How KelpDAO's $290M Exploit Nearly Killed DeFi | Stani Kulechov & Mike Silagadze
Jason YanowitzStani KulechovMike Silagadze
- Mike Silagadze stands “100%” behind his claim that the Kelp exploit could have dwarfed FTX. North Korean hackers stole about $200 million through Kelp’s LayerZero-based bridging setup, but the larger threat was the $1.5 billion of rsETH outstanding: had Kelp followed what Mike believed was strong legal advice to declare bankruptcy, that collateral could have frozen for years across Aave, Compound, Euler and other protocols. Mike called that a potential Armageddon scenario; Yanowitz raised a hypothetical $30–$40 billion impact.
- Aave — in Mike’s words “the least responsible” party — took ownership and built DeFi United. Stani says Aave could have applied a haircut, registered the deficit, and paid it from the protocol treasury, balance sheet and revenue, but chose an ecosystem-wide solution to restore confidence. He rejects “bailout” because this was voluntary skin-in-the-game rather than taxpayer-funded support, with participants supplying liquidity and betting on DeFi and Aave.
- Mike’s team committed 5,000 ETH despite having no rsETH exposure in its vaults — and explored acquiring KELP outright. The team went “pretty far down” one of several acquisition paths, despite the risk of buying a black box. Its logic was existential: “if DeFi blows up, [the team] can’t exist.”
- The recovery was, per Mike, “stupidly lucky”: ETH stayed near $2,300 for about two weeks. A random 20% drop could have hit lending markets at 100% utilization, where positions could not be liquidated, causing a worse bad-debt cascade. Arbitrum’s vote and collective action also recovered roughly 30,000 ETH, or about $80 million, though Mike said he did not know the exact details.
- Stani’s structural takeaway: he is “less confident” in lending as purely infrastructure because someone has to take the risk. Aave wants to expand beyond the roughly $100–$200 billion DeFi market toward becoming financial and credit infrastructure, with underwriting tied more closely to the DAO’s balance sheet and revenues, Umbrella protection and potentially insurance. Ether.fi hopes to migrate its neobank lending market to an Aave V4 instance for tokenized stocks, commodities and other RWAs.
- Mike argues DeFi insurance is currently uneconomic and “decentralization theater” must end. Proper risk pricing could require 10%–15% returns, while some protocols pay 6% for risks that warrant 30%. His proposed security measures include blacklists, pausability, automated monitoring and default timelocks, in response to sophisticated North Korean operations. Ideas ranged from a paid “NATO of crypto” security council to Stani’s proposed counterattack or “vigilante group.”
- Ether.fi’s token is down about 30% in a year and Aave’s about 40%–50%, despite Ether.fi’s revenue and products. Mike says “correlation is just 1.0 on everything” and that tokens often provide no meaningful claim beyond “a meme coin with the name of the protocol.” Ether.fi is working on, but has not yet pre-committed to, an open-source investor-protection framework; Yanowitz proposed GAAP-equivalent disclosures, and Stani said there was substantial work the teams could do together.
1. The theft wasn’t the whole crisis — a Kelp bankruptcy freezing $1.5B of rsETH was
- Mike’s mechanism, spelled out: DPRK hackers exploited the structure Kelp chose for its cross-chain setup (“they of course were using LayerZero”), taking about $200 million. But the default response to a hack of that size is to “pull back, lawyer up, get super defensive.” Mike believed Kelp’s counsel was advising strongly toward bankruptcy. That could have converted a $200 million problem into a $1.5 billion one: “there was a billion and a half dollars of rsETH sitting out there,” which might have been locked for years.
- The cascade: frozen rsETH sat across Aave, Compound, Euler and other protocols; CeFi exchanges and DeFi projects held assets in those lending markets, so a liquidity crunch could have spread broadly — “a clear Armageddon scenario.” Yanowitz raised the possibility of a $30–$40 billion impact, while Mike compared the potential outcome with FTX.
- Stani’s nuance: the asset itself was basically backed on mainnet, with the effect more related to its use in other markets. The challenge was that “if you choose the TradFi path” of everyone taking protective measures, the situation could not be solved collectively.
- Then the luck factor, in Mike’s telling: ETH stayed essentially flat for about two weeks at roughly $2,300. A 20% drop — “which happens like any random Tuesday, right? Iran starts shooting again” — could have hit lending markets at 100% utilization, where “you can’t liquidate,” producing a much worse cascade of bad debt. That created the extreme time pressure.
2. DeFi United: Aave owned a problem it didn’t cause; Mike’s team committed 5,000 ETH
- Mike’s credit to Aave: “the one team that really just stood up and said, no, we’re going to fix this.” Out of all the parties, Aave was “the least responsible,” but took ownership. Stani confirms that Aave could have applied a haircut, registered the deficit, and paid it from the protocol treasury, balance sheet and revenue. Instead, with protocols, LPs and cascading stakeholders involved, it pursued a solution intended to make the ecosystem as whole as possible and restore confidence.
- Mike’s team had no rsETH exposure in its vaults, and its Aave position was effectively short ETH through its looping structure. The increased interest on ETH borrows cost roughly 400 ETH. Nevertheless, the team committed 5,000 ETH because if DeFi failed, the team could not exist; whether Kelp was a competitor “doesn’t matter.”
- The road not taken: Mike said his team explored three or four options in parallel, including acquiring KELP outright, with legal documents moving back and forth. “You’re basically buying a black box” with unknown liabilities that could take the buyer down too, but they were willing to consider it.
- Stani credited Mike and his team with helping push lawyers aside and bring founders and teams together. On terminology, he rejected “bailout,” which he associated with taxpayer-funded intervention; here, participants had skin in the game and supplied liquidity voluntarily, “betting on DeFi and betting on Aave.” After the announcements, stablecoin markets cooled and hundreds of millions of dollars of liquidity became available.
