The total: over $10 billion lost to smart contract exploits since The DAO hack in 2016. Most were preventable with a pre-deployment security review. This table shows which ones — and which weren't.
Each post-mortem explains exactly what failed technically and what a pre-deployment audit would have caught.
| Protocol | Date | Amount Lost | Exploit Type | Chain | Audit Preventable? | Post-Mortem |
|---|---|---|---|---|---|---|
| FTX (not smart contract) | Nov 2022 | $8.9B | Fraud / misappropriation (not a smart contract exploit) | Off-chain | Not code | Coming soon |
| Bybit | Feb 2025 | ~$1.5B | Compromised Safe UI / delegatecall substitution | Ethereum | Not code | Read |
| Ronin Bridge | Mar 2022 | $625M | Validator key compromise (5/9 threshold) | Ethereum/Ronin | Code bug | Read |
| Poly Network | Aug 2021 | $611M | Cross-chain parameter manipulation (EthCrossChainManager) | Ethereum/BSC/Polygon | Code bug | Read |
| BNB Bridge | Oct 2022 | $566M | Forge proof attack on BSC Token Hub | BSC | Code bug | Coming soon |
| Wormhole | Feb 2022 | $320M | Missing sysvar check in signature verification (Solana) | Solana/Ethereum | Code bug | Read |
| Euler Finance | Mar 2023 | $197M | Protocol invariant violation via donateToReserves() | Ethereum | Code bug | Read |
| Nomad Bridge | Aug 2022 | $190M | Trusted root initialization to 0x00 in upgrade | Ethereum | Code bug | Read |
| Beanstalk | Apr 2022 | $182M | Flash loan governance attack | Ethereum | Code bug | Coming soon |
| Axie Infinity (Ronin) | Mar 2022 | $173M | Social engineering + key management (overlaps with Ronin) | Ronin | Not code | Coming soon |
| Cream Finance | Oct 2021 | $130M | Flash loan + AMM price oracle manipulation | Ethereum | Code bug | Read |
| BadgerDAO | Dec 2021 | $120M | Frontend compromise (Cloudflare API injection) | Ethereum | Not code | Coming soon |
| Mango Markets | Oct 2022 | $117M | Oracle price manipulation on Solana DEX | Solana | Code bug | Coming soon |
| The DAO | Jun 2016 | $60M | Reentrancy (splitDAO function) | Ethereum | Code bug | Read |
Table shows exploits where recoverable on-chain. Off-chain fraud (FTX etc.) excluded from "smart contract exploits" count.
Of the 10 major exploits above that involved actual code bugs, every single one was a pattern detectable in static analysis or thorough code review. SmartContractAuditor.ai catches reentrancy, access control flaws, oracle dependencies, and arithmetic bugs in under 60 seconds — free to start.
Free vulnerability scan · Instant results · No sales call required