Close Menu
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
What's Hot

Has Satoshi returned? An old Bitcoin wallet that has been dormant since 2010 has woken up

June 8, 2026

Federal lawsuit seeks to halt UFC event on White House South Lawn

June 8, 2026

TradFi futures soar on crypto exchanges as spot trading slows down: CryptoQuant

June 7, 2026
Facebook X (Twitter) Instagram
Trending
  • Has Satoshi returned? An old Bitcoin wallet that has been dormant since 2010 has woken up
  • Federal lawsuit seeks to halt UFC event on White House South Lawn
  • TradFi futures soar on crypto exchanges as spot trading slows down: CryptoQuant
  • Kimi Antonelli wins F1 Monaco GP after crash and red flag
  • At least 12 people shot near Ohio festival, gunman still at large
  • Ethereum breakdown warning: this major level could trigger further downtrend
  • Why ceasefires won’t stop deadly attacks in Gaza, Lebanon and the Gulf
  • Want to join SpaceX? Kraken opens early IPO access via xStocks
Facebook X (Twitter) Instagram
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
Crypto Heatmap
Cryptosphere Update
Home » Hackers misuse audited defi protocols: what are they missing?
Breaking Views

Hackers misuse audited defi protocols: what are they missing?

Leslie StewartBy Leslie StewartJune 4, 2025No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Hackers Misuse Audited Defi Protocols: What Are They Missing?
Share
Facebook Twitter LinkedIn Pinterest Email

Disclosure: The opinions and opinions expressed here belong to the authors solely and do not represent the views or opinions of the crypto.news editorial.

Defi is under attack, but not from the threats used by the industry to defend. Developers scan lines of code carefully for vulnerabilities, but attackers change tactics and take advantage of unnoticed economic weaknesses under perfect programming.

For example, a jelly token exploit at HyperRedgar, where an attacker could siphon over $6 million from HyperRedgar’s insurance fund. That exploit is not caused by coding errors, but by lattice incentives and priceless risks that no one has scrutinized.

Defi Cybersecurity has come a long way. Smart contract auditing, designed to catch bugs in software code, is the standard these days. But you need to extend that range beyond just a line of code. Smart contract audits are essentially insufficient unless you also analyze economic and game-theoretical risks. Overreliance on industry code-only auditing is outdated and dangerous, and projects are vulnerable to endless attack cycles.

Recent attacks drive the risk of economic exploitation

In March 2025, the Hyperliquid exchange, which audited the contract, was ambushed by a $6 million exploit containing jelly tokens. how? The attacker found no bugs in the code. They designed a short aperture by abusing Hyperliquid’s own liquidation logic, pumping up Jelly’s prices and manipulating risk parameters on the platform.

In other words, Hyperliquid designers did not price specific market actions. This is an surveillance that traditional audits have not caught. The Hyperliquid case shows that projects cannot be saved built on unstable economic assumptions.

Shortly before the Jelly incident, Fantom’s lending protocol, Polter Finance, was released $12 million in the flash loan attack. This is another common type of attack that relies on economics that do not code vulnerabilities. The attacker took out the flash loan, manipulated the project’s priced Oracle, and tricked the system into treating unworthy collateral as billions of value.

The code did exactly what was supposed to be, but the design was flawed, allowing for an extreme price swing to bankrupt the platform. The exploit proved to be so devastating that the promising project, Polter Finance, was forced to shut down operations.

These are not isolated attacks/events. They are part of the growth pattern of defi. In post-case cases, clever enemies leverage protocols by manipulating market input, incentives, or governance mechanisms to trigger results the developers didn’t expect. We have seen farms hit by reward loopholes, stable pegs attacked through coordinated market movements, and insurance funds emitted by extreme volatility.

Enhanced auditing through economic and game theory analysis

Traditional audits check if “code does what it should be”, but do you check if “what it should be” makes sense under adversarial conditions? Unlike closed programs, the Defi protocol lives in a dynamic and hostile environment. Prices fluctuate, users adapt strategies, and protocols interconnect in complex ways.

