Hackers Drain $17 Million in 40 Days Using Five Zombie Contracts as DeFi ATMs

Hackers Drain $17 Million in 40 Days Using Five Zombie Contracts as DeFi ATMs

N
News Editor
2026-06-26 09:31:31
In the past 40 days, hackers have stolen nearly $17 million by exploiting five abandoned but still active smart contracts from DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause is incomplete contract decommissioning: funds, permissions, and callable entry points remain on-chain. This incident highlights systemic risks of 'zombie contracts' in DeFi and calls for strict retirement audits and asset recovery procedures.

Incident Overview: $17 Million Drained in 40 Days

According to MarsBit, over the past 40 days, hackers have exploited five deprecated but still operational smart contracts to siphon approximately $17 million from several DeFi projects. The contracts belong to DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. Attackers leveraged residual permissions, unwithdrawn liquidity, or leftover admin functions in these contracts to transfer funds out with ease.

Affected Projects and Attack Techniques

All five contracts share a common flaw: the project teams upgraded or migrated to new versions without properly killing the old contracts. For instance, Raydium Legacy AMM still had locked LP tokens and permissions; DxSale's old sale contract retained admin withdrawal functions; TrustedVolumes' deprecated contract held user deposits; Huma Finance V1 and Aztec Connect's legacy versions also had unreclaimed fund entry points. Attackers used on-chain analysis to identify these 'zombie contracts' and directly invoked privileged functions or exploited uncleared approvals to drain assets.

Systemic Risk of Zombie Contracts

Zombie contracts refer to smart contracts that have been abandoned by their project teams but remain deployed on-chain with stored state and funds. On Ethereum and similar platforms, once a contract is deployed, it cannot be truly deleted unless the SELFDESTRUCT opcode is called. Even if a team stops using a contract, if they fail to call selfdestruct or manually withdraw all assets, the contract becomes a high-value target. In this case, none of the five contracts completed a proper decommissioning process, enabling the theft.

Security Recommendations and Industry Lessons

For DeFi projects, every time a contract is upgraded or migrated, teams must: 1) call selfdestruct to destroy the old contract (if business logic allows); 2) withdraw all native tokens and ERC-20 tokens manually; 3) revoke all external approvals and permissions (e.g., approve, setAuthority); 4) remove admin roles. For users, it's advisable to regularly check old contracts they have interacted with for residual balances or outstanding approvals and revoke them. The $17 million loss serves as a stark reminder that smart contract security must include not only auditing new deployments but also proper afterlife management for legacy contracts.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.