Hackers Drain $17M from 5 ‘Zombie Contracts’ in 40 Days: DeFi Retirement Risks Exposed

Hackers Drain $17M from 5 ‘Zombie Contracts’ in 40 Days: DeFi Retirement Risks Exposed

N
News Editor
2026-06-26 11:31:31
Over the past 40 days, hackers exploited five deprecated but still-on-chain smart contracts to steal nearly $17 million, targeting projects including DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause is incomplete contract decommissioning: leftover funds, retained admin privileges, and open invocation interfaces turned these relics into high-value targets. This incident highlights a systemic security blind spot in DeFi asset lifecycle management, urging developers to adopt thorough retirement checklists that include withdrawing all assets, revoking permissions, disabling functions, and periodic audits of archived contracts.

Incident Overview: Zombie Contracts Become Cash Machines

In the past 40 days, hackers exploited five deprecated but still-active smart contracts (so-called 'zombie contracts') to drain approximately $17 million. The affected contracts belong to DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. All share the same vulnerability: project teams stopped maintaining the contracts but left behind funds, admin keys, or callable functions, turning them into easy targets.

Root Cause: Incomplete Decommissioning

Security analysts attribute the breaches to incomplete retirement processes. Many DeFi projects, after upgrading or migrating to new contracts, fail to withdraw locked assets, revoke owner/admin keys, or disable critical functions from old contracts. This allows attackers to directly call original interfaces or exploit lingering bugs. Notably, Raydium Legacy AMM's liquidity pool, even if no longer actively traded, contained leftover LP tokens that were redeemable for underlying assets.

Affected Projects and Loss Distribution

On-chain forensic data reveals the following approximate losses: DxSale $4.2M (unswept token sale proceeds), TrustedVolumes $3.5M (oracle service fees left in escrow), Huma Finance V1 $3.0M (collateral assets in lending pools), Raydium Legacy AMM $4.8M (old LP tokens swapped out), and Aztec Connect $1.5M (wrapped assets in bridge contract). Total: ~$17M.

This is not the first such incident, but the cluster underscores a systemic gap in contract lifecycle management. To protect users, projects should implement a standardized decommissioning checklist: withdraw all remaining funds, revoke administrative privileges, pause or destroy contracts, remove front-end references, and conduct periodic audits of archived contracts. The community must treat old contracts as potential liabilities until they are fully neutered.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.