30 Security Mistakes DeFi Developers Make
DeFi protocols are high-value targets. These common mistakes have led to billions in losses. Learn from others' failures to build more secure protocols.
Oracle Mistakes
Price oracle vulnerabilities that lead to manipulation.
Using spot prices from DEXes
Using instantaneous spot prices from AMMs allows flash loan manipulation to move prices within a single transaction.
No staleness check on oracle data
Using stale oracle prices when Chainlink hasn't updated in hours or days.
Missing oracle fallback
Protocol breaks completely when primary oracle fails or returns zero.
Ignoring oracle decimal differences
Assuming all Chainlink feeds have 8 decimals when some have different precision.
Single oracle dependency
Trusting one oracle source without cross-validation for critical operations.
Flash Loan Mistakes
Vulnerabilities exploitable through flash loans.
Governance votes based on current balance
Allowing votes based on token balance at time of vote enables flash loan governance attacks.
Rewards based on deposit amount without time lock
Distributing rewards proportional to deposits without lockup allows flash loan reward stealing.
Share price manipulation on first deposit
First depositor can donate tokens to inflate share price, griefing subsequent depositors.
Collateral value from manipulable source
Using AMM liquidity token value based on reserves allows collateral manipulation.
Liquidation triggers based on spot price
Liquidation decisions using spot prices allow predatory liquidations via price manipulation.
Reentrancy Mistakes
Various forms of reentrancy vulnerabilities.
State updates after external calls
Updating balances or state after making external calls violates checks-effects-interactions.
Missing reentrancy guard on withdraw
Withdraw functions making ETH transfers without reentrancy protection.
Cross-contract reentrancy blind spots
Only checking single contract reentrancy when protocol has multiple contracts sharing state.
ERC-777 callback reentrancy
Accepting any ERC-20 without considering ERC-777 tokens have transfer hooks.
Read-only reentrancy in view functions
View functions returning stale data when called during reentrancy.
Math and Logic Mistakes
Calculation errors and business logic flaws.
Division before multiplication
Order of operations causing precision loss. Dividing before multiplying loses precision.
Rounding always favoring users
Rounding in a direction that allows users to extract dust amounts repeatedly.
Unchecked array operations
Loops over unbounded arrays that can grow beyond gas limits.
Integer overflow in fee calculations
Fee percentage times amount overflowing before division.
Missing slippage protection
Swaps without minimum output parameter allowing sandwich attacks.
Incorrect share calculations
Vault share math that allows rounding exploitation or share inflation.
Token Handling Mistakes
Errors in handling various token types.
Assuming all ERC-20s return bool
Not using SafeERC20 when some tokens (USDT) don't return bool on transfer.
Not handling fee-on-transfer tokens
Assuming received amount equals transfer amount for tokens with transfer fees.
Ignoring token decimals
Assuming 18 decimals when USDC has 6 and others vary.
Approval race condition
Approving new amount without resetting to zero first for tokens with approval race condition.
Not considering token blocklists
Ignoring that USDC/USDT can blocklist addresses, breaking protocol flows.
Access Control Mistakes
Permission and authorization vulnerabilities.
Missing access control on critical functions
Administrative functions without onlyOwner or role checks.
Single key controlling everything
One EOA can pause, upgrade, and withdraw all funds.
No timelock on critical operations
Upgrades and parameter changes execute immediately without delay.
Incorrect modifier ordering
Putting access control modifier after other checks allows bypass in some cases.
Key Recommendations
Study every DeFi exploit post-mortem. The patterns repeat with variations.
Get multiple audits from different firms. Each auditor catches different issues.
Deploy with low caps first. Increase limits gradually as protocol proves secure.
Have a bug bounty program. Ethical hackers finding bugs is better than malicious ones.
Build monitoring and alerts from day one. Fast response limits damage.
