Hackers Drain $17M from 5 ‘Zombie Contracts’ in 40 Days: DeFi Retirement Risks Exposed
Over the past 40 days, hackers exploited five deprecated but still-on-chain smart contracts to steal nearly $17 million, targeting projects including DxSale, TrustedVolumes, Huma Finance V1, Raydium Legacy AMM, and Aztec Connect. The root cause is incomplete contract decommissioning: leftover funds, retained admin privileges, and open invocation interfaces turned these relics into high-value targets. This incident highlights a systemic security blind spot in DeFi asset lifecycle management, urging developers to adopt thorough retirement checklists that include withdrawing all assets, revoking permissions, disabling functions, and periodic audits of archived contracts.

