DeFi lost $600M in H1 2026. Here is how to measure risk.
BACK TO BLOG
May 22, 2026·8 min read

DeFi lost $600M in H1 2026. Here is how to measure risk.

Three protocols. Three different attack vectors. A combined $600 million in losses. And in each case, the thing that failed was not what the security review had been looking at.

Resolv had undergone 18 independent smart contract audits before March 22, 2026. The auditors found nothing wrong. Nothing was wrong with the smart contract. An attacker compromised an AWS key that controlled the minting function, printed 80 million unbacked stablecoins from a $200K deposit, and drained $23 million before the protocol could respond.

Ten days later, Drift Protocol lost $285 million, more than half its TVL, in a social engineering attack that took months to execute. The attacker built a relationship with the team, got legitimate signers to pre-approve transactions they did not understand, and walked away with 18 types of assets while the protocol’s smart contracts executed without error.

Then KelpDAO. On April 18, attackers linked to North Korea’s Lazarus Group targeted the off-chain verification infrastructure for KelpDAO’s cross-chain bridge, fed false data to the single verifier node, and released ~$292 million in rsETH against a burn that never happened. On-chain, every transaction looked valid.

It is a systematic problem with how DeFi risk gets evaluated.


Why evaluating risk in silos leaves critical blind spots

Smart contract audits assess code. They do not assess who holds the admin keys, how those keys are stored, or what happens if an off-chain service gets compromised. They did not catch Resolv, Drift, or KelpDAO: three of the largest losses of 2026.

Operational security reviews assess processes and team structures. They do not assess collateral quality, liquidity depth, or whether a vault’s oracle can respond appropriately when an asset comes under stress. A clean operational review says nothing about collateral risk.

TVL is a size metric. It does not measure risk. A vault with $500M TVL can carry significantly more risk than a vault with $50M TVL if the collateral is illiquid or the price feed is misconfigured.

APY tells you what a vault pays when conditions are stable. It tells you nothing about what happens when conditions change.

None of these signals (audits, operational reviews, TVL, APY) captures the full picture on its own. DeFi users are making allocation decisions based on partial information, and the gaps are where capital gets lost.


What a complete risk assessment covers

A DeFi lending market carries five independent sources of risk. Any evaluation that omits one of them is incomplete.

Collateral quality determines whether the assets backing a loan hold their value under stress and can be liquidated before losses compound. Collateral with thin markets and model-based valuations creates different risk than liquid, mark-to-market assets.

Smart contract risk reflects both the quality of the code and the governance structures surrounding it. Audit count is a proxy, not a measurement. Track record, upgrade mechanisms, and the scope of admin privileges all factor in.

Oracle risk determines whether the price feed used for liquidations responds appropriately to market conditions. As discussed in how oracle design affects DeFi risk, a fixed-price oracle on the wrong asset can delay necessary liquidations, while a market-based oracle on a fundamentally sound asset can trigger unnecessary ones.

Liquidity risk measures whether positions can be exited at a fair price in a stress scenario. An asset with $5M of on-chain liquidity creates meaningfully different conditions than one with $500M.

Counterparty risk covers the operational and custodial exposures introduced by the entities involved: bridges, oracles, custodians, and the protocol teams themselves. Drift and Resolv failed on this dimension. No smart contract audit would have caught either exploit.

Credora’s methodology quantifies these five dimensions independently and combines them into a single output: Probability of Significant Loss (PSL), which is the annualized probability that a depositor loses more than 1% of principal. PSL drives the letter grade on the A+ to D rating scale. For the full methodology, see what PSL measures and how it is calculated.


The Credora App: APY and risk rating on the same row

APY without a risk number is half the picture. The Credora app at app.credora.network puts both numbers on the same row.

