40 Days, 5 Attacks, $17M Stolen
In just 40 days, hackers exploited five smart contracts that had been deprecated by their respective projects yet remained operational on-chain, siphoning off nearly $17 million. These so-called 'zombie contracts' – retired in name but still holding balances, admin keys, or external call permissions – turned into ATMs for attackers.
Targets and Attack Vectors
The affected projects include DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. Attackers typically interacted with vestigial functions or unrevoked approvals, draining tokens without triggering modern security measures.
Industry Implications
This spate of thefts underscores the critical need for thorough contract retirement protocols. Project teams must revoke all permissions, withdraw liquidity, and transfer or burn remaining assets before decommissioning a contract. Failure to do so leaves open a long-term vulnerability that can be exploited at any time.

