DeFi's Institutional Appeal Hampered by Persistent Security Flaws, Says JPMorgan
Decentralized finance's (DeFi) appeal to institutional investors is being hindered by persistent security vulnerabilities and stagnant total value locked (TVL), according to a report by JPMorgan. TVL, which measures the total value of crypto assets deposited in DeFi protocols, has been affected by the KelpDAO exploit, resulting in a $20 billion loss. This exploit exposed structural risks, including the vulnerability of cross-chain bridges, which can be used to drain lending protocols. In response to recent exploits, crypto participants have been seeking refuge in stablecoins, similar to how traditional investors shift to cash in uncertain times. The report highlights that hacks and exploits remain a central risk for crypto, as they undermine trust in systems that rely on code rather than intermediaries. The complexity and interconnectedness of blockchain infrastructure amplify these vulnerabilities, with cross-chain bridges being a primary vulnerability. Repeated exploits erode confidence across the ecosystem, driving users and institutions away, and prompting stricter regulation. The report notes that hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits still being the primary vulnerability. Growth in DeFi also remains muted, with TVL partially recovering in dollar terms but remaining largely unchanged in terms of ether (ETH). In periods of stress, investors continue to rotate into stablecoins, such as Tether's USDT, which benefits from deeper liquidity and faster off-ramps.