KelpDAO’s $293 Million Exploit Exposes DeFi’s Bigger Risk Beyond Smart Contracts

KelpDAO’s $293 Million Exploit Exposes DeFi’s Bigger Risk Beyond Smart Contracts

N
News Editor 01
2026-07-23 10:30:15
The KelpDAO exploit shifted attention from contract bugs to bridge infrastructure, governance, operational security, and third-party dependencies, showing how DeFi’s biggest failures now often emerge outside core code.
KelpDAODeFiLayerZerobridgescybersecurity

The $293 million KelpDAO exploit last month did more than hit one protocol. It highlighted how DeFi’s most serious weaknesses are increasingly found outside smart contracts, in the surrounding layers of bridge infrastructure, governance, operational security, and third-party services.

Eugene Mamin, chief technical master at Lido Labs Foundation, told CoinDesk that in many of these cases the contracts behaved exactly as they were written to behave. The problem was that the people giving the instructions were not the legitimate ones. That distinction matters. It suggests DeFi’s central security problem is shifting away from contract logic and toward the human and infrastructural systems wrapped around it.

Shared bridge infrastructure turned one weakness into a wider threat

The KelpDAO exploit was linked to a vulnerability involving LayerZero’s bridge infrastructure. What made the incident notable was not just the initial weakness, but how risk traveled outward through dependent protocols. In a tightly connected DeFi stack, a failure in shared infrastructure does not stay neatly contained.

Mamin said that when a protocol reuses someone else’s infrastructure, it also inherits that provider’s threat model. Sam MacPherson, CEO of Phoenix Labs, made a similar point: if too much of the market relies on the same infrastructure, concentration can quietly become systemic risk, and failures begin to cascade instead of remaining isolated.

Security focus is moving away from pure contract bugs

Early DeFi exploits usually came from smart contract flaws such as reentrancy issues, oracle manipulation, or broken logic. That is no longer the only battlefield. MacPherson said smart contract risk is largely a solved problem, and that many recent hacks have come from poor operational security instead.

That does not mean contracts are flawless. The article notes that auditing tools, formal verification, bug bounty programs, and AI-assisted code review have made core contracts much stronger than they were during DeFi’s rapid expansion. The harder problem now is architectural complexity: protocols depend on bridges, bridges depend on validators and messaging systems, and governance depends on multisigs, cloud infrastructure, SaaS providers, and teams spread across jurisdictions.

Each extra layer adds another failure point. That is the trade-off.

DeFi users are starting to reward predictability

The incident also arrived at a time when crypto investors appear less willing to tolerate risk-heavy experimentation. Mamin said the protocols trusted with serious capital tend to be the ones that do the same thing the same way for years. In his words, “boring is a feature.”

For a long stretch, DeFi rewarded growth, leverage, and yield. Complexity was often treated as innovation. After years of exploits, liquidations, and cascading failures, users seem to be rotating toward simpler structures and more predictable behavior. MacPherson said the market is starting to favor systems built for resilience over maximum upside. He added that Spark has recently seen deposits rise in part because users are moving into more conservative lending markets and simpler collateral setups.

The attack surface looks more like traditional cybersecurity again

Another lesson from the KelpDAO case is that some of DeFi’s most dangerous attack vectors now resemble ordinary cybersecurity failures. Mamin pointed to weaknesses in personal laptops, SaaS platforms, key management systems, and software supply chains as major unresolved risks for the sector.

His conclusion was blunt: the attack surface has not shrunk, it has rotated back toward Web2 roots. For DeFi teams, that means security work can no longer stop at contract audits. The harder job sits across infrastructure, operations, vendors, and access control.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.