Hackers Drain $17M in 40 Days via ‘Zombie Contracts’ – Abandoned Smart Contracts Become Cash Machines

Hackers Drain $17M in 40 Days via ‘Zombie Contracts’ – Abandoned Smart Contracts Become Cash Machines

N
News Editor
2026-06-26 15:31:46
过去40天内,黑客利用五个已废弃但仍在链上运行的智能合约盗走近1700万美元,涉及DxSale、TrustedVolumes、Huma Finance V1、Raydium Legacy AMM和Aztec Connect等项目。这些“僵尸合约”因退役不彻底,仍保留资金或权限,成为高价值攻击目标。本文解析事件详情与防范建议。
zombie contractshackDeFi securitycontract retirementDxSaleRaydiumAztec Connect

Overview: $17 Million Stolen in 40 Days

Over the past 40 days, hackers have exploited five abandoned yet still active smart contracts to steal nearly $17 million, according to MarsBit. These so-called 'zombie contracts' were supposed to be decommissioned but retained funds, permissions, or callable entry points, making them lucrative targets. Attackers called outdated functions or leveraged leftover admin privileges to drain assets.

Projects Involved: DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, Aztec Connect

The incident affected multiple well-known DeFi projects:

  • DxSale – A decentralized token launchpad. Its retired contract still held admin keys, allowing re‑takeover.
  • TrustedVolumes – An on‑chain volume aggregator. The abandoned contract retained an owner key used to extract accrued funds.
  • Huma Finance V1 – Credit protocol first generation. The lending pool was not closed, and hackers used leftover allowances to empty assets.
  • Raydium Legacy AMM – Solana ecosystem’s old AMM. Liquidity was not fully withdrawn; the attacker drained the remaining funds through the old pool.
  • Aztec Connect – Privacy bridge protocol. The pause mechanism had failed, and the hacker utilized the old contract interface to bridge funds out.

Root Cause: Incomplete Contract Retirements

Security analysts pinpoint the core issue: project teams failed to execute a proper retirement process when upgrading contracts.

  • Funds not withdrawn – User deposits, liquidity, or protocol fees remained in the old contract.
  • Permissions not revoked – Admin roles like onlyOwner were not removed from the chain, allowing re‑elevation.
  • Functions still callable – No selfdestruct or pause mechanism was implemented, leaving the contract externally reachable.
These 'zombie contracts' linger on-chain, becoming hidden attack vectors.

Industry Recommendations

Project teams should adopt the following practices:

  1. Withdraw all assets – Transfer residual funds to new contracts or multisig wallets before retiring.
  2. Revoke all permissions – Use functions like renounceOwnership to eliminate admin keys on-chain.
  3. Implement kill switches – Include pause or selfdestruct logic to render the contract unusable after decommission.
  4. Monitor abandoned contracts – Include legacy contracts in security monitoring setups to catch abnormal transactions.
For users, it is advisable to regularly check and revoke approvals to old contracts to prevent passive asset transfer.

This event underscores the importance of full lifecycle management in DeFi security. Innovation speed must be balanced with rigorous contract retirement procedures to stop ‘zombie contracts’ from becoming hackers’ ATMs.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.