Decentralised News Logo
Crypto Trading

DeFi’s Exploit Losses Fell 80%. Its Concentration Risk Rose 62%. Both Are Real.

The DeFi Safety Claim Nobody Has Actually Measured Two Ways.

DN Market Structure Series

"DeFi Learned Its Lesson," Tested Against Its Own Concentration Data

Exploit losses really did fall 80% after Terra and FTX. But the same flight-to-safety that made DeFi's code more audited also concentrated its capital into fewer protocols than at any point since the crash. Includes the DN DeFi Systemic Concentration Heatmap.

DECENTRALISED NEWS · MARKET STRUCTURE & RISK SERIES · SEPTEMBER 2026

Four years after Terra's collapse and the FTX bankruptcy, a specific reassurance has become standard in DeFi commentary: the industry grew up. Audits are routine, bug bounties are large, insurance funds exist, and the reckless yield-farming excess of 2021 is gone. Every part of that is at least partly true, and the exploit data backs it up more convincingly than most people making the claim seem to realize. What almost nobody checks alongside it is a completely different, less flattering question: while individual protocols got measurably harder to hack, did the ecosystem as a whole get harder to break? Those are not the same question, and the answer to the second one is no.

This piece runs both tests side by side, using the same rigor. The exploit-loss data genuinely supports "DeFi learned its lesson" as a claim about code quality and infrastructure design. The TVL concentration data tells a nearly opposite story about systemic structure. Both are true at the same time, and the tension between them is the actual, useful finding here.

80%
Decline in DeFi exploit losses, 2022 ($2.62B) to 2024 ($534M)
1,942 → 3,134
TVL concentration (HHI), Dec 2022 to June 2026, moderate to highly concentrated
73% → 3%
Bridge exploits as a share of total DeFi losses, 2022 to 2025
$1.3B+
DeFi losses through roughly two-thirds of 2026, already above all of 2024

DN AI Summary

DeFi protocol exploit losses fell from a $2.62 billion peak in 2022 to $534 million in 2024, an 80% decline, according to Web3 security firm Immunefi, with bridge exploits (once 73% of all losses) falling to 3% by 2025 and the median loss per incident dropping from $6 million to $1.5 million. That part of "DeFi learned its lesson" holds up. What it misses: total value locked concentration, measured by the Herfindahl-Hirschman Index across the largest protocols, rose from approximately 1,942 (moderately concentrated) in December 2022 to approximately 3,134 (highly concentrated by US antitrust standards) by June 2026, as capital consolidated into a smaller set of blue-chip protocols, Lido and Aave alone now represent roughly 38% of total TVL, up from a more distributed top tier in 2022. Losses also rebounded in 2026: DeFi protocols lost more than $1.3 billion through roughly two-thirds of the year, already exceeding all of 2024, driven by a new threat model, months-long social engineering campaigns by nation-state actors like North Korea's Lazarus Group against Drift Protocol ($285 million) and KelpDAO ($292 million), rather than the smart-contract bugs and bridge failures that dominated 2022.

What genuinely got better

Start with the part of the claim that is simply true, because it's substantial. Immunefi's 2026 Ecosystem Vulnerability Audit, covering six years of DeFi protocol losses across major blockchains, found exploit-driven losses fell from $2.62 billion in 2022 to $534 million in 2024, an 80% decline, before ticking back up to $680.3 million in 2025, still 74% below the 2022 peak. The composition of those losses shifted dramatically in ways that reflect real architectural improvement, not just smaller numbers. Bridge exploits, which accounted for nearly three-quarters of all DeFi losses in 2022, the year of the $625 million Ronin Bridge hack and the $320 million Wormhole exploit, shrank to just 3% of losses by 2025. Ecosystem-class attacks like oracle manipulation and reentrancy bugs fell from 19% of all breaches in 2022 to below 1% in 2025. Infrastructure failures, including key compromises, dropped from 30.7% to 10.3% of incidents. The median loss per incident fell 75%, from $6 million in 2022 to $1.5 million in 2025.

None of that is spin. It reflects specific, identifiable engineering responses: better bridge validator design after Ronin and Wormhole, more rigorous oracle architecture after years of manipulation exploits, and more mature key-management practices industry-wide. If the "DeFi learned its lesson" claim were only about whether individual protocols got harder to exploit through code-level attacks, the data would support it clearly.

