2025 was a year of smart contract exploits. Protocols that passed multiple audits, protocols that had been battle-tested for years, protocols built by teams with2025 was a year of smart contract exploits. Protocols that passed multiple audits, protocols that had been battle-tested for years, protocols built by teams with

Audited, Tested, and Still Broken: Smart Contract Hacks of 2025

2026/01/04 14:57
10 min read

2025 was a year of smart contract exploits. Protocols that passed multiple audits, protocols that had been battle-tested for years, protocols built by teams with deep security expertise. They all fell victim to attacks that revealed something uncomfortable: we’re getting better at finding traditional bugs, but we’re still missing fundamental flaws in how protocols think about economics, mathematics, and system design.

This retrospective examines the most technically interesting incidents of the year, ordered by what they teach us about smart contract security. We’ll explore how economic invariant violations let attackers mint infinite tokens, how precision errors in AMM math turned tiny rounding mistakes into million-dollar exploits, and how system boundary failures exposed vulnerabilities that no single-component audit could catch.

The Standouts: Deep Protocol Failures

These hacks reveal fundamental issues in protocol design, failures that go beyond simple mistakes and touch on core assumptions about how DeFi systems should work.

Yearn Finance: Legacy Infrastructure Exploits ($9.3M total)

December 2025

Yearn Finance suffered two related exploits in December 2025, both targeting legacy infrastructure that remained on-chain after protocol upgrades.

First exploit: Economic Invariant Violation ($9M) — December 1

Yearn Finance’s legacy yETH stableswap pool was drained in a single transaction. The attacker found a flaw in the share calculation logic that allowed minting a near-infinite number of yETH tokens. About 1,000 ETH (worth around $3 million) was sent to Tornado Cash.

The attacker found an edge case in the stableswap formulas where share calculations could be manipulated. The vulnerability existed in the accounting logic itself. When the protocol calculated shares for deposits or withdrawals, the math could be manipulated to create shares out of thin air.

Second exploit: Legacy Contract Risk ($300K) — December 17

Following the first exploit, Yearn’s V1 contracts were targeted. When protocols upgrade, old contracts don’t disappear. They remain on-chain, potentially holding value. In Yearn’s case, the V1 contracts still had funds locked in them, and those funds became a target after the first exploit drew attention to Yearn’s legacy infrastructure.

Why it matters (auditor and organizational perspective):

The first exploit shows an important gap in audit methodology. Static analysis tools don’t verify economic invariants. Fuzzers test code paths, not economic models. Audit processes need to clearly verify that accounting logic maintains intended invariants across all operation sequences.

The second exploit highlights that legacy contracts represent ongoing risk. The first exploit may have drawn attention to Yearn’s legacy infrastructure, leading to the second. Protocols need clear plans for sunsetting old contracts, migrating remaining value, and monitoring for unexpected interactions.

Mitigation: Implement invariant tests that assert share-to-value relationships hold across all operations. Use differential fuzzing to compare accounting calculations against reference implementations. Have clear deprecation strategies for legacy contracts with ongoing monitoring.

The vulnerability class: Economic invariant violation and legacy contract risk.

Deep dive: Yearn Finance DeFi Project Hacked for $9M | PeckShield Alert | Yearn Finance V1 Exploit

Balancer: Rounding Error Exploitation ($70–128M)

November 3, 2025

Small rounding errors in Balancer’s stable pool calculations were amplified through high-frequency batch swaps, resulting in a $70–128 million drain across multiple chains. Attackers executed hundreds or thousands of swaps, with each swap amplifying the previous rounding error until those tiny errors accumulated into massive value extraction.

How it worked:

Balancer’s stable pools use complicated formulas to maintain price stability. These formulas involve rounding at multiple steps. In normal operation, rounding errors are small. But attackers found a way to structure batch swaps that consistently benefited from the rounding direction, extracting value through repeated operations.

Why it matters (protocol designer perspective):

AMM math needs to be correct under adversarial conditions. Every rounding decision becomes a potential attack vector when dealing with large capital and the ability to execute many transactions quickly. Designers need to think adversarially: what happens if an attacker executes this operation a thousand times?

What audits missed: Standard audit processes tested individual swaps, not sequences of hundreds or thousands. Rounding errors were measured as less than 1 wei per swap and treated as negligible. No invariant was asserted over N repeated operations. Fuzzers without stateful sequence modeling couldn’t discover this.

Mitigation: Assert invariants that hold across repeated operations. Test with adversarial batch sizes. Use formal verification to prove rounding error bounds remain acceptable under any sequence of operations.

The vulnerability class: Mathematical precision error in AMM formulas.

