The OWASP Smart Contract Top 10 2026 dropped yesterday, built on data from 122 incidents totaling $905.4 million in losses during 2025.
Is this progress or just business as usual?
Let me break down the numbers, because the answer is more complicated than either the optimists or pessimists want to admit.
The Context: Historical Comparison
2021: $1.3B in DeFi hacks (mostly protocol exploits)
2022: $3.1B stolen (bridge hacks dominated—Ronin $625M, Wormhole $325M, Harmony $100M)
2023: $1.7B (fewer bridge hacks, more sophisticated protocol attacks)
2024: $1.2B (increased security maturity, but also market downturn reducing TVL targets)
2025: $905M (OWASP data)
So yes, $905M is lower than recent years. But before we celebrate:
Normalizing For TVL
You can’t evaluate security in absolute dollars—you need to compare to total value locked.
DeFi TVL by year:
- 2021: $180B peak → loss rate 0.72%
- 2022: $100B average → loss rate 3.1% (ouch)
- 2023: $70B average → loss rate 2.4%
- 2024: $120B average → loss rate 1.0%
- 2025: $150B average → loss rate 0.60%
So yes, as a percentage of TVL, 2025 was the safest year for DeFi ever.
But here’s the uncomfortable question: Is 0.60% acceptable?
Comparing To Traditional Finance
TradFi fraud rates for comparison:
- Credit card fraud: ~0.05% of transaction volume
- ACH fraud: ~0.03%
- Wire fraud: ~0.01%
DeFi’s 0.60% loss rate is 12-60x higher than traditional finance.
Now, skeptics will say “that’s unfair—TradFi has chargebacks, insurance, and law enforcement.”
Exactly. That’s the whole point.
Breaking Down The Attack Vectors
The $905M wasn’t evenly distributed. OWASP’s data shows clear patterns:
Top vulnerability categories by losses:
- Business Logic Flaws - $287M (31.7%)
- Access Control Issues - $198M (21.9%)
- Proxy & Upgradeability (SC10) - $142M (15.7%)
- Reentrancy - $35.7M (3.9%) - Down from #2 to #8
What Improved vs What Got Worse
Improvements:
- Reentrancy protection now standard
- Audit coverage increased (71% vs 43% in 2021)
- Bug bounties paid out $65M in 2025
- Tooling matured (Slither, Mythril, Certora)
Concerns:
- Attack sophistication increased (multi-step exploits)
- Economic attacks outpacing technical audits
- Governance became attack vector
- Composability creates emergent risks
The Institutional Question
What would make DeFi acceptable for institutions?
Option 1: Insurance (currently too expensive at 5-15% APY)
Option 2: Custodial on-ramps (Coinbase/Gemini manage risk)
Option 3: Higher security standards (mandatory audits, insurance, monitoring)
My Proposal: DeFi Security Ratings
We need S&P-style ratings:
AAA-rated: Multiple audits, formal verification, 7-day timelocks, insurance covering 50%+ TVL
B-rated: Single audit, 24h timelock, team multi-sig, no insurance
Market forces drive security improvement.
The Bottom Line
Is DeFi improving? Yes.
Is it improving fast enough? No.
Is $905M sustainable? Absolutely not.
We’re trending right, but need 10x improvement rate for institutional capital.