Elite security assurance for Layer 1s, DeFi protocols, and Web3 infrastructure.
Feb 25 • 9 tweets • 2 min read
We analyzed the 100 largest protocol hacks - $10.77 billion in total losses.
Only 20% were audited.
Audited protocols = just 10.8% of losses.
Audits work. But when audited protocols DO get exploited, the cause is always the same.
A thread on what the data actually shows:
80.5% of losses in 2024 came from off-chain attack vectors.
Key compromise. Social engineering. UI manipulation. Custody infrastructure.
Not code bugs.
The largest hacks aren't exploiting smart contracts. They're exploiting business processes.
(Source: @HalbornSecurity Top 100 DeFi Hacks Report, 2025 edition)