Executive Summary
DeFi’s hack-to-TVL ratio has fallen from roughly 14% five years ago to a projected 1.49% in 2026, even as TVL is forecast to grow 31%. Re7’s research, combined with Utila’s analysis of recent incidents, points to an important shift in the security discussion: several major losses have resulted from compromised interfaces, excessive signing authority, configuration failures, and insufficient transaction controls rather than newly discovered smart-contract vulnerabilities.
Recent DeFi Security Findings
Smart-contract vulnerabilities remain a critical part of DeFi security, but recent incidents show that audited code does not address every source of loss.
Re7 asked eight security firms and protocols whether AI had been responsible for a significant hack by discovering a new smart-contract vulnerability. None identified one. The incidents examined instead involved social engineering, compromised signing infrastructure, configuration errors, and weak authorization models.
According to Re7, hack volume as a percentage of total value locked has declined from roughly 14% five years ago to a projected 1.49% in 2026, while TVL is forecast to grow by 31%.
Read the full Re7 analysis: Why DeFi’s Toughest Moments Make the Strongest Case for Staying In It
Transaction Authorization Risks
Recent incidents analyzed by Utila show how weaknesses in transaction authorization can become irreversible onchain actions.
In the Drift incident, attackers compromised the signing process through a malicious interface. Signers approved transactions that transferred control of the multisig without sufficient visibility into what they were authorizing.
Resolv exposed a related weakness. A compromised signing credential carried extensive authority without additional quorum requirements or transaction-level controls capable of rejecting an abnormal issuance request. The transaction was cryptographically valid, but the credential had more authority than it should have been able to exercise without additional checks.
Smart-contract audits cannot fully address these risks. They assess code and trust assumptions, but they do not determine how privileged transactions are approved, how much authority individual credentials hold, or whether abnormal activity can be stopped before execution.
Controls at the Authorization Layer
Transaction decoding and simulation can give approvers visibility into what they are signing. Contract and function restrictions can define permitted interactions. Limits, approval quorums, role separation, timelocks, and monitoring can constrain what happens when a credential, interface, or operator is compromised.
Utila applies these controls before signing and execution. Organizations can define which protocols, contracts, functions, destinations, and transaction types a wallet may interact with, alongside transaction limits and approval requirements. The policy layer can reject an action even when the underlying signing request is valid.
The same architecture applies to AI agents initiating financial transactions. Rather than giving an autonomous system unrestricted signing authority, wallet infrastructure can separate initiation from authorization: the agent requests an action, while independent policies determine whether it can proceed.
Read Utila’s research on securing agentic payments
Implications for Institutions
Re7’s data shows a declining hack-to-TVL ratio even as DeFi grows. At the same time, recent incidents demonstrate that institutional security controls must cover more than smart-contract code.
For institutions operating onchain, permissions, transaction limits, approval requirements, signing procedures, and policy enforcement all affect whether a compromised credential or malicious request can result in a loss.
Apply Institutional Controls Before Transactions Reach Blockchain
Utila gives financial institutions and digital asset businesses granular control over how onchain transactions are initiated, approved, and executed. Teams can define who is authorized to act, which destinations and smart contracts wallets can interact with, which functions can be called, how much can be transferred, and when additional approvals are required.
These policies are enforced at the wallet infrastructure layer before signing, helping reduce exposure to compromised credentials, deceptive transaction requests, excessive permissions, and operational errors.
Whether you are managing treasury, payments, DeFi positions, tokenized assets, or agent-initiated transactions, Utila provides the policy and authorization infrastructure to govern how capital moves onchain.


