DeFi security has improved, but not in the way many people assume. The industry’s biggest vulnerabilities did not disappear. The attack surface did not shrink; it evolved.
In 2022, bridge exploits accounted for 73% of all DeFi losses, while flash loan attacks made up nearly 19%. By 2025, bridge losses had fallen to just 3% of total losses, and flash loan losses had dropped below 1%. The defenses built against these attack vectors worked. However, access control failures became the largest source of losses, accounting for 59% of all DeFi losses in 2025. Unlike bridge exploits or flash loan attacks, these failures are much harder to prevent because they do not originate in smart contract code.
The Pattern Behind the Numbers
This is not a story of an industry that failed to learn. It is the story of an industry in a continuous arms race with patient, sophisticated, and financially motivated adversaries. Every time DeFi closes one avenue of attack, attackers find another. Security improves, but the problem does not disappear. It moves to a different part of the system.
The data from 2020 through 2025 shows exactly that. DeFi became much better at defending against attack vectors it had already encountered through stronger bridge designs, better audits, bug bounty programs, and improved development practices. At the same time, losses increasingly came from attack categories that require different types of defenses.
That is the central idea of this analysis. Some attack vectors now have reliable defenses, while others remain difficult to secure because they depend on operational security instead of smart contract code. Knowing the difference helps explain where DeFi has made real progress, where the biggest risks remain, and what the last six years of loss data tell us about the direction of DeFi security.
As we discussed in our research on the history of crypto hacks, the attack surface has responded to new defenses rather than disappearing. DeFi security between 2020 and 2025 provides one of the strongest examples of that pattern over a relatively short period.

The Scale of the Problem: Six Years of Lost Data
Before looking at individual attack categories, it helps to understand the overall picture of DeFi security. Immunefi tracked exploits and vulnerabilities across the major DeFi ecosystems from 2020 through 2025. Those six years cover the full history of modern DeFi security, from the flash loan attacks of 2020 to the explosive growth and record-breaking exploits of 2021, the bridge failures of 2022, the market’s stabilization in 2023, and the different attack patterns seen in 2024 and 2025.
Industry-wide DeFi protocol losses fell by nearly 80%, from a peak of $2.62 billion in 2022 to $534 million in 2024. Losses increased to $680 million in 2025, but only because a small number of major incidents drove the annual total. At the same time, the median loss per incident fell from $6 million in 2022 to $1.5 million in 2025, a decline of 75%.
$2.62B
Peak DeFi protocol losses (2022)
Bridge exploits drove most of the losses in 2022. The Ronin ($625 million), Wormhole ($320 million), and Nomad ($190 million) attacks alone accounted for more than $1.1 billion in stolen funds. Bridges became prime targets because they held large pools of assets while introducing additional technical complexity across multiple blockchains.
812
Total DeFi incidents tracked (2020–2025)
-75%
Decline in median loss per incident (2022–2025)
The gap between total losses and the median loss per incident explains what happened over these six years. The lower median shows that the average exploit causes far less damage than it did in 2022. However, annual losses are still heavily influenced by a few large attacks. DeFi security has improved in measurable ways, but well-funded, highly capable attackers can still exploit high-value targets and cause losses large enough to dominate the annual figures.

DeFi Security Attack Categories: How Protocols Get Exploited
Category 1
Reentrancy: The First Major DeFi Vulnerability
Where it started · How defenses developed · Why it’s still present
Reentrancy was one of the first vulnerabilities to expose the security challenges facing DeFi. As discussed in our research on the history of crypto hacks, the DAO hack in June 2016 used a reentrancy exploit to drain 3.6 million ETH from the world’s first major DeFi protocol. The attacker exploited a flaw in the withdrawal function that allowed the same balance to be withdrawn multiple times before the smart contract updated its internal records.
A reentrancy vulnerability happens when a smart contract sends ETH or tokens before updating its own state. That sequence allows the receiving contract to call the vulnerable function again before the balance changes, making multiple withdrawals possible. The solution is well established: update the contract’s state before making external calls or use a reentrancy guard. Both practices have been part of Solidity security guidance since 2016.
