
Research report
What 2025’s data reveals about security maturity, preventability, and what enterprise teams must change in 2026.
PDF, 22 pages
2025 dataset, EVM exploits
49 of 50
exploits preventable before deployment with deterministic testing
~$240M
in code-level losses classified as preventable (backtested)
Exploit losses$121.1M
largest single incident (Balancer), from precision and rounding bias in accounting logic
This report evaluates 2025’s EVM exploit landscape through one high-stakes question, did the vulnerable logic exist before deployment, and could a team have proven it unsafe earlier. Across the dataset, losses concentrate into repeatable logic and invariant failures, and the majority of incidents fall into detectable classes that can be surfaced with deterministic testing, not post-hoc forensics.
Snapshot, the numbers behind 2025’s onchain failures
50
EVM smart contract exploits reviewed (Solidity, onchain logic failures).
49
Exploits considered preventable prior to deployment with deterministic testing.
98%
Of incidents in the dataset fell within detectable vulnerability classes. Only one was outside scope.
~$240M
In backtested, code-level losses classified as preventable in the in-scope set.
$121.1M
Largest single breakdown (Balancer), driven by precision and rounding bias in accounting logic.
Logic
Dominant failure class by count. Valid calls, and the protocol behaved as written.
Risk owners evaluating onchain exposure and looking for actionable guidance on how to address it before capital is at stake.
CISOs and security leaders building durable security systems, controls, and processes that stand up under adversarial conditions.
Protocol engineers, core devs, and engineering leaders who want to ship securely from day one, and validate invariants before audits and deployments.
See what broke, why it broke, and what 2025’s exploit data suggests enterprise teams should validate before the next deployment.