飞凡
飞凡|Nov 04, 2025 13:20
The most difficult year for Defi is undoubtedly 2025 Apart from the shift in the track towards stablecoins rather than continuing liquidity market making, Defi has been devastated by hackers and landmines. The whole year of 2025 is already a bountiful year for hackers. In the first half of 2025 alone, hackers have stolen over 2.2 billion US dollars, Whenever the market slightly rebounds and TVL (total lock up value) and asset prices are pushed up, Structural risks and security vulnerabilities hidden within the system begin to erupt in a concentrated manner. The recent two catastrophic security incidents have severely injured the entire overseas Defi community. -Balancing (v2) was hacked (resulting in a loss of $120-130 million) The old DeFi blue chip balancer was attacked, and hackers took advantage of a permission verification flaw (manageUserBalance entrance) in an outdated v2 fund pool to gain write access to the vault, resulting in the looting of assets on multiple chains. -Stream Finance internal mine explosion (loss of approximately $93 million) This is not a hacker attack, but an internal risk control failure. The external fund manager hired by Stream Finance lost about $93 million in operations, causing its stablecoin system (xUSD/sXUSD) to collapse instantly and the price to drop to around 0.3 at one point. The project party was forced to suspend all deposits and withdrawals, and hired Perkins Coie law firm to investigate. Why are adverse events currently erupting in a concentrated manner? Is it a symbol of cow powder? I have considered four things that are more alarming than hacking incidents. 1. Old agreement+complex contract Balancing is an old blue chip company that has undergone multiple rounds of audits, but it is precisely its v2 old pool that has problems. The official cannot even suspend these old pools and can only watch helplessly as assets are stolen. The attack exploited an extremely subtle logical vulnerability (permission verification+precision loss) hidden in a complex combination of massive modules, which is almost impossible to detect in routine audits. The longer the protocol has a history, the more complex the code, and has undergone multiple migrations, the more likely it is to have forgotten vaults. Old code+huge TVL=the highest ROI (return on investment) prey in the eyes of hackers. 2. Transparent DeFi+Outsourced Fund Managers=New Black Box The explosion of Stream Finance revealed a cruel reality. In fact, a week before the incident, analysts (Cbb0fe) publicly warned that although xUSD's on chain assets were 170 million, its real leverage ratio was as high as 4.1 times through borrowing and revolving leverage, and the underlying asset liquidity was extremely poor. Many so-called actively managed DeFi or external manager protocols have essentially degenerated into CeFi with DeFi shells. Although users can see asset snapshots on the chain, they cannot see the real risk control details, leverage levels, and operational errors behind them. 3. Risk compound interest is greater than return compound interest After the balancer was hacked, Berachain, which was deeply bound to it, was forced to urgently hard fork, and Sonic had to freeze the attacker's wallet. A protocol bug forced two public chains to fix it together. After the explosion of Stream, the detachment of its xUSD stablecoin directly threatened all other DeFi protocols that used it as collateral for stablecoins. The composability on the chain not only brings compound interest on profits, but also compound interest on risks. Even stepping on a single lightning strike now could instantly trigger a whole chain of risks. The latter half of the bull market is the best cost-effective window for hackers In 2025, under favorable conditions such as ETFs and macro easing expectations, the market will be generally bullish, with TVL and token market values at high levels. The attacker's perspective: The same vulnerability, when attacked during a bear market (low TVL), may only steal a few million dollars, while when attacked during a bull market (high TVL), it can steal over 100 million dollars at once. The asset size of many protocols has grown several times in the bull market, but their security budgets and risk control processes are still at the level of a bear market. The mismatch between security and assets provides a perfect opportunity for hackers and insiders to commit evil.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads