Close Menu
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
What's Hot

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026
Facebook X (Twitter) Instagram
Trending
  • States ask DHS to explain noncitizen voter claims
  • Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate
  • A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.
  • Coinbase Chief Policy Officer Praises Draft Clarity Act
  • Bitcoin flips volatile in US trading session, soars towards $66,000
  • Singapore tightens monetary policy with unexpected measures as inflation risks reignite due to rising oil prices
  • At least 2 killed, 5 injured in Seattle shooting
  • Only 7% of major tokens are above their launch price
Facebook X (Twitter) Instagram
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
Crypto Heatmap
Cryptosphere Update
Home » Hackers misuse audited defi protocols: what are they missing?
Breaking Views

Hackers misuse audited defi protocols: what are they missing?

Leslie StewartBy Leslie StewartJune 4, 2025No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Hackers Misuse Audited Defi Protocols: What Are They Missing?
Share
Facebook Twitter LinkedIn Pinterest Email

Disclosure: The opinions and opinions expressed here belong to the authors solely and do not represent the views or opinions of the crypto.news editorial.

Defi is under attack, but not from the threats used by the industry to defend. Developers scan lines of code carefully for vulnerabilities, but attackers change tactics and take advantage of unnoticed economic weaknesses under perfect programming.

For example, a jelly token exploit at HyperRedgar, where an attacker could siphon over $6 million from HyperRedgar’s insurance fund. That exploit is not caused by coding errors, but by lattice incentives and priceless risks that no one has scrutinized.

Defi Cybersecurity has come a long way. Smart contract auditing, designed to catch bugs in software code, is the standard these days. But you need to extend that range beyond just a line of code. Smart contract audits are essentially insufficient unless you also analyze economic and game-theoretical risks. Overreliance on industry code-only auditing is outdated and dangerous, and projects are vulnerable to endless attack cycles.

Recent attacks drive the risk of economic exploitation

In March 2025, the Hyperliquid exchange, which audited the contract, was ambushed by a $6 million exploit containing jelly tokens. how? The attacker found no bugs in the code. They designed a short aperture by abusing Hyperliquid’s own liquidation logic, pumping up Jelly’s prices and manipulating risk parameters on the platform.

In other words, Hyperliquid designers did not price specific market actions. This is an surveillance that traditional audits have not caught. The Hyperliquid case shows that projects cannot be saved built on unstable economic assumptions.

Shortly before the Jelly incident, Fantom’s lending protocol, Polter Finance, was released $12 million in the flash loan attack. This is another common type of attack that relies on economics that do not code vulnerabilities. The attacker took out the flash loan, manipulated the project’s priced Oracle, and tricked the system into treating unworthy collateral as billions of value.

The code did exactly what was supposed to be, but the design was flawed, allowing for an extreme price swing to bankrupt the platform. The exploit proved to be so devastating that the promising project, Polter Finance, was forced to shut down operations.

These are not isolated attacks/events. They are part of the growth pattern of defi. In post-case cases, clever enemies leverage protocols by manipulating market input, incentives, or governance mechanisms to trigger results the developers didn’t expect. We have seen farms hit by reward loopholes, stable pegs attacked through coordinated market movements, and insurance funds emitted by extreme volatility.

Enhanced auditing through economic and game theory analysis

Traditional audits check if “code does what it should be”, but do you check if “what it should be” makes sense under adversarial conditions? Unlike closed programs, the Defi protocol lives in a dynamic and hostile environment. Prices fluctuate, users adapt strategies, and protocols interconnect in complex ways.

Most Web3 teams have engineers who can catch software bugs during development, but they have little internal economic expertise. It is important that audits fill that gap and identify vulnerabilities in incentive design and economic logic.

A truly rigorous audit involves scrutiny of fee mechanisms, liquidation formulas, collateral parameters, governance processes, and more. They told the auditor, “Given these rules, how can someone benefit from bending them?”

For example, during an audit conducted by Oak Security, we found that insurance funds on permanent swap platforms could be completely discharged by volatility because they did not consider the “Vega risk” (protocol sensitivity to volatility) in the Pricing model. This was not a code bug, but a design flaw that would cause collapse in the turbulent market. Only deep dives in game theory and economics captured it. Luckily we were able to flag the issue before launch.

These economic exploitations are well documented and not too difficult to find, but only surface when the auditor asks the right questions and thinks beyond the code on the page.

Founders need to ask more from their auditors

The founders of the protocol must require that the auditor examine all components of the trading system, including implicit logic and off-chain components, to ensure comprehensive security. In the best scenario, all mission-critical logic is brought to the chain.

If you are a founder or investor, it is important to ask the auditor. How about OracleManipulation? What about liquidity crunch scenarios? Have you analyzed the talk nemics of attack vectors? If the answer is silent or waving, you need to dig deeper.

The cost of these blind spots is simply too high. Not only is it incorporated into economic and game theory analysis, it is not just “good.” It’s a matter of survival of the Defi project. Code reviews and economic reviews need to cultivate a culture that gets used to all key protocols.

Raise the bar now. Before another multi-million dollar lesson forced our hands.

Jan Philippe Fritz

Jan Philippe Fritz He is the managing director of Oak Security, a cybersecurity company specializing in Web3 auditing. Prior to his role in Oak Security, Dr. Fritz gained extensive experience in econometrics and risk modeling, serving positions at institutions such as the European Central Bank and Diuberlin. He holds a PhD. Economics at Humboldt University in Berlin.

audited DeFi Hackers missing misuse protocols
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Leslie
Leslie Stewart

Related Posts

Concerns about AI-powered DeFi hack epidemic are exaggerated for now, but not for long

July 23, 2026

Two US soldiers killed in Jordan, one missing, military says

July 18, 2026

Morpho’s $175M DeFi round puts the future of on-chain credit to the test

June 13, 2026

MiCA architect says EU should prioritize tokenization over DeFi rules

June 9, 2026
Add A Comment

Comments are closed.

Popular Posts

The Future of Digital Prosperity: How AI and Web3 Are Shaping the Creator Economy 2.0

October 14, 2024

Bitcoin flips volatile in US trading session, soars towards $66,000

July 27, 2026

BitMEX faces proposed class action lawsuit seeking return of 622BTC

July 25, 2026

LINK has become the most undervalued asset in cryptocurrencies

July 24, 2026
Latest Posts

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

About
About

At Cryptosphere Update, we are dedicated to bringing you in-depth coverage of the rapidly evolving crypto landscape, from market trends and emerging blockchain projects to regulatory developments and expert analysis. Our mission is to keep you informed and ahead of the curve in the ever-changing world of digital assets.

Facebook X (Twitter) Instagram Pinterest YouTube
Don't Miss

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026
Newsletter

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

© 2026 Cryptosphere Update. All Rights Reserved.
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.