# Aztec Discloses Critical Proving-System Flaw in Its Live Alpha V5 Privacy Network

Core contributors found the defect on 27 July through internal auditing assisted by artificial intelligence (AI) tools, and say an attacker could construct a proof that verifies for a transaction the network should reject.

- Published: 2026-09-09T05:46:55.977Z
- Canonical: https://polylog.news/crypto/2026-09-09/aztec-discloses-critical-proving-system-flaw-in-its-live-alp
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Aztec Network (disclosure)](https://aztec.network/blog/alpha-v5-proving-system-vulnerability), [Aztec Network (Alpha V5)](https://aztec.network/alpha-v5), [Aztec Network (ecosystem)](https://aztec.network/blog/dark-forest-aztec-game-goes-live)

Aztec, the privacy-focused Ethereum layer-2 network, has [disclosed a critical vulnerability in the proving system behind its Alpha V5 network](https://aztec.network/blog/alpha-v5-proving-system-vulnerability). Core contributors identified the defect on 27 July 2026 through internal auditing assisted by AI tooling. In the disclosure, Aztec says an attacker could build a proof that passes verification for a transaction the network is supposed to reject, and that such a transaction could then move the chain into a state outside the rules the protocol intends to enforce. Contributors say funds, applications and contract state on V5 should be treated as exposed until incident response finishes and node operators complete the required network actions.

This is the second proving-system disclosure of its kind at Aztec inside a year. In March the team disclosed a critical flaw affecting Alpha V4 and warned that exploitation could lead to theft of user funds, then asked users to withdraw before a governance vote made the details public. The [Alpha V5 network](https://aztec.network/alpha-v5) launched as the successor and now carries live applications, including the on-chain strategy game Dark Forest, [which went live on Aztec](https://aztec.network/blog/dark-forest-aztec-game-goes-live).

The pattern deserves attention on its own terms. Aztec says human audits, both internal and external, were already complete when the AI-assisted review surfaced the problem. That is a statement about the limits of conventional audit coverage for zero-knowledge circuits, where the failure is not a logic error a reviewer can read but an under-constrained relation that lets a false statement satisfy the verifier. Nothing in an audit report certifies that the constraint set matches the intended rules.

Aztec has raised its bug bounty to $2 million and continues AI-assisted review. The disclosure follows the standard practice of privacy networks: describe the class of failure, withhold the reproduction path, and time publication to an upgrade. That protects users during the patch window, and it also means outsiders cannot yet judge how close the network came to an exploited state.

## What this means

Privacy layer-2 networks ask users to trust a circuit rather than a set of readable contracts, and a soundness bug there breaks supply integrity rather than a single application. Users holding assets on Aztec V5 and teams building on it bear the exposure directly, and slower institutional adoption across the wider privacy sector is the broader consequence. The finding also sets a precedent that AI-assisted review is now the technique catching defects that completed human audits missed, which raises the expected disclosure rate across every zero-knowledge system running today.

## What to watch

- Whether Aztec publishes the constraint-level detail after the network upgrade, which other zero-knowledge teams need in order to check whether their own circuits share the pattern.
- Whether users withdraw from Alpha V5 applications during the response window, which measures how much the disclosure costs a network still building its user base.
- Whether competing privacy networks adopt AI-assisted circuit review and report findings, which would show whether this is an Aztec-specific backlog or an industry-wide one.
