Hackers Drain $17M in 40 Days via Five Zombie Contracts – DeFi’s Dead Code Becomes a Cash Cow

Hackers Drain $17M in 40 Days via Five Zombie Contracts – DeFi’s Dead Code Becomes a Cash Cow

N
News Editor
2026-06-26 12:31:33
Over the past 40 days, hackers have stolen nearly $17 million by exploiting five abandoned yet still active smart contracts from DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause: incomplete contract retirement left funds, permissions, or entry points intact, turning these “zombie contracts” into high-value targets. The incident highlights systemic gaps in DeFi contract lifecycle management and the urgent need for stricter retirement protocols, permission cleanup, and real-time monitoring of deprecated contracts.

Attack Overview: $17M Drained from Five Zombie Contracts in 40 Days

According to MarsBit, over the past 40 days, hackers have siphoned nearly $17 million by exploiting five smart contracts that were officially deprecated but remained operational on-chain. The affected projects span multiple DeFi verticals: DxSale (initial DEX offering platform), TrustedVolumes (volume incentive protocol), Huma Finance V1 (credit protocol), Raydium Legacy AMM (automated market maker on Solana), and Aztec Connect (privacy bridge). Rather than discovering novel vulnerabilities, the attackers simply called residual administrative functions or transfer methods that should have been disabled during contract retirement.

Detailed Breakdown of the Five Zombie Contracts

All five contracts had been abandoned by their respective project teams but still held funds or privileged roles:

  • DxSale: The retired DEX launchpad contract retained unclaimed liquidity and token minting permissions.
  • TrustedVolumes: Old staking/farming contract had an undeleted admin role that allowed withdrawal of reserve tokens.
  • Huma Finance V1: The deprecated credit pool contract still had an active withdraw function for locked funds.
  • Raydium Legacy AMM: The legacy AMM on Solana left LP tokens and governance permissions accessible.
  • Aztec Connect: The decommissioned privacy bridge contract had a lingering balance of user assets that could be withdrawn via a known method.
Attackers used on-chain monitoring tools to detect contracts with non-zero balances or unprotected admin roles, then crafted direct transactions to drain assets.

Root Cause: Incomplete Contract Retirement as a Systemic Risk

The core issue is that DeFi projects failed to follow best practices when retiring contracts: they did not call selfdestruct or reclaim to remove funds, did not revoke admin or withdrawal roles, and did not close deposit/withdraw entry points. Once on-chain, these zombie contracts become perpetual attack surfaces. After the incidents, teams from DxSale and Raydium issued statements confirming ongoing investigations, but most stolen funds have already been laundered through mixers or cross-chain bridges, making recovery unlikely.

Industry Implications: Urgent Need for Lifecycle Governance Standards

This series of attacks, occurring in quick succession and targeting diverse protocols, underscores a critical gap in DeFi security: contract lifecycle governance. Projects must implement mandatory retirement SOPs that include complete fund evacuation, permission revocation (role removal), function freezing, and re-audit of deprecated contracts. On-chain security platforms (e.g., Forta, SlowMist) should add zombie contract addresses to high-priority watchlists. Users are advised to immediately revoke all approvals and withdraw assets from any protocol they no longer use, as these inactive contracts are increasingly becoming the preferred target for opportunistic hackers.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.