JPMorgan (JPM) says persistent security flaws curb DeFi’s institutional appeal

Share This Post

Persistent security vulnerabilities and stagnant total value locked (TVL) are weighing on decentralized finance’s (DeFi) institutional appeal, according to Wall Street investment bank JPMorgan (JPM).

TVL refers to the total value of crypto assets deposited in DeFi protocols, and is commonly used as a gauge of the size, usage and overall health of the ecosystem.

The KelpDAO exploit, which the bank said erased about $20 billion in TVL within days, exposed structural risks.

An attacker breached a cross-chain bridge, minted $292 million in unbacked rsETH and used it as collateral to drain lending protocols, leaving roughly $200 million in bad debt. Contagion spread beyond directly affected platforms, underscoring how DeFi’s interconnectedness can amplify shocks.

“Much as traditional investors shift towards cash in uncertain times, crypto participants have responded to recent exploits by seeking refuge in stablecoins,” wrote analysts led by Nikolaos Panigirtzoglou in the Wednesday report.

Hacks and exploits remain a central risk for crypto because they directly undermine trust in systems that rely on code rather than intermediaries. Smart contract bugs, phishing and cross-chain bridge flaws can expose large pools of locked assets, with attackers often needing to exploit just a single weak point to trigger outsized losses.

These vulnerabilities are amplified by the complexity and interconnectedness of blockchain infrastructure. Cross-chain bridges, for example, expand functionality but also increase the attack surface, and have been responsible for billions of dollars in losses because they rely on complicated designs, shared infrastructure and sometimes weak validation mechanisms.

Beyond the immediate financial damage, repeated exploits erode confidence across the ecosystem. Each major hack can drive users and institutions away, prompt stricter regulation and slow adoption, making security a foundational constraint on crypto’s growth.

The bank’s analysts noted hack losses this year are tracking 2025 levels, with infrastructure and bridge exploits still the primary vulnerability despite gains in smart contract auditing.

Growth also remains muted. While TVL has partially recovered in dollar terms, it is largely unchanged in terms of ether (ETH), suggesting limited organic expansion and raising questions about DeFi’s ability to scale for institutional use, the report said.

In periods of stress, investors continue to rotate into stablecoins. Following the exploit, capital flowed from DeFi lending into Tether’s USDT, which benefits from deeper liquidity and faster off-ramps, reinforcing its role as a preferred flight-to-safety asset, the report said.

Read more: The $292 million Kelp DAO exploit shows why crypto bridges are still one of the industry’s weakest links

Related Posts

Algorand Names William Herkelrath CEO to Lead Institutional, Quantum Push

Algorand has named William Herkelrath as chief executive officer,...

Italy’s Central Bank Orders Sanctions Screening for Crypto Transfers

Cointelegraph is committed to providing independent, high-quality journalism across...

Tether pushes into private credit with $400 million fund with Fasanara

The USDT issuer will help source lending opportunities and...

German Finance Ministry Proposes 25% Crypto Tax Starting 2028

Cointelegraph is committed to providing independent, high-quality journalism across...

U.S. Treasury sanctions another widespread cyber-scam hub, Xinbi Guarantee

Chinese-language platform Xinbi is accused of operating on crypto...

Canary Capital Launches the First U.S. Spot Staked TRX ETF

BRENTWOOD, Tenn., Sept. 09, 2026 (GLOBE NEWSWIRE) — Canary...