Deprecated, unverified, and abandoned smart contracts have emerged as one of DeFi's most exploited attack surfaces in 2026. Between December 2025 and June 2026, attackers drained more than $50 million from contracts that protocol teams had moved on from but never fully decommissioned. The inciden...
"Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds." — Manuel Aráoz, Co-Founder, OpenZeppelin
Deprecated, unverified, and abandoned smart contracts have emerged as one of DeFi's most exploited attack surfaces in 2026. Between December 2025 and June 2026, attackers drained more than $50 million from contracts that protocol teams had moved on from but never fully decommissioned. The incidents span multiple chains — Ethereum, Solana, BNB Chain, and TRON — and share a common trait: code that was left callable on-chain long after front-end interfaces were shut down.
The trend accelerated in the second quarter. On June 10, Raydium lost $1.34 million from five AMM V3 pools deprecated since 2021. In May, DxSale's legacy liquidity lockers on BNB Chain were drained of $7.3 million across 1,400 LP positions. Transit Finance lost $1.88 million through a contract deprecated since 2022 on TRON. On January 8, Truebit suffered the largest single incident: $26.2 million stolen via an integer overflow in a contract compiled with Solidity v0.5.3 — a compiler version from 2019 that lacks automatic overflow checks.
Chainalysis, in a June 9 report, attributed $36.7 million in losses directly to unverified contracts over the preceding six months. The firm warned that AI-assisted decompilation tools are enabling attackers to scan thousands of opaque bytecode contracts at scale, identifying exploitable flaws at an estimated cost of $1.22 per contract scanned, according to Cecuro security researchers.
DeFi protocols have lost more than $840 million across 50-plus incidents in the first five months of 2026, according to data tracked by Halborn. May alone accounted for $68.3 million in losses across twelve incidents exceeding $1 million each, down from $630 million in April — a month dominated by the $292 million KelpDAO and $285 million Drift Protocol breaches.
Within this broader loss environment, a distinct subcategory has emerged: exploits targeting code that was never meant to still be running. These are not zero-day attacks on active protocols. They are strikes against contracts that teams abandoned, deprecated, or simply forgot about — what security researchers have begun calling "zombie contracts."
Chainalysis's June 9, 2026, report identified five protocols where exploited contracts were unverified on block explorers at the time of attack: Truebit, Trusted Volumes, Aperture Finance, Ekubo, and others. Combined losses: $36.7 million. The firm noted the attackers in several cases were the same wallet clusters, suggesting coordinated campaigns that methodically probe dormant code across multiple chains.
Separately, CryptoSlate reported on June 11 that at least eight legacy-contract exploits have been publicly documented since March 2025, suggesting the phenomenon predates this year's spike but has intensified as AI tooling lowers the cost of reconnaissance.
The attack vectors vary, but the underlying pattern is consistent: dormant code retains permissions and holds assets.
Raydium (June 10, 2026 — $1.34M lost): An attacker targeted five liquidity pools belonging to Raydium's legacy AMM V3 program on Solana. The pools had been inactive since 2021, deprecated after the collapse of the Serum on-chain order book. The attacker created a counterfeit SPL token mint, called the legacy withdraw function, and the contract — which did not verify the LP mint address — treated the attacker as a 100% liquidity provider. Approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC were drained. Funds were bridged to Ethereum and routed through Tornado Cash. Raydium stated it would reimburse affected liquidity providers from its treasury.
DxSale (May 29, 2026 — $7.3M lost): PeckShield flagged an exploit of DxSale's legacy liquidity lockers on BNB Chain. The attacker manipulated unlock timestamps, reduced locking fees to 1 wei using a privileged setFee function, and executed batch withdrawals across 1,400 LP positions locked since 2021. On-chain investigators noted that ownership of the locker contract had been transferred 269 days before the attack through approximately 80 separate wallet hops — a transfer never publicly announced. Telegram channels reportedly offered "internal access to unlock old DxSale LPs" as early as August 2025, raising questions about insider involvement.
Truebit (January 8, 2026 — $26.2M lost): The largest single zombie-contract exploit of 2026. An integer overflow vulnerability in Truebit's bonding curve mechanism allowed the attacker to mint vast quantities of TRU tokens at near-zero cost. The contract had been deployed on Ethereum since 2021, compiled with Solidity v0.5.3 — a version predating automatic overflow protections introduced in Solidity 0.8.0. The contract's source code was never verified on Etherscan. Proceeds were laundered via Tornado Cash.
Aperture Finance (January 25, 2026 — $3.67M lost): The attacker exploited weaknesses in how v3 and v4 contract versions handled token approvals and function calls, siphoning funds through unverified contracts.
Transit Finance (May 13, 2026 — $1.88M lost): A deprecated contract on TRON, unused since 2022, was drained of stablecoins. Transit Finance's current contract version was unaffected. The protocol pledged to compensate affected users and issued a 48-hour white-hat bounty window.