3. Who froze, who showed up — and the Arbitrum subplot
- Mike’s theory of the laggards: teams that acted slowly were often responding to fear. Facing lawsuits and “even criminal liability in some cases,” it was easy to “lock up and freeze.” Having run businesses through litigation, Mike said the fear of inaction was greater than the fear of rushing into the unknown. He described expletive-filled Telegram chats; Stani declined to name absent teams, saying that might be possible in a few months or a year.
- Stani’s surprise: TradFi institutions were “the most supportive,” offering help despite having less skin in the game. Early DeFi behavior was “selfish… all the way to DLP level” until DeFi United shifted the focus from blame to mitigation. Frax and other projects without direct exposure contributed; Ether.fi, Lido, Ethena, Mantle and others helped, while the Aave side also reached out to the Ethereum Foundation, Ethereum OGs and Joseph Lubin, who was willing to step in.
- The movie-worthy beat: Yanowitz described Arbitrum as effectively taking back stolen ETH through a vote and collective action. Mike said he did not know the exact details, but said that without the action the attackers could have moved the funds through THORChain-like laundering channels. Recovering roughly 30,000 ETH, about $80 million, made the hole more manageable.
- Remaining work included one outstanding Mantle proposal, Arbitrum’s lengthy governance process, a Compound proposal with actions including liquidation of the attacker’s position, and an Aave proposal whose on-chain liquidation vote was due about an hour after the recording. Stani also emphasized continuing security, education and institutional outreach.
4. Stani’s redesign: underwriting tied to balance sheets, not “free-for-all” infrastructure
- On Aave deposits falling from roughly 70–75 to 25–30, Stani said TVL is not a pure growth metric. It includes stablecoin, BTC, ETH and staking-yield leverage, so deleveraging shows up sharply in the charts and looping may reactivate when confidence returns.
- Stani also said DeFi has remained roughly a $100–$200 billion market for the past few years and that Aave’s larger ambition is to become “the backbone of all finance and credit.” But he is “less confident of this model of lending as purely infrastructure, because someone needs to take the risk.” If risk management is removed from one layer, it moves elsewhere.
- Future underwriting risk should be tied more closely to the Aave DAO’s balance sheet and revenues. Stani pointed to Aave’s Umbrella protection mechanism and possible insurance products, while keeping Aave focused on prime assets rather than listing anything that can be listed. Keeping problematic assets and configurations out has been part of Aave’s success.
- Mike said Ether.fi hopes to migrate its DeFi neobank lending market to an Aave V4 instance, allowing users to borrow against tokenized stocks, commodities and other RWAs. He favored decentralized pockets isolated from one another rather than one giant pool that spreads contagion.
- Aave’s Horizon market was Stani’s live example of diversification: it grew while the broader incident unfolded because users were lending against different asset classes. Still, he noted that in a confidence shock, liquidity can move away from many protocols simultaneously.
5. Insurance is uneconomic at current yields — speculative premium is the root cause
- Mike said DeFi insurance “would cost you 15% a year,” while the risks involved may require 10%–15% returns to compensate. As speculative premium has declined, yields have compressed and users have moved farther out on the risk curve for lower returns. Some protocols pay 6% when the risk might warrant 30%.
- His root-cause diagnosis: “everything is trickling down from people betting on the price of Bitcoin, ETH, and whatever else going up.” Unless real businesses generate cash flows that drive the system, there will not be enough yield to cover the risk. In the current environment, “any sane underwriter is going to charge you way more than the yield you’re getting in DeFi.”
6. Fighting a nation-state: stop the “decentralization theater”
- Mike’s concrete agenda: “we really need to stop the decentralization theater.” He supports blacklists, including temporary 24- or 48-hour blocks that require governance to become permanent; emergency contract pauses; off-chain monitoring that can trigger pauses; and default timelocks. An anomalous $300 million movement should be detectable, but protocol design often prevents timely intervention.
- His distinction is between a base blockchain such as Ethereum, which needs maximum autonomy and decentralization, and a DeFi protocol with a DAO, labs and operating companies, which needs emergency tools. He wants these protections to become expected listing and audit disclosures rather than “decentralization shibboleths.”
- Stani agreed that emergency response is critical. He said many recent incidents, including the Kelp bridge exploit, involved key compromises rather than contract bugs, making Web2 security around signing, infrastructure and frontends a major weakness. He said his side had recently received a SOC 2 attestation and warned that teams cannot rely on weak signing mechanisms or a frontend “built by Cloud” anymore.
- Mike described North Korea as having a government function dedicated to stealing crypto funds, staffed by highly capable computer scientists. Leaked communications, he said, show a professional operation with leads and business-like processes. These are “multi-month, sometimes multi-year compromises.” Yanowitz cited roughly $700 million in hacks so far that year.
- Proposed defenses included Mike’s paid security council — “almost like a NATO of crypto” — and Stani’s more speculative counterattack: infiltrating laundering infrastructure and forming a “vigilante group of crypto experts” to recover victims’ funds.
7. The investability problem: “a meme coin with the name of the protocol”
- Yanowitz noted that Ether.fi’s token was down about 30% over the year and Aave’s roughly 40%–50%. Mike said “correlation is just 1.0 on everything,” making asset selection nearly pointless, but identified a deeper issue: “when you look at it, you buy a token, what do you actually have a claim to? You just have a meme coin with the name of the protocol.”
- Buybacks by Ether.fi and, as Mike recalled, Aave provide some connection between token and protocol health, but only to a degree. Mike said Ether.fi is working on an open-source investor-protection framework for token holders, though he did not want to pre-commit to it. He pointed to Morpho’s Morpho One structure, where the foundation owns the labs company, as making it harder for that company to rug token holders.
- Yanowitz proposed GAAP-equivalent accounting and disclosure standards so protocols can be compared apples-to-apples, along with a framework for value accrual and investor protections. Stani said there was substantial work he and Mike could do together.
