Decentralized Finance (DeFi) offers open and permissionless financial services, but its core infrastructure remains exposed to serious security failures. Representative infrastructure classes such as decentralized exchanges (DEXs), protocols for loanable funds (PLFs), and cross-chain bridges matter because failures can propagate widely. This work presents a layered and empirically grounded framework for DeFi vulnerability prioritization. We analyze 558 exploit incidents from 2021–2025 and trace their mechanisms, vulnerabilities, and threat vectors across representative DeFi infrastructure classes. We introduce three complementary components: (1) a Risk Priority Number (RPN) used as an interpretable FMEA-style baseline for attack ranking, (2) an Adversarial Feasibility Score (AFS) that captures exploit feasibility from mapped adversarial-trait prevalence and accessibility, and (3) a Vulnerability-Centric Risk Score (VRS) defined as a structured priority ranking combining empirical likelihood, absolute economic severity, and attacker feasibility. The main validated model uses median per-incident USD loss as a consistent severity signal across the full incident dataset. Temporal validation shows that the structured vulnerability-priority model outperforms the multiplicative baseline and improves on the empirical base rank across both temporal holdouts and both future targets. The resulting framework provides an auditable remediation ordering for protocol developers, auditors, and risk managers.
Arora et al. (Fri,) studied this question.