacy-focused layer-2 network on Ethereum where private functions are executed and proven on the user's own device, has disclosed a critical defect in the proving system behind its Alpha V5 release. According to the project, an attacker may be able to construct a proof that passes verification for a transaction the network should reject, producing a state transition outside the rules V5 is meant to enforce.
Core contributors identified the flaw on July 27 through internal auditing assisted by artificial-intelligence tooling, after both internal and external human audits had already been completed. Aztec's disclosure states that funds, applications and contract state on V5 should be treated as exposed to a protocol-level failure until incident response finishes and network operators carry out the required actions, and that contributors cannot determine whether the flaw was exploited before it was found. Reviewers have not identified other critical or high-severity issues in V5.
This is the second proving-system failure in Aztec's alpha sequence. The project disclosed a critical V4 proving vulnerability in March and withheld the technical details until V5 shipped, following a policy of holding back specifics until users can move their funds. That policy trades short-term user awareness for reduced attacker advantage, and reasonable people disagree about the balance. Aztec has raised its bug bounty to $2 million.
The type of bug matters beyond Aztec itself. A soundness defect is not a smart-contract bug and cannot be caught by other nodes re-executing the transaction, because in a proof-based system there is nothing to re-execute against. The question of what exactly a proof binds is being worked out in public elsewhere: a recent Ethereum Research post on proof boundaries argues that the hard part of a homomorphic tally is not adding encrypted ballots but specifying precisely what the proof must commit to for the sum to represent an election rather than an arbitrary valid computation. The same gap, between a proof that verifies and a proof that means what its designers intended, is what Aztec found in its own system.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec gains reputational credit for disclosing before mainnet and for its artificial-intelligence auditing program, while competing zero-knowledge rollups gain a talking point about proving-stack risk.
Every substantive detail rests on Aztec's own disclosure with no independent confirmation available, the project states it cannot determine whether anyone exploited the flaw, and the embargo on technical specifics means outside reviewers cannot yet check either the severity claim or the assurance that no other critical issue exists.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Rollups and privacy networks that replace re-execution with proofs concentrate their entire security assumption into the proving stack, so a soundness bug there is unbounded rather than contained to one contract. Users of proof-based privacy networks are exposed through a channel they cannot monitor, because a valid-looking proof leaves no on-chain trace of the violation. The practical consequence is slower, more conditional adoption of confidential execution by institutions, and more weight on escape hatches, staged rollouts and proof-system diversity as the criteria buyers apply before committing balances.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network (Alpha V5)
Comments
0No comments yet.