The next DeFi drain could come from legacy contracts everyone forgot

DeFiJune 11, 2026·6 min read

A $1.34 million exploit of Raydium’s phased-out AMM V3 pools exposes a systemic risk across DeFi: deprecated contracts that remain callable on-chain but invisible to users and unsupported by protocol infrastructure. Institutional investors face blind-spot losses from legacy smart contracts that exploit tracking systems categorize as routine bugs, when the real vulnerability is that nobody decommissioned them.

  • Raydium’s legacy AMM V3 pools held $10.2 million in idle liquidity across five pools after Serum’s deprecation rendered them functionless.
  • At least eight documented exploits since March 2025 have targeted deprecated or obsolete DeFi contracts, totaling approximately $10.8 million in losses.
  • Exploit classification systems routinely misidentify legacy-contract attacks as standard smart contract bugs, masking a lifecycle-management failure across the DeFi ecosystem.
  • $22.5M Total losses from legacy and zombie-contract exploits including Raydium incident
  • 10 Documented incidents involving deprecated infrastructure since March 2025
  • $1.34M Amount drained from Raydium’s unsupported legacy AMM V3 pools

On a Solana blockchain still considered a frontier for institutional adoption, Raydium’s recent exploit reveals a category of loss that standard risk models do not track. The attack targeted liquidity pools that Raydium had formally deprecated, phased out of the protocol’s active product line, yet left callable and exploitable on-chain.

The attacker bypassed critical validation checks that the current AMM V3 implementation enforces: they created a fake LP mint token, presented it as legitimate collateral, and drained real assets from five pools that had fallen into a state of technical limbo between active deployment and full decommissioning.

The broader pattern suggests this is not an isolated operational failure but a scaling problem in how DeFi protocols manage contract lifecycles. Exploit tracking systems, the tools institutional investors and risk managers rely on to categorize losses, classify these incidents under existing taxonomies: smart contract bugs, access control failures, oracle flaws.

None of those categories captures the core issue: a contract that should have been shut down, but wasn’t.

Raydium’s V3 pools remained live after Serum dependency made them obsolete

Raydium’s original AMM V3 pools existed solely to place orders on the Serum decentralized order book. When Serum itself deprecated its core infrastructure, the V3 implementation lost its fundamental purpose. The protocol launched a new product line with upgraded validation logic, moving users and liquidity to current pools.

But the old pools never closed: they stayed on-chain, callable, and accumulated idle capital of approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC.

The legacy program skipped two critical safety checks present in Raydium’s current implementation. Current pools verify the LP mint address and validate token proportions against a virtual supply mechanism to ensure collateral integrity. The V3 pools enforced neither check.

An attacker exploited this gap by creating a new mint, passing it off as the legitimate LP token, and withdrawing real assets without providing proportional backing, a classical proportion-control bypass that worked only because the old contract never implemented the guard in the first place.

The $1.34 million loss covered five distinct pools, all outside the active product path and marked as unsupported in Raydium’s user interface and SDK documentation. No current user could accidentally access these pools; the attack required direct blockchain interaction and familiarity with the deprecated program’s structure.

That specificity matters to institutional investors: it means this was not a zero-day affecting live trading infrastructure, but a predictable failure of contract retirement discipline.

Eight documented incidents in nine months trace a pattern of zombie contracts across protocols

The Raydium incident sits within a measurable trend. Public exploit reports identify at least eight clear cases since March 2025 where deprecated, obsolete, or legacy DeFi contracts became the primary attack surface. These incidents total approximately $10.8 million in direct losses.

Expanding the definition to include broader vault and product-level deprecation failures raises the count to roughly ten incidents totaling $22.5 million, a figure that includes Raydium and reflects losses from contracts that exploit tracking databases routinely misclassify.

The March 2025 1inch exploit drained roughly $5 million by targeting an obsolete Fusion v1 resolver contract. October 2025 saw Abracadabra lose $1.8 million when deprecated Cauldron V4 contracts remained exploitable due to a logic flaw that only affected the old implementation. December’s Yearn incident involved a legacy iEarn TUSD vault that had been phased out of the active product ecosystem.

None of these protocols deliberately kept these contracts online; all had moved users and capital to newer implementations. But the infrastructure persisted on-chain.

The commonality is not a technical flaw confined to one team or architecture. Rather, it reflects how DeFi protocols handle the transition from active product to dormant legacy status. Most deprecate by announcement and SDK update: they redirect users, stop routing traffic to old contracts, and document the transition in changelogs.

Few actually execute full decommissioning, the technical process of rendering a contract permanently non-callable or entirely removing its state. The gap between announced deprecation and technical decommissioning is where losses accumulate.

Exploit classification systems systematically miss the lifecycle-state risk layer

Standard exploit taxonomies break incidents into five categories: smart contract code bugs, access control failures, oracle and accounting issues, private key compromises, and bridge security flaws. Each describes a technical mechanism, the flaw that allowed funds to move. None captures the prerequisite: that a contract should not still have been callable in the first place.

A database entry for the Raydium incident would list “missing validation checks” as the root cause, correctly identifying the technical gap. But that classification obscures the fact that the V3 contract was deprecated infrastructure that should have been inaccessible. The 1inch loss gets tagged as a “resolver contract bug” without noting that the contract was obsolete.

Abracadabra’s incident appears as a logic flaw affecting Cauldron V4, not as a failure to decommission retired vault code.

This labeling problem has real consequences for institutional risk management. Portfolio managers and compliance teams use exploit databases to model DeFi exposure. If losses from deprecated contracts roll into the same “smart contract bug” bucket as zero-day flaws in active code, the risk profile becomes distorted.

A protocol with zero defects in its current implementation but poor lifecycle management looks identical to one with active code vulnerabilities. The institutional buyer cannot distinguish between these risks because the information system conflates them.

Exploits of zombie contracts are a governance and operations failure, not a cryptography or code-audit problem.

DeFi protocols face mounting pressure to decommission rather than simply deprecate

The recurring pattern has begun forcing protocol teams to address contract lifecycle more deliberately. Several have announced technical decommissioning procedures: not merely directing users away from old contracts, but rendering them non-callable through state migration, asset transfer-out, or self-destructing code mechanisms.

Some are retroactively adding kill-switches to legacy contracts, enabling admins to freeze calls and drain remaining balances.

However, this shift remains voluntary and inconsistent. There is no standard for how long a contract should remain callable after deprecation, no agreed timetable for full decommissioning, and no regulatory or community pressure comparable to what zero-day exploit prevention commands.

A protocol can announce a contract as deprecated and still leave it live for months or years without facing reputational consequence, until an attacker finds it.

For institutional investors, the operational question is whether DeFi can scale to support proper lifecycle management at the pace protocols currently ship new products. Raydium alone has gone through multiple AMM iterations; Yearn runs dozens of vault implementations across different assets and strategies. As the installed base of contracts grows and products cycle faster, the number of deprecated implementations waiting for decommissioning will only increase. The $22.5 million in documented losses represents the incidents that made it into public reports; the

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe