TL;DR — the decision rule
A corpus of ~40 stablecoin depegs and DeFi/CeFi blowups, classified by root cause and mapped to our rubric. The honest finding: you cannot rank “most common cause” from this data (it is thematically sampled and visibility-biased), but the consequence pattern is clear and actionable.
The largest single blow-up is reflexive token economics (Terra) — but that is one outlier. The largest robust permanent-loss cluster is opaque off-chain counterparty insolvency / re-hypothecation / attestation failure (Celsius, Voyager, Genesis, BlockFi, Babel, Orthogonal — multiple independent billion-dollar events). Bridges and smart-contract exploits dominate the headlines but are heavily recovered (high gross, lower permanent loss). Treat off-chain solvency & attestation dependencies as the top under-priced risk in any eval — it is both the most reliable permanent-loss signal and our framework’s biggest blind spot. Never size off a “most common by count” claim.
Scope & caveat (read first — every eval citing this inherits it)
This is a thematically-sampled, visibility-biased corpus — five category lists, curated. So:
- No “most common by count” claim is valid. Category counts are an artifact of how many lists targeted each theme; loud, timestamped exploits are over-counted while quiet failures — soft depegs that recovered, redemption pauses, share-price haircuts, graceful wind-downs — are systematically invisible (they leave no exploit tx to index).
- Use this for mechanism lessons and framework coverage-gap mapping, not base rates.
- Loss figures are as reported by third-party sources, not independently on-chain-verified.
Taxonomy (root-cause categories)
- A — Reflexive / emissions economics: peg or yield backed by the protocol’s own token, or paid from emissions/new deposits.
- B — Oracle manipulation: spot/thin price used as truth; flash-loan-skewed feed drives bad liquidations or over-borrowing.
- C — Smart-contract bug: reentrancy, missing health check, rounding — usually amplified by flash-loan capital.
- D — Key / governance / OPSEC compromise: weak multisig, flash-loan governance, or signer-device/supply-chain attack.
- E — Off-chain counterparty insolvency / re-hyp / attestation failure: backing depends on an off-chain entity whose solvency or attestation is unverifiable on-chain.
- F — Bridge / cross-chain compromise: the messaging/custody layer under an asset is drained.
- G — Bank-run / liquidity-mismatch depeg: liquid liabilities, illiquid backing; the buffer exhausts and the queue freezes.
What the corpus supports (ranked honestly)
- Largest single event: A — reflexive (Terra, ~$45–50B UST+LUNA as reported). One observation carrying the dollar lead → read as “the worst tail is a reflexive death spiral,” not “most frequent.”
- Largest robust permanent-loss cluster: E — off-chain insolvency (Celsius ~$1.2B deficit; Voyager ~$1.3B; Genesis multi-billion; BlockFi; Babel; Orthogonal). Multiple independent billion-dollar events → the most reliable dollar signal, more so than the single Terra outlier.
- Most over-represented by visibility / most recovered: B + C + F — loud and individually nameable, but heavily netted by recovery (Poly Network ~$0 net, Wormhole replenished, Euler ~$197M largely returned, Angle agEUR recovered). High gross, lower permanent loss.
- Most frequent technical mechanism (bin-dependent, do not cite as “most common”): oracle manipulation (B) and key/governance compromise (D).
- The under-counted tail: quiet soft-depegs that recovered (USDC/SVB, USDD, DAI/USDT wobbles), redemption pauses (TUSD), and pro-rata haircuts (Maple pools). These are the modal bad outcome and are nearly absent from any list like this.
Framework coverage map
Plain rubric section names; coverage is for catching the failure pre-incident.
| Category | Rubric section / lens | Coverage |
|---|---|---|
| A — Reflexive / emissions | Mechanism design (Hard-no: reflexive collateral / emissions yield) | Well — for the rule. Conditional on the analyst not being captured by the yield narrative. |
| G — Bank-run / liquidity | Oracle & liquidity (stress-haircut), Backing & redemption | Well. The stress-liquidity haircut is purpose-built for this. |
| B — Oracle manipulation | Oracle & liquidity + contagion “audit every price feed” | Partial. The dimension text is scoped to our exit feed; internal liquidation-oracle manipulation is covered only by re-reading it via the contagion lens. Tighten the wording. |
| C — Smart-contract bug | Smart-contract surface | Partial, structural. Audits don’t catch novel bugs in audited, mature code; only time-in-production + scope-of-deployed-version helps. |
| D — Key / gov (config) | Governance & counterparty, Key-compromise threshold | Well on config (thresholds, timelocks, signer look-through). |
| D — Key / gov (OPSEC) | — | Blind spot. No treatment of signer-device / supply-chain malware / blind-signing (Radiant, Multichain). |
| E — Off-chain solvency / re-hyp | Backing & redemption, Governance & counterparty | Blind → now partially closed (see rubric change below). We checked attestation form but had no balance-sheet / re-hyp / counterparty-concentration test. |
| F — Bridge / cross-chain | Concentration line only | Blind vs dollars. Bridges (Ronin, Wormhole, Nomad, Harmony, Multichain, BNB, Poly) are treated as a concentration surface, not as first-class entities to run key-compromise on; bridge code bugs fall in C’s gap. |
| (meta) | — | Narrative / classification capture. Every “Well” assumes the analyst correctly labels the mechanism; the modal historical failure was mislabeling a risky thing as safe in real time (Anchor’s “real yield”, audited-Euler, “decentralized” Ronin). No pre-mortem step. |
Recommended framework changes (ranked)
- Off-chain counterparty solvency & re-hypothecation Hard-no — applied in this change to the Governance & counterparty section, with the playbook principle “trace every off-chain leg to an audited balance sheet, or treat it as a discretionary promise.” Highest leverage: it maps to the most robust permanent-loss cluster (E) and generalizes to every RWA / CeFi-backed / delta-neutral product. Would have flagged Celsius, the Maple defaults, msUSD.
