The $292 million Kelp DAO exploit, followed by stress across crypto lending markets, exposed how fragile parts of DeFi still are. The timing made the impact sharper. Wall Street firms were moving deeper into onchain finance, and the incident showed how much infrastructure still needs to mature before larger institutional allocations can scale safely.
In the weeks before the hack, Apollo Global Management, which oversees $900 billion, entered a strategic partnership with Morpho to support lending markets and secured an option to acquire the protocol’s governance tokens. Around the same period, BlackRock brought its tokenized money market fund to Uniswap. Institutional interest was already visible. The exploit did not erase that trend, but it forced a harder look at the foundation underneath it.
Industry view: a slowdown, not a stop
Nick Cherney, head of innovation at Janus Henderson, which manages about $500 billion, said DeFi platforms are opening new ways for investors to use capital more efficiently, and early builders inevitably face risk. In his view, failures such as the Kelp DAO exploit can slow momentum for a time, yet they also pressure the market to fix its weak spots.
He described the episode as a speed bump rather than a roadblock. His argument rests on a longer shift already underway: tokenized real-world assets, including funds, bonds and credit, are beginning to anchor DeFi markets. Those assets bring legal structures and risk controls that traditional finance has built over decades. Incidents like this, he said, may push that transition faster.
Security standards can no longer stay optional
Paul Vijender, head of security at Gauntlet, said DeFi and onchain asset management operate in a highly adversarial environment, where security is only as strong as the weakest link. From his perspective, the industry is being pushed toward zero-trust architecture, meaning no part of the system should be assumed safe by default.
In practical terms, that means layered defenses: continuous monitoring, tighter controls and built-in redundancy, without depending on a single safeguard. Evgeny Gokhberg, founder of digital asset manager Re7 Capital, argued that many so-called best practices now need to be treated as baseline requirements.
He pointed to timelocks for key governance actions, stricter multi-signature controls, tighter collateral standards and stronger protections around bridges. Bridges remain one of the most common failure points in DeFi. After this exploit, those controls look less like enhancements and more like minimum operating requirements.
What institutional-grade DeFi still needs
Bhaji Illuminati, CEO of Centrifuge Labs, said traditional finance had decades to build layers of protection, while DeFi is trying to compress that process into a much shorter period. For institutions to allocate capital at scale, she said, three conditions need to be in place.
The first is clarity: investors need to know exactly what they own, with verifiable collateral and legal structures that match real-world risk. The second is reliability: smart contracts, oracles and governance processes must behave in predictable and auditable ways. The third is liquidity that can hold under pressure, so capital can move in and out without distorting markets when conditions tighten.
She said openness and security are not mutually exclusive; the real objective is to make trust explicit and verifiable. She also argued that every layer of the DeFi stack now needs to treat security as the top priority, a demand she said becomes even more urgent in the age of artificial intelligence.

