$440M lost to smart contract bugs in 2025. The patterns are known.
Crypto lost over $3.4 billion to hacks in 2025 (Chainalysis). That headline number is dominated by infrastructure attacks: Bybit's $1.5 billion key compromise accounted for 44% of the total alone.
Strip out the private key leaks, social engineering, and supply chain attacks, and genuine smart contract exploits account for roughly $440-500 million (SlowMist, CertiK). Still hundreds of millions. Still mostly preventable.
The exploits
Cetus Protocol, $223M (Cyfrin analysis). The largest DEX on Sui. An integer overflow in a third-party math library's overflow-check function: checked_shlw compared against 0xFFFFFFFFFFFFFFFF << 192 instead of 0x1 << 192. The attacker minted enormous liquidity positions for 1 token unit each.
Balancer V2, $128M (Trail of Bits analysis). A rounding asymmetry in _upscaleArray compounded through 65+ chained micro-swaps in a single transaction. Six chains affected. The exploit contract contained console.log instructions.
GMX V1, $42M (Sherlock analysis). Reentrancy in executeDecreaseOrder() caused AUM desynchronization. The attacker re-entered during an ETH refund to open positions that bypassed ShortsTracker updates. The vulnerability came from a 2022 code change that was never re-audited.
Abracadabra, $13M. Logic flaw in cauldron liquidation incentives. The attacker manipulated self-liquidated positions to profit from improperly calculated incentives. This was the protocol's second major exploit in 18 months.
Cork Protocol, $12M (Dedaub analysis). A Uniswap V4 hook with missing authorization checks, combined with permissionless fake market creation and a rollover pricing flaw. The hook used a pre-patch V4 periphery version.
Why these keep happening
None of these are novel attack classes. Integer overflows, reentrancy, rounding errors, access control gaps. They've been in every security checklist since 2018. The patterns repeat: overflow leads to minting, reentrancy leads to desynchronization, rounding errors lead to drains. Different protocols, same root causes.
The pattern repeats because the gap isn't knowledge, it's coverage.
Cross-contract composition. Protocols don't exist in isolation. Cork's vulnerability required understanding the interaction between a custom hook, Uniswap V4's callback system, and a market creation flow. Each component was reasonable in isolation.
Third-party dependencies. Cetus's bug wasn't in their code. It was in integer-mate, a math library. The overflow check was wrong at the library level, invisible to anyone reviewing only the protocol's own contracts.
State changes over time. GMX's vulnerability was introduced in a 2022 code change and sat dormant for three years. The original audit was clean. The incremental change was never audited.
These patterns are hard to catch with static analysis alone. They require reasoning about economic impact, cross-contract state, and whether a theoretical attack path is actually profitable.
Questions about this research?
Get in touch