Deep dive: Balancer DeFi Protocol Suffers Massive Exploit | Balancer Hack Explained with Multi-Chain Details

GMX: System Boundary Failure ($42M)

July 9, 2025

GMX, a perpetuals trading protocol that handles billions in trading volume, was exploited for $42 million. The exploit didn’t come from a bug in the core trading logic. It emerged at the boundaries between components: where oracles meet margin calculations, where liquidation logic interacts with bridge infrastructure.

How it worked:

The vulnerability existed in how these components interacted, not in any single component. When oracles update prices, margin requirements change, and liquidation logic responds. The attacker likely found a way to manipulate these interactions, perhaps by timing oracle updates with margin calculations. About $9.6 million was bridged to Ethereum immediately after the exploit, suggesting careful planning.

Why it matters (system architecture perspective):

Well-audited individual components can still fail when integrated. The vulnerability doesn’t exist in any single contract. It exists in the space between components, in how they communicate and interact. As protocols become more complicated and composable, the attack surface grows at component boundaries.

What audits missed: Traditional audit processes typically focus heavily on components in isolation. Integration testing exists, but it may not cover adversarial scenarios where an attacker can time operations across component boundaries.

Mitigation: Implement integration tests that simulate full system behavior. Use adversarial simulation frameworks that can model interactions between components. Test timing attacks where operations are sequenced to exploit component interactions.

The vulnerability class: System integration failure.

Deep dive: GMX Exploit Coverage

Cork Protocol: Liquid Staking Derivative Handling ($12M)

May 28, 2025

Cork Protocol lost about 3,761 wstETH (worth around $12 million) due to a vulnerability in how it handled liquid staking derivatives. Liquid staking derivatives like stETH, wstETH, and osETH introduce hidden state changes. The exchange rate between wstETH and ETH changes over time as staking rewards accumulate.

How it worked:

The exploit involved a mismatch between how Cork Protocol modeled wstETH’s value accrual and how it actually works. The protocol likely assumed a static 1:1 relationship that doesn’t hold. An attacker could deposit wstETH when the exchange rate is favorable, wait for it to accrue value, then withdraw more than they should be able to.

Why it matters (organizational perspective):

This highlights an organizational knowledge gap. Many development teams treat all ERC-20 tokens the same way, but liquid staking derivatives work differently. This isn’t just a code problem. It’s a knowledge management problem. Teams need processes to identify and document token-specific behaviors before integration.

Mitigation: Always use the token’s exchange rate functions (e.g., wstETH.getStETHByWstETH()). Never assume a 1:1 relationship. Account for value accrual over time in any calculations involving LSDs.

The vulnerability class: Token mechanics misunderstanding.

Deep dive: Cork Protocol Hacked for $12M, Smart Contracts Paused

Interesting Edge Cases

These hacks reveal narrower but still instructive lessons about specific vulnerability classes.

Bunni: Precision Error Accumulation ($2.4–8.3M)

September 2, 2025

Bunni, a concentrated liquidity protocol, was exploited through a precision/rounding bug in its LP accounting system. The exact loss varies by source ($2.4M initially reported, later analysis suggests up to $8.3M).

How it worked:

The attacker found a way to make repeated deposits and withdrawals that exploited rounding in their favor. Each operation extracted a tiny amount, but over many operations, those tiny amounts added up to millions.

Why it matters (testing methodology perspective):

Most test suites model single operations, not operation sequences. A test might verify that a single deposit calculates shares correctly, but it won’t catch precision errors that only appear after dozens of operations. Fuzzers that don’t model stateful sequences miss these issues.

Mitigation: Use established math libraries (e.g., PRBMath, ABDKMath). Test sequences of operations, not just single operations. Consider using higher precision internally even if external interfaces use standard precision.

The vulnerability class: Precision/rounding error in LP accounting.

Deep dive: Bunni V2 Exploit: $8.3M Drained

Garden Finance: Multi-Chain Attack Pattern ($5.5M)

October 30, 2025

Garden Finance was exploited for $5.5 million plus across multiple chains. The attacker exploited on one chain, then used cross-chain bridges to move stolen assets to other chains, swapping them through different DEXs to obscure the trail.

Why it matters (threat modeling perspective):

Multi-chain deployments create new attack surfaces. Threat models need to account for cross-chain attack vectors. Attackers might exploit your protocol on one chain, then use cross-chain infrastructure to escape or obscure their tracks.

Mitigation: Design threat models that include cross-chain attack vectors. Understand how bridges work and their security assumptions. Consider implementing cross-chain monitoring and alerting.

The vulnerability class: Multi-chain attack pattern.