- Stani’s longer-term vision is DeFi as financial plumbing, like HTTP and IP for the internet or Stripe for internet payments. Expanding into traditional assets, RWAs and real-world credit could diversify the economic base and potentially reduce the current token correlation. He closed: “DeFi will win. The show goes on.”
Full transcript
This episode is brought to you by Fidelity Crypto. You'll hear more about them later in today's episode. Nothing said on Empire is a recommendation to buy or sell any investments or products. This podcast is for informational purposes only and the views expressed by anyone on the show are solely their opinions, not financial advice or necessarily the views of Blockworks. Our hosts, guests, and the Blockworks team may hold positions in the companies, funds, or projects discussed. All right, everyone, welcome back to Empire. [music] We've been talking about Kelp DAO and Aave and all the craziness that's unfolded over the last 2 weeks: DeFi United, the bailout, whatever you want to call it. I've been talking to Stani on the side, and Mike—obviously, Ether.fi stepped up in a huge way—so I decided to bring them both on the podcast.
We've got Mike, who's the CEO and co-founder of Ether.fi, as well as Stani, who many of you already know. He's been on the podcast many times, but he's the founder of Aave. So, Stani, Mike, welcome, guys. They're right here. How much sleep have we gotten collectively in the last 2 weeks?
More in the last few days. I think it seems like the worst is over and the ecosystem kind of pulled through. It's been better in the last little while, but it was an intense week for sure.
Yeah, I think the first day after the bridge exploit—the first few days—was probably the most difficult. I couldn't really sleep much for various reasons, but also because we were sort of against the clock. Obviously, now it's a little bit easier, but there's still a good amount of work to do. So, we're still running low.
The thing that surprisingly, I guess, bothered me is that, at least to me, it was so obvious immediately, within a matter of hours, that this was an existential threat to DeFi. It was just sort of step 1, 2, 3, 4. I was like, all right, game over. This is it.
It was so clear that people needed to spring into action and immediately start addressing this thing, or else it was going to spiral. And I think, in fact, if it wasn't for the work that Stani and his team and some others have done, that was the default path. I don't think people recognize that without that intervention, without the effort that people put in, the default path was just a complete blowup of DeFi.
I think not everyone really understood where we were at that point in the space because, effectively, this wasn't about Aave. It was about DeFi as an ecosystem overall and how to manage these big capital movements that are done quite programmatically.
I think the protocols involved and the teams involved typically are really diligent. We work with them on a day-to-day basis, but when something like this happens, where you have a remote dependency, things happen and it creates an attack vector that affects the whole space. That's where everyone needs to move and figure out what the next steps are, because that's the first thing to figure out.
I think, to Mike's credit, Mike was there at the very beginning and realized what the potential paths were, including the extreme worst-case scenarios. He realized how important this is for DeFi, and that wasn't the case for everyone at first glance, but it helped quite a lot during the process.
1. How The KelpDAO Exploit Could Have Killed DeFi
Yeah, Mike, can you maybe walk us through why this was such a big deal? I'm reading your tweet here. It says, “We committed 5,000 ETH to the Kelp hack recovery fund because we thought there was a real risk that this could have killed DeFi. FTX would have looked small in comparison.”
I'm not sure if that's just a bold statement to get your tweet more viral or if you genuinely believe that, but I'd really love to hear the thought process behind it.
Yeah, it's pretty straightforward, honestly, and I 100% stand by that. I'm sure lots of people have read about the high-level events that took place, but the basic idea is that Kelp had a certain structure for its cross-chain and bridging setup. They were, of course, using LayerZero, but they had a certain structure that they decided on, and that was exploited by DPRK, North Korean hackers.
The direct impact was about $200 million that were stolen. But what it meant—and the default path for teams when something like this happens—is to pull back, lawyer up, and get super defensive. That's what was happening. It's hard to fault a team for doing that, right? You're in this extreme situation, you don't know what to do, and most people haven't lost $200 million before, so you don't know what you would do if you were placed in that spot.
The default is, all right, lawyer up, pull back. What's the safest thing that you can do? Well, the safest thing you can do is declare bankruptcy. Say, all right, this wasn't our fault. We're now encumbered by bankruptcy.
Now, if that happens—if they had chosen to go down that path, which I don't want to speak out of turn, but I think their counsel was advising them very strongly to do this—then it's not a $200 million problem anymore. Now, it's a $1.5 billion problem, because there was $1.5 billion of rsETH sitting out there. If Kelp had gone into bankruptcy, that's now locked up. That $1.5 billion isn't moving anywhere for probably years, as we've seen how long these things take to play out.
Now you have $1.5 billion that's stuck in DeFi, a lot of it in Aave markets, but also on Compound, Euler, and a lot of other protocols. Every one of those protocols, frankly, is now affected because you have $1.5 billion of assets that aren't going to move. There's going to be at least a liquidity crunch because you won't be able to pull them out for years, which then would have had a cascade effect on the lending protocols.
Every CeFi exchange has assets in various lending protocols. Tons of DeFi protocols have assets in Aave and everybody else. So, this wasn't just going to impact Kelp. It was going to impact everybody. That was what, to me, seemed like a clear Armageddon scenario.
Again, everyone's default path was sort of to pull back, lawyer up, throw their hands up, and walk away. The one team that really just stood up and said, no, we're going to fix this—let's raise a recovery fund and actually make sure that this blowup doesn't happen—was Aave. They just took responsibility and really ran with it.
In many ways, there was plenty of blame to go around, but out of all the parties, they were the least responsible. They just took ownership and really ran with it. That was great to see, and I think, in the end, all the work combined ended up averting that disaster scenario.
If you think about it from the asset perspective, the asset itself is basically backed on mainnet, so most of the backing is there. Obviously, the effect is more on alts use.
The challenge is what Mike said: if you choose a TradFi path where everyone just throws their hands up and takes protective measures, nothing here can actually be solved. We saw a lot of that, and we saw a lot of direction going toward that.
