zk.money restarts to offer Aztec private transfers, but the V5 vulnerability risk must be checked first
Aztec Labs reopened zk.money self-custody wallets on September 29, 2026. Users can deposit DAI, USDC, or USDT from Ethereum, and then transfer in DAI within the Aztec network; when depositing USDC and USDT, they are converted into DAI. Internal transfers within Aztec can conceal the amount, balance, and payer/recipient, but when funds are deposited from Ethereum, the sending address and amount on the main network remain public. CoinDesk reports that the alpha version will limit each deposit, payment, and withdrawal to below $2,500, and set a daily total deposit cap; these limits are risk controls in the experimental phase, not guarantees of funds.
More importantly is the network security status. Aztec’s official documentation describes the current alpha as software still in early operation and not fully audited, meaning critical flaws could still emerge. On August 7, 2026, Aztec disclosed that contributors found a serious vulnerability in the V5 alpha proving system on July 27: an attacker could construct state transitions that do not follow protocol rules. The team could not determine whether the vulnerability had been exploited before it was discovered; the remediation plan is to address it in the subsequent V6. At the time, the official guidance required treating the funds, application, and contract state on V5 as potentially subject to protocol-level failures until emergency remediation is completed and the operations required by the network operators are carried out.
CoinDesk reported on September 29 that zk.money would go live before the vulnerability fix; Aztec Labs CEO said there were payment issues caused by another Oxide check bug, but the report did not say whether it could protect against the V5 proving system vulnerability. Self-custody means the app operators cannot directly spend or freeze users’ wallet assets, but it cannot eliminate the risk of losses caused by defects in the underlying network or contracts.
【My analysis and response】
This relaunch makes it easier for users to try private payments in the Ethereum ecosystem, but privacy only covers part of the activity after assets enter Aztec—deposit addresses and amounts still leave a trace on L1. The new wallet’s limits also cannot replace an audit. Since the V5 issue disclosed by Aztec relates to network state validation, until there is a specific fixed version and independent audits, I will not equate availability with suitability for storing funds intended for real use. If it is only for technical testing, you should first confirm the current network version, the official emergency status, and the scope of applicability, and use only small isolated addresses whose full loss you can afford; do not mistake public deposit records for already being anonymized.
Spillover to the crypto market could come from growth in private payment usage and changes in L2 activity, but there is currently no data indicating新增 active users, trading volume, or fee revenue. The product-related $ETH is for Ethereum mainnet deposits and transaction fees. Binance spot ETHUSDT was queried at 00:24 (Beijing time) on September 30; the trailing 24-hour quoteVolume is about 888.87 million USD. This is data for a single spot trading pair; it cannot show that zk.money’s launch creates ETH demand, nor does it represent total market trading volume.
Going forward, we should first see whether the V6 fix is actually deployed, whether Aztec has confirmed completion of emergency remediation, whether independent audits and the migration plan are publicly available, and whether zk.money has disclosed its current running version and Oxide’s specific protection boundaries; then we should monitor privacy transaction volume, limit adjustments, and user retention. If the product is proven to run in a version isolated from the V5 vulnerability and has been audited, the security assessment can be re-evaluated; if it still relies on unpatched V5 or lacks verifiable mitigation measures, then privacy convenience should not be a reason to keep depositing funds.
Source:
CoinDesk, September 29, 2026: “Ethereum users get another way to pay privately as zk.money returns after three years”: https://www.coindesk.com/tech/2026/09/29/embargo-12-et-ethereum-users-get-another-way-to-pay-privately-as-zk-money-returns-after-three-years
Aztec official Alpha mainnet notes and privacy limitations: https://docs.aztec.network/participate/alpha
Aztec official Ethereum—Aztec bridging notes (L1 deposit amount and sender visible): https://docs.aztec.network/participate/basics/bridging
Aztec official V5 proving system vulnerability disclosure, August 7, 2026: https://aztec.network/blog/alpha-v5-proving-system-vulnerability
zk.money official entry: https://launch.zk.money/
Market data: Binance spot publicly available REST API, ETHUSDT, trailing 24 hours, query time 2026-09-30 00:24 (Beijing time); non-derivatives data.
The above is personal analysis and does not constitute investment advice.