- Bridge sub-checklist (proposal) — evaluate the bridge under an asset as a first-class entity (security model: light-client vs multisig vs MPC vs optimistic; signer composition + jurisdiction; upgrade/init safety; audit-of-deployed-version).
- Signer-OPSEC clause (proposal) — in the key-compromise section: blind-signing, developer-device compromise, payload substitution.
- Oracle-feed wording fix (proposal) — extend the Oracle & liquidity dimension to explicitly cover the protocol’s internal liquidation/valuation feed, not only our exit pricing.
- Pre-mortem step (proposal) — one line forcing “name the narrative that would make us wrong,” to counter classification capture.
Methodology
Data sources & how to reproduce
Compiled via the failure-mode-research workflow (7 agents: 5 parallel category researchers → synthesis that read rubric.md + eval-playbook.md and mapped causes to dimensions → an adversarial critique that pressure-tested sampling bias and framework overclaims), run 2026-06-21 (run id wf_4c410b6f). Sources are third-party postmortems and reporting (Rekt.news, Chainalysis, CoinDesk, Fortune, regulator filings — CFTC/Fed, audit firms). Loss figures are as reported, not on-chain-verified this session; disputed figures are marked. The corpus is curated, not a census — see the Scope & caveat above.
Appendix — selected incidents (sourced)
| Incident | Date | Reported loss (qualified) | Root cause | Category | Section that catches it | Source |
|---|---|---|---|---|---|---|
| Terra UST/LUNA | 2022-05 | ~$45–50B mktcap (as reported; broader contagion contested) | Reflexive algo peg, zero exogenous collateral | A | Mechanism design (Hard-no) | Chainalysis |
| Iron Finance | 2021-06 | ~$2B TITAN mktcap (as reported, not realized redemptions) | TWAP-lag partial-collateral redemption | A | Mechanism design | Fed note |
| USDR (TangibleDAO) | 2023-10 | depeg to ~$0.53; ~$45M mktcap | Liquid liabilities, illiquid RWA backing; buffer exhausted | G | Oracle & liquidity; Backing & redemption | DL News |
| Main Street msUSD | 2026-06 | ~71% in 24h; ~$30.5M mktcap | Single off-chain PoR verifier (Accountable) exited | E | Governance & counterparty (new) | crypto.news |
| USDC / Circle (SVB) | 2023-03 | recovered; nadir ~$0.87; $3.3B at SVB | Reserve concentration at a single bank | E / G | Backing & redemption | CoinDesk |
| bZx | 2020-02 | ~$0.95M | Single-source DEX spot oracle | B | Oracle & liquidity | Rekt |
| Cream Finance | 2021-10 | ~$130M | Manipulable pricePerShare oracle, no TWAP | B | Oracle & liquidity | Immunefi |
| Mango Markets | 2022-10 | Thin perp oracle, no circuit breaker | B | Oracle & liquidity | CFTC | |
| Euler Finance | 2023-03 | ~$197M (largely recovered) | donateToReserves missing health check | C | Smart-contract surface (partial) | Chainalysis |
| Beanstalk | 2022-04 | $182M ($77M net) | Flash-loan governance, no timelock | D | Governance & counterparty | Immunefi |
| Radiant Capital | 2024-10 | ~$50M | DPRK supply-chain malware, blind-signing | D (OPSEC) | Blind spot | Radiant post-mortem |
| Maple / Orthogonal | 2022-12 | $36M; pool depositors ~80% loss | Borrower misrepresented solvency to off-chain underwriter | E | Governance & counterparty (new) | CoinDesk |
| Celsius Network | 2022-06 | ~$1.2B deficit; $4.7B owed | CeFi re-hyp / maturity mismatch, concealed insolvency | E | Governance & counterparty (new) | Fortune |
| Genesis Global | 2023-01 | $2.3B to 3AC; ~$1.1B hole papered with IOU | Intragroup loan concealed insolvency | E | Governance & counterparty (new) | CoinDesk |
| Goldfinch / Stratos | 2023-10 | ~$7M on $20M pool | No on-chain covenant on RWA loan sub-allocation | E | Governance & counterparty (new) | CoinDesk |
| Tether (USDT) | 2016–21 | no depositor loss; CFTC $41M fine | Reserve attestation misrepresentation | E | Backing & redemption | CFTC |
Bridges (Ronin, Wormhole, Nomad, Harmony, Multichain, BNB Bridge, Poly Network) are in the full workflow corpus (run wf_4c410b6f); omitted from this table pending a dedicated bridge sub-study, since they are the framework’s other major blind spot and warrant their own checklist (recommendation #2).