Morning Edition · Thursday, September 10, 2026Published at 1:53 AM EDT · New York
Core contributors found the flaw on 27 July through internal artificial-intelligence-assisted auditing, cannot rule out prior exploitation, and have deferred the fix to the next version of the protocol.

Aztec, the privacy-focused Ethereum layer-2 network, has disclosed a critical vulnerability in the proving system underpinning its live Alpha V5 network. According to the project, an attacker may be able to construct a zero-knowledge proof (a cryptographic argument that a computation was performed correctly, without revealing its inputs) that passes verification for a transaction the network is supposed to reject. If the network accepted such a proof, the resulting state transition would fall outside the rules V5 is designed to enforce, placing funds, applications and contract state at risk.
Core contributors say they identified the defect on 27 July 2026 through internal auditing assisted by artificial intelligence, after internal and external human audits had already been completed. They also state plainly that they cannot determine whether anyone exploited the flaw before the finding. Reviewers have not identified other high-severity or critical issues in V5 Alpha, and the fix is planned for V6, expected later in 2026.
The disclosure follows the same pattern Aztec used earlier this year, when it withheld details of a critical V4 proving bug until a governance upgrade moved users off the affected version. That sequencing is deliberate. A soundness defect cannot be quietly patched around, because publishing it before users can exit would give any attacker the technical detail needed to replicate the exploit.
The class of failure matters more than this one network. Most rollups treat validator re-execution as the backstop that catches bad state. Re-execution catches an invalid transaction. It does not catch a valid-looking proof of an invalid transaction, because the proof itself is the thing being trusted. Aztec's Alpha V5 release and the applications now deployed on it run on software the team itself labels experimental, an honest framing that most production zero-knowledge systems do not offer.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec gains credit for disclosing a soundness flaw before an exploit is proven, and rival zero-knowledge networks that run multiple provers or working exit mechanisms gain a marketing argument against single-prover stacks.
Every detail comes from Aztec's own post with no independent researcher confirming the flaw's scope, and the load-bearing nuance is that the company found the defect on 27 July, kept the live network running, and has deferred the fix to V6, the same embargo sequence it used for the V4 bug earlier this year.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Proof soundness is the single trust assumption a zero-knowledge rollup cannot delegate. When it breaks, the users exposed are those with assets sitting inside the rollup, and the only remedy is exiting before disclosure or waiting for an upgrade. For the wider layer-2 sector, the finding shifts the security question from "is the contract audited" to "who else can verify the prover," which favours networks with proof-system diversity, working escape hatches and published upgrade timelines, and penalises those whose security rests on a single unreviewed proving stack.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network (Alpha V5) · Aztec Network (Apps)
Comments
0No comments yet.