The smart-contract risk surface
Inventory the four main ways DeFi protocols lose user funds, and give a retail-grade risk checklist.
Lesson path
Crypto and DeFi
DeFi Primer
Pass the check before saving this lesson.
Pass the check to unlock nextOpen track mapChange starting pointToday's tiny win: make one idea click.
Inventory the four main ways DeFi protocols lose user funds, and give a retail-grade risk checklist.
Four ways DeFi loses your money
DeFi's biggest selling point — code instead of humans — is also its biggest risk. The code is final. If it does the wrong thing, no customer service is going to refund you. Roughly $3 billion+ has been lost to DeFi exploits between 2022 and 2024 (the figure moves as new incidents and recoveries happen, so the precise number is a target for verification). That money was not 'stolen' in the traditional sense — most of it was extracted by exploiting code that did exactly what it was programmed to do.
Risk surface one: implementation bugs. The contract itself has a logic flaw. The classic shape is a reentrancy bug, where a function can be called repeatedly before the first call finishes — letting an attacker drain the pool with rapid repeat calls. Audits catch most of these, but not all. New protocols have more of them than mature ones, by a wide margin.
Risk surface two: oracle manipulation. A lending protocol needs to know the price of every collateral. It gets that from an 'oracle' — typically Chainlink. If the protocol uses a thin or flash-loan-manipulable price source instead, an attacker can briefly distort that price, borrow more than they should, and walk away. Many of the biggest exploits in 2022-2024 started with a bad price feed.
Risk surface three: governance capture. Most DeFi protocols are 'governed' by a token. Hold enough tokens, you can vote to change the rules. An attacker buys or borrows enough votes to push through a malicious upgrade — like 'send the treasury to this address'. Mature protocols defend with time-locks (a 48-hour delay between vote and execution) so the community can react. Young protocols often don't.
Risk surface four: bridge exploits. Bridges hold huge amounts of liquidity on both sides — that liquidity is the target. The 2022 Ronin bridge ($600M+), Wormhole ($320M+), and Nomad ($190M+) hacks were all bridge-specific. The technical issue varies, but the pattern is consistent: bridges concentrate capital in a single attack surface, and attackers have all the time in the world to study the code.
Retail risk checklist before depositing into any DeFi protocol: (1) Has it been audited by at least one reputable firm? (2) Has it been live for 12+ months without a major incident? (3) Is the total value locked in the protocol north of $100M? (4) Is the governance token widely distributed, with time-locked upgrades? Not foolproof — but skip protocols that flunk multiple items.
Recap: DeFi loses funds through four main surfaces — code bugs, oracle manipulation, governance attacks, and bridge exploits. Bridges are the worst single category. Use a 4-point retail checklist before depositing into anything.
Knowledge check
Answer before moving on.
1. Which DeFi attack surface has historically lost the most user funds?
2. A new DeFi protocol launches with one audit, $5M TVL, two months of history, and a small team holding 60% of governance tokens. What's the right read?
Pass the check before saving.
Use the knowledge check first. After you pass it, this card turns into the save-and-continue handoff.