Time-to-Hack: How fast vulnerable smart contracts get exploited?

Original research measuring the interval between a vulnerable contract's deployment and its exploitation, from 2020 onward. Full dataset at time-to-hack.decurity.io.

· 1 MIN READ · DECURITY

We uncover how the timeline for attacks has shortened and what’s causing this trend from 2020 onward.

Do you ever wonder if smart contract attacks are really getting faster every year?

It feels like it, right? Back in the day, finding bugs often meant reading code line by line. Now, we have dozens of static analyzers, automated tools, and MEV bots constantly scanning the blockchain.

While these tools can be great for defence, they can also be misused by attackers, potentially turning simple vulnerabilities into costly exploits in record time.

We wanted to know: Are hackers really attacking smart contracts faster now? Or do some vulnerable ones just get missed? So, we looked into the details of many hacks to see how long they took. We found some really important trends for anyone in web3, and the most significant discovery was just how crucial speed is in these attacks.

️The full research is available at https://time-to-hack.decurity.io/

Time-to-Hack: How fast vulnerable smart contracts get exploited? was originally published in Decurity on Medium, where people are continuing the conversation by highlighting and responding to this story.

Need this expertise on your protocol?

The researchers who write this are the ones who run the audits.

REQUEST FORM