Search

Search for projects by name or address

Zk.Money v1 (Aztec v1) logo
Zk.Money v1 (Aztec v1)

Badges

About

Zk.Money v1 (Aztec v1, or sometimes called Aztec 2.0) is an open source layer 2 network that aims to enable affordable, private crypto payments via zero-knowledge proofs.



About

Zk.Money v1 (Aztec v1, or sometimes called Aztec 2.0) is an open source layer 2 network that aims to enable affordable, private crypto payments via zero-knowledge proofs.


Total
Canonically BridgedCanonically Bridged ValueCanonical
Natively MintedNatively Minted TokensNative
Externally BridgedExternally Bridged ValueExternal

ETH & derivatives
Stablecoins
BTC & derivatives
Other

The section shows the operating costs that L2s pay to Ethereum.



Total cost
Avg cost per L2 UOP
Avg cost per day

This section shows how "live" the project's operators are by displaying how frequently they submit transactions of the selected type. It also highlights anomalies - significant deviations from their typical schedule.


Avg. proof subs. interval
Avg. state updates interval

Escape-hatch verifier exploit

2026 Jun 17th

$2.2M of assets are drained by exploiting an unsound verification key.

Learn more

Aztec operator sunset

2023 Jul 8th

Aztec stops their rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. operators. Users now have to run the Rollup manually.

Learn more
On 2026-06-17 the immutable rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. contract was exploited for ~$2.16M (1,158 ETH, ~150k DAI and renBTC) through its emergency escapeHatch() withdrawal function. Ownership of the rollup contract is irrevocably renounced, so it cannot be paused or patched, and Aztec is not running a rollup processor (operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades.). Aztec stated the affected product is deprecated and unrelated to the current Aztec NetworkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. or the AZTEC token.
On 2026-06-17 the immutable rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. contract was exploited for ~$2.16M (1,158 ETH, ~150k DAI and renBTC) through its emergency escapeHatch() withdrawal function. Ownership of the rollup contract is irrevocably renounced, so it cannot be paused or patched, and Aztec is not running a rollup processor (operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades.). Aztec stated the affected product is deprecated and unrelated to the current Aztec NetworkA constellation of nodes (peers) that communicate via a peer-to-peer protocol, for example, in propagating transactions and blocks to other nodes. or the AZTEC token.
Sequencer failureState validationData availabilityExit windowProposer failure
Sequencer failure
Self sequence

In the event of a sequencerA party responsible for ordering and executing transactions on the rollup. The sequencer verifies transactions, compresses the data into a block, and submits the data related to it to enable state reconstruction to Ethereum L1 as a single transaction. The data can be either transaction data or state diffs. failure, users can force transactions to be included in the project’s chain by sending them to L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development.. Proposing new blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. requires creating ZK proofs.

State validation
Validity proofs (SN)

SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setupGeneration of a piece of data that must then be used for some cryptographic protocol to run. Generating this data requires some secret information. The "trust" comes from the fact the secret must be destroyed after the ceremony, otherwise cryptographic properties of the protocol could be broken. Once the data is generated, and the secrets are forgotten, no further participation from the creators of the ceremony is required. There are two types of trusted setups for SNARKs: (i) trusted setup per circuit where it is generated from scratch for each circuit, (ii) trusted universal setup per proving system where it can be used for several circuits..

Data availability
Onchain

All of the data needed for proof construction is published on Ethereum L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development..

Exit window
∞

Users can exit funds at any time because contracts are not upgradeable.

Proposer failure
Self propose

If the ProposerIn the context of L2s, the actor that proposes a claimed state root on L1. The term is also used in the context of Ethereum to refer to the actor that proposes a new block. fails, users can leverage the source available proverAn entity that generates the cryptographic proof to convince the verifier that the statement is true. In a ZK-Rollup, the prover generates the ZK (validity) proof to submit to the verifier contract. to submit proofs to the L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. bridgeA message-passing protocol between two blockchains. At its most basic, a token bridge consists of a smart contract which can escrow funds on one side of the bridge, and instruct the release or minting of corresponding assets on the other side, but bridges could also support arbitrary messages. How these instructions are validated is a critical factor in assessing the trust assumptions of a bridge..

Zk.Money v1 (Aztec v1)
Zk.Money v1 (Aztec v1) is a
Stage 2
Appchain
ZK Rollup.
The project passes the walkaway test: users can exit in the presence of malicious operators even if the Security Council disappears.

Rollup operators cannot compromise the system, but being application-specific might bring additional risk.

Aztec v2 is a private rollup that allows users to transfer assets privately. Arbitrary smart contracts are not supported.

