Exploit
An exploit is the deliberate use of a vulnerability in code, logic or system design to make a system do something its creators did not intend, in crypto usually to drain funds from a smart contract, bridge or exchange.
Exploit versus hack
The words are often used interchangeably. Exploit stresses that the attacker used the system's own rules against it: every transaction was technically valid, but a flaw let the attacker take more than they should. A hack can also mean breaking in from outside, for example stealing private keys or compromising a server.
Common types of exploits
Code bugs, such as reentrancy or missing access checks, let attackers call functions in harmful ways. Oracle manipulation pushes the price a protocol relies on, often using a flash loan, an uncollateralized loan repaid in the same transaction, to borrow huge sums for a few seconds. Logic and economic exploits abuse reward formulas or rounding errors. Key compromises, where attackers gain control of admin or validator keys, have caused some of the largest bridge losses.
Front ends can be attacked too: a hijacked website or domain can serve a fake interface that asks users to sign malicious approvals.
An example
In March 2022 attackers drained the Ronin bridge, which connected the Axie Infinity game network to Ethereum, after gaining control of five of its nine validator keys. With enough signatures they could approve withdrawals that looked legitimate to the bridge contract.
What it means for users
Once funds leave an exploited contract, they are usually moved and laundered quickly. Some are recovered through negotiation, bounties or freezes by stablecoin issuers, but many are not. As a user you cannot audit every protocol, but you can limit exposure: prefer long-running, audited systems, watch for upgrade keys, avoid connecting your wallet to unfamiliar sites and revoke old token approvals.
Ask Coach about it
Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.
What are the most common ways DeFi protocols get exploited, and what warning signs can users see?Ask Coach →
Frequently asked questions
Is exploiting a smart contract legal if the code allows it?
Generally no. Courts in several countries have treated such attacks as fraud or theft, regardless of the claim that code is law.
Can exploited funds be returned?
Sometimes. Attackers occasionally return funds for a bounty, and some tokens can be frozen by their issuer, but recovery is never guaranteed.
What is a white-hat hacker?
A security researcher who finds and reports a vulnerability, or rescues funds, rather than stealing them, often in return for a bug bounty.
Related terms
Learn it step by step
AC Learning explains these ideas in interactive lessons — the first eight sections are free.
Open AC Learning → Create a free accountAll glossary terms · Educational reference only — not investment, legal, tax or financial advice.