Morning Edition · Tuesday, September 15, 2026Published at 1:52 AM EDT · New York
Core contributors found the defect in the live Alpha V5 privacy network on 27 July using internal artificial-intelligence-assisted auditing, and the fix ships with V6.

Aztec, the privacy-focused layer-2 network on Ethereum, has published a disclosure describing a critical defect in the proving system behind its live Alpha V5 release. According to the team's write-up, an attacker could construct a proof that passes verification for a transaction the network is supposed to reject, producing a state transition outside the rules the protocol intends to enforce. Core contributors identified the flaw on 27 July through internal auditing assisted by artificial intelligence, and the repair is scheduled for the V6 release.
This is a soundness failure, not a bug in an application contract. In a zero-knowledge rollup, the proof is the only check between a submitted transaction and the network's accounting of who owns what. Optimistic rollups can fall back on other participants re-executing transactions and challenging a bad result. A proof-based system cannot, because there is nothing to re-execute if the verifier accepts a fraudulent proof as valid.
The disclosure follows the same pattern as Aztec's March disclosure of a critical vulnerability in Alpha V4, which the team said affected the proving system as a whole and could enable theft of user funds. In both cases Aztec withheld details until a fixed version was ready, and told V4 users to withdraw before the disclosure went public.
Aztec has been explicit that its Alpha releases are test-phase software, with applications such as an on-chain game running on the network and a bug bounty raised to $2 million. The straightforward reading is that the disclosure process worked as designed. The less comfortable reading is that two consecutive versions of a production-labeled privacy network shipped with proof defects that only internal review caught.
Part of a tracked trend
Proving-System Bugs Become a Distinct Rollup Risk
Soundness defects in zero-knowledge proving systems will keep surfacing as a risk class separate from smart-contract exploits, because validator re-execution — the fallback most rollups rely on — cannot catch them, forcing teams into embargoed disclosure timed to upgrades and pushing users toward proof-system diversity and escape hatches.
Start a discussion in Townsquare.
More from this edition
Aztec controls the disclosure timeline and the severity characterization, which protects deposited funds during the embargo and also protects the network's reputation, while competing rollups that publish adversarial audit results gain a comparison point.
Every load-bearing detail (the 27 July discovery date, the artificial-intelligence-assisted attribution, the severity, and the claim that no attacker found it first) comes from Aztec's own write-up with no independent researcher confirming it, and no evidence has been published either way on whether the flaw was exploited before the fix.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Proof-based chains concentrate their entire security assumption into one piece of cryptographic machinery, so a soundness bug is not a loss capped at one contract's balance but a defect in the ledger's own accounting. Users of privacy rollups are exposed through the withdrawal path, because a forged state transition can move funds before anyone can observe it, and the confidentiality that makes these networks valuable also removes the on-chain trail that lets outsiders detect the theft. Teams that publish on this timeline face a second cost: every embargo period is a stretch of time during which insiders know more than depositors.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Aztec Network · Aztec Network · Aztec Network
Comments
0No comments yet.