KelpDAO 的 2.9 亿美元攻击险些杀死 DeFi|Stani Kulechov 与 Mike Silagadze
Jason YanowitzStani KulechovMike Silagadze
- Mike Silagadze 对“这次 Kelp 漏洞攻击的影响可能远超 FTX”这一判断,仍然“100%”坚持。 朝鲜黑客通过 Kelp 基于 LayerZero 的跨链桥接架构窃取了约 2 亿美元,但更大的风险是市场上尚有 15 亿美元 rsETH:如果 Kelp 按 Mike 所理解的法律顾问强烈建议申请破产,这些抵押品可能在 Aave、Compound、Euler 及其他协议中冻结数年。Mike 称这可能演变成一场“世界末日”级别的危机,Yanowitz 则提出了 300亿–400亿美元影响的假设。
- Aave——用 Mike 的话说,是“责任最小的一方”——接下了问题,并组建 DeFi United。 Stani 表示,Aave 本可以对资产进行折价处理、确认亏空,再从协议金库、资产负债表和收入中填补,但最终选择了一个覆盖整个生态、重建市场信心的方案。他反对使用“救助”一词,因为这不是纳税人出资的支持,而是参与者自愿承担风险、提供流动性并押注 DeFi 和 Aave。
- Mike 的团队尽管金库里没有 rsETH 敞口,仍承诺投入 5,000 ETH,并研究过直接收购 KELP。 尽管收购一个黑箱存在巨大风险,这支团队仍把几条收购路径推进到了相当深入的阶段。其逻辑关乎生死存亡:“如果 DeFi 爆掉,[这支团队]也不可能存在。”
- Mike 称,这次恢复过程“幸运得离谱”:ETH 在约 2 周时间里维持在 2,300 美元附近。 如果市场随机下跌 20%,借贷市场可能正好处于 100% 利用率,仓位无法清算,进而引发更严重的坏账级联。Arbitrum 的投票和集体行动还追回了约 30,000 ETH、约 8000万美元,不过 Mike 表示自己并不了解具体细节。
- Stani 的结构性结论是:他对借贷作为纯粹基础设施的模式“没那么有信心”了,因为总得有人承担风险。 Aave 希望从约 1000亿–2000亿美元的 DeFi 市场继续扩张,成为金融和信贷基础设施;未来的承保应更多与 DAO 的资产负债表和收入挂钩,并结合 Umbrella 保护机制及潜在保险产品。Ether.fi 希望将其新银行式借贷市场迁移至 Aave V4 实例,支持用户以代币化股票、大宗商品及其他 RWA 作为抵押品借贷。
- Mike 认为,当前 DeFi 保险在经济上不可行,“去中心化表演”必须结束。 合理的风险定价可能要求 10%–15% 的回报,但一些协议只支付 6%,对应的风险却可能需要 30% 的回报。他提出的安全措施包括黑名单、可暂停机制、自动监控和默认时间锁,以应对高度成熟的朝鲜黑客行动。讨论中的方案既包括付费的“加密版北约”安全委员会,也包括 Stani 提议的反击行动或“治安团体”。
- Ether.fi 的代币一年下跌约 30%,Aave 下跌约 40%–50%,尽管 Ether.fi 拥有收入和产品。 Mike 表示,“所有东西的相关性都是 1.0”,而且代币除了“一个挂着协议名字的 meme coin”之外,往往并不代表任何有意义的权利。Ether.fi 正在研究开源的投资者保护框架,但尚未对此作出预先承诺;Yanowitz 提议采用等同 GAAP 的披露标准,Stani 则表示双方还有大量工作可以合作推进。
1. 真正的危机不只是被盗,而是 Kelp 破产并冻结 15 亿美元 rsETH
- Mike 解释了事件机制:朝鲜黑客利用了 Kelp 为跨链架构选择的结构——“他们当然用了 LayerZero”——窃取了约 2 亿美元。但面对如此规模的攻击,市场通常会本能地“撤退、找律师、全面防御”。Mike 认为 Kelp 的法律顾问强烈建议其申请破产。这样一来,2 亿美元的问题就可能变成 15 亿美元的问题:“外面有 15 亿美元的 rsETH”,而这些资产可能被冻结数年。
- 级联风险在于:被冻结的 rsETH 分布在 Aave、Compound、Euler 及其他协议中;中心化交易所和 DeFi 项目又把资产放在这些借贷市场里,因此流动性紧缩可能迅速扩散——“这显然是世界末日级别的场景”。Yanowitz 提出了 300亿–400亿美元影响的可能性,Mike 则将潜在结果与 FTX 相提并论。
- Stani 补充说,资产本身在主网上基本有足额支持,问题更多来自它在其他市场中的使用。但如果“选择 TradFi 的路径”,让所有人都采取保护性措施,整个系统就无法通过集体行动解决问题。
- 按 Mike 的说法,随后起作用的是运气:ETH 在约 2 周时间里基本横盘于 2,300 美元附近。如果下跌 20%——“这不就像任何一个普通周二都会发生的事吗?伊朗又开始开火了”——借贷市场可能正处于 100% 利用率,届时“你无法清算”,坏账级联会严重得多。这也造成了极端的时间压力。
2. DeFi United:Aave 接下了并非自己造成的问题,Mike 的团队承诺投入 5,000 ETH
- Mike 对 Aave 的评价是:“唯一一支真正站出来说‘不,我们要解决这个问题’的团队。”在所有相关方中,Aave“责任最小”,却主动接下了问题。Stani 证实,Aave 本可以对资产进行折价处理、确认亏空,再从协议金库、资产负债表和收入中支付。但由于涉及多个协议、LP 以及一层层被波及的利益相关方,Aave 最终追求的是一个尽可能修复整个生态、重建信心的方案。
- Mike 的团队金库没有 rsETH 敞口,其在 Aave 上的仓位通过循环策略实际上是做空 ETH。ETH 借款利率上升让团队额外付出了约 400 ETH。即便如此,团队仍承诺投入 5,000 ETH,因为如果 DeFi 失败,团队也无法存在;Kelp 是否是竞争对手“并不重要”。
- Mike 表示,团队曾并行探索 3、4 条路径,其中包括直接收购 KELP,双方甚至来回推进法律文件。“你基本上是在买一个黑箱”,里面可能存在未知负债,最终连买方也可能被拖垮,但团队仍愿意考虑这条路。
- Stani 认为,Mike 及其团队帮助大家把律师暂时放到一边,让创始人和各团队坐到一起。至于“救助”这个词,他明确反对,因为这个词让人联想到纳税人出资的干预;这次是参与者真正承担风险、自愿提供流动性,“押注 DeFi,也押注 Aave”。公告发布后,稳定币市场趋于平静,数亿美元流动性重新可用。
3. 谁停滞不前,谁真正出手——以及 Arbitrum 的支线
- Mike 对迟迟没有行动的团队有一套解释:它们往往是在恐惧中做决策。面对诉讼,甚至在某些情况下的“刑事责任”,团队很容易“僵住、冻结”。Mike 曾在诉讼期间经营企业,他说,自己更害怕什么都不做,而不是贸然进入未知领域。他形容 Telegram 群聊充斥着脏话;Stani 拒绝点名那些缺席的团队,但表示几个月后或一年后也许可以谈。
- Stani 意外发现,TradFi 机构反而“最支持”这次行动,尽管它们承担的风险更小,仍主动提供帮助。早期 DeFi 的行为“自私……一直自私到 DLP 层面”,直到 DeFi United 将重点从追责转向止损。Frax 及其他没有直接敞口的项目也参与了贡献;Ether.fi、Lido、Ethena、Mantle 等项目提供了帮助,Aave 一侧还联系了 Ethereum Foundation、Ethereum OG 以及 Joseph Lubin,后者愿意介入。
- Yanowitz 描述了一个颇具电影感的情节:Arbitrum 通过投票和集体行动,实际上追回了被盗 ETH。Mike 表示自己并不了解具体细节,但如果没有这次行动,攻击者可能会通过类似 THORChain 的洗钱渠道转移资金。追回约 30,000 ETH、约 8000万美元后,资金缺口变得更容易处理。
- 后续工作包括 1 项尚未完成的 Mantle 提案、耗时较长的 Arbitrum 治理流程,以及一项包含清算攻击者仓位等行动的 Compound 提案;Aave 提案的链上清算投票则预计在录音结束约 1 小时后进行。Stani 还强调,安全建设、教育和对机构的沟通都必须继续。
4. Stani 的重构:承保应与资产负债表绑定,而不是“自由放任式”基础设施
- 针对 Aave 存款从约 70–75 降至 25–30,Stani 表示,TVL 并不是纯粹的增长指标。里面既有稳定币、BTC、ETH,也有质押收益杠杆,因此去杠杆会在图表上显著体现;当信心恢复后,循环借贷可能重新启动。
