Skip to main content

Shepley Capital

DEFI & WEB3
DeFi and Web3 - Cryptopedia by Shepley Capital

Smart Contract Exploits Explained: How DeFi Hacks Work and How to Protect Yourself

A smart contract exploit is an attack on a DeFi protocol that takes advantage of a bug, logic error, or economic design flaw in the protocol’s code to extract funds or manipulate the protocol’s behaviour in ways that benefit the attacker at the expense of other users. Unlike hacks of centralised systems (where attackers typically breach password authentication, steal private keys, or exploit server vulnerabilities), smart contract exploits attack the logic of immutable on-chain programs that cannot be updated without a governance process. The attacker does not “break in” to anything; they interact with the smart contract in ways that the contract’s code allows but that the developers did not intend. This distinction matters for Australian DeFi investors because it means that well-intentioned, fully transparent code can still be exploited if the logic contains vulnerabilities, and that the exploited contract continues running exactly as coded — the exploit is not a bug in the blockchain, but a bug in the specific code deployed by the protocol. Understanding how exploits work is the foundation of understanding the DeFi security landscape and making informed decisions about which DeFi protocols to trust with capital.

Reentrancy: The Original Smart Contract Vulnerability

Reentrancy is the vulnerability class that made smart contract security famous, through the 2016 DAO hack that led to the Ethereum hard fork. A reentrancy vulnerability occurs when a smart contract sends ETH or calls an external contract before updating its own state, allowing the external contract to call back into the original before the state update has occurred. The classic pattern: Contract A processes a withdrawal request by (1) sending ETH to the user’s address, then (2) deducting the withdrawn amount from the user’s balance. If the user’s address is another smart contract rather than a simple wallet, the receive function of that contract is called when ETH arrives. At this point, the original contract has sent the ETH but has not yet updated the balance, so a recursive call back into Contract A at this moment shows the balance still at the full original value, allowing another withdrawal. This recursive cycle continues until the contract runs out of ETH or gas.

Modern DeFi protocol development has largely addressed simple reentrancy through standardised patterns: the “checks-effects-interactions” pattern (updating internal state before making any external calls) and reentrancy guard modifiers (which set a lock flag at the start of a function and check it before re-entry is allowed). These patterns are now standard in smart contract development and are verified by all reputable DeFi smart contract auditors. The risk today is in cross-function reentrancy (where two different functions in the same contract interact through reentrancy in ways that create unexpected state combinations) and cross-contract reentrancy (where reentrancy through one contract in a DeFi protocol stack creates vulnerabilities in another contract in the same stack). These more sophisticated reentrancy patterns have appeared in audited protocols post-2020, demonstrating that well-known vulnerability classes continue to evolve. The history of DeFi hacks is partly a chronicle of increasingly sophisticated variations on foundational smart contract security failures.

For Australian DeFi investors evaluating whether a protocol is vulnerable to reentrancy, the primary indicator is the audit track record: DeFi smart contract audits from reputable firms explicitly check for all known reentrancy patterns. A recent audit from a top-tier firm that found and resolved reentrancy issues is strong evidence that the protocol is protected against this class. However, the caveat applies: if the protocol has been materially updated since its last audit, the updated code may have reintroduced vulnerabilities that the audit covered in the previous version. Checking the audit date against the deployment date of the current contract version (verifiable on Etherscan) confirms whether the audit covers the code currently running. For any DeFi protocol you are considering, the combination of recent audit coverage and smart contract code verification provides the minimum assurance that standard vulnerabilities like reentrancy have been addressed.

Flash Loan Attacks

Flash loan attacks frequently use reentrancy as a component of more complex exploit strategies. A flash loan provides the attacker with an uncollateralised loan for the duration of a single transaction block; if this capital is used to trigger a reentrancy in the target protocol, the reentrancy can be exploited at a scale that requires enormous capital (making it impractical without the flash loan) at essentially zero cost (since the flash loan is repaid within the same transaction). The Euler Finance hack (2023) used a combination of flash loans and a specific vulnerability in the donate() function to create a large artificial bad debt while simultaneously holding a donation claim against the protocol. Australian DeFi investors who understand that flash loans amplify the impact of any reentrancy vulnerability to potentially unlimited scale can appreciate why reentrancy protection is taken so seriously in modern DeFi protocol design and security audit practice.

