Value Locked in DeFi Surges. So Do the Exploits

The growth of DeFi is a net positive, but it does draw the interest of hackers and exploiters.

AccessTimeIconNov 5, 2021 at 6:44 p.m. UTC
Updated May 11, 2023 at 4:54 p.m. UTC
AccessTimeIconNov 5, 2021 at 6:44 p.m. UTCUpdated May 11, 2023 at 4:54 p.m. UTC
AccessTimeIconNov 5, 2021 at 6:44 p.m. UTCUpdated May 11, 2023 at 4:54 p.m. UTC

The phrase “Code is Law” is often tossed around in the decentralized finance (DeFi) industry, posing that DeFi is able to self-regulate because code is intended to be used exactly how it was written. As CoinDesk reporter Andrew Thurman said, “Where one man might see an exploit, another may just see ‘crypto trading’.”

Top 5 Largest DeFi Exploits (EasyFi, Uranium, PolyNetwork, Compound, Cream)

Under this self-regulation, the hacker of Indexed Finance is willing to argue in court that his or her permissible exploit of the DeFi protocol should be considered a fair game arbitrage trade. As the industry grows in size, the exploits grow more serious, with Cream depositors losing $130 million last week. Shortly after, it was announced that Aave had a similar vulnerability and tens of billions of dollars in deposits were at risk.

You’re reading an excerpt from Money Reimagined, a weekly look at the technological, economic and social events and trends that are redefining our relationship with money and transforming the global financial system. Subscribe to get the full newsletter here.

Triple digit yield and price appreciation have been enough to bring $256 billion in total value locked (TVL) into DeFi and there are no signs of slowing down. Could the current growth rate be sustainable with inherent risk stemming from exploits and counterparty concentration becoming more obvious?

DeFi developers will undoubtedly learn from their mistakes and the industry will naturally become safer over time. However, the Aave vulnerability showed investors that no protocol is 100% safe. While it may stand against the ethos of DeFi, smart contract insurance and regulation could become key in onboarding the next generation of risk-averse DeFi users.

Learn more about Consensus 2024, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to to register and buy your pass now.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Edward Oosterbaan

Edward was an analyst on the CoinDesk Research team focusing on Ethereum and DeFi. He holds ETH, AVAX, OHM and a small amount of other cryptocurrencies.