$905M Lost in 2025 Smart Contract Hacks: Is This Progress or Just A Smaller Disaster?

The OWASP Smart Contract Top 10 2026 dropped yesterday, built on data from 122 incidents totaling $905.4 million in losses during 2025.

Is this progress or just business as usual?

Let me break down the numbers, because the answer is more complicated than either the optimists or pessimists want to admit.

The Context: Historical Comparison

2021: $1.3B in DeFi hacks (mostly protocol exploits)
2022: $3.1B stolen (bridge hacks dominated—Ronin $625M, Wormhole $325M, Harmony $100M)
2023: $1.7B (fewer bridge hacks, more sophisticated protocol attacks)
2024: $1.2B (increased security maturity, but also market downturn reducing TVL targets)
2025: $905M (OWASP data)

So yes, $905M is lower than recent years. But before we celebrate:

Normalizing For TVL

You can’t evaluate security in absolute dollars—you need to compare to total value locked.

DeFi TVL by year:

  • 2021: $180B peak → loss rate 0.72%
  • 2022: $100B average → loss rate 3.1% (ouch)
  • 2023: $70B average → loss rate 2.4%
  • 2024: $120B average → loss rate 1.0%
  • 2025: $150B average → loss rate 0.60%

So yes, as a percentage of TVL, 2025 was the safest year for DeFi ever.

But here’s the uncomfortable question: Is 0.60% acceptable?

Comparing To Traditional Finance

TradFi fraud rates for comparison:

  • Credit card fraud: ~0.05% of transaction volume
  • ACH fraud: ~0.03%
  • Wire fraud: ~0.01%

DeFi’s 0.60% loss rate is 12-60x higher than traditional finance.

Now, skeptics will say “that’s unfair—TradFi has chargebacks, insurance, and law enforcement.”

Exactly. That’s the whole point.

Breaking Down The Attack Vectors

The $905M wasn’t evenly distributed. OWASP’s data shows clear patterns:

Top vulnerability categories by losses:

  1. Business Logic Flaws - $287M (31.7%)
  2. Access Control Issues - $198M (21.9%)
  3. Proxy & Upgradeability (SC10) - $142M (15.7%)
  4. Reentrancy - $35.7M (3.9%) - Down from #2 to #8

What Improved vs What Got Worse

:white_check_mark: Improvements:

  • Reentrancy protection now standard
  • Audit coverage increased (71% vs 43% in 2021)
  • Bug bounties paid out $65M in 2025
  • Tooling matured (Slither, Mythril, Certora)

:cross_mark: Concerns:

  • Attack sophistication increased (multi-step exploits)
  • Economic attacks outpacing technical audits
  • Governance became attack vector
  • Composability creates emergent risks

The Institutional Question

What would make DeFi acceptable for institutions?

Option 1: Insurance (currently too expensive at 5-15% APY)
Option 2: Custodial on-ramps (Coinbase/Gemini manage risk)
Option 3: Higher security standards (mandatory audits, insurance, monitoring)

My Proposal: DeFi Security Ratings

We need S&P-style ratings:

AAA-rated: Multiple audits, formal verification, 7-day timelocks, insurance covering 50%+ TVL
B-rated: Single audit, 24h timelock, team multi-sig, no insurance

Market forces drive security improvement.

The Bottom Line

Is DeFi improving? Yes.
Is it improving fast enough? No.
Is $905M sustainable? Absolutely not.

We’re trending right, but need 10x improvement rate for institutional capital.

Will, excellent analysis but I want to challenge one assumption: that lower losses = better security.

What if 2025’s $905M represents attackers becoming more selective, not protocols becoming more secure?

The Efficient Market Hypothesis For Hacks

2022: Low-hanging fruit everywhere. Hack everything you find.

2025: Easy targets gone. Remaining vulnerabilities require deep understanding, multi-step chains, significant capital, and operational security to cash out.

Attackers now focus on highest-TVL targets and newest protocols only.

The reduction might just mean attackers are optimizing ROI.

The Survivor Bias Problem

Protocols that survived to 2025 didn’t get hacked in 2021-2024.

Was that better security or luck?

Uniswap V2: $10B+ TVL, no hacks
Countless clones: Exploited

Was it security or just more eyeballs and higher reputation cost?

Where I Agree

1. TradFi comparison is damning (0.60% vs 0.05%)
2. Composability is double-edged
3. Insurance is missing

But insurance has adverse selection problems. Protocols most likely to buy it are most likely to get hacked.

Real-Time Monitoring Proposal

Instead of ratings based on past audits, continuous monitoring:

  • AI detects anomalies
  • Economic attack detection
  • Governance warnings
  • Formal property validation

Tech exists (Forta, Chaos Labs, OpenZeppelin Defender). Problem is adoption.

You’re both focused on “make current DeFi more secure” instead of “build simpler protocols.”

Complexity Is The Vulnerability

31.7% losses were business logic flaws.

You can’t have business logic flaws in protocols that do one thing.

Uniswap V2: 500 lines, immutable since 2020, billions in TVL, zero hacks.

Euler Finance: Complex multi-collateral lending, $197M hack.

Each feature adds 10x attack surface.

Flash Loans Were A Mistake

They enable $300M+ in attacks for minimal legitimate benefit.

Ban them.

The Real Data

OWASP says $905M. But that excludes:

  • Bridge hacks: $400M+
  • Social engineering: $200M+
  • MEV extraction: $500M+
  • Rug pulls: $1B+

Total ecosystem losses: ~$3B.

What Would Actually Help

  1. Formal verification as mandatory
  2. Immutability as default
  3. Ban flash loans
  4. Limit composability (whitelisted integrations only)
  5. Reduce parameters (3-5 max, not 20-50)

$905M isn’t progress. It’s a sign we built something too complex to secure.

Privacy protocols have BETTER security than transparent DeFi.

The Data

2025 privacy protocol losses:

  • Tornado Cash: $0
  • Aztec: $0
  • Railgun: $0
  • Penumbra: $0

Transparent DeFi: $905M

Why?

Privacy forces simplicity:

  • No oracle manipulation (can’t see prices)
  • No front-running (can’t see txns)
  • No MEV extraction (encrypted mempool)
  • No governance attacks (encrypted voting)

Privacy is a security feature.

ZK Proofs Change Everything

Current: Trust contracts are secure
Future: Cryptographic proof of validity

Every swap comes with ZK proof it followed rules.

Can’t hack what’s mathematically proven.

The Caveat

ZK circuit bugs are catastrophic. But privacy eliminates entire OWASP categories.

By 2028: Fewer oracle/front-running attacks, but possible new “ZK Circuit Vulnerabilities” category.

From L2 perspective: Rollups had better security in 2025.

L2 bridges: 0 major hacks

Why?

  1. Simpler (lock/unlock only)
  2. Better audited (multiple firms + formal verification)
  3. Better governed (security councils standard)
  4. More monitoring (fraud proofs, watchtowers)

L2s could provide security as infrastructure:

  • Monitoring all apps
  • Circuit breakers
  • Formal verification
  • Insurance pools

Apps deploy and inherit security.

This is the path to institutional capital.