~/defi/hacks $ cat kak-lomayut-defi-vektory.md
How DeFi Is Being Compromised: Five Areas Account for Billions in Losses
DeFi loses billions a year, but the variety of attacks is misleading: the vast majority of incidents involve just five recurring attack vectors.
Five attack vectors
- 1. Oracle manipulation. The protocol reads the price from a thin pool-the attacker manipulates it using flash loan volume and borrows or withdraws based on the manipulated valuation. A timeless classic of the genre.
- 2. Recursion and logical bugs. Errors in the code: re-entering a function before the balance is updated, rounding errors, forgotten permission checks. These can be fixed through audits-and yet they still happen.
- 3. Private keys and multisigs. The costliest vulnerability in recent years isn’t the code, but people: phishing of signers, compromised deployers, and fake signing interfaces. The Bybit hack (2025, ~$1.5 billion, Lazarus) is the pinnacle of this category.
- 4. Bridges. Custodial services for third-party assets with intermediary validators-the decade’s main victims: Ronin, Wormhole, Nomad. See the “Bridges” section for more details.
- 5. Governance attacks. Buying up or borrowing votes → malicious proposal → treasury. It’s cheap when the token is cheaper than the treasury.
What does this mean for users?
Diversifying across protocols isn’t paranoia-it’s a response to the sector’s baseline risk. Code age and bug bounties work. And the most underestimated risk isn’t smart contracts, but team operations: keys, signers, phishing. We keep a chronicle of incidents in the “Hacks” section.