- Stani 还表示,过去几年 DeFi 一直是约 1000亿–2000亿美元的市场,而 Aave 更大的目标是成为“所有金融和信贷的底层骨架”。但他对借贷作为纯粹基础设施的模式“没那么有信心了”,因为“总得有人承担风险”。如果把风险管理从某一层拿掉,风险只会转移到其他地方。
- 未来的承保风险应更多与 Aave DAO 的资产负债表和收入绑定。Stani 提到了 Aave 的 Umbrella 保护机制和潜在保险产品,同时强调 Aave 会继续聚焦优质资产,而不是任何能上架的资产都上架。把问题资产和有问题的配置挡在系统外,一直是 Aave 成功的一部分。
- Mike 表示,Ether.fi 希望把其 DeFi 新银行式借贷市场迁移到 Aave V4 实例,让用户能够以代币化股票、大宗商品及其他 RWA 作为抵押品借贷。他更偏好彼此隔离的去中心化资金池,而不是一个会传播传染风险的巨型资金池。
- Aave 的 Horizon 市场是 Stani 提到的一个实时分散化案例:在更广泛的事件持续发酵时,Horizon 仍在增长,因为用户借贷所针对的是不同资产类别。不过他也指出,在信心冲击下,流动性可能同时从多个协议撤出。
5. 按当前收益率,保险在经济上不可行——投机溢价是根因
- Mike 表示,DeFi 保险“每年会收你 15%”,而相关风险可能需要 10%–15% 的回报才能得到补偿。随着投机溢价下降,收益率被压低,用户只能以更低回报承担风险曲线更远端的风险。有些协议支付 6%,但其风险可能需要 30% 的回报才合理。
- 他对根因的判断是:“所有东西都在逐层传导,源头是人们押注 Bitcoin、ETH 以及其他资产价格会上涨。”除非真实企业产生现金流、为系统提供驱动,否则就没有足够收益覆盖风险。在当前环境下,“任何理性的承保人都会向你收取远高于 DeFi 收益率的价格”。
6. 对抗民族国家级对手:停止“去中心化表演”
- Mike 提出的具体议程是:“我们真的必须停止去中心化表演。”他支持黑名单机制,包括先实施 24 小时或 48 小时的临时封禁,再由治理程序决定是否永久化;他还支持紧急暂停合约、能够触发暂停的链下监控,以及默认时间锁。3亿美元的异常资金转移本应能够被发现,但协议设计往往让系统来不及干预。
- 他区分了 Ethereum 这样的底层区块链与 DeFi 协议:前者需要最大限度的自主性和去中心化,后者拥有 DAO、实验室和运营公司,则需要紧急处置工具。他希望这些保护措施成为项目上架和审计时的标准披露,而不是不可触碰的“去中心化图腾”。
- Stani 同意紧急响应至关重要。他表示,近期许多事件,包括 Kelp 跨链桥攻击,涉及的都是密钥泄露,而不是合约漏洞;围绕签名、基础设施和前端的 Web2 安全,才是主要薄弱环节。他说团队最近已经获得 SOC 2 鉴证,并警告项目不能再依赖薄弱的签名机制,或依赖一个“由 Cloud 搭出来”的前端。
- Mike 表示,朝鲜政府设有专门窃取加密资金的职能部门,成员是能力很强的计算机科学家。他说,泄露的通信显示这是一套专业化运作,有明确负责人和类似企业的流程。这些攻击往往是“持续数月,有时甚至数年”的渗透。Yanowitz 提到,截至当年已经发生约 7亿美元的黑客攻击损失。
- 提出的防御方案包括 Mike 设想的付费安全委员会——“几乎就是加密版的北约”——以及 Stani 提出的、更具推测性的反击方案:渗透洗钱基础设施,组建一个“由加密专家组成的治安团体”,追回受害者资金。
7. 可投资性难题:“一个挂着协议名字的 meme coin”
- Yanowitz 指出,Ether.fi 的代币一年下跌约 30%,Aave 下跌约 40%–50%。Mike 表示,“所有东西的相关性都是 1.0”,这让资产选择几乎失去意义,但他认为更深层的问题是:“你仔细想想,买下一个代币后,你到底拥有什么权利?你只是买了一个挂着协议名字的 meme coin。”
- Ether.fi 的回购,以及 Mike 记忆中的 Aave 回购,确实在一定程度上把代币与协议健康状况连接起来,但作用有限。Mike 表示,Ether.fi 正在研究一套面向代币持有人的开源投资者保护框架,但不愿对此提前作出承诺。他提到 Morpho 的 Morpho One 结构:由基金会持有实验室公司,这让实验室公司更难直接卷走代币持有人的价值。
- Yanowitz 提议采用等同 GAAP 的会计和披露标准,让不同协议能够进行可比分析,同时建立价值归属和投资者保护框架。Stani 表示,他和 Mike 之间还有大量工作可以共同推进。
- Stani 对长期的设想是,让 DeFi 成为金融管道,就像 HTTP 和 IP 之于互联网、Stripe 之于互联网支付。扩展至传统资产、RWA 和现实世界信贷,可以分散经济基础,并有望降低当前代币之间的相关性。他最后表示:“DeFi 会赢,节目还会继续。”
完整逐字稿
This episode is brought to you by Fidelity Crypto. You'll hear more about them later in today's episode. Nothing said on Empire is a recommendation to buy or sell any investments or products. This podcast is for informational purposes only and the views expressed by anyone on the show are solely their opinions, not financial advice or necessarily the views of Blockworks. Our hosts, guests, and the Blockworks team may hold positions in the companies, funds, or projects discussed. All right, everyone, welcome back to Empire. [music] We've been talking about Kelp DAO and Aave and all the craziness that's unfolded over the last 2 weeks: DeFi United, the bailout, whatever you want to call it. I've been talking to Stani on the side, and Mike—obviously, Ether.fi stepped up in a huge way—so I decided to bring them both on the podcast.
We've got Mike, who's the CEO and co-founder of Ether.fi, as well as Stani, who many of you already know. He's been on the podcast many times, but he's the founder of Aave. So, Stani, Mike, welcome, guys. They're right here. How much sleep have we gotten collectively in the last 2 weeks?
More in the last few days. I think it seems like the worst is over and the ecosystem kind of pulled through. It's been better in the last little while, but it was an intense week for sure.
Yeah, I think the first day after the bridge exploit—the first few days—was probably the most difficult. I couldn't really sleep much for various reasons, but also because we were sort of against the clock. Obviously, now it's a little bit easier, but there's still a good amount of work to do. So, we're still running low.