Even so, reentrancy has not disappeared. After declining in 2022, reentrancy attacks increased again in 2023 before becoming less common in 2024. Read-only reentrancy attacks accounted for much of the increase in 2023, particularly on Layer 2 protocols. This variant exploits view functions in protocols that relied on Curve Finance’s reentrancy lock without accounting for read-only calls. Because it behaves differently from classical reentrancy, several security audits failed to identify the weakness.
Reentrancy also shows that documenting a vulnerability is not enough to stop it from appearing in new code. Every new protocol comes with different development teams, coding practices, and design choices. New EVM features also create opportunities for familiar vulnerabilities to appear in ways that earlier security guidance did not anticipate. That is why reentrancy is still part of every serious discussion about DeFi security, nearly a decade after the DAO hack.
Category 2
Flash Loan Attacks: The Rise and Partial Taming
19% of 2022 losses → under 1% in 2025 · Defenses that worked
Flash loans, introduced by Aave in January 2020, are uncollateralized loans that must be borrowed and repaid within a single transaction. They were designed to improve capital efficiency for arbitrage and liquidations. Attackers quickly realized they could also use them to manipulate protocol price feeds without providing any upfront capital. A typical attack borrowed millions of dollars in a single transaction, manipulated an asset’s price, exploited the distorted price to extract value, repaid the loan, and kept the profit. Everything happened within the same transaction block.
Flash loan attacks became one of the most technically sophisticated exploit categories between 2020 and 2022. The bZx attacks in February 2020 provided the first successful example. The attacker borrowed ETH through a flash loan, manipulated the Uniswap price of WBTC, used the inflated price on bZx to obtain an undercollateralized loan, then repaid the flash loan and kept the difference. The entire exploit required no upfront capital. Harvest Finance, Cream Finance, and dozens of smaller protocols later suffered similar attacks using the same approach with minor variations.
Why Flash Loan Attacks Declined
Flash loan attacks accounted for nearly 19% of DeFi losses in 2022. By 2025, they accounted for less than 1%. Few attack categories show such a sharp decline, and the reason is straightforward. The industry built effective defenses against the underlying weakness.
Time-weighted average price (TWAP) oracles calculate prices over a period of time instead of relying on a single market price. That makes short-term price manipulation much more expensive because attackers must influence prices across multiple blocks instead of just one transaction. Many protocols also replaced spot price oracles with Chainlink’s decentralized price feeds, removing the pricing weakness that made many flash loan attacks possible.
The decline in flash loan attacks stands out as one of DeFi security’s strongest examples of successful defense. The vulnerability was well understood, practical solutions became widely available, and protocols adopted those solutions. At the same time, the improvement did not happen overnight. Developers first had to recognize the weakness, then update existing protocols, and finally apply those same protections to new deployments.

Category 3
Bridge Exploits: The 2022 Catastrophe and Its Lessons
73% of 2022 DeFi losses to 3% in 2025 · The greatest improvement across a single attack category
Cross-chain bridges became DeFi’s biggest security failure in 2022. They also saw the biggest improvement over the following three years. Bridges held enormous amounts of value because a single contract secured assets moving between multiple blockchains. If attackers bypassed the bridge’s verification process, they could gain access to every locked asset instead of targeting individual users or protocols.
The three largest bridge exploits of 2022 exposed three very different weaknesses. Ronin lost $625 million after attackers compromised five of the nine validator keys needed to approve withdrawals through a targeted phishing campaign against Sky Mavis. Wormhole lost $320 million because of a flaw in its signature verification process that allowed the attacker to mint wrapped ETH without backing collateral. Nomad lost $190 million after a configuration mistake in its message verification system made it possible to replay and forge message proofs. Once the weakness became public, hundreds of copycat attackers joined the exploit.
Three Attacks, Three Different Failures
Although these attacks targeted bridges, they did not share the same cause. Ronin stemmed from compromised validator keys. Wormhole failed because of a smart contract vulnerability. Nomad failed because of a configuration error. Together, they became three of the largest exploits in DeFi history within a matter of months.
