Two Bridges, One Lesson: What DeFi's Biggest Hacks Reveal About Its Own Data
Not financial, legal, or insurance advice. This piece draws on findings from Foreshock's full backtest report; every figure below can be independently checked there.
Bridges have taken some of the largest single losses in DeFi history. Two of them, Poly Network and Ronin, sit on opposite sides of a question that matters more than either hack on its own: once a protocol has been hit, what happens to the record of it, and what does that record predict?
The two cases point in opposite directions. One shows a warning sign that held for years. The other shows how easily the industry can lose the memory of its own worst day.
The warning sign that held
Poly Network lost $611 000 000 in August 2021, one of the largest DeFi exploits on record. Almost two years later, in July 2023, it was hit again: a private key compromise, $5 000 000 lost. Small by comparison, but it happened.
Foreshock's backtesting reconstructs a protocol's risk score using only what was knowable on a given historical date, no hindsight allowed. Run against the day before that second incident, Poly Network's reconstructed score had already been sitting above the flagging threshold for its peer group for nearly two years, driven by nothing more exotic than the fact of the first hack itself. Across Foreshock's full incident ledger, protocols with a prior incident reach a second one at roughly 27 times the rate of protocols with no incident history at all.
That is not a claim that Foreshock predicted the 2023 incident in any deep sense. It didn't detect a code flaw or a governance weakness. It shows something narrower and more useful: a single, plain, already-public fact, that this protocol had been hacked before, was sitting in the data the whole time and pointed the right direction for years. Treating "has this happened here before" as a real, ongoing input, not a closed chapter, is the plainest lever a risk read has, and Poly Network is the clearest case of it paying off.
The record that went missing
Ronin lost $624 000 000 in March 2022, at the time one of the largest DeFi exploits ever recorded, and then $12 000 000 again in August 2024. Both incidents are confirmed by the industry's major trackers. Neither one could be scored by Foreshock's backtest.
The reason isn't a data-entry gap Foreshock happened to hit. The industry's primary data aggregator no longer carries a listing date for this protocol at all, not an outdated one, none. Without it, a protocol's age on the day of either incident can't be reconstructed, which is enough on its own to drop both events out of any point-in-time analysis. The aggregator's own tracked history for this listing only extends back to April 2024, two years after the first hack had already happened.
That is a different failure mode than Poly Network entirely. It isn't that the signal was weak or ambiguous. It's that the record needed to compute any signal at all had quietly stopped existing, for one of the largest incidents in the industry's own history. An aggregator can lose or restructure a listing for reasons that have nothing to do with covering up anything, and the result is the same either way: the event still happened, but the data needed to learn from it doesn't.
Why both matter to anyone reading a risk score
Put side by side, these two cases describe the two ways a risk signal can fail before it ever reaches an analysis: the signal can be there and go unused, or the record it depends on can simply disappear. Poly Network shows the cost of the first. Ronin shows the cost of the second, and it's the one that's easier to miss, because nothing about it looks like an error. The data source just quietly stopped having what a backtest needed.
This is the specific reason Foreshock maintains its own cross-referenced incident ledger rather than reading a single tracker at query time: a single aggregator's gaps, restructurings, or lost fields become the reader's blind spots too, unless something keeps its own independent copy. It's also why "has this protocol had a prior incident" carries real, lasting weight in Foreshock's scoring, rather than fading in relevance once the news cycle moves on.
Neither point requires trusting Foreshock's word for it. The exact scores, thresholds, and the full ledger reconciliation behind both cases are in the full backtest report, methodology and all.
