Hackers Steal Nearly $17 Million in 40 Days as 'Zombie Contracts' Become Their ATMs

marsbitОпубліковано о 2026-06-26Востаннє оновлено о 2026-06-26

Анотація

According to an analysis published by ZeroDrift on June 22, 2026, attackers have stolen approximately $16.9 million over 40 days from five deprecated but still operational smart contracts across various blockchains. The primary issue is not a specific vulnerability but the incomplete decommissioning of legacy contracts. These "zombie contracts" often retain economic value, operational permissions, and callable functions, making them prime targets long after teams cease active development. The most significant loss occurred at DxSale, where an old locker contract lost about $7.3 million due to a forgotten control path becoming accessible again. Other affected projects include TrustedVolumes (~$5.87M), Raydium's legacy AMM pool (~$1.34M), Aztec Connect (~$2.28M), and Huma Finance V1 pool (~$101k). These incidents involved diverse systems—RFQ settlement, credit pools, liquidity lockers, AMMs—demonstrating the widespread nature of the risk. The analysis highlights that automated tools are lowering the cost for attackers to systematically scan for these long-tail targets, which have public code and weaker monitoring. In contrast, defensive practices for contract retirement remain underdeveloped. While the DeFi industry has mature audit processes for new deployments, it lacks strict protocols for securely sunsetting old contracts, which only become truly "retired" after all funds, permissions, authorizations, and trust assumptions are removed.

Author: ZeroDrift

Key Points

  • DxSale was the most severe case, with attackers stealing approximately $7.3 million.
  • The issue is not a single vulnerability, but the incomplete decommissioning of old contracts, which still retain economic value and operational permissions.

According to an analysis released by ZeroDrift on June 22, 2026, attackers stole approximately $16.9 million from five deprecated but still active smart contracts over the past 40 days.

An 'abandoned contract' is not equivalent to an 'inactive contract'. Many contracts, although no longer actively developed or maintained by their teams, remain deployed on-chain and can receive funds, execute transactions, or move assets. As long as they hold funds, authorizations, or callable entry points, they remain viable targets for attack.

These incidents occurred between May 7 and June 15, 2026. TrustedVolumes lost approximately $5.87 million, Huma Finance V1 pool lost around $101,000, DxSale V1 Locker lost about $7.3 million, Raydium Legacy AMM pool lost roughly $1.34 million, and Aztec Connect lost approximately $2.28 million in two consecutive attacks.

Chart: Cumulative losses from five abandoned contract-related incidents over 40 days. Source: ZeroDrift / X.

Contracts No One Watches May Still Hold Funds

The DxSale case is particularly illustrative. Its old locker contract was originally designed for long-term liquidity locking, ensuring funds couldn't be withdrawn before a set date. However, the risk of such systems stems precisely from their intended purpose: they are meant to hold value over the long term.

Over time, as teams shift focus to new products, monitoring weakens, personnel changes, and old permission paths and historical assumptions are gradually forgotten. ZeroDrift points out that in the DxSale incident, an old control pathway became viable again, leading to the withdrawal of liquidity that should have been locked.

The five incidents are not repetitions of the same exploit. They occurred in different systems, with different architectures and across different blockchains, involving components such as RFQ settlement, credit pools, LP lockers, AMMs, and rollup exits.

What they truly share is the underlying state: these contracts are no longer the active development focus of their teams yet still retain economic value on-chain.

Automated Analysis is Amplifying Old Contract Risks

Old contracts are naturally suited for discovery by automated tools: their code is public, their on-chain history is complete, monitoring is weaker, and they often retain outdated security assumptions. In the past, systematically searching for these long-tail targets required significant manual effort; now, code similarity searches, transaction simulation, on-chain data analysis, and AI-assisted review are lowering the cost of such searches.

ZeroDrift also emphasizes that there is currently no public evidence that AI was involved in these five specific attacks. What truly warrants attention is the shift in cost structure: it is becoming increasingly easier for attackers to systematically scan 'yesterday's products,' while defenders have not yet systematized the management of 'yesterday's responsibilities' to the same degree.

The DeFi security industry has developed relatively mature audit processes for contract launches, but contract retirement, migration, and decommissioning still lack equally strict discipline. A contract does not automatically become secure simply because a team stops maintaining it. It is only truly retired when its funds, permissions, authorizations, entry points, and trust assumptions have all been removed.

Пов'язані питання

QAccording to the article, what is the primary reason that abandoned smart contracts remain vulnerable to attacks?

AAbandoned contracts remain vulnerable because they are not properly retired. While no longer actively maintained by their teams, they are still deployed on-chain, can hold funds, retain permissions, and have callable entry points. As long as they possess economic value and operational access, they remain targets.

QWhich specific attack discussed in the article resulted in the largest financial loss, and how much was stolen?

AThe attack on DxSale's V1 Locker contract resulted in the largest financial loss. Approximately $7.3 million was stolen from it.

QWhat common underlying state do all five attack cases from May 7 to June 15, 2026, share, according to ZeroDrift's analysis?

AThe common underlying state is that all the targeted contracts were no longer the active development focus for their respective teams, but they still retained economic value on the blockchain.

QHow is the rise of automation and analysis tools changing the risk landscape for legacy smart contracts?

AAutomated tools like code similarity search, transaction simulation, on-chain data analysis, and AI-assisted review are lowering the cost for attackers to systematically scan and target legacy contracts. This shifts the cost structure, making it easier to exploit 'yesterday's products' while defense hasn't systemized the management of 'yesterday's liabilities'.

QWhat key gap in the current DeFi security practices does the article highlight regarding the lifecycle of smart contracts?

AThe article highlights a gap in the contract retirement process. While the DeFi security industry has mature auditing processes for contract launch, there is a lack of equally strict discipline for contract exit, migration, and decommissioning. A contract is not automatically safe just because the team stops maintaining it.

Пов'язані матеріали

Торгівля

Спот
活动图片