Ripple's Chief Technology Officer David Schwartz has issued a stark warning about the security of DeFi cross-chain bridges, arguing that many projects end up weakening their own safeguards during real-world deployment. His comments come shortly after the KelpDAO attack, which resulted in losses exceeding $280 million, further shaking confidence in decentralized finance infrastructure.
Schwartz: Security Features Become 'Optional'
In a series of posts on X, Schwartz revealed that he had evaluated numerous DeFi bridge systems for Ripple's stablecoin RLUSD, focusing exclusively on security and risk. He found that while many bridges appeared technically sound on paper, in practice "they often recommended not bothering to use the most important security mechanisms, because these entail convenience costs and operational complexity." This trade-off, he argued, renders the protections effectively useless.
He further emphasized: "An asset is not fully guaranteed if there is serious doubt whether the supposed backing will actually be used to support the asset. I think a widespread haircut is not unlikely." This broadened the discussion from bridge design to collateral trust and market behavior during stress events.
The KelpDAO Exploit: LayerZero Infrastructure Exploited
On April 18, KelpDAO's rsETH token was exploited on Ethereum and Arbitrum networks, leading to a loss of over $280 million and leaving Aave V3 with significant bad debt. Investigator ZachXBT first flagged the vulnerability. On April 20, Schwartz added: "The attack was far more sophisticated than I expected and targeted the LayerZero infrastructure, taking advantage of KelpDAO's negligence." He stressed that the issue was not a failure of interoperability tools but a lack of implementation discipline by the team.
This incident underscores a pervasive industry trend: teams often prioritize speed and convenience over rigorous security configuration. Even when robust safeguards exist, the risk remains high if they are not actively enforced.
Industry Impact and Reflection
Schwartz's warning adds urgency to the debate over cross-chain security. With bridges now handling hundreds of billions of dollars in assets, the KelpDAO event has exposed misaligned incentives—commercial pressure, scalability demands, and operational simplicity often outweigh architectural safety. Calls are growing for mandatory activation of security features and stricter audits, rather than leaving them optional.
KelpDAO is working with security experts to recover funds, while LayerZero has promised to strengthen its infrastructure. But Schwartz's analysis reminds us that technology alone cannot solve problems caused by deliberate choices to bypass it. Until the industry treats security as non-negotiable, the window dressing will remain just that.