From Aave's perspective, one path for us would have been to just focus on how we solve this from Aave's perspective, apply a haircut, call it a day, register the deficit, and pay that from the protocol treasury, balance sheet, and revenue. Then we could make the protocol whole and move on.
What we realized is that there were so many stakeholders involved in this incident: protocols, LPs, different teams, cascading effects, and whatnot. We realized that if we really wanted to get everyone at the same table, we needed to find a conclusion that really satisfied everyone. That was basically to make everyone as whole as possible, find the means of doing that, and figure out how everyone could contribute in the most responsible way.
That's the big difference here, and why DeFi United was born. It wasn't about how we write this off on Aave, but how we make this whole ecosystem whole and restore confidence. Restoring that confidence is far greater than the impact on any individual protocol.
I think Mike and Etherscan played a huge role by mediating, getting everyone at the table, and pushing the lawyers off the table. These people don't belong in Web3. Things need to be solved between founders and teams, natively.
To Mike and his team's credit, they were the ones taking a lot of ideas and putting them on the table. You don't necessarily do that from the perspective of, why would you come and help other protocols in the same landscape where they offer similar products?
And doing that for the sake of restoring the whole confidence in the space is very rare. I don't think that is even a solution that people think about in traditional finance. Once DeFi United started to kick in and we saw the support, it sort of changed the whole narrative from, “Oh, these things are just pointing fingers at each other,” to, “Okay, let's all come together and restore.”
I won't call it a rescue or a bailout, because a bailout is obviously forced by taxpayers and whatnot. This was more like, “Hey, we all have skin in the game. We all believe in the space, and we're all improving our security, but we need to act now so that we can restore confidence.”
Yeah, Stani, you said—I saw one of your tweets. You said it was the hardest couple of weeks that you experienced in your entire life. Was there a moment in time, maybe on day 1 or day 2 of this unfolding, when you thought, “Maybe this is the thing that kills Aave”?
I wasn't thinking about Aave, to be honest. I was thinking more about DeFi and what the consequences of DeFi would be. I do think that Aave is built to be resilient. When you think about protocol building, you optimize not for the 99% that works, but, let's say, the 0.01% when things don't work, and how you reestablish the resiliency, basically.
We've obviously seen multiple market and credit cycles from the 2010s and the aftermath, and even in the early days of DeFi, like Black Thursdays and Mondays and whatever there was. It sort of shows the resiliency. For me, what was more important was to understand what we actually have to do to ensure that people have confidence in DeFi, because we don't just work on smart contracts; we also do a lot of policy work and work with institutions.
Institutions were actually the most supportive. We got a lot of emails from TradFi institutions offering help and trying to figure out how to progress, because they have so much belief in the technology, even though we have more skin in the game. That was really surprising. I was more worried about how this affects DeFi than anything else.
I think we felt really lonely until a lot of the other stakeholders, like Mike and his team, came up and started putting solutions on the table. That was a very difficult place to be in, and you were so limited by time constraints and resources. I think even DeFi United could have been done in various different ways, but when you have to move fast and execute, you operate on what you can do during that particular day.
2. Fidelity Crypto Ad
This episode is brought to you by Fidelity Crypto, a platform built in-house with the same discipline Fidelity applies to everything. So you can invest in crypto confidently. [music] Trade crypto backed by industry leading security. Get started at fidelity.com/crypto. [music] Crypto is offered by Fidelity Digital Assets and A is not insured by [music] FDIC or SIPC and includes risk of complete loss. Fidelity Brokerage Services [music] LLC, member NYSE SIPC. Mike, why did Stani credit you for going above and beyond? I know you said it could be FTX-level, and that the cascading effect could have really taken down DeFi, but why? Can you walk me through a little more detail about how DeFi United came to be, why you decided to make this the moment that you guys really stepped up, and what other ideas you were considering as solutions?
I don't know exactly how much I can say, but I'll err on the side of transparency. We threw around a lot of different ideas. One of the big ones we were talking about was Etherscan acquiring KELP—basically just taking on the liability.
Trying to do that in the span of a week is terrifying, because you're basically buying a black box and have no idea what was in there that could have taken us down as well. But we were willing to do it. I think in the end it wasn't the right solution, but we went pretty far down that path.
Did you give them an offer?
Yeah, we were exploring three or four different things in parallel. This meant legal documents going back and forth, so this was one of the paths that we were going down. The thing we were trying to optimize for was simply: How do we get this sorted as quickly as possible?
Another thing I think people don't appreciate is just how stupidly lucky we got. ETH had been basically flat for about 2 weeks, at $2,300 on the dot. There would have been a big problem if ETH had suddenly dropped by 20%, which happens on any random Tuesday. Iran starts shooting again, ETH drops 20%, and the problem suddenly gets a lot bigger, especially when, you know, you lose
Explain that. Why does the problem get so much bigger then?
In lending markets—and I'm sure Stani can comment more on this—when utilization is 100%, you can't liquidate. That could have led to a much worse cascade, where you would have had a lot of bad debt in place.
That created this extreme time urgency, because we were watching the price and hoping that it didn't move. We needed to act quickly, mostly to restore confidence. Even just making an announcement about what we were doing went a long way toward giving people the feeling that this was going to be taken care of.
As soon as the announcements went out, you immediately saw at least the stablecoin markets start cooling off. Now there were hundreds of millions of dollars of liquidity available. The ETH market was also cooling off, and there was a lot of unwinding taking place. So I thought, “Okay, we're past the worst-case scenario.”
Etherscan was in this unique position because we actually had no exposure. None of our vaults had any rsETH exposure. Our position even in Aave was such that we were short ETH, because the looping on our vaults is such that it uses wrapped ETH or asset as our staking asset as collateral and borrows ETH.
We could easily unwind it without taking any exposure. Our total cost for the increased interest rates on the ETH borrows was something like 400 ETH, so it wasn't a major issue for us. But what I saw was that if DeFi blows up, Etherscan can't exist.
