Key Highlights
Total DeFi exploit losses dropped to $680.3 million in 2025, a 74% decline from the $2.62 billion recorded in 2022, with the average loss per exploit falling from $6 million to $1.5 million over the same period.
Bridge exploit losses collapsed from 73% of all DeFi losses in 2022 to just 3% in 2025, while flash-loan attacks fell from 54% of total losses in 2020 to less than 1% by 2025.
Despite growing concern that AI tools are lowering the barrier for attackers, improved smart contract auditing, faster bug bounty response, and stronger security standards are measurably outpacing the evolving threat landscape.
The DeFi ecosystem has become measurably safer over the past three years, according to Immunefi's six-year Ecosystem Vulnerability Scoreboard, which covered exploit-driven losses across major blockchain ecosystems from 2020 through 2025. Total losses fell to $680.3 million in 2025, down 74% from the $2.62 billion peak recorded in 2022, with the average loss per individual exploit declining from $6 million to $1.5 million over the same period.
The improvement is most visible in two historically dominant attack vectors. Bridge exploits, which drove catastrophic losses in 2021 and 2022 as cross-chain infrastructure scaled faster than security practices, fell from 73% of all DeFi losses in 2022 to just 3% in 2025. Flash-loan attacks saw an even steeper decline, dropping from 54% of all losses in 2020 to less than 1% by 2025. Infrastructure failures such as private-key compromises and database breaches also fell, from 30.7% of losses in 2022 to 10.3% in 2025. The full breakdown of attack vectors and loss data is available in Immunefi's published research.
The findings land against a backdrop of heightened concern about AI-assisted attacks. The same AI tools improving security auditing are increasingly accessible to malicious actors, and the industry has debated whether this creates a structural escalation in the threat environment. Immunefi's data suggests the defensive side of that arms race is currently winning: better smart contract standards, broader adoption of formal verification, and faster bug bounty programs have collectively pushed losses down even as protocol total value locked and transaction volume have grown.
Security researchers have noted the trend reflects a maturing industry rather than a permanent resolution. The largest individual exploits still account for a disproportionate share of annual losses, and protocol complexity continues to grow. Immunefi's report points to ongoing vigilance in bridge design, access control, and pre-deployment auditing as the areas where further improvement will have the greatest impact on future loss figures.