Note:
We're still in the process of formalizing how to properly integrate appchains in the Stages framework.

Learn more about Stages
Please keep in mind that these stages do not reflect project security, this is an opinionated assessment of project maturity based on subjective criteria, created with a goal of incentivizing projects to push toward better decentralization. Each team may have taken different paths to achieve this goal.

All data required for proofs is published onchain

All the data that is used to construct the system state is published onchain in the form of cheap calldata. This ensures that it will always be available when needed.

  1. RollupProcessor.sol#L359 - Etherscan source code
Learn more about the DA layer here: Ethereum logoEthereum
Node software

There are three ways to run a nodeA software client that participates in the network. and use the escape hatchThe facility for any user of a rollup to exit the system with their assets under any circumstance. Most relevant in rollups with a centralized proposer, wherein users do not have the ability to propose blocks, but can nonetheless exit the rollup by interacting with a smart contract on L1.: By running the Aztec v2 Ejector during the escape hatch window, 2) by running falafel, 3) by running the SDK in escape hatch mode and connecting to an escape hatch server. The two latter methods are no longer recommended by the Aztec team.

Compression scheme

No compression scheme is used.

Genesis state

No genesis state is used.

Data format

The data format used can be found here.

Validity proofs

Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract.

  1. RollupProcessor.sol#L395 - Etherscan source code
2025 May 12, 09:49 UTC
1change

Discovery rerun on the same block number with only config-related changes.

New and verified contracts

+ Status: CREATED
contract VerificationKeysLibrary (eth:0xF3761B450571a49Fa8e2aF6e37e1Eb3516209d56)
+++ description: None
2025 July 14, 12:44 UTC
4changes

Discovery rerun on the same block number with only config-related changes.

New and verified contracts

+ Status: CREATED
contract AztecFeeDistributor (0x41A57F5581aDf11b25F3eDb7C1DB19f18bb76734)
+++ description: Contract responsible for collecting transaction fees and reimbursing gas to whitelisted Rollup Providers.
+ Status: CREATED
contract TurboVerifier (0x48Cb7BA00D087541dC8E2B3738f80fDd1FEe8Ce8)
+++ description: Turbo Plonk ZK verifier.
+ Status: CREATED
contract RollupProcessor (0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba)
+++ description: None
+ Status: CREATED
contract Aztec Multisig (0xE298a76986336686CC3566469e3520d23D1a8aaD)
+++ description: None
2025 May 09, 10:53 UTC
High severity
3changes

The public address (private key was made public so anyone can operate the chain) set a 7702-authorization to a drainer because there were some minor tokens in the EOA.

EOA FirstAnvilAddress (0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266) {
+++ description: None
proxyType:
- "EOA"
+ "EIP7702 EOA"
unverified:
+ true
values:
+ {"$implementation":"0x698Cd6D2618bAa3E35ECb7322919C5fce95886Cf"}
}
2024 May 06, 14:22 UTC
1change

Ownership of the rollup contract is renounced.

contract RollupProcessor (0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba) {
+++ description: None
values.owner:
- "0xE298a76986336686CC3566469e3520d23D1a8aaD"
+ "0x0000000000000000000000000000000000000000"
}
2024 March 25, 10:52 UTC
1change

Rollup processors receive gas reimbursements from the AztecFeeDistributor for having called the processRollup() function. The reimburseConstant, which is a constant added to each dynamically calculated gas reimbursement is now set to 0. Context: Zk.money V1 (this project) is sunset for a long time now. Users can only exit by running a local docker container that runs the rollup. They have to pay the processRollup() transaction fee but get refunded by the AztecFeeDistributor.

contract AztecFeeDistributor (0x41A57F5581aDf11b25F3eDb7C1DB19f18bb76734) {
+++ description: None
+++ description: Tip that gets added to a gas reimbursement for processing the rollup.
+++ severity: LOW
values.reimburseConstant:
- 678600
+ 0
}

No regular operators

Only specific addresses appointed by the owner are permitted to propose new blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. during regular rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. operations. Since EOL, these operators are not regularly processing the rollup anymore.

  1. RollupProcessor.sol#L97 - Etherscan source code
  2. RollupProcessor.sol#L369 - Etherscan source code

Users can force any transaction

Because the blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. production is open to anyone if users experience censorship from the operatorAn operator is the entity charged with managing a rollup and progressing its state. A rollup operator can be a centralized sequencer, proposer, prover, challenger, pauser of admin that is able to perform upgrades. they can propose their own blocks which would include their transactions.The private key of one of the permissioned operators is public (first Anvil address), therefore anyone can in principle resume regular operations. No funds need to be deposited to that address since submitting signatures is enough. Every 16h a special 48m window (escape hatchThe facility for any user of a rollup to exit the system with their assets under any circumstance. Most relevant in rollups with a centralized proposer, wherein users do not have the ability to propose blocks, but can nonetheless exit the rollup by interacting with a smart contract on L1.) is open during which any address can propose new blocks.