#Aztec #隐私支付 #ETH
Aztec Labs reopened zk.money self-custody wallets on September 29, 2026. Users can deposit DAI, USDC, or USDT from Ethereum, and then transfer in DAI within the Aztec network; when depositing USDC and USDT, they are converted into DAI. Internal transfers within Aztec can conceal the amount, balance, and payer/recipient, but when funds are deposited from Ethereum, the sending address and amount on the main network remain public. CoinDesk reports that the alpha version will limit each deposit, payment, and withdrawal to below $2,500, and set a daily total deposit cap; these limits are risk controls in the experimental phase, not guarantees of funds.
More importantly is the network security status. Aztec’s official documentation describes the current alpha as software still in early operation and not fully audited, meaning critical flaws could still emerge. On August 7, 2026, Aztec disclosed that contributors found a serious vulnerability in the V5 alpha proving system on July 27: an attacker could construct state transitions that do not follow protocol rules. The team could not determine whether the vulnerability had been exploited before it was discovered; the remediation plan is to address it in the subsequent V6. At the time, the official guidance required treating the funds, application, and contract state on V5 as potentially subject to protocol-level failures until emergency remediation is completed and the operations required by the network operators are carried out.
CoinDesk reported on September 29 that zk.money would go live before the vulnerability fix; Aztec Labs CEO said there were payment issues caused by another Oxide check bug, but the report did not say whether it could protect against the V5 proving system vulnerability. Self-custody means the app operators cannot directly spend or freeze users’ wallet assets, but it cannot eliminate the risk of losses caused by defects in the underlying network or contracts.
【My analysis and response】
This relaunch makes it easier for users to try private payments in the Ethereum ecosystem, but privacy only covers part of the activity after assets enter Aztec—deposit addresses and amounts still leave a trace on L1. The new wallet’s limits also cannot replace an audit. Since the V5 issue disclosed by Aztec relates to network state validation, until there is a specific fixed version and independent audits, I will not equate availability with suitability for storing funds intended for real use. If it is only for technical testing, you should first confirm the current network version, the official emergency status, and the scope of applicability, and use only small isolated addresses whose full loss you can afford; do not mistake public deposit records for already being anonymized.
Spillover to the crypto market could come from growth in private payment usage and changes in L2 activity, but there is currently no data indicating新增 active users, trading volume, or fee revenue. The product-related $ETH is for Ethereum mainnet deposits and transaction fees. Binance spot ETHUSDT was queried at 00:24 (Beijing time) on September 30; the trailing 24-hour quoteVolume is about 888.87 million USD. This is data for a single spot trading pair; it cannot show that zk.money’s launch creates ETH demand, nor does it represent total market trading volume.
Going forward, we should first see whether the V6 fix is actually deployed, whether Aztec has confirmed completion of emergency remediation, whether independent audits and the migration plan are publicly available, and whether zk.money has disclosed its current running version and Oxide’s specific protection boundaries; then we should monitor privacy transaction volume, limit adjustments, and user retention. If the product is proven to run in a version isolated from the V5 vulnerability and has been audited, the security assessment can be re-evaluated; if it still relies on unpatched V5 or lacks verifiable mitigation measures, then privacy convenience should not be a reason to keep depositing funds.
Source:
CoinDesk, September 29, 2026: “Ethereum users get another way to pay privately as zk.money returns after three years”: https://www.coindesk.com/tech/2026/09/29/embargo-12-et-ethereum-users-get-another-way-to-pay-privately-as-zk-money-returns-after-three-years
Aztec official Alpha mainnet notes and privacy limitations: https://docs.aztec.network/participate/alpha
Aztec official Ethereum—Aztec bridging notes (L1 deposit amount and sender visible): https://docs.aztec.network/participate/basics/bridging
Aztec official V5 proving system vulnerability disclosure, August 7, 2026: https://aztec.network/blog/alpha-v5-proving-system-vulnerability
zk.money official entry: https://launch.zk.money/
Market data: Binance spot publicly available REST API, ETHUSDT, trailing 24 hours, query time 2026-09-30 00:24 (Beijing time); non-derivatives data.
The above is personal analysis and does not constitute investment advice.
#Aztec #隐私支付 #ETH