Deep dive: Garden Finance Breach Coverage

Nemo Protocol: When “Safe” Languages Aren’t Enough ($2.4M)

September 8, 2025

Nemo Protocol on Sui was exploited for $2.4M. The attacker bridged stolen USDC via Circle from Arbitrum to Ethereum. The exploit happened despite Move’s safety features.

Why it matters (tooling perspective):

Move’s type system prevents certain bugs, but it doesn’t address an entire class of protocol-level vulnerabilities. If your protocol’s economic logic is flawed, if your access control is weak, if your oracle integration is vulnerable, Move’s type system doesn’t help.

The vulnerability class: Economic logic error in non-EVM ecosystem.

Deep dive: Nemo Protocol Exploit Details

The Rest: Operational Failures

Several other hacks in 2025 represent straightforward operational failures rather than novel technical vulnerabilities:

  • Unleash Protocol ($3.9M, December 30): Unauthorized drain, likely compromised permissions
  • ArcadiaFi ($2.5M, July 15): Allowance/approval abuse on Base chain
  • NewGoldProtocol ($2M, September 18): Token exploit, funds routed through Tornado Cash
  • SuperRare ($730K, July 28): NFT platform exploit
  • USPD ($1M, December 5): Token approval exploit
  • 402bridge ($17K, October 28): Small bridge exploit

These incidents follow well-known patterns: compromised admin keys, excessive token approvals, and access control failures. The solutions are known: use multisig for admin functions, implement proper access controls, monitor for excessive approvals.

Summary

Looking across 2025’s hacks, several patterns emerge. Economic correctness matters as much as code security. Yearn’s infinite mint and Balancer’s rounding errors show that protocols need formal verification of their economic models, not just code audits. System boundaries hide complexity. GMX’s exploit demonstrates that well-audited components can still fail when integrated. Integration testing and adversarial simulation are essential.

Precision and rounding remain dangerous. Bunni’s exploit is a reminder that fixed-point arithmetic vulnerabilities persist. Test operation sequences, not just single operations. Cross-chain creates new attack surfaces. Garden Finance and Nemo Protocol show that multi-chain deployments require security models that account for cross-chain attack vectors. Language safety doesn’t eliminate economic bugs. Nemo Protocol demonstrates that type-safe languages prevent certain bugs but don’t address economic logic errors. Legacy contracts are ongoing risks. Yearn’s December exploits show that deprecated contracts remain vulnerable, and one exploit can draw attention to legacy infrastructure. Have clear deprecation strategies and ongoing monitoring.

Like this article? Click follow to stay updated.


Audited, Tested, and Still Broken: Smart Contract Hacks of 2025 was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0,003926
$0,003926$0,003926
-%0,30
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Mystake Review 2023 – Unveil the Gaming Experience

Mystake Review 2023 – Unveil the Gaming Experience

Cryptsy - Latest Cryptocurrency News and Predictions Cryptsy - Latest Cryptocurrency News and Predictions - Experts in Crypto Casinos Did you know Mystake Casino
Share
Cryptsy2026/02/07 11:32
Strategic Move Sparks Market Analysis

Strategic Move Sparks Market Analysis

The post Strategic Move Sparks Market Analysis appeared on BitcoinEthereumNews.com. Trend Research Deposits $816M In ETH To Binance: Strategic Move Sparks Market
Share
BitcoinEthereumNews2026/02/07 11:13
Unprecedented Surge: Gold Price Hits Astounding New Record High