The Ronin attack deserves particular attention. As discussed in our research on the history of crypto hacks, the Lazarus Group stole $625 million by compromising the people responsible for protecting validator keys. The attack showed that strong smart contract security cannot protect a protocol when attackers gain control of the infrastructure and credentials that govern it.
Bridge exploits accounted for 73% of all DeFi losses in 2022. By 2025, that figure had fallen to just 3%. Better bridge designs played a major role. Multi-party computation, optimistic rollup verification windows, and zero-knowledge proof settlement made attacks much more difficult. At the same time, Layer 2 native bridges and canonical bridges reduced reliance on many third-party bridge protocols that dominated the market in 2021 and 2022.
Even with that progress, bridge security is still a major challenge. Early 2026 provided another reminder when the KelpDAO bridge exploit caused $292 million in losses through a single-verifier LayerZero configuration. The category has improved dramatically, but DeFi security still depends on careful bridge design, secure operations, and regular security reviews.
Category 4
Access Control Failures: The Category That Took Over
59% of all H1 2025 losses · $1.83 billion · The hardest problem to solve with code
Access control failures have become one of the biggest challenges in DeFi security. They accounted for roughly 59% of all DeFi losses during the first half of 2025, totaling about $1.83 billion. By comparison, smart contract vulnerabilities accounted for just 8%, or $263 million in stolen funds.
Access control failures cover a wide range of vulnerabilities, but they all share one characteristic. An unauthorized party gained the ability to perform an action reserved for trusted operators. In some cases, an administrative function had no access restriction, allowing anyone to call it. In others, developers implemented the permission logic incorrectly by checking the wrong address, using the wrong comparison, or overlooking edge cases in the authorization model. Some attacks involved no coding mistake at all. The access control system worked exactly as intended, but attackers compromised the person controlling the privileged keys through phishing or other forms of social engineering.
When the Code Isn’t the Weakness
Off-chain attacks accounted for 80.5% of stolen funds in 2024, while compromised accounts made up 55.6% of all recorded incidents. Those figures show how DeFi security has changed over the past few years. An audited smart contract with properly implemented access controls can still fail if an attacker compromises the administrator’s private keys or convinces an authorized signer to approve a malicious transaction.
As discussed in our research on the history of crypto hacks, the Bybit attack in February 2025 shows why this category is so difficult to defend against. Code fixes alone are not enough. Protocols also need strong operational security, including multi-signature wallets, hardware security modules, transaction simulation before signing, and security training for people with administrative access.
The Drift Protocol incident on Solana provides another example. The attack caused $285 million in losses after a six-month North Korean social engineering campaign combined governance manipulation with oracle abuse. It showed that nation-state attackers are willing to spend months gaining trust before launching an attack. No smart contract audit can stop that kind of operation. DeFi security also depends on strong operational practices, careful access management, and governance controls that reduce the chances of a successful compromise.

Category 5
Governance Attacks: When Voting Becomes a Weapon
Flash loan governance · Long-term infiltration · Governance manipulation
On-chain governance allows token holders to vote on protocol upgrades, treasury allocations, and changes to key protocol parameters. The goal was to decentralize decision-making, so protocol changes reflected the will of the community instead of a founding team. This approach distributed authority across many participants and reduced reliance on a single organization to make decisions.
Governance also created a new attack vector. Any system that gives voting power based on token ownership can be manipulated by anyone who acquires enough tokens through purchases, borrowing, or market manipulation. The Beanstalk governance attack in April 2022 showed how effective that strategy could be. An attacker used a flash loan to obtain majority voting power, passed a malicious proposal that emptied the protocol’s treasury, then repaid the flash loan within the same transaction. The governance process followed its own rules. The attacker simply gained enough voting power to control the outcome.
How Governance Defenses Changed
Time locks became the primary defense against flash loan governance attacks. By delaying proposal execution after a successful vote, they prevent attackers from borrowing voting power, approving a proposal, and executing it in a single transaction. Governance attacks accounted for 5% of recorded incidents in 2022 and 5.6% in 2024. The widespread adoption of time locks has made flash loan governance attacks far more difficult.
