Morning Edition · Saturday, September 12, 2026Published at 1:48 AM EDT · New York
Contributors found through internal AI-assisted auditing that an attacker could construct a proof the network would accept for a transaction it should reject.

Aztec, the privacy-focused Ethereum layer-2 network, has disclosed a critical vulnerability in the proving system behind its Alpha V5 release. Core contributors identified the defect on July 27 through internal auditing assisted by artificial intelligence tools. The flaw is a soundness failure: an attacker could construct a zero-knowledge proof that passes verification for a transaction the network should have rejected.
The distinction matters because of what it breaks. A smart-contract bug lets an attacker misuse rules the chain still enforces correctly. A soundness bug in the proving system means the chain's own verification of validity returns the wrong answer. On a network where transaction contents are private by design, the usual fallback of having validators re-execute transactions and compare results does not apply, because there is nothing public to re-execute. Aztec said internal and external human audits have completed, that reviewers have not found other high-severity or critical issues in Alpha V5, and that the correction is planned for V6.
This is the second such disclosure in the same product line. Aztec disclosed a critical vulnerability in Alpha V4 in March, saying it affected the proving system as a whole and could lead to severe disruption and theft of user funds, and it advised V4 users to withdraw before the V5 governance vote made the details public. The pattern that has now formed is embargoed disclosure timed to a scheduled upgrade, which is the only sequencing available when the bug is in the verifier itself.
Aztec has continued to ship in parallel. The network has published documentation on how transaction fees work on the chain and an Alpha V5 release page, and it has raised its bug bounty to $2 million. Notably, the finding came from internal AI-assisted review rather than an external attacker or a bounty hunter, which is the same discovery channel now surfacing defect backlogs across open-source cryptographic libraries.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec controls the disclosure timeline and benefits from presenting a soundness failure as a finding of its own auditing rather than an incident, while competing zero-knowledge rollups gain from the argument that single-prover designs carry a risk class audits do not cover.
Every load-bearing detail, including the July 27 discovery date and the claim that no other critical issues were found, comes from Aztec's own post with no independent confirmation, and the post goes further than the article does by stating that funds, applications and contract state on V5 should be treated as exposed until operators complete the required network actions, with V6 described as informed by the findings rather than as a scheduled fix with a published date.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Rollups that rely on a single proving system carry a risk class their audits are not scoped to catch, and the exposure sits with anyone holding assets on those chains during the window between discovery and the upgrade that fixes it. Privacy networks are the most exposed, because confidentiality removes the re-execution check that transparent rollups fall back on, which pushes serious deployments toward proof-system diversity, escape hatches, or staged mainnet launches with capped value at risk.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network · Aztec Network
Comments
0No comments yet.