The thing that surprisingly, I guess, bothered me is that, at least to me, it was so obvious immediately, within a matter of hours, that this was an existential threat to DeFi. It was just sort of step 1, 2, 3, 4. I was like, all right, game over. This is it.
It was so clear that people needed to spring into action and immediately start addressing this thing, or else it was going to spiral. And I think, in fact, if it wasn't for the work that Stani and his team and some others have done, that was the default path. I don't think people recognize that without that intervention, without the effort that people put in, the default path was just a complete blowup of DeFi.
I think not everyone really understood where we were at that point in the space because, effectively, this wasn't about Aave. It was about DeFi as an ecosystem overall and how to manage these big capital movements that are done quite programmatically.
I think the protocols involved and the teams involved typically are really diligent. We work with them on a day-to-day basis, but when something like this happens, where you have a remote dependency, things happen and it creates an attack vector that affects the whole space. That's where everyone needs to move and figure out what the next steps are, because that's the first thing to figure out.
I think, to Mike's credit, Mike was there at the very beginning and realized what the potential paths were, including the extreme worst-case scenarios. He realized how important this is for DeFi, and that wasn't the case for everyone at first glance, but it helped quite a lot during the process.
1. How The KelpDAO Exploit Could Have Killed DeFi
Yeah, Mike, can you maybe walk us through why this was such a big deal? I'm reading your tweet here. It says, “We committed 5,000 ETH to the Kelp hack recovery fund because we thought there was a real risk that this could have killed DeFi. FTX would have looked small in comparison.”
I'm not sure if that's just a bold statement to get your tweet more viral or if you genuinely believe that, but I'd really love to hear the thought process behind it.
Yeah, it's pretty straightforward, honestly, and I 100% stand by that. I'm sure lots of people have read about the high-level events that took place, but the basic idea is that Kelp had a certain structure for its cross-chain and bridging setup. They were, of course, using LayerZero, but they had a certain structure that they decided on, and that was exploited by DPRK, North Korean hackers.
The direct impact was about $200 million that were stolen. But what it meant—and the default path for teams when something like this happens—is to pull back, lawyer up, and get super defensive. That's what was happening. It's hard to fault a team for doing that, right? You're in this extreme situation, you don't know what to do, and most people haven't lost $200 million before, so you don't know what you would do if you were placed in that spot.
The default is, all right, lawyer up, pull back. What's the safest thing that you can do? Well, the safest thing you can do is declare bankruptcy. Say, all right, this wasn't our fault. We're now encumbered by bankruptcy.
Now, if that happens—if they had chosen to go down that path, which I don't want to speak out of turn, but I think their counsel was advising them very strongly to do this—then it's not a $200 million problem anymore. Now, it's a $1.5 billion problem, because there was $1.5 billion of rsETH sitting out there. If Kelp had gone into bankruptcy, that's now locked up. That $1.5 billion isn't moving anywhere for probably years, as we've seen how long these things take to play out.
