Morning Edition · Sunday, September 13, 2026Published at 1:57 AM EDT · New York
Core contributors found the defect on 27 July through internal AI-assisted auditing, cannot rule out prior exploitation, and have scheduled the fix for the next network version.

Aztec Network, an Ethereum layer-2 built for private smart contracts, has disclosed a critical vulnerability in the proving system that secures its live Alpha V5 network. Core contributors identified the defect on 27 July 2026 during internal auditing assisted by artificial intelligence tools. According to the disclosure, an attacker may be able to construct a proof that passes verification for a transaction the network is supposed to reject, which would allow a state transition outside the rules the protocol intends to enforce.
Aztec told users to treat funds, applications and contract state on V5 as exposed to a protocol-level failure until contributors finish incident response and operators complete the required network actions. Contributors said they cannot determine whether anyone exploited the flaw before they found it. Reviewers have not identified other critical or high-severity findings in V5, and the correction is planned for V6, the next version of the network.
This is the second proving-system failure Aztec has disclosed this year. It warned V4 users to withdraw before publicly disclosing an earlier critical flaw, and it has since raised its bug bounty to two million dollars.
The class of bug matters more than the individual product. A soundness defect in a zero-knowledge proving system is not a smart-contract bug. The fallback that most optimistic rollups rely on, honest parties re-executing transactions and challenging bad state, does not exist in the same form for a validity-proof chain, because the chain accepts whatever the verifier accepts. That places unusual weight on a small number of cryptographic implementations, and on the fee and operator design that decides who can push a proof on-chain in the first place. Aztec's own account is also a data point in a separate argument: the flaw was surfaced by machine-assisted review rather than by an attacker.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec controls the account by disclosing before any attacker acts, artificial-intelligence auditing vendors and rival zero-knowledge teams gain a marketing case, and depositors on Alpha V5 carry whatever exposure exists.
The sole account of the defect is Aztec's own post, which gives no technical detail, no third-party confirmation and no on-chain evidence, so "cannot rule out prior exploitation" is consistent with both a near miss and an undetected loss, and the credit to AI-assisted review is unverifiable from outside.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Validity-proof chains concentrate their entire security budget in one verifier. When that verifier can be fooled, every application and every balance on the network inherits the defect at once, and users have no re-execution fallback to catch it. The exposed parties are depositors on Alpha V5 and the teams building on it, plus the wider set of zero-knowledge rollups whose users now have to price proving-system risk as a separate line item from contract audits. Two outcomes are possible from here: Aztec ships V6 with no evidence of exploitation and the episode reinforces the case for AI-assisted auditing, or on-chain analysis later shows an anomalous state transition, which would make prover diversity and escape hatches a hard requirement rather than a research topic.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network (disclosure) · Aztec Network (Alpha V5) · Aztec Network (gas design)
Comments
0No comments yet.