Morning Edition · Saturday, August 29, 2026Published at 1:48 AM EDT · New York
Core contributors found the defect through internal AI-assisted review, and it is the second consecutive Aztec release whose proving system carried a fund-threatening bug.

Aztec, the Ethereum layer-2 network built for private smart contracts, has disclosed a critical vulnerability in the proving system of its Alpha V5 release. Core contributors identified the defect in late July through internal review assisted by AI tooling, not through an external attack.
The failure class matters more than any single bug. In a zero-knowledge rollup, the proof is the guarantee. An attacker who can construct a proof that verifies for a transaction the network should reject does not need to break a contract, steal a key or manipulate a price. The chain accepts the invalid state as correct. This is precisely the risk that ordinary validator re-execution cannot catch, because on a privacy network there is no public transaction body for other nodes to re-run. The soundness of the prover is the last line, and when it fails there is no second check behind it.
Aztec has now been through this cycle twice in one year. In March the team disclosed a critical proving-system vulnerability in Alpha V4, kept the technical detail private until the successor release shipped, and told V4 users to withdraw ahead of the cutover. Alpha V5 was itself presented as the version that fixed those flaws. The team has raised its bug bounty to $2 million and continues to publish operational documentation, including how transaction fees work on the network.
The context is a privacy sector that is being pitched to institutions as production-ready. Aztec's total value secured is small next to the general-purpose rollups. Layer-2 networks tracked by L2Beat hold $44.01 billion in total, with Base at $12.36 billion and Arbitrum One at $11.61 billion. Repeated soundness defects in a live privacy network give the institutions weighing confidential execution a concrete reason to wait for proof-system maturity, and they give the argument for proof diversity and working escape hatches its strongest evidence yet.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec's competitors in confidential execution and the general-purpose rollups gain from a second soundness disclosure in one year, and Aztec itself gains reputational credit for finding the defect internally before an attacker did.
Every load-bearing fact here comes from Aztec's own disclosure and nothing has been independently verified, because the technical detail is embargoed until users migrate, so outsiders cannot confirm the severity, the exploitability, or the claim that no other critical defect remains in the release.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Proving-system soundness is a risk category separate from smart-contract bugs, and it is the one class of failure that a rollup's users cannot independently detect. Anyone holding assets on a zero-knowledge network is exposed to a defect that only the prover team can find, which is why the disclosure timeline is bound to the upgrade schedule rather than to the discovery date. Two outcomes are live: either privacy rollups converge on multiple independent proof implementations and reliable exits, in which case the risk becomes priced and bounded, or the disclosures keep arriving one release apart and institutional confidential-execution pilots stay in testing rather than moving real balances.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network · Aztec Network
Comments
0No comments yet.