DeFi's Institutional Appeal Limited by Persistent Security Risks, JPMorgan Warns

According to JPMorgan, the persistence of security flaws in decentralized finance (DeFi) is hindering its appeal to institutional investors. The total value locked (TVL) in DeFi protocols, a key metric for gauging the ecosystem's size and health, has been stagnant, with the recent KelpDAO exploit resulting in a $20 billion loss. This exploit exposed the structural risks in DeFi, as an attacker was able to breach a cross-chain bridge, mint unbacked assets, and drain lending protocols, resulting in significant losses. The incident highlights the interconnectedness of DeFi and the potential for contagion to spread beyond directly affected platforms. In response to such exploits, crypto participants have been seeking refuge in stablecoins, similar to how traditional investors shift to cash in uncertain times. The report notes that hacks and exploits remain a central risk for crypto, as they directly undermine trust in systems that rely on code rather than intermediaries. The complexity and interconnectedness of blockchain infrastructure amplify these vulnerabilities, with cross-chain bridges being a particular weak point. Repeated exploits erode confidence across the ecosystem, driving users and institutions away, and prompting stricter regulation. The bank's analysts observed that hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits remaining the primary vulnerability. Growth in DeFi also remains muted, with TVL partially recovering in dollar terms but largely unchanged in terms of ether, suggesting limited organic expansion. In times of stress, investors continue to rotate into stablecoins, with capital flowing from DeFi lending into assets like Tether's USDT, which benefits from deeper liquidity and faster off-ramps.