Web3 security firm GoPlus Security has issued a warning about a surge in smart contract exploits, particularly targeting contracts deployed years ago. Attackers are increasingly using AI-powered tools to scan on-chain code and identify vulnerabilities at scale.
Notable Incidents: Heavy Losses from Old Contracts
GoPlus Security highlighted three recent attacks:
- Token of Power (TOP): A 7-year-old contract was exploited on Ethereum on June 9, resulting in a loss of approximately $1.5 million.
- WUSD.fi: A 3-year-old contract was hit on May 25, losing around $200,000.
- Aztec Network: Two separate exploits on June 14 and June 18 targeted its 2-year-old contracts, causing cumulative losses exceeding $4 million.
These three incidents alone account for over $5.7 million in damages, underscoring the systemic risk posed by legacy smart contracts.
Limitations of Traditional Audits and the AI Alternative
Conventional security audits are typically performed during deployment and rarely revisited. However, as new attack vectors emerge and AI enables attackers to rapidly scan millions of lines of code, once-audited contracts become vulnerable. GoPlus Security emphasized that traditional methods cannot effectively cover historical contracts already in production.
As a remedy, the firm recommends adopting an AI-driven 'Always-on Audit' service. This approach continuously monitors smart contracts, quickly scanning for new vulnerabilities while maintaining a balance between reliability and cost. It allows projects to proactively patch issues before they are exploited.
Market Implications
The warning serves as a wake-up call for the entire crypto ecosystem: old contracts are not immune to new attacks. Even thoroughly audited protocols must undergo periodic reviews. With AI democratizing both offensive and defensive capabilities, the era of one-off audits is giving way to continuous, automated security monitoring. Projects relying on legacy code—especially long-running DeFi protocols, token contracts, and bridges—should prioritize implementing always-on auditing to stay ahead of adversaries.

