
A JPMorgan research team led by analyst Nikolaos Panigirtzoglou said in a report published on April 23 that persistent security vulnerabilities and a stagnating total value locked (TVL) are eroding the appeal of decentralized finance (DeFi) to institutional investors. The report emphasized that the KelpDAO vulnerability wiped out roughly $20 billion in DeFi TVL within days, exposing structural risks.
According to JPMorgan’s report published on April 23, the analysts’ team noted that in 2026, losses from hacker attacks in the crypto market are expected to be on par with the 2025 level. Despite progress in smart contract audits, bridge and infrastructure vulnerabilities remain the main sources of risk.
The report directly quoted the analysts’ team: “Just as traditional investors shift to holding cash during uncertain times, crypto participants are also coping with the recent attacks by seeking stablecoins.”
According to the report, although DeFi TVL denominated in U.S. dollars has partially recovered, DeFi TVL denominated in ether (ETH) has basically remained unchanged. JPMorgan analysts said this indicates that DeFi’s natural growth is limited, raising questions about whether DeFi has the scalability to meet the needs of institutional users.
According to JPMorgan’s report, the attack path of the KelpDAO vulnerability was: the attacker compromised the cross-chain bridge infrastructure, minted unsecured rsETH with a value of about $292 million, and deposited it as collateral into a lending protocol, ultimately resulting in roughly $200 million in bad debt.
JPMorgan’s report said the impact of this attack spread beyond the directly affected platforms, highlighting how interoperability in the DeFi ecosystem can amplify the reach of a single vulnerability. The report also noted that cross-chain bridges—due to their complex design and architecture, shared underlying infrastructure, and sometimes weak verification mechanisms—have historically led to cumulative losses of billions of dollars across the industry.
According to JPMorgan’s report, after the KelpDAO vulnerability incident, capital flowed from DeFi lending protocols into Tether’s USDT. With stronger liquidity and faster withdrawal speeds, USDT further strengthened its position as a safe-haven asset in the crypto market.
JPMorgan analysts said in the report that repeated attack events weaken market trust in DeFi systems that rely on code rather than intermediaries. Smart contract vulnerabilities, network phishing, and cross-chain bridge shortcomings are the key technical risks that lead to large amounts of locked assets being exposed.
According to JPMorgan’s publicly available information, this DeFi security analysis report was released on Wednesday, April 23, written by a research team led by analyst Nikolaos Panigirtzoglou.
According to JPMorgan’s report, the KelpDAO vulnerability erased about $20 billion in DeFi TVL within days. The attacker minted $292 million of unsecured rsETH as collateral and ultimately caused about $200 million in bad debt, with the impact spreading beyond the directly affected platform.
According to JPMorgan’s report, while DeFi TVL denominated in U.S. dollars has partially recovered, DeFi TVL denominated in ETH has basically remained unchanged. The analysts said this indicates that DeFi’s natural growth is limited, and they raised questions about whether DeFi can meet institutional users’ needs.
Related News
CryptoQuant: KelpDAO Exploit Triggers the Most Severe Crisis Since 2024, Aave TVL Plunges 33%
JPMorgan: DeFi hackers are increasingly common, and interest in compression mechanisms to address TVL stagnation is drawing capital into USDT
The SEC received a joint letter signed by 30 firms, calling for the establishment of regulatory rules for DeFi brokers.
Ether.fi launches an aWETH exit channel, with Aave fund outflows exceeding $16.2 billion
Aave TVL lost 15.1 billion in just three and a half days, while Spark bucked the trend and grew into the biggest beneficiary