Back to Blog
SecurityUpdated September 16, 2026·4 min read

DeFi security: how protocols get exploited, how to assess one before depositing, and how to limit what an exploit can take from you

DeFi losses come from a short list of causes — logic bugs, oracle manipulation, admin-key compromise, bridge failures and front-end hijacks — and each leaves signs you can check before depositing. A ten-point assessment, the meaning and limits of audits, approval hygiene, and how to keep the money that is not in DeFi out of reach of what happens in DeFi.

Where the money goes

Year after year, DeFi exploit losses cluster in the same categories:

CauseWhat happensRecent scale
Smart-contract logic bugsRe-entrancy, rounding, access-control mistakes, unchecked inputsHundreds of millions per year across many protocols
Oracle manipulationAttacker moves the price a protocol reads (thin pool, flash loan) and borrows or liquidates against the false priceLarge, episodic
Admin key compromiseThe upgrade or pause key is stolen or misused; the attacker changes the contractIncludes some of the largest single incidents
Bridge failuresVerifier bugs or key theft on cross-chain bridgesThe largest category historically; see the bridges guide
Front-end and interface hijacksThe website is compromised; users sign malicious transactions that look routineThe 2025 Bybit theft (~$1.5B) was an interface compromise against a multisig
User-side approvals and phishingDrainers, fake claims, malicious permitsThe largest source of individual losses

Two conclusions. First, a protocol's risk is not only its code; it is its oracle, its admin keys, its bridge dependencies and its website. Second, the last row is under your control and is where most people actually lose money.

Ten checks before depositing

  1. Age and survivorship. Has the protocol held significant value through at least one full market cycle without incident? Time under attack is the best audit.
  2. Audits — plural, recent, public. Read the reports, not the badge. Look for unresolved high-severity findings and whether the audited commit matches the deployed code.
  3. Admin keys. Who can upgrade or pause? A single EOA is a red flag; a multisig with a timelock (24–72 hours) is the standard; immutable contracts are the gold standard for simple protocols.
  4. Oracle design. Where do prices come from? Time-weighted, multi-source oracles (Chainlink, TWAPs over deep pools) resist manipulation; a spot price from one pool does not.
  5. Bridge dependencies. Is the asset you deposit native on this chain, or a bridged derivative? Bridged assets add the bridge's risk to the protocol's.
  6. Bug bounty. A live, funded bounty on a known platform signals that the team expects to be attacked and pays to hear about it first.
  7. Open source and verified. Contract source verified on the explorer; matches the repository.
  8. Concentration. A handful of addresses holding most of the TVL or governance tokens can drain or vote away the protocol.
  9. Economic design. Where does the yield come from? If it exceeds visible borrowing demand and fees, the excess is incentives or a Ponzi. The stablecoins in DeFi guide explains the sources.
  10. Incident history and response. Has it been exploited? How did the team respond — transparent post-mortem and compensation, or silence?

No protocol passes all ten perfectly. The point is to know which risks you are taking.

What an audit does and does not mean

An audit is a time-boxed review of a specific version by a specific firm. It reduces the chance of common bugs; it does not prove absence of bugs, does not cover the oracle or the admin keys unless scoped, and does not apply to code deployed after it. Protocols with multiple audits from reputable firms and a history of surviving have a much better record than either alone. "Audited" in a token's marketing, with no report linked, means nothing.

Limiting what an exploit can take from you

The decisive habits are on your side, not the protocol's:

  • Only what you deposit is at risk — unless you gave an approval. An unlimited approval lets a compromised contract take the whole balance of that token, not just what you deposited. Approve exact amounts where possible; revoke approvals you no longer need (tools such as revoke.cash).
  • A DeFi wallet separate from savings. Anything in the DeFi wallet is exposed to every contract it has approved. Savings live in a hardware wallet that has never signed a DeFi transaction.
  • Front-end caution. Bookmark protocol sites; verify the domain; on a large transaction, read the calldata or simulate it with a wallet that shows what will change. The interface is the weakest link.
  • Native assets on-chain, not bridged. Reduces the dependency count.
  • Size to the risk. A new protocol with one audit gets a small position; an old one with a timelock and a bounty can hold more.

Getting in and out without an exchange

DeFi is used from your own wallet on a specific chain. Moving between chains and assets is where an account-free swap fits: ETH → USDT (ERC-20) to fund an Ethereum position, USDC (ERC-20) → USDT (TRC-20) to take profits to the cheapest rail, USDC (ERC-20) → BTC to leave stablecoins entirely. The swap itself has none of the DeFi risks above — no contract to approve, no oracle, no bridge; two ordinary transfers and a status page.

Frequently asked questions

Is DeFi insurance worth it? Cover protocols pay on specific, defined exploits and have limited capacity. Useful for large positions in specific protocols; read the policy's exclusions.

Are the biggest protocols safe? Safer, not safe. Age, multiple audits and timelocks reduce risk; the largest ones have also been targets of the most sophisticated attacks.

Can I lose more than I deposit? Directly, no. Through an unlimited approval, yes — the rest of that token's balance in the wallet.

How often should I review approvals? Quarterly, and immediately after using any new site.

What is the safest way to earn yield on stablecoins? The largest, oldest lending market for a fully reserved stablecoin, on a chain where gas does not eat the return, with exact-amount approvals — and an amount you could lose.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →