Unit 4 · Level 3 · The DeFi risk stack
Smart-contract risk
A smart contract does exactly what its code says, including the parts the authors didn't mean. The DAO hack drained roughly $60M back in 2016; the Ronin bridge lost over $600M in 2022; Euler Finance, audited multiple times, lost roughly $200M in 2023 (later returned). None of that means DeFi is doomed. It means audits REDUCE risk and nothing erases it. Deposited money lives one undiscovered bug away from zero.
Free to play. No ads, no token, no account needed to start.
What you get asked
What does a smart-contract audit actually give you?
Auditors are skilled humans reading code under deadline; they catch a lot and miss some. Euler was audited and still lost roughly $200M. Treat 'audited' as a floor, never a ceiling.
An audit ___ smart-contract risk; it never removes it.
Multiple audits by different firms shrink the risk further, but 'unhackable' is a word no honest engineer uses.
Match each safety signal to what it really means:
Stack the signals: audited AND bountied AND battle-tested beats any one alone. A week-old fork has none of the three.
Why have cross-chain bridges suffered some of the biggest hacks in DeFi history?
A bridge is a vault holding everyone's crossing funds at once. Ronin lost over $600M and Wormhole roughly $320M in 2022 alone. Big honeypot, big hunters.
Given that contract risk never hits zero, what's the rational move?
Diversify across contracts like you diversify across assets. Time is the best auditor: code that has guarded billions for years has passed the exam that matters. 🐜
The rest of this unit
Code, oracles, and admin keys: the risks stacked under every APY.