JPMorgan Warns of DeFi's Vulnerability to Security Breaches, Hindering Institutional Adoption
Decentralized finance (DeFi) is facing significant challenges in attracting institutional investors due to persistent security vulnerabilities and stagnant total value locked (TVL), according to a report by JPMorgan. TVL, which measures the total value of crypto assets deposited in DeFi protocols, has been impacted by the KelpDAO exploit, resulting in a $20 billion loss. This incident exposed the structural risks associated with DeFi, including the potential for contagion beyond directly affected platforms. Analysts at JPMorgan noted that crypto participants have been seeking refuge in stablecoins in response to recent exploits, similar to how traditional investors shift towards cash during uncertain times. The report highlighted that hacks and exploits remain a central risk for crypto, as they undermine trust in systems that rely on code rather than intermediaries. Smart contract bugs, phishing, and cross-chain bridge flaws can expose large pools of locked assets, with attackers often needing to exploit just a single weak point to trigger significant losses. The complexity and interconnectedness of blockchain infrastructure amplify these vulnerabilities, with cross-chain bridges increasing the attack surface and relying on complicated designs, shared infrastructure, and sometimes weak validation mechanisms. Repeated exploits erode confidence across the ecosystem, driving users and institutions away, prompting stricter regulation, and slowing adoption. The report noted that hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits still the primary vulnerability despite gains in smart contract auditing. Furthermore, growth remains muted, with TVL partially recovering in dollar terms but largely unchanged in terms of ether (ETH), suggesting limited organic expansion and raising questions about DeFi's ability to scale for institutional use.