$17 Million Stolen in 40 Days: 'Zombie Contracts' Become a New DeFi Security Threat

$17 Million Stolen in 40 Days: 'Zombie Contracts' Become a New DeFi Security Threat

N
News Editor
2026-06-26 15:01:45
Over the past 40 days, hackers stole nearly $17 million by exploiting five abandoned yet still-active smart contracts (zombie contracts) on the blockchain. The affected projects include DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause is incomplete contract retirement, leaving funds, permissions, or callable entry points open to exploitation. This incident highlights a critical vulnerability in DeFi lifecycle management and has sparked industry-wide concern over zombie contract risks.
zombie contractsDeFi securityhacker attackDxSaleRaydiumHuma FinanceAztec Connectcontract retirement

Incident Review: Five Zombie Contracts Drained

According to MarsBit, hackers stole approximately $17 million over the past 40 days by exploiting five abandoned yet still-operational smart contracts (zombie contracts) from DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The attackers called functions that had not been properly disabled, draining funds directly from contract balances or using unrevoked approvals. Notably, these contracts retained native tokens or delegated allowances even after being deprecated, making them high-value targets.

Root Causes and Risks of Zombie Contracts

Zombie contracts are smart contracts that have been abandoned by their projects but remain active on-chain because they were never fully destroyed or had their permissions withdrawn. Common causes include: failure to transfer remaining funds before migration; not revoking admin keys; leaving token approvals uncancelled; and not executing the selfdestruct function. Such contracts are widespread in DeFi ecosystems because many projects only "hide" old contracts through proxy patterns or frontend redirects rather than removing them permanently from the chain. Attackers exploit these residual permissions to perform "reanimation" attacks, directly extracting contract balances or calling authorized transfers.

The five contracts involved in this incident are typical examples. For instance, the Raydium Legacy AMM contract still held about $4 million in liquidity pool tokens after its replacement, and the owner's withdrawal function had not been disabled. Hackers simply called the withdraw function to drain the pool. Similarly, Huma Finance V1's old loan contract retained some collateral and still had valid signature verification, allowing attackers to initiate malicious liquidations.

Lessons for DeFi Projects and Mitigation Strategies

This series of attacks exposes a systemic flaw in smart contract lifecycle management across DeFi. First, projects should execute the selfdestruct operation (or at least transfer funds, revoke permissions, and pause critical functions) when retiring a contract. Second, establish a contract retirement checklist: close all external call entry points; revoke all ERC20 approvals; freeze token transfers within the contract; and permanently disable admin keys. Third, users should regularly check their own approved contract addresses for unrevoked permissions to avoid personal asset loss if a zombie contract is exploited. Finally, on-chain monitoring tools should include zombie contract status changes in their alert systems to help security teams detect abnormal withdrawal attempts early.

Fortunately, some of the affected teams have already intervened and patched remaining vulnerabilities. However, hundreds of zombie contracts remain at risk. According to a security firm's estimate, there are still over 30,000 old contracts on Ethereum mainnet that have not been fully decommissioned, of which about 12% still hold a total of more than $50 million in tokens or NFTs. This provides a persistent "ammunition depot" for hackers.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.