Morning Edition · Friday, September 11, 2026Published at 1:49 AM EDT · New York
Core contributors found the defect on 27 July through internal artificial-intelligence-assisted auditing, after internal and external human audits had already finished without catching it.

Aztec, the privacy-focused Ethereum layer-2 network, disclosed a critical defect in the proving system behind its Alpha V5 release. According to the team, an attacker may be able to construct a proof that passes verification for a transaction the network should reject. That is a soundness failure, not a liveness problem: the verifier wrongly accepts an invalid transaction as valid.
Two details matter more than the bug itself. Core contributors identified it on 27 July 2026 through internal auditing assisted by artificial intelligence, after internal and external human audits had already completed. And the team states it cannot determine whether anyone exploited the flaw before the finding. Aztec says funds, applications and contract state on V5 should be treated as exposed to a protocol-level failure until operators complete the required network actions, and that reviewers have found no other critical or high-severity issues in V5 so far.
Soundness bugs sit in a different risk class from smart-contract exploits. A rollup that relies on validity proofs has no fallback of re-execution by independent validators to catch a forged proof, so the proving stack becomes a single point of correctness for every user balance it secures. Layer-2 networks tracked by L2Beat currently secure $48.85 billion in total value.
Aztec, which converts a soundness defect into evidence of disclosure discipline, and the vendors selling machine-assisted auditing that the disclosure credits with the find.
Every load-bearing detail comes from Aztec's own post with no external confirmation, and V5 is an alpha release, so "funds at risk" describes a test-stage network rather than the $48.85 billion the article cites for layer-2 networks generally.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The failure surface for zero-knowledge rollups is the circuit and the verifier, not the application code that auditors usually price. Users and applications on proof-based networks are exposed through a channel they cannot inspect, because a forged proof looks identical to a valid one on chain. The disclosure also carries a second signal for the audit industry: machine-assisted review caught what completed human audits missed, which shifts where security budgets go. Two outcomes are in play. Either proof-system diversity and working escape hatches become standard requirements before networks hold serious value, or teams keep launching single-prover systems and the next such bug is found by an attacker rather than an auditor.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Alpha V5
Comments
0No comments yet.