Web3 security company GoPlus Security has issued a warning about a significant increase in smart contract exploit attacks, with older contracts deployed years ago becoming prime targets. Attackers are now using AI technology to rapidly discover and exploit these legacy vulnerabilities, posing a serious threat to on-chain assets.
Why Are Aged Contracts Targeted?
Legacy contracts deployed 3–7 years ago often lack modern security practices and are rarely updated. With the help of AI models that can analyze bytecode and transaction history at scale, attackers can pinpoint critical flaws—such as reentrancy, access control issues, or integer overflows—within hours, whereas manual review takes weeks. Traditional periodic audits cannot keep pace with evolving attack vectors, leaving these old contracts as low-hanging fruit.
Recent Exploit Incidents
GoPlus Security highlighted four recent attacks:
- June 9: Token of Power (TOP) contract, deployed 7 years ago on Ethereum, lost ~$1.5M.
- May 25: WUSD.fi contract, deployed 3 years ago, lost ~$0.2M.
- June 14 & 18: Aztec Network suffered two exploits on a 2-year-old contract, totaling over $4M in losses.
These four incidents alone account for more than $5.7M in losses within a single month. The repeated attacks on Aztec Network within four days suggest attackers are systematically probing the same contract for multiple vulnerabilities, outpacing traditional patching workflows.
Continuous Audit: The AI-Powered Countermeasure
GoPlus Security argues that traditional audit methods alone are insufficient. Their proposed solution is an AI-driven continuous audit (Always-on Audit) service that monitors on-chain transactions, contract state changes, and threat intelligence in real time. It automatically scans legacy contracts on a periodic or event-triggered basis, identifying anomalies and sending alerts quickly. This approach balances cost and reliability, making it accessible even for protocols with limited budgets but significant locked value.
The firm recommends integrating continuous audit from the moment a new contract is deployed and reactivating scans after upgrades or major events. As AI amplifies the offensive side, the defensive side must also evolve through automation and intelligence.

