DeFi Rekt Report October 2025: $38.6 Million Lost Across 9 Exploits
October 2025 saw a total of $38.63 million lost across nine distinct security incidents in both centralized and decentralized platforms.
April 2024 has played out with a marked decrease in total losses compared to last month. Yet, the landscape of decentralized finance (DeFi) remains challenged by sophisticated exploits and attacks. In this report, we analyze the trends and notable incidents of April.
In the month of April, DeFi observed a decrease in the total losses. The total toll came to around $12,467,500, which is less than what we reported last month at $91,883,000. Even though there has been a decrease in overall loss amount this month, April also showed no successful fund recovery unlike March, where the crypto community recovered a decent sum of $62,500,000. This change reminds us yet again of the types of risk we take when investing in DeFi.
While the month saw various significant losses, the individual losses were less than earlier months this year. Some notable cases are as follows.
First off, Hedgey Finance faced a $2,000,000 loss from a flash loan attack. This points to the continuing weakness against such exploits in DeFi.
Next, with a similar loss quantum, we have xBridge which suffered a $1,900,000 loss because of operational mistakes.
Grand Base witnessed a loss of $1,700,000 because of access control issues, highlighting the crucial importance of gatekeeping access and permissions.
A fake version of the SAGA protocol was the target of a rugpull that resulted in a $1,600,000 loss. This is another poignant reminder that deception is abound, and that we should always verify a project’s legitimacy before committing funds.
Finally, other big-ticket losses include Wilder and Condom, with losses of $1,400,000 and $900,000 respectively, due to access control issues and rugpulls.
The top types of exploits we saw this month can be summed up by rugpulls, flash loan attacks, and access control breaches.
Rugpulls made up six incidents amounting to $3,158,000 lost, underscoring the ongoing risk posed by malicious actors within the community. These kinds of exploits use trust as a tool and manipulate market methods to dishonestly take money from others without leaving much evidence or many chances for getting it back again.
Additionally, as we have seen in many other instances, there were flash loan attacks. This is a common kind of exploit that uses the special features of DeFi protocols to briefly change asset prices. Two attacks of this sort happened, causing a loss worth $2,350,000. These occurrences point out the tactics used by attackers in abusing features of DeFi protocols for personal gain.
Third on the list, we have access control issues. We saw two incidents this month, with a total loss of $3,100,000. The importance of strong access control and careful auditing of smart contracts is highlighted by these events as unauthorized actions can cause significant financial harm.
Furthermore, the ‘Other’ category of exploits included seven incidents that caused a total loss of $3,859,500. These occurrences typically encompass different causes such as security breaches, contract weaknesses, or other threats that are not easily classified into the usual types of DeFi exploits but still lead to similar harm.
The array of exploit types that happened in April 2024 reminds us again of how threats in DeFi are always changing and adjusting. This emphasizes the need for protocols to consistently improve their security, as well as for investors to exercise the needful caution, and stay knowledgeable about possible dangers related with investing in DeFi.
In April 2024, we observed a notable distribution of incidents across various blockchain networks, which emphasized the persistent vulnerabilities within these systems. Below is an analysis of the chains targeted and the categories most affected during this month:
In first place, we have Ethereum: We saw four cases on Ethereum leading to losses of $5,384,500. This underscores Ethereum’s central role in the DeFi sector, where its extensive user base and complex DeFi applications continue to attract attention from attackers.
Next up, BNB Chain: There were seven incidents on Binance Smart Chain, totaling $3,310,000 in losses. The BNB Chain’s popularity due to its compatibility with Ethereum and lower transaction costs also marks it as a frequent target for malicious activities.
In third place, we have Base. Two incidents on Base Chain resulted in $2,050,000 lost. Despite being less prominent than Ethereum or BSC, and being a relatively new chain, Base Chain is firmly on the radar as a target for potential attackers.
Following close behind, we had Solana: We noted three cases on Solana with losses amounting to $1,423,000. As Solana grows in popularity for its high throughput and low fees, it also becomes more appealing to exploiters.
Rounding up the top 5, we have Arbitrum where there was a comparably small, single-incident loss of $300,000.
In April 2024, we registered exploits across a wide range of attack vectors. Here are some of the major ones:
Token platforms: We saw losses of $3,158,000 this month across six cases involving token-based incidents. This has been a recurring theme due to two key reasons. First, that the barrier to entry to creating a malicious token is low, and second, that many tokens tend to be poorly coded from a smart contract risk perspective, as can be seen from many examples having low scores in the De.Fi Scanner.
Bridges: A single case on a blockchain bridge resulted in a substantial loss of $1,900,000. This is perhaps unsurprising, given that bridges are often seen as high-reward targets. After all, bridges tend to have large amounts of liquidity locked, due to their role in allowing users to deposit assets from one chain, and withdraw them on another.
