Morning Edition · Wednesday, September 2, 2026Published at 1:46 AM EDT · New York
An attacker could construct a proof that passes verification for a transaction the network should reject, and the fix is scheduled for the next major version.

Aztec, the privacy-focused Ethereum layer-2 network, disclosed a critical vulnerability in the proving system of its Alpha V5 release. Core contributors identified the defect on 27 July 2026 during internal auditing assisted by artificial intelligence tools. The network says an attacker could build a proof that passes verification for a transaction the protocol should reject, producing a state transition outside the rules V5 is meant to enforce.
That is a soundness failure, not a bug in an application contract. In a zero-knowledge rollup, the proof is the rule. Optimistic systems and ordinary chains rely on other nodes re-executing transactions to catch invalid state, and a privacy network cannot fall back on that, because the transaction contents nodes would need to check are the very thing being hidden. Aztec told users to treat funds, applications and contract state on V5 as exposed to a protocol-level failure until contributors finish incident response and operators carry out the required network actions. The permanent fix is planned for V6, due later in 2026.
This is the second consecutive version affected. Aztec disclosed a critical vulnerability in Alpha V4 in March 2026, saying it touched the proving system as a whole and could lead to theft of user funds, and The Defiant reported that users were told to withdraw before 25 June ahead of the disclosure becoming public. The pattern is consistent with a deliberate policy: hold the details until an upgrade path exists, then publish.
The disclosure lands while V5 carries live applications, including a fully on-chain version of the strategy game Dark Forest that uses private state as a game mechanic. Aztec says reviewers have found no other high-severity or critical V5 defects, that internal and external human audits are complete, and that machine-assisted review continues.
The method of discovery matters as much as the bug. The defect was found by an audit process using AI tooling, on code that had already passed human review. Proving systems are mathematically dense, thinly staffed globally, and now reviewed by automated tools that can run without stopping.
What this means
Soundness bugs sit outside the risk model most rollup users apply. A user checking a rollup's contracts, audits and bridge design gains nothing if the verifier accepts a forged proof, and on a privacy network no one can re-derive the correct state from public data to prove that something went wrong. Holders of assets on any zero-knowledge network that has not published a proving-system security review carry a risk that no bug bounty scoped to application code prices.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network · Aztec Network
Comments
0No comments yet.