However, time locks cannot stop every governance attack. A determined adversary can spend months building influence through token accumulation, community participation, or control of trusted accounts before submitting a malicious proposal. Those long-term campaigns require a different set of defenses, including stronger governance oversight, voting safeguards, and careful review of high-impact proposals.
DeFi Security Infrastructure: What Auditing Catches
Smart contract audits have become a standard part of launching any serious DeFi protocol. Today, the audit industry employs thousands of security researchers and generates hundreds of millions of dollars in annual revenue for firms such as Trail of Bits, OpenZeppelin, Certora, Halborn, and many others. The key question is what audits catch and where their limits begin.
Audits work well when the problem exists within a protocol’s codebase. They can identify reentrancy vulnerabilities, integer overflow and underflow bugs, access control implementation errors, and many types of business logic flaws through manual review and automated analysis. A thorough audit performed by an experienced security firm will identify many of the code-level vulnerabilities that have appeared repeatedly throughout the history of DeFi security.
Where Audits Reach Their Limits
An audit reviews a code base, not an entire ecosystem. It cannot fully account for how a protocol will behave when interacting with other protocols, changing oracle prices, governance decisions, or unexpected market conditions. Vulnerabilities created by protocol composability are much harder to identify because they arise through interactions between multiple systems, not within a single smart contract.
That limitation explains why audits alone cannot secure a protocol. DeFi security also depends on evaluating oracle integrations, APIs, governance mechanisms, market conditions, and other external dependencies that influence how a protocol behaves after deployment. These risks have encouraged wider use of complementary practices such as formal verification, which mathematically proves that a contract behaves according to its specification, invariant testing, which verifies that important properties hold across different execution states, and economic security analysis, which evaluates how a protocol’s incentive structure responds to adversarial behavior.
The Security Stack Leading Protocols Use in 2026
Multiple independent audits: Leading protocols no longer rely on a single audit. Many commission two or three independent firms, each bringing different expertise and testing for different classes of vulnerabilities. The added cost is high, but each audit increases the chances of finding issues another team may overlook.
Formal verification: Formal verification uses mathematical proofs to confirm that specific contract properties hold under every possible input. Tools such as Certora Prover have uncovered vulnerabilities in audited code that manual reviews failed to detect. Aave, Compound, and Uniswap use formal verification to protect critical parts of their smart contracts.
Beyond Code Reviews
Bug bounty programs: Immunefi has paid more than $100 million in bug bounties to security researchers who disclosed vulnerabilities instead of exploiting them. The largest individual payout reached $10 million. Bug bounty programs give researchers a financial incentive to report security flaws through responsible disclosure. They will not stop determined nation-state attackers, but they have encouraged many ethical researchers to report vulnerabilities before criminals discover them.
On-chain monitoring and circuit breakers: Leading protocols monitor contract activity throughout the day and automatically pause sensitive functions when unusual behavior appears. Examples include unexpected transaction sequences, abnormal oracle price movements, or governance proposals submitted by newly funded wallets. During the Euler Finance hack in March 2023, monitoring systems helped the protocol respond sooner than in many earlier incidents by detecting the abnormal outflow of funds.
Time locks and multi-signature controls: Administrative actions, including changes to fee rates, collateral ratios, and oracle sources, should require approval from multiple authorized signers and include a mandatory delay before execution. Together, these controls make compromised administrative access much harder to exploit by increasing both the time and coordination needed to carry out malicious changes.

Bug Bounties: The Market That Changed DeFi Security
Immunefi, the largest DeFi bug bounty platform, changed the economics of DeFi security by giving researchers a legitimate and well-paid alternative to exploiting vulnerabilities in live protocols.
Before bug bounty programs became common, security researchers faced a difficult choice. Reporting a serious vulnerability meant accepting whatever reward a protocol decided to offer, if it offered one at all. Exploiting the same vulnerability could generate millions of dollars, although it also carried legal and ethical consequences. For some researchers, the financial gap between those two options made responsible disclosure much less attractive.
