Share this article

The State of DeFi Exploit Risk

DeFi protocols can rival or surpass traditional financial security standards and introduce frameworks to better assess risks in real-world asset applications for smarter capital allocation, says Cicada Partners Co-Founder Christian Lantzsch.

Oct 8, 2025, 4:38 p.m.
city street photography
(Daryan Shamkhali/ Unsplash)

What to know:

You're reading Crypto Long & Short, our weekly newsletter featuring insights, news and analysis for the professional investor. Sign up here to get it in your inbox every Wednesday.

The decentralized finance (DeFi) sector has undergone a remarkable security transformation, achieving a 90% reduction in exploit losses since 2020 and positioning itself as mature financial infrastructure capable of institutional adoption. Our analysis reveals that DeFi protocols have not only survived the “experimental era” but have systematically evolved into some of the most secure financial systems in existence, with daily loss rates plummeting to just 0.0014% by 2024.

This evolution represents more than statistical improvement; it demonstrates that decentralized financial systems can achieve and maintain institutional grade security when comprehensive risk frameworks are implemented. The journey from 30.07% annualized losses in 2020 to 0.47% in 2024 marks the transition from experimental protocols to mature financial infrastructure capable of serving institutional scale capital deployment.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Long & Short Newsletter today. See all newsletters
Average Lending Loss Per Day

Five distinct security phases have defined DeFi’s maturation: The "Experimental Era" of 2020 saw devastating 30.07% annualized losses due to unaudited smart contracts and fundamental vulnerabilities. The "First Security Revolution" of 2021 delivered an unprecedented 96% improvement through widespread adoption of professional auditing, bug bounty programs and formal verification. After a brief optimization plateau in 2022 and concerning backslide in 2023, the "Comprehensive Security Achievement" of 2024 established new standards with 74% loss reduction despite increased protocol complexity.

Attack patterns have fundamentally shifted, revealing both progress and evolving challenges. Yield aggregators, which dominated early DeFi hacks at 49% in 2020, have declined to just 14% by 2024 as protocols matured. Conversely, trading and automated market maker (AMM) platforms emerged as primary targets, growing from 0% to 18% of attacks as attackers focus on high-value, high-liquidity protocols. Most significantly, private key compromises have become the fastest-growing attack vector, jumping from 0% to 20% of incidents, highlighting that as technical security improves, attackers increasingly target operational security weaknesses.

Exploit Losses By Application Type Chart

The lending sector exemplifies this transformation most dramatically, achieving an extraordinary 98.4% improvement in security from 2020 baseline levels. DeFi lending protocols now maintain daily loss rates of just 0.00128%, making them 62.5 times more secure than during the experimental period. This improvement encompasses comprehensive protection against smart contract vulnerabilities, flash loan attacks, pricing manipulation, oracle failures and governance exploits.

Why this matters: The security achievements documented in this analysis fundamentally challenge prevailing narratives about DeFi risk and demonstrate that decentralized protocols can match or exceed traditional financial system security standards. The introduction of the Structural Risk Factor (SRF) framework provides a methodology for accurately assessing protocol risks in real-world asset (RWA) applications, enabling more informed capital allocation decisions. As institutional adoption accelerates and regulatory frameworks crystallize, these security improvements position DeFi as legitimate financial infrastructure rather than experimental technology, with profound implications for the future of stablecoins and global finance.

The data reveals that DeFi has successfully transitioned from high-risk experimental protocols to secure financial infrastructure, with comprehensive defense systems now addressing multiple attack vectors simultaneously rather than defending against individual threats in isolation. This transformation establishes the foundation for complex decentralized financial products and institutional-scale capital deployment, proving that community-driven security innovation can achieve results that rival centralized alternatives.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

CoinDesk 20 Performance Update: Bitcoin (BTC) Drops 3.6% as Index Trades Lower

9am CoinDesk 20 Update for 2025-12-11: leaders

Bitcoin Cash (BCH), down 2.8%, also traded lower.