The platform currently covers 20 rated lending vaults, 15 rated markets, and 21 rated assets across Ethereum and Base. Every entry displays TVL, APY, and a Credora rating from A+ to D. Savings USDS on Spark carries a 3.65% APY at an A- rating. Staked USDS on the same protocol offers 6.31% at B+. The yield difference is visible. The risk difference is visible. The comparison is now possible.

The asset database covers the categories that matter for DeFi lending: RWA-backed stablecoins (USDC, USDT, PYUSD, RLUSD), liquid staking tokens (stETH, rETH, pufETH, weETH), wrapped Bitcoin derivatives (cbBTC, wBTC, tBTC), and liquid restaking tokens. Each carries an independent rating based on the five-dimension framework above.

The Rating Changes feed tracks 1,000 rating events, showing how PSL scores and letter grades shift as market conditions change. A vault that moved from A- to B+ last month has a measurable risk change. Not a narrative, a number.


Rate My Portfolio: your personal DeFi risk score

The Rating & Simulation section of the app makes the framework personal.

Connect your wallet, enter any EVM address, or build a portfolio manually by adding positions and tokens. The app reads your Morpho positions and token holdings and calculates a composition-based portfolio risk score: a single number that reflects the Credora ratings of your current holdings weighted by their percentage of your portfolio.

This answers the question that yield-chasing obscures: not “what APY am I earning?” but “what risk am I taking to earn it?” A portfolio concentrated in B+ and C-rated vaults carries materially different risk than one concentrated in A and A- vaults, even when the yield difference looks small.

You can also look up any EVM address without connecting a wallet, useful for reviewing a strategy before committing capital.


The Credora Index: the benchmark DeFi was missing

Coming soon to the app: the Credora Index tracks weighted-average APY across every Morpho rating band (A+ through D), updated continuously. It provides four views: yield by rating band, alpha versus unpriced risk, historical spread evolution, and risk-adjusted benchmarking.

The core use case: if you are earning less than the A+ band average while holding B-rated positions, you are taking excess risk that the market is not compensating you for. The Index makes this visible.


Start with your portfolio risk score

The three exploits that defined Q1 2026 had different mechanisms: a compromised cloud key, months of social engineering, a poisoned verification node. What they had in common was that users in those protocols had no single place to see the combined risk picture (code quality, operational exposure, collateral structure, oracle design, liquidity depth) before committing capital.

That is what the Credora app provides. Not reassurance. A number, and the methodology behind it.

Go to app.credora.network, connect your wallet, and see your portfolio risk score and the individual ratings behind it.


Frequently asked questions

What is a DeFi risk score and how is it calculated?

A DeFi risk score quantifies the probability of capital loss in a lending market or portfolio. Credora’s score, PSL (Probability of Significant Loss), is the annualized probability that a depositor loses more than 1% of principal, calculated using Monte Carlo simulation across 100,000 scenarios drawn from historical market conditions. The score covers five independent dimensions: collateral quality, smart contract risk, oracle design, liquidity, and counterparty risk.

Why did smart contract audits not prevent the Resolv, Drift, and KelpDAO hacks?

Smart contract audits assess on-chain code. All three Q1 2026 exploits originated off-chain: a compromised AWS key (Resolv), social engineering of governance signers (Drift), and compromised RPC infrastructure (KelpDAO). The smart contracts in each case worked as designed. Counterparty and operational risk, the dimensions audits do not measure, were the failure points in each incident.

How do I check the risk of my current DeFi portfolio?

Go to app.credora.network and open the Rating & Simulation section. Connect your wallet or enter any EVM address to see a composition-based risk score for your current positions. You can also build a portfolio manually if you prefer not to connect. The score reflects your holdings weighted by Credora ratings across 108 rated vaults, 177 markets, and 51 assets.


Ratings and data provided are for informational purposes only. Not investment advice or a solicitation to buy or sell assets. Always conduct your own due diligence. Credora does not guarantee the completeness or real-time accuracy of any information provided. A full disclaimer is included in each risk assessment report published at reports.credora.network.