Floor price broken. Truth verified. zk.money just went live, and the code has a hole in it.
Not a small hole. A known one. The kind that lets bad transactions get accepted. And the team shipped anyway.
I spent Tuesday night reading the Aztec Labs deployment notes while Amsterdam rain hammered the window. Two numbers jumped off the screen: $2,500 max per transaction. $50,000 max daily deposits across the entire network. That is not a growth ceiling. That is a blast radius.
When a team voluntarily caps total user exposure at fifty grand a day, they are not telling you the product is ready. They are telling you they have already stress-tested the failure in a spreadsheet and decided how much money they are willing to lose proving a point.
The point, from where I sit, is this: Aztec has decided that owning the compliance lane is worth more than waiting for the cryptography to mature. They are running a live fire exercise on a public chain, with real users as the instrument, and a centralized insurance policy as the backstop.
Trust bridge crossed. Risk accepted.
To understand why this matters, you have to know what died first.
zk.money v1 launched in 2021. Over 75,000 wallets touched it. It processed roughly $100 million. It was, for a season, the only working privacy payment rail on Ethereum that didn't require a PhD to operate. Then in 2023 Aztec shut it down. CEO Joe Andrews framed the closure as a timing problem — the infrastructure privacy payments needed simply didn't exist yet. He was not wrong. The proving system couldn't handle scale. The UX was brutal. The regulatory climate post-Tornado Cash made nobody want to touch privacy with tenure.
So Aztec went dark and built an L2.
Now the L2 is live. And zk.money is back on top of it — but the proving layer it sits on, Alpha V5, carries an unfixed critical vulnerability. A fix ships with V6. V6 is scheduled for late 2026.
Read that timeline again. The current architecture is expected to run flawed for the next two years. Maybe longer. The team disclosed the vuln on August 7 and turned the lights on anyway.
Here is the engineering detail that actually matters, and most coverage is skipping it.
zk.money does not rely on proving alone. Every send and every withdrawal requires a cosignature from Oxide — a middleware protocol running a sealed enclave, a TEE. Think of it as a second lock on the vault door. If the Aztec proof system gets compromised and begins accepting fraudulent transactions, the enclave still has to sign off. Two keys. Both must fail before user funds walk out.
This is clever. It is also a retreat.
Tornado Cash and RAILGUN lean on cryptography alone — math as the trust anchor, no servers, no operators, no humans in the loop. Aztec just replaced that with a hardware-assurance model, a center of gravity that has an IP address and an operations team. The trust model moved from "you must break math" to "you must break math and compromise a sealed server." That is a lower ceiling on decentralization, dressed in the language of defense in depth.
I have audited rollups with this exact pattern before. Every time I see a TEE bolted onto a zk design, the underlying admission is the same: the proving system is not trusted enough to stand alone. Aztec is not hiding that. They built the crate around the machine and printed the warning label in large type.
Data checked. But the check reveals more than the limits do.
The daily cap tells the same story in dollar terms. Fifty thousand a day, annualized, is under $18.3 million if every slot filled. zk.money v1 moved $100 million. The relaunch is permitted to handle one-fifth of its predecessor's volume per year. Either Aztec believes its own infrastructure is fragile, or it believes regulators are watching closely enough that scale itself is the risk.
Both can be true.
Here is the part almost nobody is writing about, and it is the sharpest edge in this story.
Aztec is screening deposit and withdrawal addresses against sanctions lists. That is a deliberate split from the Frosties and the hardened privacy crowd. It is also a structural admission about where the value lives.
Look at the flow: fiat in, publicly traceable. Fiat out, publicly traceable. The privacy exists only in the middle — the internal leap between wallet and wallet. That is not a mixer. That is a corridor with glass walls at both ends. Regulators can see who enters and who leaves. They cannot see who walks with whom in the hallway.
The compliance cost lands on the user. Every transaction gets screened. Every deposit and withdrawal routes through an address check. Honest users pay in friction and fees — $0.35 to deposit, $0.20 to withdraw — while the wallet that just wants to move money privately gets a compliance invoice stapled to the receipt. The KYC theater runs the other direction too: anyone who wants to launder value has 50,000 reasons per day to find elsewhere. The screening is real. The enforcement surface is narrow enough that it barely touches the actual threat.
That is not a criticism of Aztec. It is a description of the trade. They chose the corridor. The corridor has a ceiling. The ceiling has a daily limit. The limit is the product.
And there is a quieter dependency underneath all of this. zk.money does not accept arbitrary assets. USDC, USDT, DAI go in. Everything converts to DAI. One stablecoin. One issuer. One peg. If DAI wobbles, the entire wallet's settlement layer wobbles with it. That concentration simplifies the attack surface and concentrates the counterparty risk at the same time. I have not seen a disclosure addressing this.
Here is my contrarian read, and I will state it plainly because the data supports it.
The flawed launch is not recklessness. It is a bet with a payout structure most people are misreading.
If the vuln gets exploited, the maximum loss is capped by the daily limit. Fifty grand. Aztec can absorb that. It is a rounding error against the strategic value of being first. If the vuln holds, the team has a live privacy product, real user telemetry, and a compliance posture they can show regulators while competitors are still drafting white papers.

Every privacy protocol is racing the same clock. Ethereum's Hegotá proposal could put native private transfers on L1. If that lands, every L2 privacy wallet becomes a feature, not a product. Aztec is not waiting for that future to arrive before planting the flag.
There is an uncomfortable parallel to 2018 that I cannot shake. That winter, I managed Telegram communities for three startups that had shipped on unblemished code and died anyway — because no one needed them. The teams that survived were not the ones with the cleanest audits. They were the ones that shipped something people actually used, flaws acknowledged and contained. A capped loss is survivable. A perfect product nobody touches is not.
Aztec knows this. The $50,000 ceiling and the Oxide cosignature are not safety theater. They are a hedge against their own uncertainty, priced into the product.
Liquidity gone? Not here. Liquidity is deliberately throttled. Run? There is nowhere to run to — that is the design.
The real signal is not in the exploit disclosure or the fee schedule. It is in who spends the next two years watching the daily cap fill up.
If the $50,000 limit keeps striking, Aztec will raise it, and the compliance corridor becomes the industry template. If it never fills, the launch was a message, not a business — a live proof to regulators that private payments can be monitored and contained. Either way, the V6 fix in late 2026 will tell you whether the proving system was ever meant to stand alone, or whether the enclave was always the product.
Watch the cap. It is the only number that matters, and it is the only number that is moving.