Morning Edition · Sunday, September 6, 2026Published at 2:01 AM EDT · New York
Core contributors found the defect on 27 July through internal artificial-intelligence-assisted auditing and now tell users to treat funds and applications on the privacy network as exposed until operators complete the required actions.

Aztec, the privacy-focused Ethereum layer-2 network, disclosed a critical vulnerability in the proving system behind its Alpha V5 release. According to the project, an attacker may be able to construct a proof that passes verification for a transaction the network should reject. If the network accepted such a proof, it would produce a state transition outside the rules V5 is meant to enforce. Aztec says core contributors identified the defect on 27 July 2026 through internal auditing assisted by artificial intelligence, after both internal and external human audits had already finished.
The project told users to treat funds, applications and contract state on Alpha V5 as exposed to a protocol-level failure until contributors finish incident response and network operators carry out the required actions. Reviewers have not identified other high-severity or critical defects in V5 at this time.
This is the second proving-system failure Aztec has disclosed this year. It reported a critical vulnerability in Alpha V4 in March, saying the flaw affected the proving system as a whole and could lead to theft of user funds, and it told V4 users to withdraw before 25 June because the V5 governance proposal would make the underlying V4 bugs public.
The category matters more than the individual bug. A soundness defect is not a smart-contract bug that a careful reader of Solidity can spot. It exists within the mathematics and the circuit implementation that determine which state transitions are valid at all. Most optimistic and hybrid rollups rely on validators re-executing transactions, but on a network where transaction contents are encrypted by design, that fallback does not exist. The safety of user balances depends on the correctness of the verifier and on the operators who can pause or upgrade the chain, which is the opposite of the credible-neutrality claim privacy rollups make in their marketing.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec, which converts a proving-system failure into evidence of disclosure discipline, and the competing zero-knowledge networks and audit firms that can now sell verifier diversity and automated review as a paid requirement.
Every technical detail comes from Aztec's own post with no third-party reproduction, and the load-bearing unknown is not whether the defect exists but whether it was exploitable in practice, since a project that also disclosed a critical V4 proving flaw in March has a reputational interest in framing a second failure as a controlled catch rather than a near miss.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Soundness bugs move risk from application developers to the chain itself, and the people exposed are every user and application holding value on that chain, because a forged proof can rewrite balances without breaking any contract. Aztec's disclosure also shows who is finding these defects now: automated review caught what earlier human audits had missed. Two outcomes are in play. Either proof-system diversity and fast emergency-override mechanisms become standard for zero-knowledge rollups, which raises engineering cost and slows launches, or teams keep shipping single-verifier designs and each disclosure forces another emergency upgrade window during which operators hold effectively total control.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network (Alpha V5) · The Defiant
Comments
0No comments yet.