How DeFi exploits actually happen

Most large DeFi losses are not sophisticated cryptography breaks. They come from a small set of repeating mistakes, and legacy contracts left deployed after an upgrade are among the most common.

The recurring categories

Oracle manipulation: a protocol prices an asset using a source that can be moved cheaply, and the attacker moves it before borrowing against inflated collateral.

Legacy contracts: a protocol upgrades to a new implementation but the old contract stays deployed and still holds approvals from users who never revoked them.

Access control: a privileged function is left callable by anyone, usually through an initialisation step that was never locked after deployment.

CategoryRoot causeTypical defence
Oracle manipulationPrice feed with thin liquidityTime-weighted prices, multiple sources
Legacy contractsOld deployment left liveRevoke approvals, disable old contracts
Access controlUnlocked initialiserAudit of privileged functions
ReentrancyState updated after external callChecks-effects-interactions pattern

Why approvals are the user's exposure

Interacting with a protocol usually means granting it permission to move your tokens, often an unlimited allowance. That permission persists after you stop using the protocol.

If the contract holding that approval is later compromised, funds can be taken from wallets that have not interacted with it for months. Revoking unused approvals is the single most effective user-side habit.

FAQ

Does an audit prevent exploits?

It reduces the chance but does not eliminate it. Several audited protocols have been drained, frequently through contracts outside the audited scope.

What is a bug bounty worth?

Bounties give researchers a legitimate alternative to exploiting a flaw. Their size matters: a bounty far below the exploitable amount changes nobody's incentives.