Most Web3 teams have engineers who can catch software bugs during development, but they have little internal economic expertise. It is important that audits fill that gap and identify vulnerabilities in incentive design and economic logic.

A truly rigorous audit involves scrutiny of fee mechanisms, liquidation formulas, collateral parameters, governance processes, and more. They told the auditor, “Given these rules, how can someone benefit from bending them?”

For example, during an audit conducted by Oak Security, we found that insurance funds on permanent swap platforms could be completely discharged by volatility because they did not consider the “Vega risk” (protocol sensitivity to volatility) in the Pricing model. This was not a code bug, but a design flaw that would cause collapse in the turbulent market. Only deep dives in game theory and economics captured it. Luckily we were able to flag the issue before launch.

These economic exploitations are well documented and not too difficult to find, but only surface when the auditor asks the right questions and thinks beyond the code on the page.

Founders need to ask more from their auditors

The founders of the protocol must require that the auditor examine all components of the trading system, including implicit logic and off-chain components, to ensure comprehensive security. In the best scenario, all mission-critical logic is brought to the chain.

If you are a founder or investor, it is important to ask the auditor. How about OracleManipulation? What about liquidity crunch scenarios? Have you analyzed the talk nemics of attack vectors? If the answer is silent or waving, you need to dig deeper.

The cost of these blind spots is simply too high. Not only is it incorporated into economic and game theory analysis, it is not just “good.” It’s a matter of survival of the Defi project. Code reviews and economic reviews need to cultivate a culture that gets used to all key protocols.

Raise the bar now. Before another multi-million dollar lesson forced our hands.

Jan Philippe Fritz

Jan Philippe Fritz He is the managing director of Oak Security, a cybersecurity company specializing in Web3 auditing. Prior to his role in Oak Security, Dr. Fritz gained extensive experience in econometrics and risk modeling, serving positions at institutions such as the European Central Bank and Diuberlin. He holds a PhD. Economics at Humboldt University in Berlin.

audited DeFi Hackers missing misuse protocols
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Leslie
Leslie Stewart

Related Posts

Another day passes with Auburn student still missing in Japan, parents say

June 4, 2026

Two University of South Florida doctoral students missing, police say

April 22, 2026

North Korean IT workers have been operating within DeFi protocols for years, researchers warn

April 6, 2026

Circle CirBTC unveils new token designed to expand Bitcoin’s role in DeFi

April 3, 2026
Add A Comment

Comments are closed.

Popular Posts

Department of Justice removes press release regarding charges against January 6th rioters

May 23, 2026

DappRadar reports record sales of 18 million units in 2025’s largest market revival

October 11, 2025

Why ceasefires won’t stop deadly attacks in Gaza, Lebanon and the Gulf

June 6, 2026

Chainalysis reveals $100 million peptide market built on cryptocurrencies

June 4, 2026
Latest Posts

Has Satoshi returned? An old Bitcoin wallet that has been dormant since 2010 has woken up

June 8, 2026

Federal lawsuit seeks to halt UFC event on White House South Lawn

June 8, 2026

TradFi futures soar on crypto exchanges as spot trading slows down: CryptoQuant

June 7, 2026

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

About
About

At Cryptosphere Update, we are dedicated to bringing you in-depth coverage of the rapidly evolving crypto landscape, from market trends and emerging blockchain projects to regulatory developments and expert analysis. Our mission is to keep you informed and ahead of the curve in the ever-changing world of digital assets.

Facebook X (Twitter) Instagram Pinterest YouTube
Don't Miss

Has Satoshi returned? An old Bitcoin wallet that has been dormant since 2010 has woken up

June 8, 2026

Federal lawsuit seeks to halt UFC event on White House South Lawn

June 8, 2026

TradFi futures soar on crypto exchanges as spot trading slows down: CryptoQuant

June 7, 2026
Newsletter

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

© 2026 Cryptosphere Update. All Rights Reserved.
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.