Ekubo Protocol (May 2026 — $1.4M lost): A custom extension smart contract contained a verification error that allowed the attacker to drain funds via existing ERC-20 approvals, according to Halborn's May 2026 review.
A structural factor distinguishing 2026's legacy-contract exploits from prior years is the role of AI in vulnerability discovery. Chainalysis's June 9 report described how attackers now use AI-driven tools — combining decompilers such as Dedaub and Heimdall with large language models — to analyze unverified EVM bytecode at scale.
The workflow, as described by Chainalysis: LLMs ingest decompiled bytecode, scan for flaws such as reentrancy bugs, access control gaps, and arithmetic errors, then triage targets by estimated exploitability and potential yield. What previously required a skilled reverse engineer spending days on a single contract can now be partially automated across an entire chain's unverified contract inventory.
Cecuro, an AI audit firm, quantified the capability gap. In a benchmark study evaluating 90 real-world exploited contracts representing $228 million in losses, Cecuro's purpose-built AI security agent detected vulnerabilities in 92% of cases — compared to 34% for a general-purpose AI coding agent using the same underlying model. The firm estimated that AI exploit capability doubles every 1.3 months, with scanning costs of approximately $1.22 per contract.
The asymmetry is structural. As Manuel Aráoz, OpenZeppelin's co-founder, stated publicly in May 2026: defenders must fix every bug; attackers need only one. Aráoz personally recommended that associates exit DeFi protocols entirely, although OpenZeppelin's current CEO Demian Brener publicly distanced the company from that position, reaffirming commitment to "continuous, AI-augmented security."
The zombie-contract problem exposes a gap in DeFi's operational model: there is no standard protocol for decommissioning smart contracts.
In traditional software, deprecated services are shut down — servers are turned off, APIs are sunset, endpoints are blocked. On-chain, immutability means contracts persist indefinitely. Unless a contract includes a self-destruct function (deprecated in Ethereum post-Dencun), a pause mechanism, or a proxy pattern allowing migration, it remains callable forever.
Several compounding factors:
| Date | Protocol | Chain | Amount Lost | Vector | |------|----------|-------|-------------|--------| | Jan 8 | Truebit | Ethereum | $26.2M | Integer overflow in unverified bonding curve | | Jan 25 | Aperture Finance | Ethereum | $3.67M | Token approval exploit in v3/v4 contracts | | May 13 | Transit Finance | TRON | $1.88M | Deprecated 2022-era contract vulnerability | | May 2026 | Ekubo | Ethereum | $1.4M | Verification error in extension contract | | May 2026 | Trusted Volumes | Ethereum | $6.7M | Missing access controls on deprecated allowlist | | May 29 | DxSale | BNB Chain | $7.3M | Ownership override on 2021-era lockers | | Jun 10 | Raydium | Solana | $1.34M | Fake LP token mint on deprecated AMM V3 | | Total | | | $48.49M | |
Sources: Chainalysis, Halborn, PeckShield, GoPlus Security, CryptoSlate. Some incidents may overlap with Chainalysis's $36.7M unverified-contract tally, which uses a different classification methodology.
Three design-level failures underpin the crisis:
1. Immutability without lifecycle management. Blockchain's core value proposition — tamper-proof code — becomes a liability when the code is flawed and the team is gone. There is no on-chain equivalent of decommissioning a server. Contracts without pause functions, admin keys, or proxy upgrade patterns persist in perpetuity.
2. Verification is optional. Etherscan source code verification remains a voluntary, manual step. According to Chainalysis, a significant portion of deployed contracts across major chains have never been verified, creating a vast pool of opaque bytecode that only sophisticated actors can analyze. The gap between what auditors see (verified source) and what attackers see (all bytecode) is a structural advantage for offense.
3. No revocation standard for approvals. ERC-20 token approvals granted to deprecated contracts do not expire. Users who interacted with a protocol in 2021 may still have active approvals to contracts they cannot see in any current interface. Industry tools like Revoke.cash exist but require manual user action.
No consensus has formed on a solution. Several approaches are under discussion:
The $48.5 million extracted from zombie contracts in 2026 is a rounding error relative to DeFi's $840 million in total exploit losses this year. The significance is not the dollar figure but the pattern. Every chain that has hosted DeFi activity since 2020 carries a tail of deprecated contracts — code that no team monitors, no auditor reviews, and no interface surfaces. That tail is growing.
AI has changed the economics of exploitation. Scanning thousands of unverified contracts for exploitable flaws is no longer the domain of elite reverse engineers. It is a commodity operation. The defense-offense asymmetry that Aráoz described — fix every bug versus find one — is compounded when the attacker's toolkit automates discovery and the defender has moved on to a new project.
The industry's options are limited. Retroactive decommissioning is difficult without admin keys. Approval revocation requires user action. AI-augmented monitoring requires adoption. Each approach introduces trade-offs with decentralization, immutability, or user responsibility.
What the data shows: the cost of leaving code on-chain without a lifecycle plan is no longer theoretical. It is $48.5 million and counting.