Cybersicherheit

DeFi Security Failures Cost More Than Stolen Funds

mm
Securities.io zu deinen bevorzugten Quellen auf Google hinzufügen

DeFi Hacks Leave Lasting Liquidity Damage, Study Finds

A cryptocurrency protocol can repair broken code faster than it can rebuild confidence. After an exploit, the immediate question is how much money disappeared. The more consequential question may be how much capital still wants to stay.

A new study published in Finance Research Letters, “When code fails: Operational trust shocks and liquidity scarring in decentralized finance,” examines that second problem.1 Researchers Michael Zouari, Ilan Alon, and Zeev Shtudiner find that exploited protocols experience substantial liquidity deterioration relative to comparable protocols, with damage often persisting for months.

The findings offer a practical lesson for decentralized finance, or DeFi: security is part of a financial product’s economic foundation. Reliable code attracts capital, but continued participation also depends on confidence in governance, operational controls, and the ability to respond when something fails.

What The DeFi Exploit Study Measured

DeFi uses blockchain applications to provide services such as lending and trading. Instead of relying entirely on a traditional intermediary, users interact with smart contracts, programs that execute transactions according to predefined rules.

The researchers assembled 197 exploit and bridge-attack incidents across 51 chains between November 2020 and Mai 2026. These included code vulnerabilities, operational security failures such as compromised administrator keys, and attacks on infrastructure connecting different blockchains.

Of those incidents, 133 qualified for a matched analysis. Each affected protocol was compared with non-exploited protocols selected for similarities including business category and pre-event size. Comparing them over the same dates helped account for broader cryptocurrency market conditions.

The study’s most useful feature is its treatment of total value locked, or TVL. This metric measures the dollar value of assets held in a protocol, but it can change simply because cryptocurrency prices rise or fall.

The researchers instead measured changes in token quantities, valued at contemporaneous prices. This excludes pure price changes when balances remain unchanged. However, the resulting liquidity measure includes stolen assets alongside withdrawals and other balance changes. It should not be interpreted as a direct count of users choosing to leave.

How Much Liquidity Damage Followed An Exploit?

In the expanded matched sample, affected protocols experienced abnormal price-neutral liquidity losses equivalent to 27.6 percentage points of pre-event TVL by day seven. That difference widened to 33.6 points by day 30 and 42.7 points by day 90.

These figures describe differences relative to matched controls, rather than average losses among exploited protocols. The distinction matters because unaffected protocols can also gain or lose liquidity during the same period.

Study Measure Result Interpretation
Day-7 abnormal liquidity loss 27.6 percentage points Relative to matched controls, scaled to pre-event TVL
Day-90 abnormal liquidity loss 42.7 percentage points Persistent deterioration across 125 matched incidents
Severely impaired at day 180 37.5% Price-neutral ratio of 0.20 or below
Recovered at day 180 21.3% Price-neutral ratio of 0.80 or above

The 180-day percentages come from 136 affected incidents meeting the study’s flow-coverage requirement. Another 41.2% fell between the recovery and severe-impairment thresholds. These classifications measure liquidity outcomes, not whether a protocol remained technically operational.

Established protocols also suffered, although their matched losses were smaller. Raising the minimum pre-event TVL to $100 million still produced a seven-day abnormal loss of 14.6 percentage points. Scale offered no complete escape from post-exploit damage.

Why Security Functions As An Economic Asset

The deeper implication is that security protects more than the assets currently inside a contract. It also protects a protocol’s ability to attract future deposits, maintain useful markets, and support ongoing financial activity.

Consider a hypothetical lending protocol that loses a small share of its assets. Even after the vulnerability is repaired, lenders may question whether other weaknesses remain. If they withdraw, the protocol faces a second economic problem beyond the original theft.

The study provides evidence consistent with this mechanism. In its lowest-severity quartile, median seven-day net outflows were 3.1% of pre-event TVL, compared with median reported theft of 0.6%. In the next quartile, the figures were 9.5% and 7.8%.

Those comparisons suggest reassessment beyond mechanical losses. They do not prove individual motivations, and the authors say transaction-level tracing would be necessary to isolate the behavioural component. At higher exploit severity, theft itself becomes harder to separate from subsequent liquidity deterioration.

