In 2025, DeFi protocols lost $680.3 million to hacks and exploits, according to the bug bounty platform Immunefi. In 2022 the figure was $2.62 billion. So DeFi is getting safer. It still isn't safe, and how risky it is for you depends on what you're doing with it and how much of your money is in it.

DeFi didn't exist when I bought my first Bitcoin in May 2011. The oldest big lending protocols today have less than ten years behind them, which isn't much of a track record for a system holding roughly $95 billion.

The numbers, with the biggest hack taken out

Headlines about crypto hacks mix two different things. Chainalysis counted more than $3.4 billion stolen across crypto in 2025, but about 44% of that was a single hack: $1.5 billion taken from Bybit in February. Bybit is a centralized exchange. Nothing about that one was decentralized finance.

Counting DeFi alone, Immunefi has losses down 74% from the 2022 peak, and the typical exploit is shrinking too, with the median loss falling from $6 million in 2022 to $1.5 million in 2025. Chainalysis noted that DeFi losses stayed low even as the money locked in DeFi climbed back. 2026 has been rougher. The security firm CertiK counted $1.3 billion lost across 344 incidents in the first half alone, and two DeFi attacks in April, on Drift and Kelp DAO, each took close to $300 million.

How DeFi gets hacked

The big losses tend to fall into a handful of patterns.

  • A bug in the code. In May 2025 an attacker took $223 million from Cetus, an exchange on the Sui blockchain, through a math check in a shared code library that tested against the wrong limit. Cetus had been audited. $162 million of it was frozen.
  • Price manipulation. In October 2022 a trader pumped the price of the MNGO token on Mango Markets, then borrowed $114 million against the inflated value. The code did exactly what it was written to do. The price it trusted was the weak point.
  • Flash loans. Euler lost $197 million in March 2023 to an attacker using borrowed money and a flaw in one function. Most of it came back within three weeks, which almost never happens. Our flash loan explainer covers how that borrowing works.
  • Bridges. Moving tokens between blockchains means trusting whoever checks the transfer. Ronin lost $625 million in 2022 after attackers phished five of its nine validator keys. Wormhole lost $326 million the same year because the bridge didn't actually check signatures. In April 2026 a forged message through a bridge with a single verifier took about $292 million from Kelp DAO.
  • The people with the keys. On April 1, 2026, Drift on Solana lost $285 million after the people who sign its admin transactions were tricked into signing ones prepared in advance.
  • The website. Curve's contracts were fine in May 2025 when attackers hijacked its web address. A similar hijack in 2022 cost Curve users $570,000. Your wallet will sign whatever the fake site puts in front of it.

Then there's plain theft. Hypervault vanished in September 2025 with $3.6 million of depositors' money, deleted its X account and pushed about 752 ETH through the Tornado Cash mixer. Our rug pull checks cover the warning signs.

Is DeFi lending safe?

Lending adds a risk that has nothing to do with hackers: liquidation. On Aave, the biggest lending protocol, every loan has a health factor. Drop below 1 and liquidators can repay up to half your debt and take your collateral plus a bonus. At 0.95 or below they can take all of it. A fast price drop can do that overnight while you sleep.

The price feeds can fail too. On March 10, 2026, an Aave pricing glitch liquidated about $26 million of wstETH positions across 34 accounts that shouldn't have been touched. In February 2026 a setup error on Moonwell priced cbETH at about $1.12 instead of about $2,200, and the protocol was left with $1.78 million of bad debt.

Lenders also carry everyone else's mistakes. After the Kelp DAO hack, the attacker deposited the stolen tokens on Aave and borrowed about $190 million against them. Estimates put Aave's bad debt from that one move at $123 million to $230 million.

If you borrow, keep your health factor well above 1, and know the price that would liquidate you before the market finds it.

Is DeFi staking safe?

Staking ETH directly is one of the lower-risk things you can do in crypto. The main penalty, slashing, is rare. Fewer than 500 of more than 1.2 million Ethereum validators have been slashed since 2020, and when 39 were hit at once in September 2025, one lost about 0.3 ETH.

Liquid staking, where you get a token like stETH back for your ETH, adds two risks. The smart contract can fail, and the token can trade below the ETH it stands for. In June 2022, before withdrawals were possible, stETH fell to a record 8% discount as panicked holders sold. Getting out can take time as well. Lido withdrawals normally take one to five days, but in September 2025 Ethereum's exit queue held 2.5 million ETH and stretched past 46 days. Lido's own risk page warns that slashing can cost "up to 100%" of a stake in the worst case.

What an audit is worth

An audit is a paid review of the code at one point in time. It helps. In Halborn's study of the 100 biggest DeFi hacks, only 20% of the hacked protocols had been audited, and those accounted for 10.8% of the money lost. Cetus, Wormhole and Euler were all audited before they were drained, though. An audit badge on a project's website tells you someone looked at the code once. It says nothing about the people holding the admin keys.

How to cut your own risk

  • Only put in what you can afford to lose. Every protocol above had users who trusted it.
  • Check your approvals. Using a DeFi app gives its contract permission to move your tokens, and that permission still works if the contract is hacked later. Set a spending limit instead of "unlimited" and clear old approvals with a tool like revoke.cash.
  • Keep savings on a hardware wallet. It won't save you from a bad contract, but it stops malware from signing for you. Our hot vs cold wallet guide explains the split.
  • Bookmark the real site. Hijacked and fake sites mostly catch people who arrive through a link or an ad.
  • Consider cover for big positions. Nexus Mutual sells cover for smart contract exploits, oracle failures and some governance attacks. It calls itself "discretionary cover, not insurance", it excludes phishing and stolen keys, and it only covers protocols it lists. Drift's users got nothing because Drift wasn't listed and the attack was social engineering.
  • Lean toward the old and the large. A protocol that has held billions for years has already survived attacks a new one hasn't faced. Euler and Drift show it's no guarantee, but it filters out most rug pulls.

Questions people ask

Is DeFi safer than a crypto exchange?

They fail in different ways. An exchange holds your coins, so you're exposed if it's hacked or collapses, as Bybit's $1.5 billion loss in 2025 showed. In DeFi you hold your own keys, but a bug, a bad price feed or one careless signature can still cost you, and there's nobody to call.

Can I get my money back after a DeFi hack?

Sometimes. Euler's attacker returned most of the $197 million, and $162 million of the Cetus loss was frozen. Usually stolen funds are gone. Cover from a provider like Nexus Mutual is the only payout you can plan for, and only if you bought it before the hack.

Is DeFi staking safer than DeFi lending?

Plain ETH staking carries less risk than borrowing against collateral, because nothing gets liquidated. Liquid staking tokens add contract risk and can trade below their value for a while, as stETH did in 2022.