Unprecedented Surge: Gold Price Hits Astounding New Record High

BitcoinWorld Unprecedented Surge: Gold Price Hits Astounding New Record High While the world often buzzes with the latest movements in Bitcoin and altcoins, a traditional asset has quietly but powerfully commanded attention: gold. This week, the gold price has once again made headlines, touching an astounding new record high of $3,704 per ounce. This significant milestone reminds investors, both traditional and those deep in the crypto space, of gold’s enduring appeal as a store of value and a hedge against uncertainty. What’s Driving the Record Gold Price Surge? The recent ascent of the gold price to unprecedented levels is not a random event. Several powerful macroeconomic forces are converging, creating a perfect storm for the precious metal. Geopolitical Tensions: Escalating conflicts and global instability often drive investors towards safe-haven assets. Gold, with its long history of retaining value during crises, becomes a preferred choice. Inflation Concerns: Persistent inflation in major economies erodes the purchasing power of fiat currencies. Consequently, investors seek assets like gold that historically maintain their value against rising prices. Central Bank Policies: Many central banks globally are accumulating gold at a significant pace. This institutional demand provides a strong underlying support for the gold price. Furthermore, expectations around interest rate cuts in the future also make non-yielding assets like gold more attractive. These factors collectively paint a picture of a cautious market, where investors are looking for stability amidst a turbulent economic landscape. Understanding Gold’s Appeal in Today’s Market For centuries, gold has held a unique position in the financial world. Its latest record-breaking performance reinforces its status as a critical component of a diversified portfolio. Gold offers a tangible asset that is not subject to the same digital vulnerabilities or regulatory shifts that can impact cryptocurrencies. While digital assets offer exciting growth potential, gold provides a foundational stability that appeals to a broad spectrum of investors. Moreover, the finite supply of gold, much like Bitcoin’s capped supply, contributes to its perceived value. The current market environment, characterized by economic uncertainty and fluctuating currency values, only amplifies gold’s intrinsic benefits. It serves as a reliable hedge when other asset classes, including stocks and sometimes even crypto, face downward pressure. How Does This Record Gold Price Impact Investors? A soaring gold price naturally raises questions for investors. For those who already hold gold, this represents a significant validation of their investment strategy. For others, it might spark renewed interest in this ancient asset. Benefits for Investors: Portfolio Diversification: Gold often moves independently of other asset classes, offering crucial diversification benefits. Wealth Preservation: It acts as a robust store of value, protecting wealth against inflation and economic downturns. Liquidity: Gold markets are highly liquid, allowing for relatively easy buying and selling. Challenges and Considerations: Opportunity Cost: Investing in gold means capital is not allocated to potentially higher-growth assets like equities or certain cryptocurrencies. Volatility: While often seen as stable, gold prices can still experience significant fluctuations, as evidenced by its rapid ascent. Considering the current financial climate, understanding gold’s role can help refine your overall investment approach. Looking Ahead: The Future of the Gold Price What does the future hold for the gold price? While no one can predict market movements with absolute certainty, current trends and expert analyses offer some insights. Continued geopolitical instability and persistent inflationary pressures could sustain demand for gold. Furthermore, if global central banks continue their gold acquisition spree, this could provide a floor for prices. However, a significant easing of inflation or a de-escalation of global conflicts might reduce some of the immediate upward pressure. Investors should remain vigilant, observing global economic indicators and geopolitical developments closely. The ongoing dialogue between traditional finance and the emerging digital asset space also plays a role. As more investors become comfortable with both gold and cryptocurrencies, a nuanced understanding of how these assets complement each other will be crucial for navigating future market cycles. The recent surge in the gold price to a new record high of $3,704 per ounce underscores its enduring significance in the global financial landscape. It serves as a powerful reminder of gold’s role as a safe haven asset, a hedge against inflation, and a vital component for portfolio diversification. While digital assets continue to innovate and capture headlines, gold’s consistent performance during times of uncertainty highlights its timeless value. Whether you are a seasoned investor or new to the market, understanding the drivers behind gold’s ascent is crucial for making informed financial decisions in an ever-evolving world. Frequently Asked Questions (FAQs) Q1: What does a record-high gold price signify for the broader economy? A record-high gold price often indicates underlying economic uncertainty, inflation concerns, and geopolitical instability. Investors tend to flock to gold as a safe haven when they lose confidence in traditional currencies or other asset classes. Q2: How does gold compare to cryptocurrencies as a safe-haven asset? Both gold and some cryptocurrencies (like Bitcoin) are often considered safe havens. Gold has a centuries-long history of retaining value during crises, offering tangibility. Cryptocurrencies, while newer, offer decentralization and can be less susceptible to traditional financial system failures, but they also carry higher volatility and regulatory risks. Q3: Should I invest in gold now that its price is at a record high? Investing at a record high requires careful consideration. While the price might continue to climb due to ongoing market conditions, there’s also a risk of a correction. It’s crucial to assess your personal financial goals, risk tolerance, and consider diversifying your portfolio rather than putting all your capital into a single asset. Q4: What are the main factors that influence the gold price? The gold price is primarily influenced by global economic uncertainty, inflation rates, interest rate policies by central banks, the strength of the U.S. dollar, and geopolitical tensions. Demand from jewelers and industrial uses also play a role, but investment and central bank demand are often the biggest drivers. Q5: Is gold still a good hedge against inflation? Historically, gold has proven to be an effective hedge against inflation. When the purchasing power of fiat currencies declines, gold tends to hold its value or even increase, making it an attractive asset for preserving wealth during inflationary periods. To learn more about the latest crypto market trends, explore our article on key developments shaping Bitcoin’s price action. This post Unprecedented Surge: Gold Price Hits Astounding New Record High first appeared on BitcoinWorld.
Share
Coinstats2025/09/18 02:30