Roughly

Attacks became more frequent and less profitable at the same time. That is a change in where the money leaves, not in whether protocols get attacked.

Losses Fell. Attacks Did Not.

For most of the past five years the industry's working model of crypto risk began and ended with a contract bug. The apparatus built around that model changed the economics of attacking the code well enough that breaking a contract is no longer the only route to a major loss . Verification got formal, audits got repeated, bounty programs became standing rather than occasional.

None of it reduced the capital sitting inside those protocols. Immunefi, which operates bug-bounty infrastructure for the sector and has an interest in the answer, puts DeFi exploit losses 74% below their 2022 peak of $2.62 billion, at $680.3 million across full-year 2025, with the median loss per exploit falling 75% over the same stretch. TRM Labs, measuring the same period on a different axis, found that infrastructure and operational compromises made up roughly 15% of incidents but about 76% of the value stolen.

"Code is no longer necessarily the weakest link in Web3," says Jimmy Su, Chief Security Officer at

A distribution where a sixth of the incidents carry three quarters of the damage is not one a code review reaches. What separates a routine theft from a protocol-ending one now sits in operational control rather than in audited logic, and the arithmetic shows it. TRM put the median hack at roughly $219,000 against a mean of $4.7 million.

What an Audit Cannot See

An audit is a snapshot. It measures the code as it stood on a particular date and says nothing about who holds the keys to it afterward, which is why "we were audited" has never been the same statement as "we are safe."

The loss record supports the distinction, though the firm making the case sells the alternative. Immunefi's analysis of

"A protocol can pass a flawless code audit and still lose millions because of a compromised admin key,"

The economics on the defensive side are lopsided in a way that rarely gets stated plainly. Around 20% of confirmed vulnerability reports are rated critical and Immunefi paid researchers $13.45 million for 837 valid bugs in the first half of 2026 alone.

Set a median bounty of $20,000 against an average hack of roughly $25 million—and the incentive to disclose rather than exploit starts to look thin. The harder limit remains even where the incentive works. One protocol was audited eleven times and still lost $128 million.

Five Firms, Four Totals, One Definitional Argument

Five security firms measured the same six months and published four different answers. Immunefi and TRM Labs both landed at roughly $972 million across 207 incidents. SlowMist

CertiK reported $1.315 billion across 344 incidents on a scope that explicitly counts phishing and wallet compromise alongside exploits. Read that way, wallet compromise becomes the costliest category at more than $444 million, with a $13 million average per event. Code bugs are the most frequent category at 204 incidents and among the cheapest at $151.6 million.

None of the five is counting badly. They are counting different things, and none publishes a reconciliation against the others. The spread is an unresolved argument about whether a stolen seed phrase is a hack, and the answer decides what the industry believes it is defending. Budgets follow the definition, which is why the narrow one is expensive: it undercounts precisely the category that is growing.

What the Half Actually Measured

A falling loss total alongside a record incident count reads less like a safer market than a relocated one. Hardening the contracts worked, and the effect was to move attacker attention onto credentials, operations and the infrastructure sitting around the code.

That residual risk now sits where most security budgets were never built to look. This suggests resilience through the rest of 2026 may increasingly depend on how well protocols defend the access layer rather than the contract itself.

This story was distributed as a release by Jon Stojan under HackerNoon’s Business Blogging Program.