Hackers Drain Nearly $17M in 40 Days by Exploiting Five 'Zombie Contracts' – The Hidden Danger of DeFi Legacy Contracts

Hackers Drain Nearly $17M in 40 Days by Exploiting Five 'Zombie Contracts' – The Hidden Danger of DeFi Legacy Contracts

N
News Editor
2026-06-27 00:01:47
过去40天内,黑客利用五个已被弃用但仍在链上运行的智能合约,盗走近1700万美元。这些“僵尸合约”因退役不彻底,仍保有资金、权限或调用入口,成为高价值攻击目标。事件涉及DxSale、TrustedVolumes、Huma Finance V1、Raydium Legacy AMM和Aztec Connect等多个知名项目,暴露了DeFi领域旧合约管理中的系统性漏洞。本文梳理事件经过,分析根本原因,并提出可执行的安全建议。
zombie contractssmart contract securityDeFi securityhackDxSaleRaydiumAztec Connectcontract retirement

Incident Overview: 40 Days, 5 Contracts, ~$17M Lost

Over the past 40 days (as of June 27, 2026), attackers have siphoned approximately $17 million in crypto assets by exploiting five smart contracts that were abandoned but still active on-chain. These so-called 'zombie contracts' belong to five projects: DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect.

Root Cause: Incomplete Contract Retirement

Security analysis reveals that the core vulnerability lies in the failure of project teams to fully remove funds, permissions, or callable entry points when disabling old contracts. Many zombie contracts still hold user-staked tokens, admin withdrawal privileges, or integration interfaces with other protocols. Attackers monitor these dormant contracts on-chain, locate balances or loopholes, and then leverage remaining privileged functions to transfer assets out.

Project Breakdown

  • DxSale – A decentralized token launchpad; its legacy contract was exploited for several million dollars.
  • TrustedVolumes – An on-chain transaction volume aggregator; the old contract still held funds.
  • Huma Finance V1 – A credit lending protocol; the V1 contract was not fully decommissioned, allowing extraction of long-locked collateral.
  • Raydium Legacy AMM – An old automated market maker contract from Solana’s leading DEX Raydium; hackers used retained permissions to drain liquidity.
  • Aztec Connect – A privacy bridge protocol; funds in its outdated contract were transferred out.

Industry Implications: How to Prevent Zombie Contract Attacks

This string of attacks serves as a stark reminder: decommissioned contracts must undergo a complete 'kill' process – freeze all funds, revoke admin permissions, destroy the contract owner, and sever all external protocol connections. Teams should conduct regular on-chain audits to clean up historical contract balances. For users, it is critical to withdraw assets from deprecated contracts promptly and avoid leaving tokens idle in unmaintained contracts.

As the DeFi ecosystem matures, governance and security practices for legacy contracts will become an essential infrastructure requirement. This incident may push security audit firms to develop specialized scanning tools for zombie contracts, enabling project teams to detect and remediate high-risk legacy contracts in a timely manner.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.