Borrowing and Lending Platforms: Borrowing and Lending platforms are a popular target for a similar reason to bridges – these dapps tend to be core players in any given blockchain ecosystem, and tend to hold a good deal of liquidity. One incident occurred in this category, with a loss of $350,000.
Gaming: GameFi has been a trending narrative in this latest Crypto cycle. GameFi-related dapps, especially those involving NFTs and in-game assets, saw a loss of $1,400,000 in one incident, signaling the increasing attention these platforms are drawing from hackers.
Other Categories: With a total of eight incidents leading to $5,659,500 in losses, this miscellaneous category includes a variety of exploits not confined to any one type of DeFi application, showing the broad scope of security issues that need addressing.
1. Hedgey Finance – $2,000,000
The biggest hack of the month was carried out on April 19 against Hedgey Finance, with attackers using a Balancer Vault flash loan exploit that aimed at the victim contract. They manipulated the createLockedCampaign function and withdrew a considerable amount of USDC and NOBL tokens which led to total loss around $2 million. All assets were converted into DAI, then moved to an externally-owned address.
2. xBridge – $1,900,000
3. Grand Base – $1,700,000
On April 15, Grand Base saw $1.7m being lost when a deployer’s wallet was compromised, allowing unauthorized minting of $GB tokens on the Base chain. This incident caused a massive decline in token value and the transfer of about 615 ETH to Ethereum EOA wallets.
4. SAGA (Fake) – $1,600,000
An impersonator SAGA token on the BNB chain experienced a rug-pull on April 5. This caused about $1.6 million USDT to be lost. The deployer executed a huge token dump in PancakeSwap, which quickly emptied the liquidity pool, leaving investors holding a bag of now-worthless tokens.
5. Wilder – $1,400,000
The Wilder token was compromised April 16 due to a malicious contract upgrade facilitated through the Zero Name Service. Over $1.4 million in tokens were drained, with subsequent laundering attempts made through Tornado Cash. The wallet address “0x6584a486f711eb8ac47abf78a5c8e218ee758fa9” has been identified in connection with the attack.
6. Condom – $900,000
The Condom token team executed a rug pull after their presale on April 4, after gathering over $900,000. They abruptly deleted their social media channels as part of this exit scam. This incident underlines how presale events that promise returns too good to be true should always be subject to strict due diligence, given how easily the perpetrators can make off with the funds raised.
7. Chainge Finance – $716,000
On April 15, Chainge Finance lost $716,000 when funds were siphoned from a potentially-related contract on the Binance (BNB) Chain. The contract was temporarily paused post-exploit to prevent further unauthorized actions.
8. Solareum – $523,000
Solareum faced a security breach on April 2 that led to its eventual shutdown. The breach affected over 300 Solana users, with suspicions initially surrounding the BONKbot trading bot. However, the BONK team refuted this and provided data indicating that victims had interacted with Solareum.
Despite efforts to secure additional funding and enhance security measures, Solareum’s closure was prompted by the recent breach and financial constraints. Users on Solareum’s Telegram channel are demanding answers and potential compensation, while Decrypt’s attempts to reach Solareum for comment remain unanswered.
9. Sumer.Money – $350,000
A flash loan attack on April 12 targeted the Sumer Money protocol on the Base L2 blockchain, draining around $350,000. The attacker utilized an unverified contract for the attack, executing a flash loan of 150 ETH and 645,000 USDC to deposit into Summer ETH and USDC wrapper contracts. This created an opportunity to withdraw an additional 10 wrapped Coinbase Ethereum and 310,000 USDC tokens.
10. Pike Finance – $300,000
The exploit targeted the USDC pool specifically on Pike Beta, with the hacker utilizing forged CCTP messages to drain USDC from multiple chains, including Arbitrum, and Optimism. However, assets on the Base chain and other chains remain unaffected by the exploit. After the exploit stolen funds were bridged the Ethereum mainnet and deposited to the tornado cash.
October 2025 saw a total of $38.63 million lost across nine distinct security incidents in both centralized and decentralized platforms.
The third quarter of 2025 marked yet another turbulent period for the DeFi and wider crypto ecosystem, with $434,124,000 lost to exploits, scams, and security failures across both centralized and decentralized platforms.
June 2025 witnessed another alarming month for Web3 security, with a total of $114,768,000 lost during 11 separate attacks
May 2025 saw both DeFi and CeFi security once again under attack, with $275,953,000 lost across just 8 recorded incidents
April 2025 witnessed a large escalation in exploit volume and value, with a massive $5,919,684,000 being stolen in 10 confirmed events.
Q1 2025 marked one of the worst quarters in blockchain exploit history, with total recorded losses topping $2,052,584,700 across 37 incidents
© De.Fi. All rights reserved.