In the past 40 days, hackers stole nearly $17 million by exploiting five abandoned but still live smart contracts, known as 'zombie contracts'. The root cause is incomplete retirement of old contracts that still hold funds, permissions, or callable entry points. Affected projects include DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect, highlighting a critical gap in DeFi contract lifecycle management.
Event Overview
In the past 40 days, hackers exploited five abandoned but still active smart contracts on-chain to steal nearly $17 million. These 'zombie contracts' — deprecated yet retaining funds or functionality — have become lucrative targets for attackers.
Affected Projects and Root Cause
The compromised projects include DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause is incomplete contract retirement: old contracts still hold funds, administrative privileges, or executable entry points, allowing attackers to drain assets at low cost.
Risk Implications
This incident exposes a systemic neglect of smart contract lifecycle management in DeFi. Project teams must thoroughly revoke permissions, transfer funds, and monitor on-chain remnants when retiring contracts to prevent such security loopholes.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.