DeFi's Institutional Appeal Limited by Persistent Security Risks, JPMorgan Warns
According to JPMorgan, the persistence of security vulnerabilities in decentralized finance (DeFi) is deterring institutional investors, with the total value locked (TVL) in DeFi protocols remaining stagnant. The KelpDAO exploit, which resulted in a $20 billion loss, exposed the structural risks inherent in DeFi. The exploit involved an attacker breaching a cross-chain bridge, minting $292 million in unbacked rsETH, and using it as collateral to drain lending protocols, resulting in approximately $200 million in bad debt. This incident highlights the potential for contagion to spread beyond directly affected platforms, underscoring the interconnectedness of DeFi. In response to recent exploits, crypto participants have been seeking refuge in stablecoins, much like traditional investors shift towards cash in uncertain times. The report notes that hacks and exploits remain a central risk for crypto, as they directly undermine trust in systems that rely on code rather than intermediaries. The complexity and interconnectedness of blockchain infrastructure amplify these vulnerabilities, with cross-chain bridges being a particular weakness. Repeated exploits erode confidence across the ecosystem, driving users and institutions away, prompting stricter regulation, and slowing adoption. The bank's analysts observed that hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits remaining the primary vulnerability. Furthermore, growth in DeFi remains muted, with TVL partially recovering in dollar terms but largely unchanged in terms of ether (ETH), suggesting limited organic expansion and raising questions about DeFi's ability to scale for institutional use. In times of stress, investors continue to rotate into stablecoins, with capital flowing from DeFi lending into Tether's USDT, which benefits from deeper liquidity and faster off-ramps, reinforcing its role as a preferred flight-to-safety asset.