DeFi Hacks: Safer at the Core, Riskier at the Edges

By Bitcoin Suisse

In spring 2026, a single month produced a record 28 DeFi exploits along with the largest single crypto hack of the year.

A DeFi exploit is the abuse of a vulnerability in a decentralized finance protocol, that is, in the smart contracts that automatically execute financial services such as lending, trading, or staking on a blockchain. These protocols sometimes manage assets in the hundreds of millions.

Safer at the Core

At face value, the conclusion seems clear: DeFi is becoming less safe. However, a closer look at the numbers reveals two categories of attack whose trends are moving in opposite directions. One includes the year's largest single exploit. The other has become materially less damaging over time.

Although more dangerous around the edges, DeFi has actually become safer at the core. For financial service providers, the two categories carry separate due diligence requirements, and recent events demonstrated exactly why.

Attacks Are Losing Their Punch

DeFi applications are governed by smart contracts: published code that determines how a lending pool, exchange, or yield product operates. Exploiting one means finding a flaw in that code, much like finding a loophole in the terms of a financial contract.

This category of attack has become measurably less severe: average losses per incident fell from roughly 156 million dollars in the 2020–2022 period to approximately 14 million dollars since 2023, suggesting core protocol security has improved as attackers shifted toward smaller, more peripheral targets.

The rising number of hacks is better interpreted as a measure of reach than depth. More contracts are deployed across DeFi than at any prior point, more integrations have accumulated technical debt from previous growth phases, and AI-assisted tools have lowered the cost of scanning code for weaknesses. The attack surface has widened as the damage when protocol exploits succeed has contracted.

More Dangerous at the Edges

At the other end of the spectrum lies the successful attack on Kelp DAO: as an «outlier to the upside», it shows the flip side. The 292 million dollar loss, one of the largest single crypto exploits of 2026 so far, was not a protocol attack. It was a breach of the infrastructure that moves assets between blockchains: the verification layer that confirms cross-chain transactions, analogous to the messaging infrastructure connecting financial institutions.

That infrastructure relied on a single verification node to approve these transactions. Attackers attributed to North Korea's Lazarus Group compromised that node through social engineering, then used it to forge a valid-looking instruction that released 292 million dollars in rsETH, a token representing staked Ether, without any real backing. No audit of Kelp's smart contracts would have identified the vulnerability, because it did not exist in the contract code.

The Trigger for a Billion-Dollar Exodus

What followed illustrates why infrastructure failures carry a more systemic risk profile than protocol exploits. The attacker deposited the forged tokens into Aave, DeFi's largest lending platform, as collateral, then borrowed approximately 190 million dollars in real assets against them. When the forgery became apparent, Aave and two other major lending platforms froze their markets to prevent bad debt from accumulating.

Roughly 13 billion dollars in assets exited DeFi platforms over the following 48 hours, as an infrastructure failure at one protocol became a market-wide liquidity event within a day. The defining characteristic of composability risk is the capacity for a failure in one part of the system to propagate through the financial connections around it.

Two Risk Questions, Not One

The core/edge distinction has direct practical implications for financial service providers with DeFi exposure or clients holding DeFi assets.

A protocol audit, the standard due diligence tool for assessing DeFi security, would not have caught the Kelp vulnerability. Exposure to a well-audited DeFi protocol and exposure to an asset whose backing depends on cross-chain infrastructure are separate risk questions with separate failure modes. Recent events make the case for treating bridge risk, governance risk, and composability risk as independent dimensions of a DeFi position; not as subcategories of smart-contract risk, but as distinct layers that standard audit processes do not fully reach.

Catching Up at the Infrastructure Layer

Still, the same AI tooling that has lowered the cost of finding protocol weaknesses is available to defenders, giving security teams faster paths to identify and patch vulnerabilities than at any earlier point in DeFi's history.

The research team at Bitcoin Suisse expects the improvement trend at the protocol level to continue. The catch-up work that remains is concentrated at the infrastructure layer, at the edges rather than the core. For financial service providers, the useful question has shifted: not whether DeFi is safe, but which layer would be affected, and what a failure at that layer actually sets in motion.

Source: Bitcoin Suisse, Data: DefiLlama. Data as of April 30, 2026.