How DeFi exploits actually happen
Most large DeFi losses are not sophisticated cryptography breaks. They come from a small set of repeating mistakes, and legacy contracts left deployed after an upgrade are among the most common.
The recurring categories
Oracle manipulation: a protocol prices an asset using a source that can be moved cheaply, and the attacker moves it before borrowing against inflated collateral.
Legacy contracts: a protocol upgrades to a new implementation but the old contract stays deployed and still holds approvals from users who never revoked them.
Access control: a privileged function is left callable by anyone, usually through an initialisation step that was never locked after deployment.
| Category | Root cause | Typical defence |
|---|---|---|
| Oracle manipulation | Price feed with thin liquidity | Time-weighted prices, multiple sources |
| Legacy contracts | Old deployment left live | Revoke approvals, disable old contracts |
| Access control | Unlocked initialiser | Audit of privileged functions |
| Reentrancy | State updated after external call | Checks-effects-interactions pattern |
Why approvals are the user's exposure
Interacting with a protocol usually means granting it permission to move your tokens, often an unlimited allowance. That permission persists after you stop using the protocol.
If the contract holding that approval is later compromised, funds can be taken from wallets that have not interacted with it for months. Revoking unused approvals is the single most effective user-side habit.
FAQ
Does an audit prevent exploits?
It reduces the chance but does not eliminate it. Several audited protocols have been drained, frequently through contracts outside the audited scope.
What is a bug bounty worth?
Bounties give researchers a legitimate alternative to exploiting a flaw. Their size matters: a bounty far below the exploitable amount changes nobody's incentives.