Nevertheless, the business implication is clear: evaluating security spending solely against potential theft understates its possible value. Preventing an incident may also preserve the future participation that makes a financial network useful.

Why A Blockchain Can Be Secure While An Application Fails

Investors should distinguish the security of a blockchain from the security of applications operating on it. A network can continue validating transactions correctly while an application processes transactions permitted by flawed code.

The same distinction applies to administrator credentials, external price feeds, interfaces, and bridges. A failure in one component does not necessarily mean the underlying blockchain stopped functioning.

As Securities.io’s discussion of tokenized asset interoperability explains, moving assets between systems also involves standards, operational governance, and the meaning of the assets being transferred. Connectivity alone does not resolve those responsibilities.

Likewise, the tokenization lifecycle extends beyond creating a token. Financial infrastructure must maintain reliable records and processes throughout an asset’s life. DeFi’s recovery challenge illustrates why operating capability deserves attention alongside technical innovation.

What Meaningful DeFi Recovery Should Look Like

A rising TVL chart can create a misleading impression of recovery if the increase mainly reflects higher token prices. Conversely, falling prices can obscure returning deposits. The study demonstrates why separating valuation effects from balance changes improves post-incident analysis.

Recovery also requires distinguishing compensation from renewed confidence. Rescue funding may restore balances without establishing that ordinary users are willing to return. Promotional incentives may attract deposits temporarily without demonstrating durable participation.

A practical assessment should therefore examine several separate questions:

  • Has the failure’s cause been explained and independently reviewed?
  • Are token balances recovering beyond price changes and rescue funding?
  • Can users understand withdrawal conditions and compensation arrangements?
  • Have governance and operational controls changed where necessary?

This framework is an analytical implication of the findings, rather than a recovery formula tested by the researchers. Their long-term outcomes also incorporate reimbursements, migrations, governance decisions, and other responses.

Coinbase Connects Public Investors With DeFi Infrastructure

As DeFi reaches users through familiar financial applications, the commercial importance of these questions expands. Coinbase offers public-market exposure to this integration through its trading, custody, and developer businesses, alongside products connecting customers with onchain services.

COIN Preisdiagramm

In September 2026, Coinbase announced the expansion of Morpho-powered USDC lending in Brazil and Canada. Customer funds move from self-custodial wallets into Morpho lending vaults on Base, with vault curation provided by Steakhouse Financial.

The integration demonstrates how a familiar interface can make DeFi easier to access while leaving users exposed to underlying protocol risks. Coinbase’s USDC lending risk disclosures describe risks including smart-contract failures, bad debt, and withdrawal constraints.

For shareholders, the opportunity is broader adoption of infrastructure supporting digital financial activity. The corresponding challenge is whether product expansion is accompanied by effective risk communication and dependable operations. A simpler interface can reduce friction, but it cannot eliminate the economic consequences of a compromised protocol.

Coinbase’s wider infrastructure expansion also includes its recently reported collaboration with Citi on fiat and stablecoin payments. These developments provide context for its business direction. The study itself does not evaluate Coinbase or establish that it benefits from competitors’ security failures.

Latest Coinbase (COIN) News And Developments

A More Durable Foundation For DeFi Growth

The study’s findings support measured optimism because the damage was predominantly concentrated in affected protocols. Average short-term spillovers to matched peers were economically small within the researchers’ specified testing range. That finding does not exclude contagion through particular shared dependencies, but it challenges the assumption that every exploit equally undermines the entire sector.

DeFi’s next stage of development can therefore focus on making security, transparent measurement, and credible remediation central to product quality. Better code matters. So does demonstrating that capital can remain productive, accessible, and worthy of users’ continued confidence after the initial excitement fades.

References:

1 Zouari, M., Alon, I., & Shtudiner, Z. (2026). When code fails: Operational trust shocks and liquidity scarring in decentralized finance. Finance Research Letters, 113, 110877. https://doi.org/10.1016/j.frl.2026.110877

Daniel ist ein starker Befürworter des Potenzials von Blockchain, um die traditionelle Finanzwirtschaft zu revolutionieren. Er hat eine tiefe Leidenschaft für Technologie und erkundet ständig die neuesten Innovationen und Gadgets.