Aligning Security Incentives
Large bug bounty programs narrowed that gap. Immunefi’s leading programs now offer rewards of up to $10 million for serious vulnerabilities. A researcher who discovers a severe vulnerability in protocols such as Aave or Uniswap can earn that reward through responsible disclosure instead of exploiting the weakness. The incentives are still not perfect. Attackers who can exploit a vulnerability immediately and avoid identification may still choose theft. However, bug bounty programs have encouraged many independent security researchers to disclose vulnerabilities instead of abusing them.
The results are measurable. Immunefi has paid more than $100 million in bug bounties since its launch, and annual payouts have increased as protocols raised reward limits. A $10 million bounty may seem expensive, but it is far less costly than losing $100 million or $300 million through a successful exploit.
The Nation-State Threat: Lazarus Group and DeFi
North Korea’s Lazarus Group has become one of the most capable and persistent threats facing DeFi security. As discussed in our research on the history of crypto hacks, the group’s operations now extend beyond exchange wallet phishing to supply chain attacks targeting the software and interfaces used by authorized signers.
DeFi protocols also create opportunities that long-term adversaries can exploit. Open governance, anonymous contributors, and remote collaboration through platforms such as Discord and Telegram make it difficult to identify attackers who spend months earning trust before launching an attack. An attacker who becomes a trusted contributor, builds relationships with protocol developers, and learns a protocol’s technical architecture can bypass security controls that no smart contract audit would detect.
When the Code Isn’t the Target
The Drift Protocol incident offers one of the clearest documented examples of this approach. The attack caused $285 million in losses after a six-month Lazarus Group campaign combined governance infiltration with oracle manipulation. It also showed that defending against nation-state attackers requires more than secure smart contracts. Protocols also need stronger operational security, including contributor verification, restricted access to sensitive systems, monitoring of governance activity, and internal security practices that reduce the risk of long-term infiltration.
What the Loss Data Shows About Which Ecosystems Are Most Secure
Six years of loss data across the major blockchain ecosystems provide useful insight into DeFi security. While no ecosystem is immune to exploits, the data shows measurable differences in security practices, protocol maturity, and long-term performance.
Ethereum mainnet has the strongest security record relative to its total value locked (TVL). That advantage does not come from Ethereum itself being inherently more secure. Instead, many of its largest protocols have spent years strengthening their security practices. Uniswap, Aave, and Compound, which together account for much of Ethereum’s DeFi TVL, have invested heavily in audits, formal verification, bug bounty programs, and gradual protocol upgrades. When exploits occur on Ethereum, they involve newer protocols, projects with fewer audits, or protocols testing new designs.
Comparing Security Across Ecosystems
BNB Chain (formerly Binance Smart Chain) has recorded a much higher loss-to-TVL ratio and frequently appears among the highest-loss ecosystems in annual DeFi security reports. Business logic exploits accounted for many of the major BNB Chain incidents in 2024 and 2026. One reason is the ecosystem’s focus on rapid, low-cost protocol launches. Faster development cycles can leave less time for audits, testing, and security reviews before deployment.
Solana has strengthened its security over the past several years. Its architecture, particularly its execution model, creates different security challenges than Ethereum, and auditors needed time to build expertise around those differences. The Drift incident showed that even established Solana protocols face nation-state threats. At the same time, routine smart contract exploits became less common as security practices improved across the ecosystem.
The 2025-2026 Attack Surface: What’s New
The 2026 incident data includes several attack categories that saw little activity in earlier years. As DeFi expands into new protocol designs and Ethereum adds new capabilities, attackers also find new opportunities.
Attack categories reported during 2026 include EIP-7702 vulnerabilities, AMM k-value attacks, RFQ callback authorization bugs, same-transaction oracle manipulation, off-chain signing bridge drains, governance mint takeovers, zk-rollup settlement mismatches, and privacy pool proofless-deposit bypasses.
New Features, New Risks
EIP-7702, which allows externally owned accounts to temporarily behave like smart contracts, created transaction patterns that many existing security tools were not built to analyze. ZK-rollup settlement mismatch exploits point to the increasing complexity of Layer 2 settlement. Privacy pool proofless-deposit vulnerabilities show that new protocol designs can expose weaknesses only after deployment.
