According to Immunefi's 2026 Ecosystem Vulnerability Audit Report shared by ChainCatcher, DeFi protocol losses from hacking attacks declined 74% to approximately $680.3 million in 2025, down from the $2.62 billion peak in 2022. The median loss per individual attack also fell significantly, from $6 million in 2022 to $1.5 million in 2025, reflecting overall improvements in security standards.
Bridge exploits' share of total DeFi losses dropped from 73% in 2022 to 3% in 2025, while flash loan attacks declined from 54% to under 1%. Infrastructure layer risks, including private key leaks and database attacks, decreased from 30.7% to 10.3% over the same period, attributed to improvements in oracle design, reentrancy protection, and access control standards.