So I didn't give a shit about whether it was a competitor. It doesn't matter. If DeFi blows up, we can't exist. Therefore, we had to throw everything we had at it to make sure that everyone pulled together and actually gathered in a room to talk to each other and solve the problem.
As I said, thankfully, we got there. I also noticed that when Etherscan came out publicly, a lot of DeFi projects that didn't have skin in the game started contributing as well, which was really incredible—from Frax to others. So it started a really genuine movement and an understanding of why this is so important. I think this really helped bring everyone onto the same team.
Without DeFi United, and without Mike coming in and trying to get people to solve this, the first days would have been a really difficult situation. On one hand, you're dealing with raising funds. On another, you're analyzing what needs to be done for the attacker's position. On the other side, you're dealing with human relations, and then you're dealing with the DAO.
Keeping your focus engaged is really difficult. If you believe in DeFi and what it could bring, it's a situation where everyone steps up of their own will. Obviously, there are people who don't want to support it and don't see that as a path forward, and that's totally fine. But we believe that if this technology and these protocols are going to scale in the future, we have to ensure that we have stability and that these markets regain confidence quite quickly.
The challenge with DeFi is that capital moves extremely quickly, and signals move really quickly. In TradFi, there are certain bottlenecks, for example, for liquidity movements. I think that's something we have to think about going forward: If you have a temporary loss of confidence—which in our case basically means that liquidity is available for positions, but not at a specific time—you have to wait for confidence to return.
To our surprise, it was interesting to see stablecoin liquidity come back really quickly, and later ETH liquidity as well. Some of the participants who wanted to help were actually helping by supplying liquidity. They were betting on DeFi and betting on Aave, pushing confidence, and that really helped.
And they obviously enjoyed the higher rates than usual. Yeah. Are there any teams that you want to call out? Well, I guess there’s the good and the bad. Are there any teams that you think really stepped up that you want to call out? Or I guess any teams that were frustratingly absent from the conversations?
Maybe in a few months, maybe in a year, we can talk about that.
Should there be some sort of—I mean, I’m not saying, for the Game of Thrones watchers, “Shame, shame, shame”—but I feel like if this was an FTX-level event, the people who were so impacted should potentially have lost $30–$40 billion. If it really was that scale, which I think you’re right, shouldn’t everyone have stepped up? There were a lot of people who joined DeFi United. There were a lot more who did not.
Yeah, I mean, definitely there were a lot of expletives in the Telegram chats, bitching and complaining, and for sure there was frustration that one party or another didn’t step up as much as they could have.
On the other hand, I’ve run other businesses before at that scale. I’ve been in lawsuits. To me, I’m like, okay, I know how this works. I kind of have a playbook for how this turns out. Maybe some of us are wired differently. There’s less of this fear. To me, the fear of inaction was much greater than the fear of rushing into the unknown and trying to solve the problem, whereas maybe some of the other teams that didn’t step up or acted too slowly, I think it mainly came out of fear.
Because if you’re facing potentially a whole bunch of lawsuits and even criminal liability in some cases, it’s very easy to just lock up and freeze in the moment. Then that’s how things get worse, right? Through inaction.
Yeah, I agree. I think there was a lot of selfish behavior at the beginning, all the way to DLP level. And I think once we got past that finger-pointing—because I think everyone published their reports and whatnot—and DeFi United was basically launched, I think that was the pivotal moment.
At that point, it was about, okay, this is not about whose fault this is or who to blame. It’s about what the next steps are, how to restore, how to mitigate in the future, and how to solve this. The teams involved, including Ether.fi, Lido, Ethena, and a bunch of other ones, have been really helpful. Also teams like Mantle, and even on the Ethereum side, we tried to reach out to everyone, including the Ethereum Foundation and a lot of the Ethereum OGs as well. Joseph Lubin was willing to step in, along with a bunch of other people.
So, it really showcases that there are a lot of good people in our space who are willing to help. What it means for me personally is that, at least, I know in the future who the true friends are and who are willing to step in. It also means that we can be helpful and step in if this happens to someone else and there is cross-chain ethics. So, how do we prevent that?
I think the biggest win here is that people weren’t too selfish and trying to protect themselves. Instead, they turned into a mode where they were trying to figure out how to solve this on-chain, within the communities, and in a way that really restores everyone’s confidence and makes everyone happy. The happy path for everyone is 10 times harder than the happy path for Aave, the happy path for Ether.fi, or the happy path for someone else. So, there was a lot of work to do there to get to that point.
I’ve never coordinated with 6 different DAOs at the same time, with proposals and voting, and it’s been quite an experience.
And what happened with Arbitrum? I think that’s another—you could probably make a movie about this whole insane situation, right? Arbitrum, again, I’m probably speaking out of turn, but effectively took back the money that the North Koreans stole. Thankfully, through a process, that money is now on its way back to users. So, that was remarkable.
I mean, that could have been the thing that made things turn out differently, right? If that amount wasn’t recovered, that 30,000 ETH made the whole lot more manageable than without it. So, it was a pretty wild situation. Well, Mike, say one more thing about the Arbitrum situation. Why was it such a movie-like scenario?
Well, I mean, the North Koreans stole a bunch of ETH, and a bunch of it was sitting on Arbitrum. Arbitrum took—I don’t know the exact details—but they took a vote and took collective action to basically pull back that ETH.
If they hadn’t done that, if the North Koreans had pulled the money off of Arbitrum and then started their swaps on THORChain or whatever channels they were laundering it through, that money would have just been gone. Now you have another 30,000 ETH—about $80 million—to fill, which would have just made it that much more painful.
Yeah. Are we through—I know we’re through the worst of it, but are we through the whole situation?
There are still actions to be taken. Obviously, out of the 6 DAO governance proposals, there is 1 left on Mantle. The Arbitrum governance process is quite long, so that’s another one. There’s also a Compound governance proposal, because they have some actions there, including liquidating the attacker’s position.