This has happened throughout the history of DeFi security. New protocol features create new attack opportunities before security researchers fully understand them. Researchers then study those attacks, develop better detection methods, update audit checklists, and expand formal verification techniques. The next generation of protocols benefits from those lessons, while attackers search for the next weakness.
What I’m Watching
DeFi security in 2026 presents two very different stories. The good news is that bridge exploits and flash loan attacks have fallen, showing that the industry can learn from past failures and build effective defenses. The challenge is that access control failures and social engineering now account for a much larger share of losses. Those risks cannot be solved through smart contract code alone.
The metric I watch most is the ratio of code-level exploits to off-chain key compromise incidents. When code-level exploits dominate, the industry’s primary security tools, including audits, formal verification, and bug bounty programs, are well suited to the problem. When off-chain key compromise becomes the leading cause of losses, attention moves to operational security, human behavior, and organizational processes. Those areas have received far less attention across DeFi.
Three Indicators to Watch
Another area worth watching is the insurance market for DeFi protocols. Nexus Mutual and similar on-chain insurance providers price coverage according to the risk of each protocol. Lower premiums suggest greater confidence in a protocol’s security, while sudden increases may signal growing concern about its risk profile.
I also watch the adoption of formal verification among protocols securing large amounts of total value locked (TVL). Formal verification uses mathematical proofs to confirm that smart contracts behave as intended under every possible input. It is one of the strongest tools for eliminating entire classes of code-level vulnerabilities, although it requires specialized expertise and considerable resources. Protocols such as Aave V3 and the smart contracts behind Uniswap V4 have invested heavily in formal verification, while many others still rely mainly on audits.
Bridge exploits fell from 73% to 3% of DeFi losses within three years. Flash loan attacks dropped from 19% to less than 1%. Those defenses worked. The same approach of identifying vulnerabilities, building practical defenses, and applying them consistently now needs to address access-control failures, nation-state social engineering, and the new attack categories emerging in 2026. History points in that direction. The remaining question is how much those lessons will cost before they become standard practice.
Key Takeaways
DeFi protocol losses peaked at $2.62 billion in 2022. They fell to $534 million in 2024 before rising to $680 million in 2025. A handful of major incidents drove the increase. Meanwhile, the median loss per exploit fell by 75%.
Bridge exploits fell from 73% of DeFi losses in 2022 to 3% in 2025. Flash loan attacks dropped from 19% to less than 1%. Better bridge designs and stronger oracle protections drove much of that improvement.
Access control failures accounted for 59% of all DeFi losses during the first half of 2025. Off-chain attacks accounted for 80.5% of stolen funds in 2024. Operational security now carries as much weight as secure code.
Nation-state groups, particularly North Korea’s Lazarus Group, now pose one of the biggest risks to DeFi security. Their campaigns combine long-term infiltration, governance manipulation, and social engineering.
Leading protocols reduce risk by combining multiple independent audits, formal verification, bug bounty programs, on-chain monitoring, time locks, and multi-signature controls.
New protocol features create new attack opportunities. The 2026 incident data includes EIP-7702 vulnerabilities, zk-rollup settlement mismatches, and privacy pool proofless deposit bypasses. Researchers are already building defenses for these attack categories.
Sources & Further Reading
- The Ecosystem Vulnerability Scoreboard: 6 Years of DeFi Loss Data — Immunefi, May 2026
- The State of DeFi Exploit Risk — Cicada Partners, October 2025
- Top 100 DeFi Hacks Report 2025 — Halborn
- 2024 Most Exploited DeFi Vulnerabilities — Three Sigma
- Why DEX Exploits Cost $3.1B in 2025 — Yellow Research
- The Biggest Crypto Hacks and Exploits (2020–2025) — CleanSky
- Top 10 DeFi Hacks You Need to Know — Shardeum
- DeFi Security Incident Database 2020–2026 — GitHub
- Immunefi — DeFi Bug Bounty Platform
- Nexus Mutual — On-Chain Insurance for Smart Contracts
- DeFi Hacks Analysis — Chainalysis
- DeFi Protocol Hacks: Understanding Security Risks and Solutions — Startup Defense