Now you have $1.5 billion that's stuck in DeFi, a lot of it in Aave markets, but also on Compound, Euler, and a lot of other protocols. Every one of those protocols, frankly, is now affected because you have $1.5 billion of assets that aren't going to move. There's going to be at least a liquidity crunch because you won't be able to pull them out for years, which then would have had a cascade effect on the lending protocols.
Every CeFi exchange has assets in various lending protocols. Tons of DeFi protocols have assets in Aave and everybody else. So, this wasn't just going to impact Kelp. It was going to impact everybody. That was what, to me, seemed like a clear Armageddon scenario.
Again, everyone's default path was sort of to pull back, lawyer up, throw their hands up, and walk away. The one team that really just stood up and said, no, we're going to fix this—let's raise a recovery fund and actually make sure that this blowup doesn't happen—was Aave. They just took responsibility and really ran with it.
In many ways, there was plenty of blame to go around, but out of all the parties, they were the least responsible. They just took ownership and really ran with it. That was great to see, and I think, in the end, all the work combined ended up averting that disaster scenario.
If you think about it from the asset perspective, the asset itself is basically backed on mainnet, so most of the backing is there. Obviously, the effect is more on alts use.
The challenge is what Mike said: if you choose a TradFi path where everyone just throws their hands up and takes protective measures, nothing here can actually be solved. We saw a lot of that, and we saw a lot of direction going toward that.
From Aave's perspective, one path for us would have been to just focus on how we solve this from Aave's perspective, apply a haircut, call it a day, register the deficit, and pay that from the protocol treasury, balance sheet, and revenue. Then we could make the protocol whole and move on.
What we realized is that there were so many stakeholders involved in this incident: protocols, LPs, different teams, cascading effects, and whatnot. We realized that if we really wanted to get everyone at the same table, we needed to find a conclusion that really satisfied everyone. That was basically to make everyone as whole as possible, find the means of doing that, and figure out how everyone could contribute in the most responsible way.
That's the big difference here, and why DeFi United was born. It wasn't about how we write this off on Aave, but how we make this whole ecosystem whole and restore confidence. Restoring that confidence is far greater than the impact on any individual protocol.
I think Mike and Etherscan played a huge role by mediating, getting everyone at the table, and pushing the lawyers off the table. These people don't belong in Web3. Things need to be solved between founders and teams, natively.
To Mike and his team's credit, they were the ones taking a lot of ideas and putting them on the table. You don't necessarily do that from the perspective of, why would you come and help other protocols in the same landscape where they offer similar products?
And doing that for the sake of restoring the whole confidence in the space is very rare. I don't think that is even a solution that people think about in traditional finance. Once DeFi United started to kick in and we saw the support, it sort of changed the whole narrative from, “Oh, these things are just pointing fingers at each other,” to, “Okay, let's all come together and restore.”
I won't call it a rescue or a bailout, because a bailout is obviously forced by taxpayers and whatnot. This was more like, “Hey, we all have skin in the game. We all believe in the space, and we're all improving our security, but we need to act now so that we can restore confidence.”
Yeah, Stani, you said—I saw one of your tweets. You said it was the hardest couple of weeks that you experienced in your entire life. Was there a moment in time, maybe on day 1 or day 2 of this unfolding, when you thought, “Maybe this is the thing that kills Aave”?
I wasn't thinking about Aave, to be honest. I was thinking more about DeFi and what the consequences of DeFi would be. I do think that Aave is built to be resilient. When you think about protocol building, you optimize not for the 99% that works, but, let's say, the 0.01% when things don't work, and how you reestablish the resiliency, basically.
We've obviously seen multiple market and credit cycles from the 2010s and the aftermath, and even in the early days of DeFi, like Black Thursdays and Mondays and whatever there was. It sort of shows the resiliency. For me, what was more important was to understand what we actually have to do to ensure that people have confidence in DeFi, because we don't just work on smart contracts; we also do a lot of policy work and work with institutions.
Institutions were actually the most supportive. We got a lot of emails from TradFi institutions offering help and trying to figure out how to progress, because they have so much belief in the technology, even though we have more skin in the game. That was really surprising. I was more worried about how this affects DeFi than anything else.
I think we felt really lonely until a lot of the other stakeholders, like Mike and his team, came up and started putting solutions on the table. That was a very difficult place to be in, and you were so limited by time constraints and resources. I think even DeFi United could have been done in various different ways, but when you have to move fast and execute, you operate on what you can do during that particular day.
2. Fidelity Crypto Ad
This episode is brought to you by Fidelity Crypto, a platform built in-house with the same discipline Fidelity applies to everything. So you can invest in crypto confidently. [music] Trade crypto backed by industry leading security. Get started at fidelity.com/crypto. [music] Crypto is offered by Fidelity Digital Assets and A is not insured by [music] FDIC or SIPC and includes risk of complete loss. Fidelity Brokerage Services [music] LLC, member NYSE SIPC. Mike, why did Stani credit you for going above and beyond? I know you said it could be FTX-level, and that the cascading effect could have really taken down DeFi, but why? Can you walk me through a little more detail about how DeFi United came to be, why you decided to make this the moment that you guys really stepped up, and what other ideas you were considering as solutions?
I don't know exactly how much I can say, but I'll err on the side of transparency. We threw around a lot of different ideas. One of the big ones we were talking about was Etherscan acquiring KELP—basically just taking on the liability.
Trying to do that in the span of a week is terrifying, because you're basically buying a black box and have no idea what was in there that could have taken us down as well. But we were willing to do it. I think in the end it wasn't the right solution, but we went pretty far down that path.
Did you give them an offer?
Yeah, we were exploring three or four different things in parallel. This meant legal documents going back and forth, so this was one of the paths that we were going down. The thing we were trying to optimize for was simply: How do we get this sorted as quickly as possible?
Another thing I think people don't appreciate is just how stupidly lucky we got. ETH had been basically flat for about 2 weeks, at $2,300 on the dot. There would have been a big problem if ETH had suddenly dropped by 20%, which happens on any random Tuesday. Iran starts shooting again, ETH drops 20%, and the problem suddenly gets a lot bigger, especially when, you know, you lose
Explain that. Why does the problem get so much bigger then?
In lending markets—and I'm sure Stani can comment more on this—when utilization is 100%, you can't liquidate. That could have led to a much worse cascade, where you would have had a lot of bad debt in place.
