Odaily reported that, according to an analysis by BlockSec Phalcon (@Phalcon_xyz), Aztec Network’s RollupProcessorV3 contract was attacked, resulting in losses of more than $2.15 million. The analysis attributed the root cause to a mismatch at the boundary between the ZK proof verification path and the L1 settlement logic.
BlockSec Phalcon stated that numRealTxs was not effectively bound to the transaction set enforced by the ZK proof. As a result, the proof verification path and the L1 settlement logic interpreted the transaction list differently, creating a gap in how the settlement process handled the relevant deposit records.
The attacker used the vulnerability to move real deposits into slots that were not processed by the settlement logic, thereby bypassing the decreasePendingDepositBalance() function. After that, the attacker created uncollateralized private balances and withdrew them through the normal settlement process. BlockSec Phalcon said the incident involved seven different assets.