  • Funds can be frozen if the operator refuses to include their transactions and users lack resources to propose blocks themselves.

  1. Anvil - a local testnet node toolchain
  2. RollupProcessor.sol#L347 - Etherscan source code
  3. RollupProcessor.sol#L168 - Etherscan source code

Regular withdraw (deprecated)

The user initiates the withdrawal by submitting a transaction on L2Layer 2 (L2) is a category of technical solutions aimed to scale the base layer in a trust minimized way. This category includes solutions like rollups as well as state channels and plasma. Other solutions are able to scale further, but with the introduction of additional trust assumptions, which are therefore not trust minimized. Sometimes the term Layer 2 is used to refer to include these solutions too, like validiums and optimiums, but to distinguish between trust minimized and non trust minimized solutions they are often referred to as "light" L2s, opposed to "strong" L2s like rollups.. When the blockAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. containing that transaction is proven on L1Layer 1 (L1) is a blockchain that is self-reliant on its validator set for its security and consensus properties. Ethereum is an example of a layer 1. Blockchains started receiving the moniker of layer 1 once layer 2 became a meaningful area of development. the assets are automatically withdrawn to the user.

  1. RollupProcessor.sol#LL396 - Etherscan source code

EOL: Manual withdrawal using Aztec v2 Ejector

EOL: Ownership of the rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. contract is irrevocably renounced and operators are not processing the rollup. Assets in the escrow can be manually withdrawn with the Aztec v2 Ejector.

  1. Aztec v2 Ejector - Codespace template for running the Aztec v2 rollup.

Payments are private

Balances and identities for all tokens on the Aztec rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. are encrypted. Each transaction is encoded as a zkSNARK, protecting user data.

  1. Fast Privacy, Now - Aztec Medium Blog
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner

Ethereum

Actors:

Addresses that can propose new blocksAn ordered list of transactions and chain-related metadata that gets bundled together and published to the L1/DA layer. Nodes execute the transactions contained within blocks to change the rollup chain’s state. Protocol rules dictate what constitutes a valid block, and invalid blocks are skipped over. during regular rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. operation. Since the private key of one of them is public (first Anvil address), anyone can in principle resume regular operations. Every 16h a special 48m window (escape hatchThe facility for any user of a rollup to exit the system with their assets under any circumstance. Most relevant in rollups with a centralized proposer, wherein users do not have the ability to propose blocks, but can nonetheless exit the rollup by interacting with a smart contract on L1.) is open during which anyone can propose new blocks.

Aztec Multisig0xE298…8aaD

A Multisig with 1/2 threshold. Can update parameters related to the reimbursement of gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. to permissioned rollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. providers. It doesn’t affect the escape hatchThe facility for any user of a rollup to exit the system with their assets under any circumstance. Most relevant in rollups with a centralized proposer, wherein users do not have the ability to propose blocks, but can nonetheless exit the rollup by interacting with a smart contract on L1. mechanism, but it can halt regular operations by setting a reimbursement constant that is too high.

Participants (2):

0x1D93…4fdD0x7fb9…Fc5f
A dashboard to explore contracts and permissions
Go to Disco
Disco UI Banner
A diagram of the smart contract architecture
A diagram of the smart contract architecture

Ethereum

AztecFeeDistributor0x41A5…6734

Contract responsible for collecting transaction fees and reimbursing gasA virtual fuel used to execute smart contracts on a rollup. The EVM (or other VM within the rollup) uses an accounting mechanism to correspond the consumption of gas to the consumption of computing resources, and to limit the consumption of computing resources. to whitelisted RollupA blockchain that inherits consensus and data availability from another blockchain called L1. Rollups enable trust minimized bridges with the base layer via proof systems, either optimistic or zero-knowledge. A rollup without a bridge, or without considering the bridge, is called a sovereign rollup. Providers.

TurboVerifier0x48Cb…8Ce8

Turbo PlonkA zk-SNARK proving system introduced by Gabizon, Williamson and Ciobotaru in 2019 that allows proving custom circuits. Plonk is based on KZG polynomial commitments and thus requires a universal trusted setup. ZK verifierAn entity in a ZK-Rollup, often a smart contract, that verifies zero-knowledge proofs submitted by a prover..

RollupProcessor0x7379…A2ba