DeFi's Near-Death Moment | Mike Silagadze on Ether.fi, Security, and What Comes Next
Monday, 8 June 2026 · 4 min read · Listen to the episode ↗
Mike Silagadze, founder of Ether.fi, walks through the Kelp exploit in which attackers attributed to North Korea exploited a LayerZero bridge configuration to steal roughly 220 million dollars, with systemic exposure potentially reaching 30 billion dollars across DeFi had Kelp declared bankruptcy and frozen Aave markets.
The Kelp exploit, attributed to North Korea, targeted a LayerZero bridge configuration that had been reset from a two-of-two to a one-of-one setup, allowing attackers to drain ETH contracts and mint roughly 300 million dollars worth of assets, with approximately 220 million dollars stolen directly. Mike Silagadze argues the systemic risk was far larger than the direct loss: had Kelp declared bankruptcy, the entire 1.5 billion dollar Kelp ETH supply would have been encumbered, potentially freezing Aave markets and triggering contagion across 30 billion dollars of DeFi, with some centralized exchanges rendered insolvent. He says the default path without intervention would have set DeFi back to 2018 or 2019 levels.
Silagadze credits Stani and Aave as the primary drivers of the DeFi United rescue effort and says Ether.fi was the first to commit despite having no direct exposure, contributing 5,000 ETH on systemic risk grounds alone. DeFi United ultimately raised 262 million dollars and 137,000 ETH, nearly double the shortfall. He frames this as a private community-driven recovery rather than a government bailout. The legal aftermath remained messy: Arbitrum pulled attacker funds to Aave, but a law firm filed a suit claiming the exploited funds were North Korean property based on interests dating back 20 to 30 years, transferring liability to Aave rather than dismissing the order, with the restraining order potentially unresolved for a long time. Early coordination between Kelp, LayerZero, and Aave ran on roughly a 12-hour cycle through lawyers, and getting decision makers talking directly was the critical first step.
Silagadze argues the Kelp, Drift, Bybit, and Gnosis Pay exploits all failed due to basic operational security gaps rather than sophisticated smart contract vulnerabilities. In the Drift hack, attackers compromised two wallets in a multi-sig. In the Bybit hack, attackers manipulated the front-end JavaScript UI used to authorize a transfer of approximately 1.5 billion dollars. He says the protocols involved were not using available tooling including formal verification and on-chain and off-chain monitoring.
These events led Ether.fi to overhaul its security posture. Silagadze rejects what he calls decentralization theater, arguing that application layer protocols have an obligation to protect user assets even if the standard for decentralization at the blockchain layer is legitimately higher. Ether.fi is introducing a pause button that an EOA address can activate to halt the protocol for 24 hours pending security council ratification, along with rapid address blacklisting subject to the same process. He argues that the ability to pause or blacklist does not by itself allow an attacker to steal funds, and that a sufficiently decentralized ratification process can provide both permissionless self-custody and emergency protection. Some of these changes have already been deployed.
Ether.fi launched in 2023 with a vision of a vertically integrated DeFi bank rather than a liquid staking protocol, with eETH as a yield-bearing staked ETH asset, strategy vaults automating DeFi deployment, and a Visa credit card offering 3 percent cashback and yield on deployed assets. The platform has approximately 400,000 registered users and does billions of dollars per year in annualized transaction volume. Monthly revenue runs approximately five to ten million dollars, and Silagadze expects full-year revenue to exceed last year's total by roughly 40 percent. The interviewer noted that TVL, fees, and revenue had been sliding since August of the prior year, though Silagadze downplays TVL as a metric given how heavily it tracks ETH price. The Bybit hack triggered a significant contagion event, with roughly 500,000 to 600,000 ETH exiting the protocol as large funds withdrew and leveraged staking positions on Aave were unwound. ETH staking is no longer the primary revenue driver, with most revenue now coming from vault products and the cash card.
Silagadze frames Ether.fi's competitive set as Revolut, Chime, and Nubank rather than other crypto card products, and predicts the crypto card space will consolidate to a small number of players that successfully reach users outside the existing crypto audience. He identifies Brazil, Mexico, Taiwan, Hong Kong, and Thailand as key growth markets, citing demand for USD exposure, poor local banking rails, and payment infrastructure like Brazil's PIX QR code rail. Ether.fi is planning to expand into tokenized stocks, perpetuals, and prediction markets, and is developing an Omni portfolio concept consolidating cash, investments, tokenized stocks, insurance, and real estate into a single composable account, with a stated goal of giving ordinary users access to low-interest borrowing currently available only at institutional scale.
Silagadze's broader thesis is that crypto's mainstream value will come from making payments, transfers, and investment ownership cheaper and easier, with the underlying technology becoming invisible to end users. He argues the addressable market for those everyday financial utilities is far larger than the market for speculative tokens, and that successful adoption means users think about outcomes like earning more yield on their dollars rather than thinking about the technology as crypto.
This summary was generated from the episode transcript and can contain mistakes.