The Paradox The same flight to safety concentrated the ecosystem

Here is what the exploit statistics don't capture. In the immediate aftermath of Terra and FTX, in December 2022, DeFi's total value locked had fallen to $39.37 billion, spread across a top tier that included Lido and MakerDAO (both just above $5 billion), and Aave, Curve, Uniswap, and Convex Finance clustered closely together, each above $3 billion. Using those figures, the top six protocols accounted for roughly two-thirds of total TVL, with the remaining third spread across the long tail, a Herfindahl-Hirschman Index of approximately 1,942, which the US Department of Justice's own merger guidelines classify as "moderately concentrated."

By June 2026, the picture had changed shape entirely. Total DeFi TVL stood at $71.77 billion, but Lido alone held $15.17 billion and Aave $12.10 billion, a combined 38% of the entire ecosystem in just two protocols. Adding Morpho Blue ($6.83 billion) and SparkLend ($3.32 billion) brought the top four to 52% of all TVL. Run the same Herfindahl-Hirschman calculation on this snapshot and the index rises to approximately 3,134, comfortably inside the "highly concentrated" band above 2,500. The market did not diversify after its near-death experience. It consolidated, hard, into a small set of protocols that survived multiple cycles and earned enough trust to absorb an outsized share of the capital that returned.

MetricDec 2022 (post-FTX)Jun 2026Direction
Total DeFi TVL$39.37B$71.77BGrew
Top-protocol HHI~1,942 (moderate)~3,134 (high)More concentrated
Top 2 protocols' combined share~33% (Lido+MakerDAO)~38% (Lido+Aave)More concentrated
Exploit losses (annual)$2.62B (2022)$534M (2024 low)Improved

This is not a criticism of any individual protocol's decisions, and it is arguably rational behavior by allocators: after watching Terra and FTX evaporate, moving capital toward the protocols with the longest, most audited, most battle-tested track records is a sensible individual response. The problem is what it does in aggregate. A higher HHI means a single protocol-level failure now has a larger systemic footprint than it did in 2022. When the North Korea-linked KelpDAO exploit hit a LayerZero bridge configuration in April 2026, the downstream contagion produced up to $230 million in bad debt on Aave alone and triggered $13 billion in DeFi-wide TVL withdrawals within 48 hours, a systemic reaction to a single incident that a more distributed 2022-style market structure would have been less exposed to.

"The downstream contagion produced up to $230 million in bad debt on Aave and triggered $13 billion in DeFi TVL withdrawals within 48 hours." Immunefi, on the KelpDAO/Lazarus Group exploit's ecosystem-wide contagion, April 2026

2026 is quietly re-testing the improvement trend

The exploit-decline story also has a 2026 problem the "lesson learned" framing tends to skip. DeFi protocols lost more than $1.3 billion to hacks and exploits through roughly the first two-thirds of 2026, already exceeding the entire $534 million total for 2024 and closing in on 2025's full-year $680.3 million. Two incidents eighteen days apart, Drift Protocol ($285 million) and KelpDAO ($292 million), together account for more than $577 million, and both are attributed to North Korea's Lazarus Group, the same actor behind the 2022 Ronin Bridge hack. Against a total 2026 loss figure of roughly $1.3 billion, Lazarus alone accounts for at least 44% of stolen funds.

What makes 2026's losses different from 2022's is the method, not just the target. The Drift Protocol breach was not a smart-contract bug; it was a six-month social engineering operation, Lazarus operatives building trust with developers and targeting specific session credentials, combined with governance manipulation and oracle abuse once inside. This is a materially different threat model than the ecosystem-class code exploits that dominated 2022, and it is one that better audits and more rigorous bridge architecture, the exact fixes credited with 2022 to 2025's improvement, do very little to prevent. Measured as a share of total value locked, the annualized 2026 loss rate works out to roughly 2.7%, up sharply from 2025's 0.36%, though still well below 2022's 6.65% peak rate.

