Solea Audit Academy consists of three types of members: operators, full-stack developers (including AI and blockchain), and smart contract auditors.
Our primary goal is to become the world's best audit group.
What can a smart contract auditor do?
1. Low-Level Security
We identify actual vulnerabilities from errors discovered by our AI auditing software.
2. High-Level Security
Experienced auditors manually identify vulnerabilities. We classify them as Critical, High, Medium, and Low, and submit detailed reports to help clients understand and remediate them.
We plan to introduce that system to automatically identify and recommend vulnerabilities.
While we cannot guarantee 100% security, our experienced researchers will do their best to minimize security risks.
Major Smart Contract Bugs Drained Hundreds of Millions in DeFi Hacks (2025)
In 2025, while the majority of major cryptocurrency losses stemmed from private key compromises, phishing, and centralized exchange breaches (e.g., the $1.5B Bybit hack), smart contract bugs and vulnerabilities remained a significant issue in DeFi protocols. These accounted for roughly 8-11% of total hack losses, equating to approximately $263-325 million across various incidents.
Improved auditing and security practices led to a relative decline in DeFi/smart contract exploits compared to prior years, but several high-profile cases highlighted persistent risks like logic flaws, overflow/underflow errors, reentrancy, rounding precision issues, and input validation failures.
Here are some notable 2025 cryptocurrency hacking incidents specifically caused by smart contract bugs or vulnerabilities:
- Cetus Protocol (May 2025): The largest pure smart contract exploit of the year. An arithmetic overflow bug in a shared math library (on the Sui blockchain) allowed attackers to inject spoof tokens, manipulate liquidity, and drain pools in under 15 minutes. Losses: ~$223 million.
- Balancer (November 2025): Attackers exploited a rounding direction/precision error in V2 Composable Stable Pools, enabling repeated drains through chained transactions. Losses: ~$120-128 million (across Balancer and forks like Beets/Bex).
- GMX V1 (July 2025): A reentrancy vulnerability (stemming from an unaudited 2022 patch) allowed manipulation of token prices and draining. Initially ~$42 million exposed (white-hat recovery in one case).
- Abracadabra (Early 2025): Flash loan combined with a rounding vulnerability in lending contracts led to over-borrowing. Losses: ~$1.8-13 million (reports vary).
- Mobius DAO (May 2025): Mathematical bug in minting function (double multiplication error in price data conversion). Part of a month with multiple contract flaws.
- Other mentions: A March incident with a reentrancy bug in liquidity withdrawal (~$34 million); various smaller exploits involving lack of input validation, oracle manipulation via contract logic, or unchecked external calls.
Overall, common root causes included:
- Integer overflow/underflow
- Reentrancy
- Precision/rounding errors
- Faulty input validation
These underscore that even audited contracts can have overlooked edge cases, especially in complex DeFi interactions. Many protocols now emphasize multiple audits, bug bounties, and formal verification to mitigate such risks. If you're building or investing in DeFi, prioritizing projects with strong security track records is key.
Total: 3-10 days | From $800 | Public reports on GitHub.
First 5 projects: 🎁 Heavy discounts + free if tiny! Who's launching soon?
Be the first to apply!
Reward: 10% commission for referrals. Let's grow the community! 🔥
https://t.co/eNrDLwyQa0
#SoleaAuditLab
📌 The Mango Markets Exploit
Date: October 11, 2022
Loss: Approximately $100 million
Details: Mango Markets, a decentralized finance (DeFi) platform, was exploited through a combination of price manipulation and a vulnerability in its smart contract. The attacker manipulated the price of the platform's assets to borrow more than they were entitled to, resulting in a significant loss of funds. This incident highlighted the vulnerabilities in DeFi protocols and the potential risks associated with price oracles and liquidity pools.
Impact: The hack not only led to substantial financial losses but also raised concerns about the security of DeFi platforms, emphasizing the critical need for thorough smart contract audits and improved risk management strategies.
💡 A comprehensive audit could have prevented this.
Peter said "Bitcoin has no future"
He doesn't seem to be able to pinpoint the exact cause of the Bitcoin price decline.
Or maybe he's looking further ahead?
One reason for the price decline is his failure to properly audit the smart contract protocol.
📌 The Nomad Token Bridge Hack
Date: August 1, 2022
Loss: Approximately $190 million
Details: The Nomad Token Bridge, designed to facilitate token transfers across different blockchains, suffered a significant exploit when attackers took advantage of a vulnerability in its smart contract. By manipulating the contract's logic, they were able to withdraw a large amount of funds almost instantly. This incident underscored the vulnerabilities present in bridging protocols and the critical need for robust security measures in smart contracts.
Impact: The hack not only led to substantial financial losses but also intensified scrutiny on the security of token bridges, emphasizing the necessity for thorough smart contract audits to safeguard user assets.
💡 A comprehensive audit could have prevented this.