The wallet linked to the Aztec Network Private Rollup Bridge exploit deposited another 300 ETH into Tornado Cash early Friday, pushing the total laundered volume higher in a pattern blockchain analysts have tracked since the initial breach. PeckShield flagged the transaction at 06:42 UTC, valuing the move at roughly $572,100 based on ETH's $1,919.14 spot price.
| Asset | Price | 24h Change | 7d Change | 24h Volume | Market Cap |
|---|---|---|---|---|---|
| --- | --- | --- | --- | --- | --- |
| ETH | $1,919.14 | +0.40% | +2.70% | $6.34B | $231.60B |
|---|---|---|---|---|---|
| BTC | $58,200 | +0.15% | +1.80% | $22.1B | $1.14T |
| Total Market | — | +0.21% | — | $47.6B | $2.30T |
The Aztec bridge exploit first surfaced in late July when attackers manipulated the private rollup's proof verification logic to mint unauthorized shielded assets. Researchers at multiple firms traced the initial outflow to a cluster of addresses that bridged funds to Ethereum mainnet before dispersing them across decentralized exchanges and mixing protocols. Friday's deposit marks the third confirmed Tornado Cash interaction from the same wallet cluster, following two earlier tranches of 250 ETH and 180 ETH respectively.
Aztec Labs paused the affected bridge contracts within hours of detection and initiated a coordinated upgrade with validator set participation. The team has not disclosed the total value extracted, though on-chain estimates from Arkham Intelligence place the haul between $4.2 million and $5.8 million across all identified addresses. No recovery has been announced, and negotiations with the exploiter — if any — remain private.
Users who deposited into the private rollup before the pause face uncertain redemption timelines. Aztec's governance forum shows a proposal to snapshot balances at block 19,847,211 and honor withdrawals once the upgraded contracts deploy, targeted for mid-August. The exploit has reignited debate over the maturity of ZK-rollup bridge architectures, particularly those using novel proving systems without battle-tested formal verification.
Competitors including Scroll, Linea, and zkSync run similar zero-knowledge bridge designs but employ different trusted-setup ceremonies and circuit audit scopes. Security firms note that Aztec's use of PLONK-based proofs with custom gate configurations introduced attack surface not present in more standardized RISC Zero or SP1 implementations. The sector now watches whether auditors will mandate broader formal verification for confidential rollup bridges before mainnet deployment.
What triggered the move
The exploiter's latest deposit coincides with ETH's steady climb from $1,865 to $1,919 over the past week, a 2.9% gain that may have incentivized converting shielded assets before further price appreciation. Tornado Cash deposits from sanctioned addresses remain legally permissible on-chain but expose downstream recipients to OFAC screening. Exchanges including Coinbase and Kraken have automated flags for funds exiting known mixer deposits, complicating any future off-ramp.
How desks are positioning
OTC desks report elevated demand for clean ETH spot, with premiums of 15-25 basis points over exchange mid-market for size blocks above 500 ETH. The Aztec-linked coins, once mixed, trade at a discount in dark pools due to compliance overhead. Market makers note that the exploit's total volume represents less than 0.1% of daily ETH spot volume, limiting broader market impact.
Why the timing matters
The deposit arrives days before the anticipated Aztec governance vote on the balance snapshot proposal. A successful vote would lock in the redemption framework and potentially reduce the exploiter's incentive to continue rapid laundering. Conversely, a delayed or contested vote could extend the window for further Tornado Cash deposits, with analysts monitoring the wallet cluster for movements toward Railgun, Nocturne, or cross-chain bridges to Polygon and Arbitrum.