DeFi audits fail to prevent recent protocol exploits. Despite undergoing multiple audits, two DeFi protocols, Raft Finance and KyperSwap, experienced catastrophic exploits that resulted in the draining of funds. Raft Finance fell victim to an infinite mint bug, while KyperSwap had its liquidity pools drained.

DeFi audits fail to prevent recent protocol exploits. Despite undergoing multiple audits, two DeFi protocols, Raft Finance and KyperSwap, experienced catastrophic exploits that resulted in the draining of funds. Raft Finance fell victim to an infinite mint bug, while KyperSwap had its liquidity pools drained.
Blockworks
Revision history

2 recorded changes

Want your article here?

Promote with Leviathan News

Multiple DeFi exploits have shown that security audits do not guarantee safety. In the cases highlighted by Blockworks, Raft Finance and KyperSwap were both audited yet still suffered severe attacks: Raft was hit by an infinite mint bug, while KyberSwap’s liquidity pools were drained. The broader point is that audits reduce risk but cannot eliminate it, especially in complex DeFi systems where a single logic flaw can be catastrophic. Recent incidents in the sector, including a separate Yearn Finance exploit that also involved an infinite-mint style vulnerability, underscore how attackers can still drain real assets even when a protocol’s code has been reviewed.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Liquidity Pool

Comments