A wallet tied to June’s Aztec Private Rollup Bridge exploit deposited 300 ETH into Tornado Cash on Aug. 8, blockchain security firm PeckShield reported, bringing the exploiter’s total transfers to the mixer to 500 ETH.
The transfer follows the June 17 exploit of an immutable Aztec Private Rollup Bridge contract, in which attackers extracted roughly 1,158 ETH, 150,000 DAI and 0.47 renBTC worth about $2.2 million at the time.
On-chain investigators have identified the 300 ETH transfer as part of the subsequent distribution of the stolen assets. Importantly, available tracking data does not establish that the 300 ETH was sent directly to Tornado Cash.
$2.2M exploit targets deprecated Aztec infrastructure
The attack occurred on June 17, when an attacker exploited an old Aztec payments product that had been sunset years earlier.
Instead, the funds were moved from the primary exploiter wallet to an address identified by blockchain investigators as being associated with the Aztec exploit.
The development nevertheless places the stolen ETH under renewed scrutiny as blockchain analysts monitor whether the funds eventually reach privacy protocols, centralized exchanges or additional intermediary wallets.
Securityresearchers reported that the affected Private Rollup Bridge contract released 1,158 ETH, 150,000 DAI and approximately 0.47 renBTC through a vulnerable emergency-withdrawal mechanism.
Aztec Labs stressed that the incident involved legacy infrastructure rather than the project’s current network. The company described the affected system as an immutable Stage 2 rollup that had been sunset in 2022.
For investors, the distinction is critical. The incident did not represent a direct compromise of the current Aztec Network or the AZTEC token.
Instead, it demonstrated how dormant smart contracts can retain financial exposure long after their associated products have been discontinued.
Because the affected contracts were immutable and Aztec Labs no longer controlled them, the team could not simply deploy an emergency upgrade or freeze the contract once the exploit became visible.
The 300 ETH transfer changes the risk picture
Blockchain investigators subsequently traced portions of the stolen ETH away from the primary exploiter wallet.
According to tracking reported by Rekt and security analysts, roughly 802 ETH remained in the main attacker address, alongside the stolen DAI and renBTC, while approximately 300 ETH moved to another address and a further 56 ETH was sent to a second address.
Attackers can split assets across multiple wallets, creating additional layers between the original exploit address and any eventual cash-out destination.
However, investors should distinguish between fund movement and confirmed laundering.
There is currently no sufficient evidence in the available reporting to state that the 300 ETH transfer itself represents a deposit into Tornado Cash.
The address receiving the funds has instead been identified by investigators as being associated with the Aztec exploiter.
For markets, those destinations matter because large stolen-ETH transfers can eventually become potential sell-side pressure if the attacker manages to convert the assets into liquid stablecoins or fiat.
A warning about abandoned smart contracts
The Aztec incident is also part of a broader security story that investors should not overlook.
The June 17 attack came only days after another exploit involving deprecated Aztec Connect infrastructure drained approximately $2.19 million.
The two attacks targeted separate legacy contracts, but both highlighted the same uncomfortable problem: smart contracts can continue holding valuable assets after development teams have stopped actively maintaining them.
The second incident involved a separate flaw in the old system’s escape-hatch mechanism. Security researchers said the vulnerability allowed attackers to bypass expected restrictions and withdraw assets from the contract.
SlowMist’s analysis identified the affected RollupProcessor contract and described the loss as 1,158 ETH, 150,000 DAI and 0.4696 renBTC.
The Aztec Foundation sought to separate the legacy incident from the current ecosystem.
That clarification should matter to token investors. The exploit does not, based on the available evidence, establish that the current Aztec Network or AZTEC token was compromised.
Instead, the incident reinforces a different investment risk: legacy code can remain economically relevant even after a protocol has moved on.
Investors are watching the next wallet move
The immediate question is no longer simply how the attacker breached the old Aztec infrastructure. It is where the stolen ETH goes next.
The movement of 300 ETH into a secondary address gives blockchain investigators another node to monitor, while the remaining stolen assets provide an even larger pool that could still move.
The principal exploiter wallet reportedly retained hundreds of ETH alongside the stolen DAI and renBTC after the initial distribution.
A transfer into Tornado Cash, a centralized exchange, a bridge or another privacy-focused service would materially change the nature of the investigation.
Until such a destination is confirmed, however, investors should avoid treating the 300 ETH movement as proof that the funds have already entered a mixing service.
The larger lesson is arguably more important than the individual wallet transaction. The Aztec attacks demonstrate that security risk does not necessarily disappear when a protocol is deprecated.
Contracts can remain immutable, publicly accessible and financially attractive to attackers years after a team has abandoned active control.
For crypto investors evaluating Ethereum infrastructure, Layer 2s and DeFi protocols, that creates a broader due-diligence question: not only whether a protocol is secure today, but also what happens to its contracts and locked assets when the product is eventually shut down.
As investigators continue tracking the 300 ETH and the remaining stolen assets, the next major wallet movement could determine whether this remains primarily an on-chain theft investigation or develops into a much larger laundering and liquidation story.