PodBrowser
Bell Curve

Can DeFi Bounce Back? | Sam MacPherson & monetsupply

Friday, 24 April 2026 · 4 min read · Listen to the episode ↗

Sam MacPherson and monetsupply examine whether DeFi can recover from roughly 500 million dollars in hacks concentrated in approximately 30 days, including exploits tied to KelpDAO and Drift. They trace how a one-of-one DVN configuration in the Layer Zero ecosystem enabled attackers to forge messages, steal rsETH backing on Ethereum, and exit through Aave using ETH as decentralized collateral that cannot be frozen.

North Korea has materially raised the sophistication of its attacks on DeFi, with operatives spending roughly six months building in-person trusted relationships with team members before executing the Bybit-related exploit. MacPherson argued that AI is accelerating this threat, estimating that human hackers are now leveraged approximately ten times by AI tools, and that agentic AI has in the last six months become capable of autonomously executing security tasks at significantly higher quality. Anthropic's disclosure of thousands of critical vulnerabilities in every major piece of software means previously dormant attack surfaces are now far more likely to be exploited.

The RSE exploit involved a forged message within the Layer Zero ecosystem, allowing attackers to steal RSE backing held on Ethereum. Stolen funds were moved into Aave Core, used to borrow ETH, and then exited because ETH is decentralized collateral that cannot be frozen. Approximately 500 million dollars in hacks occurred in roughly the last 30 days, concentrated around the KelpDAO situation and Drift. The KelpDAO exploit centered on a one-of-one DVN configuration, meaning the bridge relied solely on Layer Zero Labs core infrastructure rather than a multi-operator setup. Monetsupply noted that a two-of-three DVN set with independent operators would have made compromise significantly harder, and that the one-of-one setup may have been the default configuration, which could explain its use. MacPherson described it as operator error and noted Sky uses a four-of-seven multi-sig for Layer Zero bridging.

Aave's exposure arose from having onboarded rsETH as collateral in a shared pool, meaning a depositor who appears to hold a safe asset is actually exposed through multiple layers of intermediation to a one-of-one DVN bridge. Spark Lend had off-boarded rsETH in February because it fell outside their risk preference, and had previously maintained low rate limits and never listed rsETH in efficiency mode. The crisis compounded when rsETH was deposited into Aave and large ETH borrows drove pool utilization to 100 percent, impairing liquidations of ETH-collateral stablecoin positions. All stablecoin markets on Aave reached 100 percent utilization around late Saturday or early Sunday. Aave stated that all rsETH on Ethereum mainnet is fully backed, leaving L2 deployments potentially holding losses, and whether OFT rsETH is the same asset as mainnet rsETH remains unresolved.

Rate limiting on cross-chain transfers is a security feature monetsupply argued clearly should have been in place. Osmosis implemented such limits years ago, and Athena implemented a rate limit on USDE cross-chain transfers. Arbitrum's security council froze approximately 65 million dollars in stolen assets, which monetsupply described as an unambiguously good outcome. The Drift exploit involved a roughly three-hour window during which Circle could have frozen USDC but did not, and monetsupply noted a significant Overton window shift over the past 18 to 24 months around the acceptability of centralized stablecoin issuers freezing funds.

MacPherson argued that DeFi custody done correctly requires governance under time locks, with separate freezing multi-sigs for immediate reaction, and that time locks are a massive deterrent to North Korea. He also argued lending protocols must scrutinize the security practices of any collateral they onboard, not just their own organization. Loss socialization in DeFi is currently discretionary rather than rules-based, unlike corporate bankruptcy which follows a defined capital stack waterfall. Sky has a documented waterfall where Spark covers losses first, then the Sky balance sheet, then SKY token minting, though MacPherson acknowledged even that documentation is incomplete. Aave's Umbrella architecture has something resembling junior capital through pool-specific stakers, but covers only Ethereum-related mainnet losses and not stablecoin losses or Arbitrum.

There is no DeFi equivalent of the FDIC or Federal Reserve. The closest analogs monetsupply identified are entities like Binance and Tether, which have large profitable balance sheets, though he cautioned that backstopping losses still requires a going concern and an equity stake, and that unclear liability among multiple at-fault parties makes intervention much harder. MacPherson said DeFi is not dead but is in a difficult period, and that the Lindy effect should no longer be assumed to provide as much safety protection as previously thought. The current moment was compared to post-FTX 2022 sentiment toward centralized exchanges, with a prediction that the crisis could drive consolidation around battle-hardened protocols.

Sky is spearheading an open-source risk initiative involving a mechanical framework covering technical and market risks modeled on traditional credit underwriting, to be sent to independent crypto-native and TradFi entities that would produce credit scores analogous to those from S&P and Moody's. The framework and scores would be open sourced and potentially aggregated similarly to how L2Beat aggregates L2 security assessments. MacPherson said Sky has been in discussions with the Ethereum Foundation about making this a joint industry effort, with something publicly available targeted for Q3 or Q4 of the current year. Monetsupply warned that quantum computing could arrive within five years, requiring quantum-resistant signing schemes, and that anything vulnerable in smart contracts or operational security needs to be locked down within one to two years before AI finds and exploits it.

This summary was generated from the episode transcript and can contain mistakes.