# Zk.Money v1 (Aztec v1) Markdown version of https://l2beat.com/layer2s/projects/aztecv1 ## Summary **Warning:** This project is archived and no longer maintained. - Total Value Secured: $49.97 (-0.02% compared to seven days ago; canonically bridged $49.97, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Stage: Stage 2 - Type: ZK Rollup - Purposes: Payments, Privacy - Host chain: Ethereum ### Risks - Sequencer failure: Self sequence (sentiment: good) - State validation: Validity proofs (SN) (sentiment: good) - Data availability: Onchain (sentiment: good) - Exit window: ∞ (sentiment: good) - Proposer failure: Self propose (sentiment: good) ### About Zk.Money v1 (Aztec v1, or sometimes called Aztec 2.0) is an open source layer 2 network that aims to enable affordable, private crypto payments via zero-knowledge proofs. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/aztecv1#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/aztecv1) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/aztecv1/breakdown) ## Onchain costs Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/aztecv1#onchain-costs). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/aztecv1#liveness). ## Milestones & Incidents - 2026-06-17 (incident): [Escape-hatch verifier exploit](https://www.aztec-labs.com/blog/aztec-2-incident.html). $2.2M of assets are drained by exploiting an unsound verification key. - 2023-07-08: [Aztec operator sunset](https://github.com/AztecProtocol/aztec-v2-ejector/). Aztec stops their rollup operators. Users now have to run the Rollup manually. - 2021-03-15: [Aztec 2.0](https://medium.com/aztec-protocol/launching-aztec-2-0-rollup-ac7db8012f4b). Private Rollup is live on mainnet, allowing user to access DeFi. ## Risk summary **Warning:** On 2026-06-17 the immutable rollup contract was [exploited for ~$2.16M](https://x.com/aztecFND/status/2067511967237939636) (1,158 ETH, ~150k DAI and renBTC) through its emergency escapeHatch() withdrawal function. Ownership of the rollup contract is irrevocably renounced, so it cannot be paused or patched, and Aztec is not running a rollup processor (operator). Aztec stated the affected product is deprecated and unrelated to the current Aztec Network or the AZTEC token. ### Funds can be frozen if 1. the operator refuses to include their transactions and users lack resources to propose blocks themselves. ## Risk analysis **Warning:** On 2026-06-17 the immutable rollup contract was [exploited for ~$2.16M](https://x.com/aztecFND/status/2067511967237939636) (1,158 ETH, ~150k DAI and renBTC) through its emergency escapeHatch() withdrawal function. Ownership of the rollup contract is irrevocably renounced, so it cannot be paused or patched, and Aztec is not running a rollup processor (operator). Aztec stated the affected product is deprecated and unrelated to the current Aztec Network or the AZTEC token. ### Sequencer failure Self sequence (sentiment: good) In the event of a sequencer failure, users can force transactions to be included in the project's chain by sending them to L1. Proposing new blocks requires creating ZK proofs. ### State validation Validity proofs (SN) (sentiment: good) SNARKs are succinct zero knowledge proofs that ensure state correctness, but require trusted setup. ### Data availability Onchain (sentiment: good) All of the data needed for proof construction is published on Ethereum L1. ### Exit window ∞ (sentiment: good) Users can exit funds at any time because contracts are not upgradeable. ### Proposer failure Self propose (sentiment: good) If the Proposer fails, users can leverage the source available prover to submit proofs to the L1 bridge. ## Stage Zk.Money v1 (Aztec v1) is a Stage 2 ZK Rollup. ### Scope of assessment #### In scope - L1 core contracts - Gas token #### Not in scope - Source code implementation of the spec - Non-gas tokens - Derivation logic spec - Source code to verification keys mapping - Trusted setup Aztec v2 is a private rollup that allows users to transfer assets privately. Arbitrary smart contracts are not supported. ### Stage 0 - [x] A complete and functional proof system is deployed. - [x] The project calls itself a rollup. - [x] State roots are posted to Ethereum L1. - [x] Inputs for the state transition function are posted to Ethereum L1. - [x] A source-available node exists that can recreate the state from Ethereum L1 data. Please note that the L2BEAT team has not verified the validity of the node source code. [View code](https://developers.aztec.network/#/A%20Private%20Layer%202/zkAssets/emergencyWithdraw) ### Stage 1 - [x] Principle: Compromising ≥75% of the Security Council is the only way (other than bugs) for a rollup to indefinitely block an L2→L1 message (e.g. a withdrawal) or push an invalid L2→L1 message (e.g. an invalid withdrawal) with a <7d exit window. - [x] Users are able to exit without the help of the permissioned operators. - [x] In case of an unwanted upgrade by actors more centralized than a Security Council, users have at least 7d to exit. - [x] The proof system meets the minimum trusted setup requirements defined in the L2BEAT [trusted setup assessment framework](https://forum.l2beat.com/t/the-trusted-setups-framework-for-zk-catalog/381). - [x] Prover source code is published. ### Stage 2 - [x] Users can exit through the escape hatch mechanism and the rollup contract is immutable. ## Data availability ### All data required for proofs is published onchain All the data that is used