That created this extreme time urgency, because we were watching the price and hoping that it didn't move. We needed to act quickly, mostly to restore confidence. Even just making an announcement about what we were doing went a long way toward giving people the feeling that this was going to be taken care of.
As soon as the announcements went out, you immediately saw at least the stablecoin markets start cooling off. Now there were hundreds of millions of dollars of liquidity available. The ETH market was also cooling off, and there was a lot of unwinding taking place. So I thought, “Okay, we're past the worst-case scenario.”
Etherscan was in this unique position because we actually had no exposure. None of our vaults had any rsETH exposure. Our position even in Aave was such that we were short ETH, because the looping on our vaults is such that it uses wrapped ETH or asset as our staking asset as collateral and borrows ETH.
We could easily unwind it without taking any exposure. Our total cost for the increased interest rates on the ETH borrows was something like 400 ETH, so it wasn't a major issue for us. But what I saw was that if DeFi blows up, Etherscan can't exist.
So I didn't give a shit about whether it was a competitor. It doesn't matter. If DeFi blows up, we can't exist. Therefore, we had to throw everything we had at it to make sure that everyone pulled together and actually gathered in a room to talk to each other and solve the problem.
As I said, thankfully, we got there. I also noticed that when Etherscan came out publicly, a lot of DeFi projects that didn't have skin in the game started contributing as well, which was really incredible—from Frax to others. So it started a really genuine movement and an understanding of why this is so important. I think this really helped bring everyone onto the same team.
Without DeFi United, and without Mike coming in and trying to get people to solve this, the first days would have been a really difficult situation. On one hand, you're dealing with raising funds. On another, you're analyzing what needs to be done for the attacker's position. On the other side, you're dealing with human relations, and then you're dealing with the DAO.
Keeping your focus engaged is really difficult. If you believe in DeFi and what it could bring, it's a situation where everyone steps up of their own will. Obviously, there are people who don't want to support it and don't see that as a path forward, and that's totally fine. But we believe that if this technology and these protocols are going to scale in the future, we have to ensure that we have stability and that these markets regain confidence quite quickly.
The challenge with DeFi is that capital moves extremely quickly, and signals move really quickly. In TradFi, there are certain bottlenecks, for example, for liquidity movements. I think that's something we have to think about going forward: If you have a temporary loss of confidence—which in our case basically means that liquidity is available for positions, but not at a specific time—you have to wait for confidence to return.
To our surprise, it was interesting to see stablecoin liquidity come back really quickly, and later ETH liquidity as well. Some of the participants who wanted to help were actually helping by supplying liquidity. They were betting on DeFi and betting on Aave, pushing confidence, and that really helped.
And they obviously enjoyed the higher rates than usual. Yeah. Are there any teams that you want to call out? Well, I guess there’s the good and the bad. Are there any teams that you think really stepped up that you want to call out? Or I guess any teams that were frustratingly absent from the conversations?
Maybe in a few months, maybe in a year, we can talk about that.
Should there be some sort of—I mean, I’m not saying, for the Game of Thrones watchers, “Shame, shame, shame”—but I feel like if this was an FTX-level event, the people who were so impacted should potentially have lost $30–$40 billion. If it really was that scale, which I think you’re right, shouldn’t everyone have stepped up? There were a lot of people who joined DeFi United. There were a lot more who did not.
Yeah, I mean, definitely there were a lot of expletives in the Telegram chats, bitching and complaining, and for sure there was frustration that one party or another didn’t step up as much as they could have.
On the other hand, I’ve run other businesses before at that scale. I’ve been in lawsuits. To me, I’m like, okay, I know how this works. I kind of have a playbook for how this turns out. Maybe some of us are wired differently. There’s less of this fear. To me, the fear of inaction was much greater than the fear of rushing into the unknown and trying to solve the problem, whereas maybe some of the other teams that didn’t step up or acted too slowly, I think it mainly came out of fear.
Because if you’re facing potentially a whole bunch of lawsuits and even criminal liability in some cases, it’s very easy to just lock up and freeze in the moment. Then that’s how things get worse, right? Through inaction.
Yeah, I agree. I think there was a lot of selfish behavior at the beginning, all the way to DLP level. And I think once we got past that finger-pointing—because I think everyone published their reports and whatnot—and DeFi United was basically launched, I think that was the pivotal moment.
At that point, it was about, okay, this is not about whose fault this is or who to blame. It’s about what the next steps are, how to restore, how to mitigate in the future, and how to solve this. The teams involved, including Ether.fi, Lido, Ethena, and a bunch of other ones, have been really helpful. Also teams like Mantle, and even on the Ethereum side, we tried to reach out to everyone, including the Ethereum Foundation and a lot of the Ethereum OGs as well. Joseph Lubin was willing to step in, along with a bunch of other people.
So, it really showcases that there are a lot of good people in our space who are willing to help. What it means for me personally is that, at least, I know in the future who the true friends are and who are willing to step in. It also means that we can be helpful and step in if this happens to someone else and there is cross-chain ethics. So, how do we prevent that?
I think the biggest win here is that people weren’t too selfish and trying to protect themselves. Instead, they turned into a mode where they were trying to figure out how to solve this on-chain, within the communities, and in a way that really restores everyone’s confidence and makes everyone happy. The happy path for everyone is 10 times harder than the happy path for Aave, the happy path for Ether.fi, or the happy path for someone else. So, there was a lot of work to do there to get to that point.
I’ve never coordinated with 6 different DAOs at the same time, with proposals and voting, and it’s been quite an experience.
And what happened with Arbitrum? I think that’s another—you could probably make a movie about this whole insane situation, right? Arbitrum, again, I’m probably speaking out of turn, but effectively took back the money that the North Koreans stole. Thankfully, through a process, that money is now on its way back to users. So, that was remarkable.
I mean, that could have been the thing that made things turn out differently, right? If that amount wasn’t recovered, that 30,000 ETH made the whole lot more manageable than without it. So, it was a pretty wild situation. Well, Mike, say one more thing about the Arbitrum situation. Why was it such a movie-like scenario?
Well, I mean, the North Koreans stole a bunch of ETH, and a bunch of it was sitting on Arbitrum. Arbitrum took—I don’t know the exact details—but they took a vote and took collective action to basically pull back that ETH.