A proposal to liquidate the attacker’s position on Aave was released and actually has an on-chain vote in an hour. So, that is happening. Once that has been done, the bucking starts, and then everything sort of restores and nature heals by that time.
There’s also a lot of work across DeFi to talk to a lot of teams, institutions, and whatnot and educate them about the incident. A lot of teams have been taking efforts to improve their trust assumptions around, for example, bridge infrastructure. I think that’s something that’s been really helpful, along with different multisig configurations.
Overall, the space is realizing the threat that is coming from North Korea and basically how to mitigate against that, especially as these exploits become very targeted. So, there is a lot of work in terms of security and education that still needs to be done, as well as restoring the whole confidence in DeFi.
3. Fidelity Crypto Ad
Take a disciplined approach to crypto investing with Fidelity crypto, a platform built in-house using over a decade of crypto experience. At Fidelity, you can trade crypto and stocks together backed by industry-leading security. When you can see your accounts in one place, it's easier to make smarter [music] decisions. Get started at fidelity.com/crypto. Crypto is offered by Fidelity Digital Assets NA, [music] is not insured by FDIC or SIPC, and includes risk of complete loss. Securities offered by Fidelity Brokerage Services LLC, member NYSE, SIPC. Stani, can we focus on Aave for a bit? I want to talk about lessons learned for the industry. Maybe there are a bunch of ideas that have been thrown around, but if you look at Aave, your guys' deposits fell from like around 70 75 to around I think 25 or 30. Obviously, this hit you guys hard.
I’m just curious: you’ve been running this thing for coming up on 10 years now. How do you think about lessons learned from the Aave perspective? Where do you go from here? How do you think about the future?
Overall, TVL is a metric that isn’t the purest way to measure growth, because a lot of the TVL, for example, comes from different business lines. It can be lending stablecoins against Bitcoin and Ethereum, leveraging yield-bearing stablecoins, or leveraging staking yields as well. That staking-yield business is quite substantial.
So, when you see deleveraging momentum, that actually shows in the charts. Once confidence picks up and the market picks up, a lot of this looping will reactivate as well. So, that is interesting.
But overall, what we think from a wider Aave perspective is that we have to expand DeFi beyond existing use cases as well. I think we’re sort of in that $100–$200 billion market size that we’ve been in for the past few years, more or less, depending on the market’s credit cycles.
What we truly want to achieve is for Aave to actually be used as the backbone of all finance and credit.
So, you know, if you issue credit, you should do that directly on or indirectly to Aave. In that way, we get more diversification for these business models, and also business models that don't necessarily depend on the native strategies that we have, for example. So, it's all about diversifying.
I think I mentioned this somewhere else: I see a future where the underwriting risk is tied more closely to the balance sheets and revenues of the Aave DAO. That means that, in the future, it becomes even more important to be able to cover black swan events and events that might be out of our control, but where you might indirectly be underwriting that type of risk. That is why I think strengthening the balance sheet and creating different ways to protect the protocol are important. We have the Aave-native protection mechanism with Umbrella, but we could also come up with different forms of insurance down the line. So, I think that's the sort of future we're heading toward.
4. How To Prevent DeFi Hacks?
How do you think about risk management as you guys try to be the credit layer for all of the global capital markets? Let's say this vision works out: you need way more assets that you can borrow and lend against. How do you think about that? I think I saw a suggestion for formal risk metrics for new assets, like bridging risk, restaking complexity, and maximum supply limits. How do you think about the risk of all these new assets?
Well, the thing is that this ties to the point of tying the lending closer to the balance sheet and to balance-sheet economics. In the future, Aave should not be in a position to underwrite all risks, because obviously there are a lot of debt or, let's say, lending businesses that are at the tail end, and they don't necessarily belong to Aave. So, I'm less confident in this model of lending as purely infrastructure, because someone needs to take the risk. If you remove risk management from one layer, it moves to another layer, for example, at that point.
From Aave's perspective, it should be the prime location for prime assets and, obviously, new use cases, but from a prime standpoint, to the extent that the balance sheet and future revenue can cover these types of initiatives. I don't see Aave—at least the Aave DAO governance pools—being a free-for-all where you list anything you can. Part of Aave's success has been that we've been able to keep a lot of these assets that had problems or configurations where their pricing or something else was an issue out of the Aave protocol. You can still license the technology and create all sorts of markets, but where the Aave brand actually stands is in that prime asset quality.
5. Launching DeFi United
One more thing here, and then, Mike, I'm going to jump to you in a second. Stani, if you're less bullish on on-chain lending infrastructure but more bullish on big balance sheets, what does that actually mean? Usually, to get a big balance sheet, you raise a boatload of capital. Are you going to go raise $1 billion? What are your plans to bolster the balance sheet?
I think what we notice is that confidence plays a big part in the lending infrastructure. If you have a model where there's no one taking that risk and no one has skin in the game, it ends up in a situation where there are misaligned incentives, and you see an arms race toward capturing more risk because of the yields, for example. We've seen this in DeFi going on and on.
But I think when you can pair skin in the game, balance sheets, and risk management, you end up in a place where you make more rational and better risk decisions. I think anyone can use Aave's infrastructure to create new, net-new lending markets, for example. But I think that the actual mass capital will sit in these large pools backed by protocol-native balance sheets. That is the direction we're heading.
Mike, how does this impact how you think about Ether.fi's strategy? You guys are so active in DeFi, right?
For sure. To give context, Ether.fi has a couple of different lines of business. We have the staking protocol, and we have the DeFi strategy vaults that we call Liquid, which obviously participate in Aave and across DeFi. Then we've got our DeFi neobank business, which includes cards, treasury management, and so forth.
Underlying that is a lending market, and we hope to migrate that to an Aave V4 instance in the next little while. That very much aligns with what Stani is saying. Our goal is to allow users to provide tokenized stocks, commodities, different assets, and more RWAs backed by real-world economic activity, and then be able to borrow against them and use them in their financial lives.