to construct the system state is published onchain in the form of cheap calldata. This ensures that it will always be available when needed. **References** - [RollupProcessor.sol#L359 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L359) ## State derivation ### Node software There are three ways to run a node and use the escape hatch: By running the [Aztec v2 Ejector](https://github.com/AztecProtocol/aztec-v2-ejector/) during the escape hatch window, 2) by running [falafel](https://github.com/AztecProtocol/aztec-2.0/tree/master/falafel), 3) by running the [SDK](https://developers.aztec.network/#/A%20Private%20Layer%202/zkAssets/emergencyWithdraw) in escape hatch mode and connecting to an [escape hatch server](https://github.com/AztecProtocol/aztec-v2-escape-hatch-server). The two latter methods are no longer recommended by the Aztec team. ### Compression scheme No compression scheme is used. ### Genesis state No genesis state is used. ### Data format The data format used can be found [here](https://github.com/AztecProtocol/aztec-2.0/blob/master/blockchain/contracts/Decoder.sol). ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. **References** - [RollupProcessor.sol#L395 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L395) ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/aztecv1#updates). ## Operator ### No regular operators Only specific addresses appointed by the owner are permitted to propose new blocks during regular rollup operations. Since EOL, these operators are not regularly processing the rollup anymore. **References** - [RollupProcessor.sol#L97 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L97) - [RollupProcessor.sol#L369 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L369) ### Users can force any transaction Because the block production is open to anyone if users experience censorship from the operator they can propose their own blocks which would include their transactions.The private key of one of the permissioned operators is public (first Anvil address), therefore anyone can in principle resume regular operations. No funds need to be deposited to that address since submitting signatures is enough. Every 16h a special 48m window (escape hatch) is open during which any address can propose new blocks. **Risks** - Funds can be frozen if the operator refuses to include their transactions and users lack resources to propose blocks themselves. **References** - [Anvil - a local testnet node toolchain](https://book.getfoundry.sh/anvil/) - [RollupProcessor.sol#L347 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L347) - [RollupProcessor.sol#L168 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L168) ## Withdrawals ### Regular withdraw (deprecated) The user initiates the withdrawal by submitting a transaction on L2. When the block containing that transaction is proven on L1 the assets are automatically withdrawn to the user. **References** - [RollupProcessor.sol#LL396 - Etherscan source code](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code#F1#L396) ### EOL: Manual withdrawal using Aztec v2 Ejector EOL: Ownership of the rollup contract is irrevocably renounced and operators are not processing the rollup. Assets in the escrow can be manually withdrawn with the [Aztec v2 Ejector](https://github.com/AztecProtocol/aztec-v2-ejector/). **References** - [Aztec v2 Ejector - Codespace template for running the Aztec v2 rollup.](https://github.com/AztecProtocol/aztec-v2-ejector/) ## Other considerations ### Payments are private Balances and identities for all tokens on the Aztec rollup are encrypted. Each transaction is encoded as a zkSNARK, protecting user data. **References** - [Fast Privacy, Now - Aztec Medium Blog](https://medium.com/aztec-protocol/aztec-zkrollup-layer-2-privacy-1978e90ee3b6#3b25) ## Permissions ### Ethereum #### Actors ##### 2 EOAs Addresses: [0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266](https://etherscan.io/address/0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266), [0xFcF75295f242C4E87203Abb5d7C9BbEda90a8895](https://etherscan.io/address/0xFcF75295f242C4E87203Abb5d7C9BbEda90a8895) Addresses that can propose new blocks during regular rollup operation. Since the private key of one of them is public (first Anvil address), anyone can in principle resume regular operations. Every 16h a special 48m window (escape hatch) is open during which anyone can propose new blocks. ##### Aztec Multisig Addresses: [0xE298a76986336686CC3566469e3520d23D1a8aaD](https://etherscan.io/address/0xE298a76986336686CC3566469e3520d23D1a8aaD) A Multisig with 1/2 threshold. Can update parameters related to the reimbursement of gas to permissioned rollup providers. It doesn't affect the escape hatch mechanism, but it can halt regular operations by setting a reimbursement constant that is too high. ## Smart contracts ### Ethereum #### AztecFeeDistributor Addresses: [0x41A57F5581aDf11b25F3eDb7C1DB19f18bb76734](https://etherscan.io/address/0x41A57F5581aDf11b25F3eDb7C1DB19f18bb76734#code) Contract responsible for collecting transaction fees and reimbursing gas to whitelisted Rollup Providers. #### TurboVerifier Addresses: [0x48Cb7BA00D087541dC8E2B3738f80fDd1FEe8Ce8](https://etherscan.io/address/0x48Cb7BA00D087541dC8E2B3738f80fDd1FEe8Ce8#code) Turbo Plonk ZK verifier. #### RollupProcessor Addresses: [0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba](https://etherscan.io/address/0x737901bea3eeb88459df9ef1BE8fF3Ae1B42A2ba#code)