The bull case
  • Code-level exploit categories that dominated 2022 (bridges, oracle manipulation, infrastructure compromise) have genuinely and dramatically declined as a share of total losses
  • Median loss per incident fell 75% from 2022 to 2025, showing individual failures are contained more effectively even when they occur
  • TVL concentration in blue-chip protocols reflects earned trust and multi-cycle survival, not carelessness; Lido and Aave have each operated through multiple full bear-bull cycles without a protocol-level failure
  • 2026's loss rate (2.7% annualized), while worse than 2025, remains well below 2022's 6.65% peak, consistent with a genuine multi-year improvement even accounting for a bad year
The bear case
  • TVL concentration has risen from moderately concentrated to highly concentrated by US antitrust standards since the 2022 crash, the opposite of what "structurally safer" implies about systemic risk
  • A single 2026 exploit produced $230 million in contagion losses on an unrelated protocol and $13 billion in ecosystem-wide withdrawals within 48 hours, evidence of exactly the interconnected fragility higher concentration creates
  • 2026's exploit losses already exceed all of 2024 with a third of the year still to go, breaking the clean multi-year improvement narrative
  • The threat model has shifted toward long-horizon, nation-state social engineering, a category that audits and bridge redesigns, the fixes credited with 2022-2025's improvement, are not built to prevent

The tool: measuring both dimensions at once

The DN DeFi Systemic Concentration Heatmap below has two panels. The first computes a Herfindahl-Hirschman concentration score from any set of protocol TVL figures you enter, classified using the same US Department of Justice thresholds used in antitrust merger review. The second computes an exploit loss rate, annual losses as a share of total value locked, so you can compare years on a normalized basis rather than raw dollars. Load the real Dec 2022 and June 2026 snapshots to see the concentration shift for yourself, and the 2022, 2025, and 2026 loss-rate presets to see that the improvement trend, while real, was not a straight line.

DN Proprietary Instrument

DN DeFi Systemic Concentration Heatmap

Two panels: TVL concentration (HHI) using real US antitrust thresholds, and exploit loss rate normalized against total value locked, so you can compare any year on equal footing.

Panel 1 · TVL Concentration (HHI)

Protocol 1 TVL ($B)
Protocol 2 TVL ($B)
Protocol 3 TVL ($B)
Protocol 4 TVL ($B)
Protocol 5 TVL ($B)
Protocol 6 TVL ($B)
Total ecosystem TVL ($B)

Load a real snapshot

Panel 2 · Exploit Loss Rate

Annual exploit losses ($B)
Total value locked ($B)

Load a real year

Panel 1: HHI = Σ (share% of each entity)², including a residual "all other protocols" bucket for the remainder of total TVL not covered by your named entries. This uses the same methodology and thresholds as the US Department of Justice/FTC Horizontal Merger Guidelines: below 1,500 is unconcentrated, 1,500-2,500 is moderately concentrated, above 2,500 is highly concentrated. Because the "other" bucket is treated as a single entity even though it likely contains hundreds of smaller protocols, this method is a conservative (lower-bound) estimate of true fragmentation in the long tail, and a correspondingly reliable read on how concentrated the top of the market has become.

Panel 2: Loss rate = annual exploit losses ÷ total value locked, both in the same units. This normalizes raw dollar losses against the size of the pool they were drawn from, so a $680 million loss year against a $190 billion ecosystem is treated very differently from the same dollar loss against a $40 billion ecosystem. Figures sourced from Immunefi's 2026 Ecosystem Vulnerability Audit and DefiLlama-based TVL trackers, cross-referenced against multiple named sources in the article above.

DN DeFi Systemic Concentration Heatmap is an illustrative educational model, not financial or security advice. It does not predict future exploits or protocol failures. Not a recommendation to use or avoid any specific protocol. May be reproduced with attribution to decentralised.news.

What would actually confirm or kill this thesis

Two specific things to watch. If TVL concentration keeps rising toward the top two or three protocols while exploit losses stay elevated above 2025's rate through the rest of 2026, that combination would confirm the bear case directly: a smaller number of larger, more interconnected failure points, hit more often, is a worse systemic structure than 2022's, regardless of how much safer any individual protocol's code has become. If instead 2026's loss spike proves to be a one-year anomaly driven by a specific, unusually capable threat actor, and the loss rate reverts back toward 2025's 0.36% while concentration stabilizes rather than continuing to climb, that would support the more optimistic reading: DeFi's core security posture has structurally improved, and 2026 was simply a bad year against an adversary category (nation-state social engineering) the whole industry, not just DeFi, is still learning to defend against.

