Incident Review: Five Zombie Contracts Drained
According to MarsBit, hackers stole approximately $17 million over the past 40 days by exploiting five abandoned yet still-operational smart contracts (zombie contracts) from DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The attackers called functions that had not been properly disabled, draining funds directly from contract balances or using unrevoked approvals. Notably, these contracts retained native tokens or delegated allowances even after being deprecated, making them high-value targets.
Root Causes and Risks of Zombie Contracts
Zombie contracts are smart contracts that have been abandoned by their projects but remain active on-chain because they were never fully destroyed or had their permissions withdrawn. Common causes include: failure to transfer remaining funds before migration; not revoking admin keys; leaving token approvals uncancelled; and not executing the selfdestruct function. Such contracts are widespread in DeFi ecosystems because many projects only "hide" old contracts through proxy patterns or frontend redirects rather than removing them permanently from the chain. Attackers exploit these residual permissions to perform "reanimation" attacks, directly extracting contract balances or calling authorized transfers.
The five contracts involved in this incident are typical examples. For instance, the Raydium Legacy AMM contract still held about $4 million in liquidity pool tokens after its replacement, and the owner's withdrawal function had not been disabled. Hackers simply called the withdraw function to drain the pool. Similarly, Huma Finance V1's old loan contract retained some collateral and still had valid signature verification, allowing attackers to initiate malicious liquidations.
Lessons for DeFi Projects and Mitigation Strategies
This series of attacks exposes a systemic flaw in smart contract lifecycle management across DeFi. First, projects should execute the selfdestruct operation (or at least transfer funds, revoke permissions, and pause critical functions) when retiring a contract. Second, establish a contract retirement checklist: close all external call entry points; revoke all ERC20 approvals; freeze token transfers within the contract; and permanently disable admin keys. Third, users should regularly check their own approved contract addresses for unrevoked permissions to avoid personal asset loss if a zombie contract is exploited. Finally, on-chain monitoring tools should include zombie contract status changes in their alert systems to help security teams detect abnormal withdrawal attempts early.
Fortunately, some of the affected teams have already intervened and patched remaining vulnerabilities. However, hundreds of zombie contracts remain at risk. According to a security firm's estimate, there are still over 30,000 old contracts on Ethereum mainnet that have not been fully decommissioned, of which about 12% still hold a total of more than $50 million in tokens or NFTs. This provides a persistent "ammunition depot" for hackers.

