TechFlow reported on June 15 that SlowMist released a technical analysis on an attack against the deprecated Aztec Connect RollupProcessor contract. According to the report, the incident was caused by a settlement-boundary bypass vulnerability in the contract, and the protocol lost about $2.19 million in assets.
SlowMist said the attacker took advantage of a mismatch between numRealTxsnumRealTxs and decoded_slotsdecoded_slots. By using that mismatch, the attacker fabricated deposits and created an inconsistency between the L1 and L2 states. With the two states no longer aligned, the attacker bypassed L1 settlement verification and completed the transfer of funds.
The report also disclosed further details on the root cause of the vulnerability, the on-chain movement of funds, and the execution path of the attack. The analysis focused specifically on the deprecated Aztec Connect RollupProcessor contract and described how the settlement validation process was bypassed before the forged deposits and asset transfer were completed.