The power of that kind of infrastructure is that it allows these more decentralized pockets that are isolated from each other, instead of having one giant pool where, if something goes wrong, it has this contagion effect on all of DeFi.
6. DeFi’s Speculative Premium
Are there any suggestions that you guys have seen that you really like? I saw a lot of people talking about why we don't have insurance yet in DeFi. I have many thoughts on that, but—
It would cost you 15% a year. I think this is the problem in DeFi. If you actually look at the risk involved, you really need to be getting paid 10% to 15% a year.
What's happened is that a lot of the speculative premium has gone away. You used to be able to do that, but now a lot of the speculative premium has gone away because of the nature of the market we're in and the market cycle. Yields have compressed, and now people are basically going further and further out on the risk curve for lower and lower yields. You have protocols that may be paying you 6% when they really should be paying you 30% for the risk that you're taking.
I think the root cause of that—the source of that—is that everything is founded on this speculative premium. Basically, one way or another, everything is trickling down from people betting on the price of Bitcoin, ETH, and whatever else going up. That has to change. Unless that changes so that it's actual economic activity, with businesses producing cash flows that drive this stuff, there's never going to be enough yield to cover the risk.
Today, in this environment, insurance is impossible because any sane underwriter is going to charge you way more than the yield that you're getting in DeFi these days.
I echo that. The reason why we're in DeFi at the moment is that a lot of the economic opportunity comes from native crypto assets. This is actually good because people are long on native assets—long on Bitcoin, ETH, and all these important DeFi protocol tokens. There is really important infrastructure there, and that's going to keep growing.
But what we have to get into is using the DeFi infrastructure that works really well on these native assets and expanding it into traditional assets, RWAs, and credit—purely using DeFi liquidity and channeling that directly to opportunities in the real world, helping consumers, businesses, and institutions with their funding and infrastructure. That's something that I've been researching quite a lot.
Then, bringing those assets in a way that they can be used more natively, in an interesting way. I think we have to get to a place where we have much wider diversity, and that changes the economics for everyone: insurance, base yield, risk profiles, and so forth.
I don't think there's just this discussion about whether lending pools should be isolated or shared. The fact of the matter is that if there's a confidence issue in DeFi, liquidity will move from all the protocols at the same time, and that creates liquidity crunches. It's more about how you diversify as widely as possible.
The Aave Horizon market was a great example because, while everything else was happening, Horizon was growing at the same time. People had confidence in lending against RWAs and weren't taking on the same kind of exposure to completely different asset classes. I think that's the way to improve the economics of these instruments.
What do you guys think about the risk of—We've had more hacks this year than ever, right? I think we're at around $700 million on the year so far. It seems like North Korea is probably enemy number one for the industry. I'm curious, Mike, how you think about how we scale this industry and scale on-chain capital markets if we're trying to fight off North Korea and there are hacks every other day.
I don't have fully formed thoughts on this, but here are some ideas I've been thinking about and things that we're doing at ether.fi: We really need to stop the decentralization theater.
Because there are a lot of things that protocols do in the name of decentralization without really helping that aspect of it, but instead just encumbering the protocol’s ability to act in emergencies. I think there’s a way to preserve the non-custodial nature of DeFi protocols and true decentralization as far as decision-making, management, and how these things operate, without putting in a lot of the sort of theatrics.
I do think that things like blacklists are actually good. We’re going to be implementing that because it allows you to act in case of an emergency, in case law enforcement—believe it or not, you operate within a universe of legal systems and you have to be able to abide by them. There are other protections that come into place, including the ability to pause and off-chain monitoring that automatically triggers contract pauses.
I think a lot of these hacks can be prevented because, in the end, it’s not that hard to detect when all of a sudden there’s an anomalous $300 million of capital that moves. That’s very easy to detect. But we put in all of these theatrics that prevent us from actually being able to act in a reasonable way.
I think there’s a difference between the standard to which a blockchain needs to be held—a blockchain like Ethereum, where you really do need this ultimate autonomy and decentralization—and a DeFi protocol that has a DAO, labs, and companies that operate it, which just need the tools to be able to intervene when things go sideways. I think the most effective protocols already do that. That just needs to become a standard rather than, as I said, sort of decentralization shibboleths that people parrot.
So, what would you actually do concretely, Mike?
Put in a blacklist so that you can actually block addresses, the same way that Tether or Circle and others have. Again, there’s a spectrum there, but having the ability to just block addresses of malicious actors with a governance process—maybe you block it for 24 or 48 hours, and then it requires a vote to solidify that block. The ability to pause the contracts in extreme circumstances. There are half a dozen other things, but things along those lines that allow you to actually—
Time locks and delays.
Locks should be default on everything. We have them pretty much everywhere, so that if someone takes over your multisig, they can’t just upgrade the protocol to pull everyone’s funds. There are certain things that should just become best practices and become expected, and they should become part of the audit to get listed on any major lending venue, DEX, or whatever. At least disclosures should be made around this stuff.
Yeah, I agree. Emergency response is very critical. I believe in decentralization where it helps in the permissionless aspect of it, but there needs to be a middle ground where you can also take faster actions. So, I agree there.
I think a lot of the hacks that happened in the past couple of months were also a lot of key compromises. They weren’t really contract hacks themselves, including the bridge exploit involving Kelp Layer 01. I think it’s more about the Web2 security aspect, and that’s something that we’ve recently received a SOC 2 attestation for. It showcases that DeFi is also moving in the direction of trying to secure the infrastructure around the contracts in the traditional way.
That’s where the weaknesses are, and the measures that these folks are trying to take to actually penetrate are unbelievable. It’s just about investing more and more resources to combat all of these things, and this is something that the whole industry has to really understand. You can’t run a DeFi frontend that’s built by Cloud anymore. It’s just asking for issues.
You can’t really have weak signing mechanisms anymore. You really have to build for scale and for the worst outcome possible, because these things will happen in the future. The important thing is to understand how to react and how to improve the security.
