Hackers Drain Nearly $17M from Five Zombie Contracts in 40 Days: A New DeFi Threat

Hackers Drain Nearly $17M from Five Zombie Contracts in 40 Days: A New DeFi Threat

N
News Editor
2026-06-26 14:01:26
In the past 40 days, hackers have stolen nearly $17 million by exploiting five abandoned but still-active smart contracts, known as 'zombie contracts'. These contracts retained funds, permissions, or callable entry points due to incomplete decommissioning, making them high-value targets. Affected projects include DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect, exposing critical lifecycle management failures in DeFi.
zombie contractssmart contract securityDeFi vulnerabilityhacker attackcontract decommissionDxSaleRaydiumAztec Connect

Incident Overview: $17M Stolen via Zombie Contracts in 40 Days

According to MarsBit, over the past 40 days hackers have exploited five abandoned yet still-operational smart contracts to drain approximately $17 million. These 'zombie contracts'—deprecated code still live on-chain—were left with residual funds, admin privileges, or callable interfaces, turning them into cash machines for attackers. The affected projects span multiple DeFi verticals: DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect, highlighting a systemic vulnerability in smart contract retirement practices.

What Are Zombie Contracts and Why Are They Targets?

A 'zombie contract' is a smart contract that has been officially deprecated by its project but not fully removed or frozen on-chain. Due to blockchain immutability, old contracts persist indefinitely. If the legacy logic still holds assets, administrative keys, or callbacks to newer versions, attackers can exploit unpatched flaws or outdated business logic to withdraw funds, mint tokens, or perform other malicious actions. In this case, each contract lost an average of ~$3.4 million, and hackers could operate without triggering immediate alerts since the contracts were no longer actively monitored.

Project-by-Project Breakdown

The five targeted contracts cover different DeFi segments:

  • DxSale: A token launch and liquidity locking platform whose deprecated V1 contract retained permission hooks.
  • TrustedVolumes: An on-chain volume verification protocol that left token pool controls intact after deprecation.
  • Huma Finance V1: An early version of a decentralized credit protocol whose lending logic remained callable.
  • Raydium Legacy AMM: The old automated market maker on Solana; although the team migrated to V2, the old pools still held LP tokens and protocol fees.
  • Aztec Connect: A legacy privacy bridge contract that still allowed withdrawal of user deposits.

All these projects made the same mistake: failing to drain funds, revoke permissions, or remove admin keys before retiring the contracts.

Security Takeaways: How to Prevent Zombie Contract Risks

This incident sends a clear warning to the entire DeFi industry. When upgrading or discontinuing services, projects must follow a complete decommission checklist: 1) Withdraw all remaining funds (transfer to a new contract or burn); 2) Revoke all external roles (owner, admin); 3) Check for any lingering call permissions to or from other contracts; 4) Publish a public notice and guide users to migrate. Additionally, on-chain monitoring systems should continuously scan deprecated contracts for unusual transactions. For users, it's critical to respond promptly to official migration announcements and never leave assets in old version contracts.

As DeFi protocol iterations accelerate, zombie contract risks will only grow. The $17 million loss is a stark reminder: security is not a one-time audit but a continuous lifecycle management process.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.