Morning Edition · Monday, August 31, 2026Published at 1:50 AM EDT · New York
Core contributors found the soundness bug through internal AI-assisted auditing on 27 July and are deferring the fix to the next release, the second critical proving-system defect Aztec has disclosed this year.

Aztec, the privacy-focused Ethereum layer-2 network, disclosed a critical vulnerability in the proving system behind its Alpha v5 release. According to the team, an attacker could construct a proof that passes verification for a transaction the network should have rejected. Core contributors identified the defect on 27 July through internal auditing assisted by automated code analysis, and the repair is scheduled for the next version rather than a patch to the running network.
This is a different class of failure from a smart-contract bug. In a zero-knowledge system, the proof is the only thing a verifier checks. If the proving circuit is unsound, the verifier accepts a false claim, and every downstream assumption about balances and ownership fails at once. Validator re-execution, the fallback that catches ordinary execution errors on optimistic systems, does not detect it, because the network never sees the underlying computation.
The disclosure follows the same pattern Aztec used in March, when it announced a critical vulnerability in Alpha v4 and shipped the fix inside the v5 release. Aztec has raised its bug bounty to $2 million and says reviewers have not identified other high-severity findings in v5 at this time. The network remains an alpha deployment, which is why the team can hold a soundness defect for a scheduled upgrade rather than trigger an emergency response.
The straightforward reading is that repeated findings in a maturing prover are what alpha testing is for. The harder one is that these bugs are being found by the team that wrote the code, and that no independent party has demonstrated it can find them first.
Aztec gains reputational credit for disclosing a soundness defect it found itself, and competing rollup teams gain a talking point that a single proving system without independent verification concentrates risk.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Every material detail, including the 27 July discovery date, the severity, and the claim that no other high-severity findings exist, rests on Aztec's own disclosure, and no outside party has published a reproduction, which is the same one-sided evidence pattern as the March Alpha v4 disclosure.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Every rollup that replaces re-execution with a single proving system inherits the same concentrated risk, and the people exposed are users whose withdrawals depend on one verifier contract. As tokenized assets and private stablecoins move onto proof-based chains, the operational question shifts from whether contracts are audited to whether anyone outside the core team can independently falsify a proof. Two outcomes divide here: either proof-system diversity and escape hatches become standard before real value arrives, or the first soundness bug found by an attacker rather than an auditor lands on a network holding institutional balances.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network
Comments
0No comments yet.