The ATO tax treatment of funds lost through reentrancy exploits and other DeFi smart contract exploits follows the general principles for crypto losses from exploitation: once it is clear the funds are irrecoverable (no reasonable prospect of recovery and the loss is confirmed), the loss is treated as a capital loss in the income year the loss is established. For Australian DeFi investors who suffer exploit losses, the ATO guidance on crypto asset abandonment and irrecoverable loss is the relevant framework, and detailed documentation of the exploit (transaction records, the exploit incident report, the confirmation of irrecoverability) supports the capital loss claim. Getting the timing and classification correct for CGT purposes in exploit scenarios requires consultation with a crypto-specialist accountant who understands DeFi tax treatment in Australia.

Oracle Manipulation and Flash Loan Attacks

Oracle manipulation exploits are attacks that target the price data inputs that DeFi protocols use to make decisions about collateral values, liquidation thresholds, and token pricing. Many DeFi lending protocols and decentralised derivatives rely on on-chain price oracles (smart contracts that provide the current price of assets) for core functions: calculating whether a borrower’s collateral value exceeds the required threshold, determining the liquidation price for a position, and pricing the minting or redemption of protocol tokens. If an attacker can temporarily manipulate the price reported by these oracles, they can exploit the protocol in ways the developers did not intend: minting more tokens than should be allowed (by artificially inflating collateral value), triggering artificial liquidations (by artificially deflating asset prices), or borrowing against temporarily inflated collateral values and then defaulting when prices return to normal.

The flash loan attack is the mechanism that makes oracle manipulation financially practical: without flash loans, manipulating an on-chain price oracle requires purchasing enormous amounts of a token to shift the pool price, then selling after the exploit (which is expensive in fees and slippage). With a flash loan, the attacker borrows a massive capital position atomically, uses it to manipulate the oracle price within the same transaction, exploits the protocol with the manipulated price, and repays the flash loan within the same transaction — all happening in a single block, leaving no residual cost if the attack fails (the transaction reverts and the flash loan is never technically extended). The efficiency of flash loan-assisted oracle manipulation made it the dominant exploit technique of 2020-2022, affecting dozens of DeFi protocols that used spot price oracles (which are easily manipulated within a single block) rather than time-weighted average price oracles (which require sustained price manipulation over multiple blocks, making flash loan attacks impractical against them).

Protocol defences against oracle manipulation have improved substantially. The primary defence is using time-weighted average price (TWAP) oracles rather than spot price oracles: a TWAP oracle computes the average price over multiple blocks (typically 30 minutes to several hours of observations), making any manipulation within a single block have negligible effect on the reported price. Chainlink’s price feeds provide off-chain aggregated price data from multiple sources, further reducing the manipulability of any single on-chain liquidity pool. DeFi protocols built after 2021 almost universally use robust oracle designs that eliminate the simple flash-loan-assisted spot price manipulation attacks that affected earlier protocols. For Australian DeFi investors evaluating oracle risk, checking which oracle system a protocol uses (identifiable from the protocol’s documentation or smart contract code) and whether it uses spot prices or TWAPs is a relevant due diligence question. The DeFi security track record for protocols using Chainlink or TWAP oracles is substantially better than those that relied on single-source spot prices.

Smart Contract

Access control vulnerabilities (where protocol functions that should be restricted to privileged addresses are accessible by any caller) represent a simpler but persistent smart contract vulnerability class. These occur when the developer forgets to add an access control modifier (like Solidity’s onlyOwner or onlyRole) to a function that should be privileged, or implements an access control check incorrectly (checking the wrong variable or failing in some edge case). The impact can be severe: if a function that mints new protocol tokens has no access control, any user can mint unlimited tokens and drain the protocol’s value. If a function that changes the protocol’s oracle address has no access control, an attacker can redirect the protocol to read prices from a malicious oracle they control. Smart contract audits check all privileged functions for appropriate access controls, making this a well-covered vulnerability class in audited protocols. For unaudited or poorly audited DeFi protocols, access control failures remain one of the most common exploit types, and the absence of a credible audit from a reputable firm is a direct indicator of elevated access control risk.

