DeFi Hacks Happening Every Day; Institutions Are Still Coming
Monday, 1 June 2026 · 4 min read · Listen to the episode ↗
DeFi lost 630 million dollars in April alone, one of the worst months on record, yet institutional interest is accelerating rather than retreating. Speakers traced recent exploits to key management failures and misconfigured permissioned roles rather than smart contract flaws, with Uniswap cited as proof that well-audited contracts can hold billions without incident.
DeFi lost 630 million dollars in April alone, described as one of the worst months on record, and 1.1 billion dollars over the prior 12 months. OpenZeppelin co-founder Manuela Arao publicly recommended exiting DeFi entirely, though OpenZeppelin the firm has since distanced itself from that position. Camille Rousseau argued that distinguishing supply chain attacks from smart contract vulnerabilities is beside the point because customers lose assets either way and the broader system remains unsafe regardless of which layer was compromised.
John Sedler and Stan Rackfady pushed back on the framing, arguing that recent exploits look more like key management failures and supply chain compromises than smart contract flaws. Uniswap has managed billions for years without a smart contract exploit, effectively functioning as a multi-billion dollar bug bounty. Sun identified the core problem as risk migrating from the smart contract layer to the operational layer, where highly permissioned roles are granted to low-security holders such as externally owned accounts rather than multi-sig wallets gated by a time lock. Protocol role configuration and guardrails around permissioned roles were identified as the two most important factors in vault security, and Sun argued DeFi needs standards analogous to SOC2 to govern who controls what roles and keys.
The Layer Zero KelpDAO attack illustrated contagion risk, where counterfeit RSEETH was posted as collateral and real WETH was stolen from Aave. John Sedler stated Aave was the only protocol that could have absorbed the exploit without users taking losses, due to its strong balance sheet and ability to bring parties together. He argued pooled lending is currently the only model proven to generate significant protocol revenue, with Aave's brand trust giving it pricing power and a treasury capable of backstopping deposits. He acknowledged uncertainty about whether isolated lending protocols can charge fees sufficient to build a comparable balance sheet. Anthony DiMartino noted that RSE was never approved and never part of any Kraken or Centaur vault, illustrating how upfront asset due diligence can prevent exposure before deployment. Centaur did not enter the vault market until October of last year because assets it was asked to add never passed its six-month due diligence process, while competing assets were launched within a week.
Vault curators on Morpho are incentivized to add higher-yielding assets first to attract total value locked and earn more fees, creating misaligned incentives. Standard Morpho vaults provide no formal disclosures, with curator information coming mainly from social media, and one speaker argued there is insufficient market differentiation between reputable curators and protocols that have been exploited. One speaker clarified that Morpho vaults are built on open smart contracts rather than custodial setups, meaning a curator cannot take arbitrary action such as swapping assets or taking hidden leverage because smart contract guardrails prevent it. John Sedler argued that deploying vault receipt tokens into various DeFi protocols is almost never worth it from a risk perspective, and that composability makes sense for simple assets like staking assets and stablecoins but not for vault receipt tokens used as collateral in lending protocols.
On AI and security, one speaker noted AI coding tools are likely being used offensively to find and exploit vulnerabilities, with Lazarus North Korea suspected of using a frontier model to find code vulnerabilities, though the speaker acknowledged no evidence for that specific claim. Stan Rackfady argued AI raises stakes for all cybersecurity but is also a defensive tool, and Vitalik Buterin's widely shared post on Ethereum's future discusses using frontier models to transcribe existing production code into formally verified codebases as a path to greater security.
Kraken's Bitcoin Vault product, which wraps Bitcoin into KBTC, borrows stablecoins against it, farms yield, and returns the spread as Bitcoin yield, reached approximately 60 million dollars in TVL within one day of launch. Anthony DiMartino reported that three enterprise deals closed in the five weeks prior to recording despite an expected pullback, and that institutional diligence processes have become more detailed rather than stopping following recent hacks. Institutions differ from retail in being slower to conduct diligence, having compliance and KYC requirements on vault participants, and requiring thinner institutional-scale pricing. Banks view vaults as a way to move lending off balance sheet in a structure analogous to a blockchain SPV, asset managers are focused on leverage looping and bringing real world assets on chain, and payments providers see vaults as a tool to retain and monetize high transaction volume as on-platform capital.
US Treasury Secretary Scott Bessent's prediction of three trillion dollars in stablecoins by 2030 was cited as a marquee moment for the current institutional wave. Anthony identified four converging forces as nearly custom built for institutional needs: stablecoin adoption growth, a more favorable US regulatory climate including the expected passage of the Genius Act and Clarity Act, expanding borrow-lend activity through vaults, and real world assets including wrapped Treasury assets coming on chain. Centaur's insurance product Firelight converts DeFi risk into over-collateralization risk, allowing users to earn slightly less yield in exchange for collateral coverage, and Anthony predicted DeFi insurance will need to become table stakes to attract the next major wave of institutional capital. Speakers noted a sharp divergence between crypto-native sentiment described as gloomy and resembling 2022 price action, and enterprise and institutional excitement described as at a high not previously seen in crypto.
This summary was generated from the episode transcript and can contain mistakes.