A quieter year for exploits is changing how DeFi teams buy security
Losses to smart-contract exploits are running well below the sector's worst years, and the spending that produced that result is shifting from audits to monitoring.

NEW YORK —
Losses from smart-contract exploits are tracking well below the totals of the sector's worst years, and the teams responsible say the improvement owes less to better audits than to what happens after deployment.
The traditional model — commission a review, publish the report, ship the code — produced a document that aged badly. Protocols now upgrade parameters weekly, integrate with contracts they do not control, and depend on oracles maintained elsewhere. None of that is captured by a report written before launch.
The spending has followed. Budgets that once went almost entirely to pre-launch review are being split with continuous monitoring services, formal verification of the highest-value functions, and bug bounty programmes large enough to compete with what an exploit would pay.
Front-end compromises and key management remain the stubborn categories. Several of the year's most expensive incidents involved no contract flaw at all: an interface served from a hijacked domain, or a multisig signer approving a transaction that displayed one thing and did another.
Insurers, who have been trying to price this risk for years, say the shift is visible in their submissions. Applicants increasingly arrive with monitoring coverage and incident-response plans, and price accordingly.