For Australian DeFi investors seeking to evaluate overall smart contract exploit risk for any specific protocol, the practical framework combines: audit quality (which firm, how recent, what findings were identified and resolved); oracle design (TWAP or Chainlink over spot price); access control architecture (multi-sig protected, timelock on sensitive functions); historical exploit record (any incidents, how were they handled and did users get compensated); and current bug bounty programme (indicating ongoing security investment). Protocols that score well on all these dimensions (multiple recent audits, robust oracle, multi-sig access control, clean exploit history, active bug bounty) represent the lower end of smart contract exploit risk in a still-risky ecosystem. Applying position sizing that reflects the residual risk even for well-secured protocols maintains the portfolio discipline needed for long-term DeFi investing success. Shepley Capital membership tracks the smart contract security landscape for Australian DeFi investors.

Economic Design Exploits and Governance Attacks

Economic design exploits target the incentive structures and mathematical models underlying DeFi protocols rather than code-level bugs. A protocol whose economic design allows an attacker to extract value by interacting with it in technically valid but economically exploitative ways has an economic vulnerability even if the smart contract code contains no bugs. The collapse of algorithmic stablecoins (particularly TerraUSD/LUNA in May 2022) was fundamentally an economic design exploit: the death spiral mechanism was baked into the design, triggered when market conditions exceeded the design’s stability assumptions. Similarly, liquidity pool impermanent loss in concentrated AMM positions can be exploited by large traders who strategically time their swaps to maximise losses for specific LP positions. For Australian DeFi investors evaluating protocols, understanding the economic model at a conceptual level (not just the code) is an important supplement to technical audit coverage.

Governance attacks (where an adversary accumulates enough governance tokens to pass malicious proposals) represent a category of exploit that operates through the legitimate governance process rather than through code vulnerability. A governance attack might involve: borrowing governance tokens through DeFi flash loans to pass a proposal in a single transaction, purchasing governance tokens on the open market over time to build a controlling stake, or exploiting low participation rates in governance votes to pass proposals with a minority of total token holders. The most famous governance attack (on Beanstalk Protocol in April 2022) used a flash loan to acquire enough governance tokens to pass a malicious proposal that drained AUD 250+ million from the protocol in a single block. DeFi governance design has responded by implementing: minimum holding periods before new tokens can vote, timelocks on proposal execution (creating a window for community response), and higher quorum requirements. For Australian DeFi investors evaluating DeFi protocol governance, checking timelock duration (24-72 hours minimum between approval and execution) and whether flash loan borrowing of governance tokens is prevented are key governance security indicators.

Defi Protocols

Composability exploits arise from the interactions between multiple DeFi protocols rather than from vulnerabilities in any single protocol. When Protocol A integrates with Protocol B (using B’s output as input), the combined system creates attack surfaces that neither Protocol A’s nor Protocol B’s individual audits cover. An attacker who understands both protocols can construct a sequence of interactions across both that violates assumptions made by each protocol individually. The Cream Finance repeated exploits (2021) demonstrated this pattern: Cream integrated with numerous protocols, and attackers found ways to exploit the interactions between Cream’s lending logic and the price mechanics of protocols it integrated with. For Australian DeFi investors who use complex multi-protocol strategies, composability exploit risk is an additional dimension of DeFi security beyond the individual protocol security of each component, and it increases with the number and depth of protocol integrations in any position. Shepley Capital membership provides analysis of composability risks in complex DeFi strategies.

Protecting against economic and governance exploits as an Australian DeFi investor requires practical portfolio management rather than code-level security (which is the domain of protocol developers). The practical measures: diversify across multiple protocols so no single governance attack or economic exploit eliminates more than a defined maximum percentage of your DeFi portfolio; monitor governance proposal submissions for protocols you are invested in (using notification services or manual forum checks) so you are aware of any malicious proposals being submitted; maintain understanding of the economic model of each protocol you use at a level sufficient to identify if the conditions that could trigger economic failure are approaching; and apply DeFi position sizing limits that reflect your overall risk management framework rather than optimising purely for yield. Shepley Capital membership provides the ongoing DeFi security analysis and governance monitoring to support Australian DeFi investors.

Frequently Asked Questions

What is a smart contract exploit?

