The number of decentralized finance (DeFi) and blockchain projects increased massively last year. Their increased popularity has also attracted the interest of hackers, who in 2021 managed to steal at least $1.8 billion.

See also: Popular PyPI and PHP libraries compromised
Blockchain is a digital ledger that records transactions in a way that is difficult to hack or alter. As a result, these technologies have enormous potential for managing cryptocurrency assets and transactions, as well as facilitating smart contracts, finance , and legal agreements.
In recent years, blockchain has led to the emergence of decentralized finance. DeFi financial products and systems are an alternative to traditional banks and financial services, relying on decentralized technologies and smart contracts to operate.
DeFi, NFTs , and cryptocurrencies are now popular targets for threat actors, who exploit vulnerabilities, logic errors, and programming flaws – as well as run phishing campaigns to steal digital funds from their victims.
In May, Microsoft introduced the term "cryware" into the standard dictionary of digital threats, including malware, infostealers, cryptojackers , and ransomware. The new term describes malicious software designed to collect and steal information from unsecured cryptocurrency wallets, otherwise known as 'hot wallets.'
See also: Microsoft: What card-skimming malware uses to hide itself
While blockchain facilitates the infrastructure that digital wallets need for transfers, deposits, and withdrawals, 'hot wallets' are stored locally and thus may be susceptible to theft.
On Tuesday, cybersecurity researchers from Bishop Fox published an analysis of the major blockchain and DeFi heists that occurred in 2021. The cybersecurity firm analyzed losses of 1.8 billion dollars.
There were 65 major «events» examined by the team, of which 90% were considered «non‑sophisticated attacks».

According to researchers, DeFi projects experienced on average five major cyber attacks per month, with peaks in May and December.
The main attack vectors in 2021 were:
- 51%, smart contract vulnerabilities
- 18%, protocol and design flaws
- 10%, wallet breaches
- 6%, rug pull, exit scams
- 4% key leaks
- 4%, frontend breaches
- 3%, arbitrage
- 2%, cryptocurrency-related bugs
- 2%, front runs
See also: Identity verification scam uses photos of abuse victims
The most common issues exploited by threat actors are known bugs, vulnerabilities contained in forks, and sophisticated attacks. Rug pulls and exit scams have been recorded to a lesser extent.
Information source: zdnet.com