The space is open, so that’s the beauty of DeFi: anyone can come and build through open innovation. That’s what got me here in the first place. But the stakes are increasingly high at the moment. We also try to do a lot of things in public, in the sense that whatever improvements we have, we try to share them with the community and other teams to raise standards across the industry. I think a lot of teams are doing the exact same thing.
I’ve got a totally separate question, more around investor relations, but is there anything else on Kelp DAO or any of this stuff that we missed that we should talk about?
Well, I think—I mean, this is probably a separate episode for you guys—but just the level of sophistication and how terrifying, frankly, these attacks have been, looking at what happened with Drift and Kelp as the most recent examples. This isn’t like they put a virus on somebody’s computer, somebody downloaded a fake Zoom application, and they took over their machine and stole their private key.
These are multimonth, sometimes multiyear, compromises that are extremely sophisticated. Watching these things, I think anybody who’s operating in the space needs to be paranoid to a very high degree, just because of how sophisticated they are.
You have an entire country where basically its top minds, its top computer science graduates, are being put into a government department whose mandate is to steal money from crypto protocols. In the same way that we have a Department of Health and a Department of Education, they have a department for stealing crypto funds.
You have some pretty sophisticated actors in this entity. If you’ve read the transcripts—there have been leaks of their Discords and communication logs—they’re treating this like a business, right? They have leads, and they’re operating in this in a very sophisticated and professional way. It really raises the bar. You need to get to a point where you’re almost impossible to compromise in order to operate in this space.
Should there be—Israel has the Iron Dome, right? It’s for attacks on its citizens, but you have to pay taxes, and those taxes go into building this defense system. Is there something like the Iron Dome of crypto? Would you impose a tax on any protocol with more than 10 million FTV or something?
Certainly, maybe you create a security council. People pay into it to be a member, and in exchange you get audits and protection. I don’t know, something like that—almost like a NATO of crypto.
I also believe that probably another strategy is to counterattack. I bet these North Korean networks are possible to infiltrate. They’ve got infrastructure, right? They have tools that they use to manage their funds and money-laundering operations.
7. Why DeFi Tokens Are Uninvestable
It’s not hard to imagine a counterattack—to pull those funds back and help victims recoup their losses. Maybe we need a vigilante group of crypto experts to go after these guys.
All right. I’ve got a final, maybe closing question or closing topic here. Mike, I would say you guys at ether.fi do everything. You’re actually the company we point to a lot when we look at good investor relations, right? You run your quarterly calls, you do reporting and public dashboards, and you generate real revenue with real users, real cash flow, and real products that touch people outside of crypto.
You’ve built an amazing, amazing, amazing business, and I commend you for that. But at the same time, the token is down about 30% in a year, and, Stani, your token is down about 40% or 50% in a year. Is there anything that you think teams can do right now to catch a bid on their token, or is this just what the bottom of a bear market looks like?
I mean, look, correlation is just 1.0 on everything. That’s the nature of the market that we’re in. Trying to pick one asset versus another is almost pointless because, again, everything is basically trading together.
I think one of the challenges we’re having is that, in many ways, crypto assets, tokens, and DeFi protocols are not investable, at least for fundamentals-based investors. When you look at it and buy a token, what do you actually have a claim to? You just have a memecoin with the name of the protocol in most cases.
We’ve done things like buybacks. I think Aave has done some buybacks, and that goes to a certain degree toward providing some confidence that there’s a connection between the token and the health of the protocol. But I really think we need to go further to actually create investor protections within this decentralized framework that we have, to make these assets investable.
And we've already seen inklings of that. I hate to mention a competitor, Stani, but Morpho has announced their Morpho One framework, and I think that's gone pretty well for them, because the structure they put in, where their labs company is actually owned by the foundation, makes it very hard for the labs company to rug token holders, as we've seen some labs companies do.
But even that, I think, doesn't go far enough. So what we're working on—and I don't want to pre-commit to it just yet—is an open-source framework for investor protections for token holders. We want to implement it internally first and then put it out there for others to use or iterate on if they want. And my hope is that this will bring in fundamentals-based investors who can actually look at a protocol and say, “Oh, wow, look, this is a great business. It's growing, it's got cash flows. It actually makes sense. There's a reason to own the token because it has some exposure to that.”
Yeah, I agree that the framework question is important. When you look at a lot of these protocols, it's really hard to compare them, because a lot of the data isn't in a format that is very representative. I think Ether.fi is doing a great job of actually putting all the pieces together, and that's something that we're going towards as well.
I do think that the correlation is sort of something that can be solved on the back of that. If DeFi protocols can reach their fullest potential—not just being limited to existing crypto assets, but actually being the protocols that run a lot of the financial plumbing, the same way that HTTP and IP protocols run the plumbing of the internet, or, let's say, Stripe as the plumbing of internet payments—I think we get to a place where people understand the direction and how we get to a place where this technology could be used in pretty much all the financial use cases.
So maybe to tie it back to this whole DeFi United and the recovery fund, Stani, you said this—I think it was a very important point—that this was not a bailout, at least in the traditional sense of a bailout, where a government takes taxpayer money and throws it at some maybe failing financial institutions to prevent systemic risk. This was a market action, right? This was many independent, in many cases competing, players coming together and helping the ecosystem thrive and survive.
In the same way, I think, as an ecosystem, the right approach here would be to put together some equivalent of GAAP accounting standards for protocols, so that disclosures and reporting—and I know you guys have actually put together some work on this—are standardized, so that people can look at DeFi protocols apples-to-apples, and then create a framework around value accrual and investor protections.
Yeah, I will ping you about that separately, Mike. A lot we can do together.
So anyways, guys, I know you guys are busy. Congrats on, I guess, getting through a tough 2 weeks and pulling together DeFi United. This was interesting for me, just to understand how big the contagion really could have been here. Hats off to both of you guys.
Thank you so much. It's been a pleasure to be here in a rough couple of weeks, but DeFi will win. The show goes on.
All right. Thanks, guys.