Skip to content

DeFi exploit

Smart-contract failures with human victims

Users lose funds when protocols are drained, or when they interact with forked malicious contracts.

DeFi exploit contexts

Includes governance hacks, reentrancy bugs, oracle manipulation, and malicious forks posing as official apps.

Victims may be liquidity providers or traders on compromised interfaces.

Incident types

  1. 01

    Protocol drain

    Attacker exploits contract logic at scale.

  2. 02

    Frontend hijack

    DNS or CDN compromise redirects to malicious router.

  3. 03

    Bridge exploit

    Locked assets minted unredeemed on destination chain.

User-side signs

  • Unannounced UI changes requesting new approvals
  • APY spikes unexplained on social media
  • Forked repo URLs not matching official GitHub

Attacker flows

Exploit proceeds move through mixers and OTC quickly.

  • — Flash-loan funded attacks repaid same block
  • — Cross-chain dispersal
  • — Stablecoin off-ramps

Evidence

  • Exploit transaction hashes
  • Block timestamps
  • Official post-mortem if published
  • Your LP position TXIDs

Investigation

01

Exploit tracing

Follow attacker wallets post-incident.

02

Victim correlation

Map user losses to pool events.

Now

  • 01Monitor official protocol channels
  • 02Preserve wallet interaction history
  • 03Do not trust random recovery bots in Discord

Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.

Frequently asked questions

Will protocols always refund?

Depends on treasury, governance, and insurance—not guaranteed.

Assess DeFi exploit exposure

Protocol name, TXIDs, and loss amounts.