If the code is the contract, what happens when the code is wrong?
In a bank, an error produces a reversal, a reconciliation and possibly a lawsuit. In a smart contract, an error produces a transfer that is final. This lesson is the honest accounting of that difference, and it belongs at the start of the course rather than buried at the end.
The bug classes, named
You do not need to write Solidity to recognise the recurring failure modes:
- Reentrancy. A contract sends value to an external address before updating its own bookkeeping; the recipient calls back in and is paid again against stale state. This is the class that drained The DAO in 2016 and it still appears.
- Access control. A function that should be restricted is left callable by anyone, or an initialiser can be run a second time by a stranger who becomes the owner.
- Arithmetic and rounding. Division truncates; a rounding direction that favours the user, repeated in a loop, is a slow drain.
- Upgrade and proxy logic. The pattern that lets a team fix bugs is itself a bug surface, and a compromised upgrade key is total loss with no exploit required.
- Oracle dependence. The contract's logic is perfect; the price it was told was wrong. Unit 4 covers this in full because it is its own attack class.
- Economic design flaws. Not bugs at all. The code does exactly what was intended, and what was intended turns out to be exploitable at scale. Terra/UST in Unit 3 is the definitive case.
Immutability cuts both ways
A published bug cannot be patched unless an upgrade path was designed in. So protocols face a genuine dilemma: build an upgrade mechanism and you have created an admin key that can also be abused or stolen; refuse one and a discovered flaw is permanent. There is no configuration of this trade-off that removes the risk — only versions that move it.
What an audit is, and what it is not
An audit is a point-in-time review of specific code by humans. That is a real, valuable service. It is not:
- a guarantee, and reputable firms say so in their own reports;
- a review of the protocols yours composes with;
- a review of the economic design;
- a statement about the code deployed after the audit;
- insurance, or any transfer of loss to anyone.
Many exploited protocols had been audited, sometimes more than once. "Audited" reduces the probability of a known bug class. It does not change the loss distribution's tail, which brings us to the numbers.
The documented record
Stated as facts, without commentary:
- The DAO, June 2016 — roughly 3.6 million ETH, via reentrancy.
- Poly Network, August 2021 — roughly $610 million, exploiting cross-chain contract permissions; most was subsequently returned by the attacker.
- Wormhole, February 2022 — roughly $320 million, via a signature-verification flaw in a bridge.
- Ronin bridge, March 2022 — roughly $620 million, via compromised validator keys.
- Euler Finance, March 2023 — roughly $197 million, via a flawed donation/liquidation interaction; the funds were later returned after negotiation.
Two patterns are worth noticing. First, bridges — contracts that pool assets to move value between chains — account for a disproportionate share of the largest losses, because they concentrate collateral behind a single verification routine. Second, industry trackers put cumulative crypto and DeFi exploit losses in the billions of dollars, and recovery is the exception, not the rule.
The sentence this course will not soften
Total loss is a live outcome in DeFi. Not a drawdown, not a bad quarter — zero, with no deposit insurance, no clearing house, no chargeback and usually no counterparty to pursue. A yield figure that does not price that possibility is not a yield figure; it is an advertisement. Everything in the remaining three units should be read against this lesson.
Try it now
- Find the published post-mortem for any one of the incidents above (most are public write-ups from the teams themselves). Identify which bug class from the list it belongs to.
- On defillama.com, open the hacks or exploits section and sort by size. What share of the largest losses are bridges?
- Take any audit report you can find publicly and read only the scope and disclaimer sections. Write one sentence stating exactly what the auditor did and did not claim.