DeFi's Institutional Appeal Hindered by Persistent Security Risks, Says JPMorgan
According to JPMorgan, the persistent security flaws in decentralized finance (DeFi) are limiting its appeal to institutional investors. The total value locked (TVL) in DeFi protocols, a key metric for measuring the size and health of the ecosystem, has been stagnant, and recent exploits have exposed the structural risks inherent in the system. The KelpDAO exploit, which resulted in a $20 billion loss, is a prime example of these risks. The exploit involved a breach of a cross-chain bridge, resulting in the minting of $292 million in unbacked rsETH, which was then used as collateral to drain lending protocols, leaving $200 million in bad debt. This incident highlights the interconnectedness of DeFi and how it can amplify shocks. In response to such exploits, crypto participants have been seeking refuge in stablecoins, such as Tether's USDT, which offers deeper liquidity and faster off-ramps. The bank's analysts note that hacks and exploits remain a central risk for crypto, as they directly undermine trust in systems that rely on code rather than intermediaries. The complexity and interconnectedness of blockchain infrastructure amplify these vulnerabilities, making security a foundational constraint on crypto's growth. Despite gains in smart contract auditing, hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits remaining the primary vulnerability. The report also notes that growth in DeFi remains muted, with TVL partially recovering in dollar terms but remaining largely unchanged in terms of ether (ETH), suggesting limited organic expansion and raising questions about DeFi's ability to scale for institutional use.