Protocol exploits require specialist investigation.

DeFi attacks are technically complex, fast-moving, and cross-chain. Our analysts include former protocol engineers and smart contract auditors who can reconstruct an exploit at the bytecode level and trace funds across any bridge or DEX.

$1.2B+
DeFi Losses Investigated
120+
Protocol Exploits Analysed
35+
Protocols Covered
8hrs
Avg. Exploit Triage Time

Every DeFi attack type, covered

Our analysts have investigated every major class of DeFi exploit. We know how they work, how funds move after the fact, and which recovery paths are viable for each type.

Flash Loan Attacks

Uncollateralised loans used to manipulate oracle prices within a single transaction block. We reconstruct the full attack sequence and identify the attacker's profit-extraction wallet.

Reentrancy Exploits

Smart contract vulnerabilities that allow recursive calls before state updates. We trace the recursive call tree, quantify losses per affected address, and identify fund destinations.

Oracle Price Manipulation

Attacks that distort on-chain price feeds to drain liquidity pools or lending protocols. We analyse the manipulation mechanism and trace profit flows.

Bridge Exploits

Cross-chain bridge vulnerabilities are responsible for some of the largest DeFi losses. We specialise in tracing funds that cross multiple bridges and settle on different networks.

Governance Attacks

Malicious proposals that pass through a governance mechanism to drain a treasury or alter protocol parameters. We document the vote manipulation and identify controlling wallets.

Rug Pulls & Exit Scams

Premeditated fund extraction by project insiders. We trace liquidity removal events, link deployer wallets to KYC'd exchange accounts, and produce reports for law enforcement.

1

How we investigate a DeFi exploit

01

Exploit Reconstruction

We replay the attack transaction by transaction, reconstructing the attacker's methodology from raw calldata and event logs.

02

Profit Quantification

We calculate the exact funds extracted, broken down by asset, affected address, and transaction block.

03

Attacker Attribution

We trace the deployer address backward to identify funding sources, prior activity, and any exchange deposits that can be linked to the attacker.

04

Fund Tracing

We follow extracted funds across chains, through DEX swaps, bridges, and into centralised exchanges where freezes can be requested.

05

Technical Disclosure

We produce a technical report documenting the vulnerability, attack vector, and security recommendations — suitable for protocol post-mortems and insurance claims.

Deep expertise across the DeFi stack

Our analysts include former engineers from Uniswap Labs, Aave, and leading security audit firms. This gives us first-principles understanding of the protocols we investigate — not just surface-level tracing.

We cover 35+ DeFi categories. If your protocol is not listed, contact us — our team will assess it and bring in specialist expertise as needed.

Lending & Borrowing (Aave, Compound, MakerDAO)
Decentralised Exchanges (Uniswap, Curve, dYdX)
Cross-chain Bridges (Wormhole, Stargate, Hop)
Liquid Staking (Lido, Rocket Pool, Frax)
Perpetuals & Derivatives (GMX, Synthetix, Drift)
Yield Aggregators (Yearn, Convex, Beefy)
NFT Protocols (OpenSea, Blur, Sudoswap)
Real World Asset Protocols (Centrifuge, Maple)