DeFi applications are governed by smart contracts: published code that determines how a lending pool, exchange, or yield product operates. Exploiting one means finding a flaw in that code, much like finding a loophole in the terms of a financial contract.
This category of smart contract security failure has become measurably less severe: average losses per incident fell from roughly $156 million in the 2020–2022 period to approximately $14 million since 2023, suggesting core protocol security has improved as attackers shifted toward smaller, more peripheral targets.
The rising number of DeFi hacks is better interpreted as a measure of reach than depth. More contracts are deployed across DeFi than at any prior point, more integrations have accumulated technical debt from previous growth phases, and AI-assisted tools have lowered the cost of scanning code for smart contract vulnerabilities. The attack surface has widened as the damage when protocol exploits succeed has contracted.