If they hadn’t done that, if the North Koreans had pulled the money off of Arbitrum and then started their swaps on THORChain or whatever channels they were laundering it through, that money would have just been gone. Now you have another 30,000 ETH—about $80 million—to fill, which would have just made it that much more painful.
Yeah. Are we through—I know we’re through the worst of it, but are we through the whole situation?
There are still actions to be taken. Obviously, out of the 6 DAO governance proposals, there is 1 left on Mantle. The Arbitrum governance process is quite long, so that’s another one. There’s also a Compound governance proposal, because they have some actions there, including liquidating the attacker’s position.
A proposal to liquidate the attacker’s position on Aave was released and actually has an on-chain vote in an hour. So, that is happening. Once that has been done, the bucking starts, and then everything sort of restores and nature heals by that time.
There’s also a lot of work across DeFi to talk to a lot of teams, institutions, and whatnot and educate them about the incident. A lot of teams have been taking efforts to improve their trust assumptions around, for example, bridge infrastructure. I think that’s something that’s been really helpful, along with different multisig configurations.
Overall, the space is realizing the threat that is coming from North Korea and basically how to mitigate against that, especially as these exploits become very targeted. So, there is a lot of work in terms of security and education that still needs to be done, as well as restoring the whole confidence in DeFi.
3. Fidelity Crypto Ad
Take a disciplined approach to crypto investing with Fidelity crypto, a platform built in-house using over a decade of crypto experience. At Fidelity, you can trade crypto and stocks together backed by industry-leading security. When you can see your accounts in one place, it's easier to make smarter [music] decisions. Get started at fidelity.com/crypto. Crypto is offered by Fidelity Digital Assets NA, [music] is not insured by FDIC or SIPC, and includes risk of complete loss. Securities offered by Fidelity Brokerage Services LLC, member NYSE, SIPC. Stani, can we focus on Aave for a bit? I want to talk about lessons learned for the industry. Maybe there are a bunch of ideas that have been thrown around, but if you look at Aave, your guys' deposits fell from like around 70 75 to around I think 25 or 30. Obviously, this hit you guys hard.
I’m just curious: you’ve been running this thing for coming up on 10 years now. How do you think about lessons learned from the Aave perspective? Where do you go from here? How do you think about the future?
Overall, TVL is a metric that isn’t the purest way to measure growth, because a lot of the TVL, for example, comes from different business lines. It can be lending stablecoins against Bitcoin and Ethereum, leveraging yield-bearing stablecoins, or leveraging staking yields as well. That staking-yield business is quite substantial.
So, when you see deleveraging momentum, that actually shows in the charts. Once confidence picks up and the market picks up, a lot of this looping will reactivate as well. So, that is interesting.
But overall, what we think from a wider Aave perspective is that we have to expand DeFi beyond existing use cases as well. I think we’re sort of in that $100–$200 billion market size that we’ve been in for the past few years, more or less, depending on the market’s credit cycles.
What we truly want to achieve is for Aave to actually be used as the backbone of all finance and credit.
So, you know, if you issue credit, you should do that directly on or indirectly to Aave. In that way, we get more diversification for these business models, and also business models that don't necessarily depend on the native strategies that we have, for example. So, it's all about diversifying.
I think I mentioned this somewhere else: I see a future where the underwriting risk is tied more closely to the balance sheets and revenues of the Aave DAO. That means that, in the future, it becomes even more important to be able to cover black swan events and events that might be out of our control, but where you might indirectly be underwriting that type of risk. That is why I think strengthening the balance sheet and creating different ways to protect the protocol are important. We have the Aave-native protection mechanism with Umbrella, but we could also come up with different forms of insurance down the line. So, I think that's the sort of future we're heading toward.
4. How To Prevent DeFi Hacks?
How do you think about risk management as you guys try to be the credit layer for all of the global capital markets? Let's say this vision works out: you need way more assets that you can borrow and lend against. How do you think about that? I think I saw a suggestion for formal risk metrics for new assets, like bridging risk, restaking complexity, and maximum supply limits. How do you think about the risk of all these new assets?
Well, the thing is that this ties to the point of tying the lending closer to the balance sheet and to balance-sheet economics. In the future, Aave should not be in a position to underwrite all risks, because obviously there are a lot of debt or, let's say, lending businesses that are at the tail end, and they don't necessarily belong to Aave. So, I'm less confident in this model of lending as purely infrastructure, because someone needs to take the risk. If you remove risk management from one layer, it moves to another layer, for example, at that point.
From Aave's perspective, it should be the prime location for prime assets and, obviously, new use cases, but from a prime standpoint, to the extent that the balance sheet and future revenue can cover these types of initiatives. I don't see Aave—at least the Aave DAO governance pools—being a free-for-all where you list anything you can. Part of Aave's success has been that we've been able to keep a lot of these assets that had problems or configurations where their pricing or something else was an issue out of the Aave protocol. You can still license the technology and create all sorts of markets, but where the Aave brand actually stands is in that prime asset quality.
5. Launching DeFi United
One more thing here, and then, Mike, I'm going to jump to you in a second. Stani, if you're less bullish on on-chain lending infrastructure but more bullish on big balance sheets, what does that actually mean? Usually, to get a big balance sheet, you raise a boatload of capital. Are you going to go raise $1 billion? What are your plans to bolster the balance sheet?
I think what we notice is that confidence plays a big part in the lending infrastructure. If you have a model where there's no one taking that risk and no one has skin in the game, it ends up in a situation where there are misaligned incentives, and you see an arms race toward capturing more risk because of the yields, for example. We've seen this in DeFi going on and on.
But I think when you can pair skin in the game, balance sheets, and risk management, you end up in a place where you make more rational and better risk decisions. I think anyone can use Aave's infrastructure to create new, net-new lending markets, for example. But I think that the actual mass capital will sit in these large pools backed by protocol-native balance sheets. That is the direction we're heading.
Mike, how does this impact how you think about Ether.fi's strategy? You guys are so active in DeFi, right?