A smart contract exploit is an attack on a DeFi protocol that takes advantage of a bug, logic error, or economic design flaw in the protocol's code to extract funds or manipulate the protocol's behaviour in ways that benefit the attacker at the expense of other users. Unlike hacks of centralised systems (where attackers typically breach password authentication, steal private keys, or exploit server vulnerabilities), smart contract exploits attack the logic of immutable on-chain programs that cannot be updated without a governance process. The attacker does not "break in" to anything; they interact with the smart contract in ways that the contract's code allows but that the developers did not intend.

What is a reentrancy vulnerability?

Reentrancy is the vulnerability class that made smart contract security famous, through the 2016 DAO hack that led to the Ethereum hard fork. A reentrancy vulnerability occurs when a smart contract sends ETH or calls an external contract before updating its own state, allowing the external contract to call back into the original before the state update has occurred. The classic pattern: Contract A processes a withdrawal request by (1) sending ETH to the user's address, then (2) deducting the withdrawn amount from the user's balance.

How do flash loan attacks work?

Flash loan attacks frequently use reentrancy as a component of more complex exploit strategies. A flash loan provides the attacker with an uncollateralised loan for the duration of a single transaction block; if this capital is used to trigger a reentrancy in the target protocol, the reentrancy can be exploited at a scale that requires enormous capital (making it impractical without the flash loan) at essentially zero cost (since the flash loan is repaid within the same transaction). The Euler Finance hack (2023) used a combination of flash loans and a specific vulnerability in the donate() function to create a large artificial bad debt while simultaneously holding a donation claim against the protocol.

What is oracle manipulation?

Oracle manipulation exploits are attacks that target the price data inputs that DeFi protocols use to make decisions about collateral values, liquidation thresholds, and token pricing. Many DeFi lending protocols and decentralised derivatives rely on on-chain price oracles (smart contracts that provide the current price of assets) for core functions: calculating whether a borrower's collateral value exceeds the required threshold, determining the liquidation price for a position, and pricing the minting or redemption of protocol tokens. If an attacker can temporarily manipulate the price reported by these oracles, they can exploit the protocol in ways the developers did not intend: minting more tokens than should be allowed (by artificially inflating collateral value), triggering artificial liquidations (by artificially deflating asset prices), or borrowing against temporarily inflated collateral values and then defaulting when prices return to normal.

What are access control vulnerabilities?

Access control vulnerabilities (where protocol functions that should be restricted to privileged addresses are accessible by any caller) represent a simpler but persistent smart contract vulnerability class. These occur when the developer forgets to add an access control modifier (like Solidity's onlyOwner or onlyRole) to a function that should be privileged, or implements an access control check incorrectly (checking the wrong variable or failing in some edge case). The impact can be severe: if a function that mints new protocol tokens has no access control, any user can mint unlimited tokens and drain the protocol's value.

What are economic design and governance attacks?

Economic design exploits target the incentive structures and mathematical models underlying DeFi protocols rather than code-level bugs. A protocol whose economic design allows an attacker to extract value by interacting with it in technically valid but economically exploitative ways has an economic vulnerability even if the smart contract code contains no bugs. The collapse of algorithmic stablecoins (particularly TerraUSD/LUNA in May 2022) was fundamentally an economic design exploit: the death spiral mechanism was baked into the design, triggered when market conditions exceeded the design's stability assumptions.

What are composability exploits?

Composability exploits arise from the interactions between multiple DeFi protocols rather than from vulnerabilities in any single protocol. When Protocol A integrates with Protocol B (using B's output as input), the combined system creates attack surfaces that neither Protocol A's nor Protocol B's individual audits cover. An attacker who understands both protocols can construct a sequence of interactions across both that violates assumptions made by each protocol individually.

What are the risks associated with Smart Contract Exploits?

Smart contract exploits are the defining risk of DeFi because they can drain a protocol completely and irreversibly, with no support desk and no recourse. Audits reduce but do not remove the risk, and heavily audited protocols have still been exploited. Composability makes it worse, since a protocol can fail because of a vulnerability in a different protocol it depends on. Position sizing that assumes total loss of any single protocol is the only protection that holds.

Choose your next topic from our Cryptopedia​

Grow your crypto portfolio with the latest insights, straight to your inbox!

Join 10,150+ CEOs, Business Owners, Parents, Students, & more receiving actionable crypto insights to grow their portfolios.