Positioning around a genuinely mixed picture

None of this is a signal to exit or pile into any specific protocol. For readers looking to size DeFi exposure with both dimensions, concentration and exploit trend, in mind rather than relying on either half of the "DeFi is safer now" claim alone, Bybit and OKX both offer direct access to the underlying tokens of the protocols discussed here, and VALR provides regulated access for South African readers.

Frequently asked questions

Partly. Exploit-driven losses fell 80% from $2.62 billion in 2022 to $534 million in 2024, and the categories of attack that dominated 2022 (bridges, oracle manipulation, infrastructure compromise) declined sharply. But total value locked concentration rose over the same period, from moderately concentrated to highly concentrated by US antitrust standards, meaning the ecosystem became more fragile in a different, structural sense even as individual protocols became harder to hack.
The HHI is a standard concentration measure, calculated as the sum of squared market shares, used by US antitrust regulators to classify markets as unconcentrated (below 1,500), moderately concentrated (1,500-2,500), or highly concentrated (above 2,500). Applied to DeFi TVL, it captures how much of the ecosystem's total capital sits in a small number of protocols.
Significantly more concentrated. In December 2022, the top DeFi protocols produced an estimated HHI of approximately 1,942 (moderately concentrated). By June 2026, with Lido and Aave alone holding roughly 38% of all TVL, the estimated HHI had risen to approximately 3,134 (highly concentrated).
Primarily due to a new threat model: months-long social engineering campaigns by nation-state actors, particularly North Korea's Lazarus Group, against Drift Protocol ($285 million) and KelpDAO ($292 million), rather than the smart-contract code bugs and bridge failures that dominated 2022. These campaigns build trust with developers over months and are not well addressed by the audits and bridge redesigns credited with the 2022-2025 improvement.
Much less so than in 2022. Bridge exploits accounted for roughly 73% of all DeFi losses in 2022 but fell to just 3% of losses by 2025, according to Immunefi, reflecting genuine architectural improvements following high-profile failures like Ronin Bridge ($625 million) and Wormhole ($320 million).
Yes, it changes the systemic footprint of any single failure. When the KelpDAO exploit hit in April 2026, the contagion produced up to $230 million in bad debt on the unrelated Aave protocol and triggered $13 billion in ecosystem-wide TVL withdrawals within 48 hours, an outcome more likely in a market where capital is concentrated in a small number of interconnected protocols.
A two-panel tool. The first computes a Herfindahl-Hirschman concentration score from protocol TVL figures you enter, using real US antitrust thresholds. The second computes an exploit loss rate (annual losses as a share of total value locked) so different years can be compared on equal footing rather than by raw dollar figures alone.
Yes. The median loss per DeFi exploit incident fell from $6 million in 2022 to $1.5 million in 2025, a 75% decline, according to Immunefi, even as the total number of discrete incidents has trended upward, suggesting more frequent but generally less catastrophic individual failures.

DN-internal: This piece connects to the DN Custody Chain Scanner's attestation-transparency framework and the DN Debasement Divergence Ledger's systemic-risk lens, applying concentration analysis to DeFi's on-chain capital structure rather than sovereign debt or custodial reserves.

Sources: Immunefi, "The Ecosystem Vulnerability Scoreboard: 6 Years of DeFi Loss Data" (2026 Ecosystem Vulnerability Audit); DeepStrike, "DeFi Hacks & Exploits Statistics 2026"; TooBit, "DeFi exploit losses drop 74% in 2025"; Cryptonews.net, "DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working"; Phemex, "Every Major DeFi Hack in 2026 So Far"; CoinLaw, "DeFi TVL drops to $71.77 billion in 2026"; Cryptonomist, "Collapse of the TVL crypto in 2022"; Blockgeeks, "2022 Market Overview Report"; dcenter Substack, "DeFi in 2023: top 5 protocols."
As of: September 10, 2026. Not financial or security advice. This is high-risk, YMYL financial content; figures reflect the most recent verified reporting available at time of writing and will change as the year progresses. The DeFi Systemic Concentration Heatmap is an illustrative educational model, not a live feed or security audit.

Newsletter

Get the most talked about stories directly in your inbox

Mission

We are dedicated to delivering the best digital asset news, reviews, guides, interviews, and more. Stay tuned!

Email: press@decentralised.news

Copyright © 2026 Decentralised News. All rights reserved.