For sure. To give context, Ether.fi has a couple of different lines of business. We have the staking protocol, and we have the DeFi strategy vaults that we call Liquid, which obviously participate in Aave and across DeFi. Then we've got our DeFi neobank business, which includes cards, treasury management, and so forth.
Underlying that is a lending market, and we hope to migrate that to an Aave V4 instance in the next little while. That very much aligns with what Stani is saying. Our goal is to allow users to provide tokenized stocks, commodities, different assets, and more RWAs backed by real-world economic activity, and then be able to borrow against them and use them in their financial lives.
The power of that kind of infrastructure is that it allows these more decentralized pockets that are isolated from each other, instead of having one giant pool where, if something goes wrong, it has this contagion effect on all of DeFi.
6. DeFi’s Speculative Premium
Are there any suggestions that you guys have seen that you really like? I saw a lot of people talking about why we don't have insurance yet in DeFi. I have many thoughts on that, but—
It would cost you 15% a year. I think this is the problem in DeFi. If you actually look at the risk involved, you really need to be getting paid 10% to 15% a year.
What's happened is that a lot of the speculative premium has gone away. You used to be able to do that, but now a lot of the speculative premium has gone away because of the nature of the market we're in and the market cycle. Yields have compressed, and now people are basically going further and further out on the risk curve for lower and lower yields. You have protocols that may be paying you 6% when they really should be paying you 30% for the risk that you're taking.
I think the root cause of that—the source of that—is that everything is founded on this speculative premium. Basically, one way or another, everything is trickling down from people betting on the price of Bitcoin, ETH, and whatever else going up. That has to change. Unless that changes so that it's actual economic activity, with businesses producing cash flows that drive this stuff, there's never going to be enough yield to cover the risk.
Today, in this environment, insurance is impossible because any sane underwriter is going to charge you way more than the yield that you're getting in DeFi these days.
I echo that. The reason why we're in DeFi at the moment is that a lot of the economic opportunity comes from native crypto assets. This is actually good because people are long on native assets—long on Bitcoin, ETH, and all these important DeFi protocol tokens. There is really important infrastructure there, and that's going to keep growing.
But what we have to get into is using the DeFi infrastructure that works really well on these native assets and expanding it into traditional assets, RWAs, and credit—purely using DeFi liquidity and channeling that directly to opportunities in the real world, helping consumers, businesses, and institutions with their funding and infrastructure. That's something that I've been researching quite a lot.
Then, bringing those assets in a way that they can be used more natively, in an interesting way. I think we have to get to a place where we have much wider diversity, and that changes the economics for everyone: insurance, base yield, risk profiles, and so forth.
I don't think there's just this discussion about whether lending pools should be isolated or shared. The fact of the matter is that if there's a confidence issue in DeFi, liquidity will move from all the protocols at the same time, and that creates liquidity crunches. It's more about how you diversify as widely as possible.
The Aave Horizon market was a great example because, while everything else was happening, Horizon was growing at the same time. People had confidence in lending against RWAs and weren't taking on the same kind of exposure to completely different asset classes. I think that's the way to improve the economics of these instruments.
What do you guys think about the risk of—We've had more hacks this year than ever, right? I think we're at around $700 million on the year so far. It seems like North Korea is probably enemy number one for the industry. I'm curious, Mike, how you think about how we scale this industry and scale on-chain capital markets if we're trying to fight off North Korea and there are hacks every other day.
I don't have fully formed thoughts on this, but here are some ideas I've been thinking about and things that we're doing at ether.fi: We really need to stop the decentralization theater.
Because there are a lot of things that protocols do in the name of decentralization without really helping that aspect of it, but instead just encumbering the protocol’s ability to act in emergencies. I think there’s a way to preserve the non-custodial nature of DeFi protocols and true decentralization as far as decision-making, management, and how these things operate, without putting in a lot of the sort of theatrics.
I do think that things like blacklists are actually good. We’re going to be implementing that because it allows you to act in case of an emergency, in case law enforcement—believe it or not, you operate within a universe of legal systems and you have to be able to abide by them. There are other protections that come into place, including the ability to pause and off-chain monitoring that automatically triggers contract pauses.
I think a lot of these hacks can be prevented because, in the end, it’s not that hard to detect when all of a sudden there’s an anomalous $300 million of capital that moves. That’s very easy to detect. But we put in all of these theatrics that prevent us from actually being able to act in a reasonable way.
I think there’s a difference between the standard to which a blockchain needs to be held—a blockchain like Ethereum, where you really do need this ultimate autonomy and decentralization—and a DeFi protocol that has a DAO, labs, and companies that operate it, which just need the tools to be able to intervene when things go sideways. I think the most effective protocols already do that. That just needs to become a standard rather than, as I said, sort of decentralization shibboleths that people parrot.
So, what would you actually do concretely, Mike?
Put in a blacklist so that you can actually block addresses, the same way that Tether or Circle and others have. Again, there’s a spectrum there, but having the ability to just block addresses of malicious actors with a governance process—maybe you block it for 24 or 48 hours, and then it requires a vote to solidify that block. The ability to pause the contracts in extreme circumstances. There are half a dozen other things, but things along those lines that allow you to actually—
Time locks and delays.
Locks should be default on everything. We have them pretty much everywhere, so that if someone takes over your multisig, they can’t just upgrade the protocol to pull everyone’s funds. There are certain things that should just become best practices and become expected, and they should become part of the audit to get listed on any major lending venue, DEX, or whatever. At least disclosures should be made around this stuff.
Yeah, I agree. Emergency response is very critical. I believe in decentralization where it helps in the permissionless aspect of it, but there needs to be a middle ground where you can also take faster actions. So, I agree there.
I think a lot of the hacks that happened in the past couple of months were also a lot of key compromises. They weren’t really contract hacks themselves, including the bridge exploit involving Kelp Layer 01. I think it’s more about the Web2 security aspect, and that’s something that we’ve recently received a SOC 2 attestation for. It showcases that DeFi is also moving in the direction of trying to secure the infrastructure around the contracts in the traditional way.
That’s where the weaknesses are, and the measures that these folks are trying to take to actually penetrate are unbelievable. It’s just about investing more and more resources to combat all of these things, and this is something that the whole industry has to really understand. You can’t run a DeFi frontend that’s built by Cloud anymore. It’s just asking for issues.
