DeFi Security Shift: Social Engineering Surpasses Code Bugs
The DeFi sector has seen a significant shift in security threats, with social engineering and compromised access now causing more losses than smart contract bugs. According to recent data, $575 million in losses have been linked to North Korean actors in two major hacks.
The largest DeFi exploit of the year occurred in April when KelpDAO suffered a loss of approximately $292 million in rsETH. Investigations revealed that the attackers gained access to the infrastructure used by the bridge's sole validator, allowing them to generate valid proof for a non-existent transaction.
In another instance, Drift lost around $285 million after attackers spent months building relationships with the team to eventually utilize pre-signed trades and gain administrative control. A fake asset was subsequently approved as collateral, enabling the withdrawal of real assets from the protocol.