You can’t really have weak signing mechanisms anymore. You really have to build for scale and for the worst outcome possible, because these things will happen in the future. The important thing is to understand how to react and how to improve the security.
The space is open, so that’s the beauty of DeFi: anyone can come and build through open innovation. That’s what got me here in the first place. But the stakes are increasingly high at the moment. We also try to do a lot of things in public, in the sense that whatever improvements we have, we try to share them with the community and other teams to raise standards across the industry. I think a lot of teams are doing the exact same thing.
I’ve got a totally separate question, more around investor relations, but is there anything else on Kelp DAO or any of this stuff that we missed that we should talk about?
Well, I think—I mean, this is probably a separate episode for you guys—but just the level of sophistication and how terrifying, frankly, these attacks have been, looking at what happened with Drift and Kelp as the most recent examples. This isn’t like they put a virus on somebody’s computer, somebody downloaded a fake Zoom application, and they took over their machine and stole their private key.
These are multimonth, sometimes multiyear, compromises that are extremely sophisticated. Watching these things, I think anybody who’s operating in the space needs to be paranoid to a very high degree, just because of how sophisticated they are.
You have an entire country where basically its top minds, its top computer science graduates, are being put into a government department whose mandate is to steal money from crypto protocols. In the same way that we have a Department of Health and a Department of Education, they have a department for stealing crypto funds.
You have some pretty sophisticated actors in this entity. If you’ve read the transcripts—there have been leaks of their Discords and communication logs—they’re treating this like a business, right? They have leads, and they’re operating in this in a very sophisticated and professional way. It really raises the bar. You need to get to a point where you’re almost impossible to compromise in order to operate in this space.
Should there be—Israel has the Iron Dome, right? It’s for attacks on its citizens, but you have to pay taxes, and those taxes go into building this defense system. Is there something like the Iron Dome of crypto? Would you impose a tax on any protocol with more than 10 million FTV or something?
Certainly, maybe you create a security council. People pay into it to be a member, and in exchange you get audits and protection. I don’t know, something like that—almost like a NATO of crypto.
I also believe that probably another strategy is to counterattack. I bet these North Korean networks are possible to infiltrate. They’ve got infrastructure, right? They have tools that they use to manage their funds and money-laundering operations.
7. Why DeFi Tokens Are Uninvestable
It’s not hard to imagine a counterattack—to pull those funds back and help victims recoup their losses. Maybe we need a vigilante group of crypto experts to go after these guys.
All right. I’ve got a final, maybe closing question or closing topic here. Mike, I would say you guys at ether.fi do everything. You’re actually the company we point to a lot when we look at good investor relations, right? You run your quarterly calls, you do reporting and public dashboards, and you generate real revenue with real users, real cash flow, and real products that touch people outside of crypto.
You’ve built an amazing, amazing, amazing business, and I commend you for that. But at the same time, the token is down about 30% in a year, and, Stani, your token is down about 40% or 50% in a year. Is there anything that you think teams can do right now to catch a bid on their token, or is this just what the bottom of a bear market looks like?
I mean, look, correlation is just 1.0 on everything. That’s the nature of the market that we’re in. Trying to pick one asset versus another is almost pointless because, again, everything is basically trading together.
I think one of the challenges we’re having is that, in many ways, crypto assets, tokens, and DeFi protocols are not investable, at least for fundamentals-based investors. When you look at it and buy a token, what do you actually have a claim to? You just have a memecoin with the name of the protocol in most cases.
We’ve done things like buybacks. I think Aave has done some buybacks, and that goes to a certain degree toward providing some confidence that there’s a connection between the token and the health of the protocol. But I really think we need to go further to actually create investor protections within this decentralized framework that we have, to make these assets investable.
And we've already seen inklings of that. I hate to mention a competitor, Stani, but Morpho has announced their Morpho One framework, and I think that's gone pretty well for them, because the structure they put in, where their labs company is actually owned by the foundation, makes it very hard for the labs company to rug token holders, as we've seen some labs companies do.
But even that, I think, doesn't go far enough. So what we're working on—and I don't want to pre-commit to it just yet—is an open-source framework for investor protections for token holders. We want to implement it internally first and then put it out there for others to use or iterate on if they want. And my hope is that this will bring in fundamentals-based investors who can actually look at a protocol and say, “Oh, wow, look, this is a great business. It's growing, it's got cash flows. It actually makes sense. There's a reason to own the token because it has some exposure to that.”
Yeah, I agree that the framework question is important. When you look at a lot of these protocols, it's really hard to compare them, because a lot of the data isn't in a format that is very representative. I think Ether.fi is doing a great job of actually putting all the pieces together, and that's something that we're going towards as well.
I do think that the correlation is sort of something that can be solved on the back of that. If DeFi protocols can reach their fullest potential—not just being limited to existing crypto assets, but actually being the protocols that run a lot of the financial plumbing, the same way that HTTP and IP protocols run the plumbing of the internet, or, let's say, Stripe as the plumbing of internet payments—I think we get to a place where people understand the direction and how we get to a place where this technology could be used in pretty much all the financial use cases.
So maybe to tie it back to this whole DeFi United and the recovery fund, Stani, you said this—I think it was a very important point—that this was not a bailout, at least in the traditional sense of a bailout, where a government takes taxpayer money and throws it at some maybe failing financial institutions to prevent systemic risk. This was a market action, right? This was many independent, in many cases competing, players coming together and helping the ecosystem thrive and survive.
In the same way, I think, as an ecosystem, the right approach here would be to put together some equivalent of GAAP accounting standards for protocols, so that disclosures and reporting—and I know you guys have actually put together some work on this—are standardized, so that people can look at DeFi protocols apples-to-apples, and then create a framework around value accrual and investor protections.
Yeah, I will ping you about that separately, Mike. A lot we can do together.
So anyways, guys, I know you guys are busy. Congrats on, I guess, getting through a tough 2 weeks and pulling together DeFi United. This was interesting for me, just to understand how big the contagion really could have been here. Hats off to both of you guys.
Thank you so much. It's been a pleasure to be here in a rough couple of weeks, but DeFi will win. The show goes on.
All right. Thanks, guys.