Markets by Trading view

Digital Assets Brief: DeFi Hacks Underscore The Significance Of Operational Security And Risk Management

Facebook
Twitter
LinkedIn
This picture describes the press release.

May 27, 2026 – Several recent hacks of decentralized finance (DeFi) protocols underscore that robust risk management is essential to defend against bad actors. This includes ensuring operational security for smart contracts and calibrating concentration limits to manage individual asset risks.

What’s Happening

A series of exploits in March and April targeting three decentralized finance (DeFi) protocols-Resolv, Drift, and KelpDAO–led to cumulative losses of around $600 million. The exploits did not result from smart contract code vulnerabilities, but rather from operational security weaknesses and a social engineering attack. Specific risk management failures in DeFi lending amplified the severity of their impact.

Why It Matters

As institutional adoption of tokenization and digital assets accelerates, addressing lessons learned from these exploits can ensure appropriate on-chain controls are in place to mitigate any operational security risks and wider ecosystem contagion.

In two recent cases, an attacker was able to create unauthorized and unbacked tokens:

  • For Resolv, an attacker took control of the access keys to the smart contract that mints (creates) new tokens. This event emphasized that issuers looking to adopt tokenization will need to implement robust operational security measures, such as segregation of multiple administrator roles. This is just as relevant for DeFi protocols as it is for the tokenization of traditional financial instruments.
  • Attackers exploited KelpDAO’s use of multiple blockchains to receive collateral and issue tokens. Hackers deceived a third-party messaging protocol used to check the total collateral amount backing the protocol’s rsETH token across the different blockchains on which it is issued. This allowed them to create new unbacked tokens without needing to take control of the minting contract. The key vulnerability was in the setup of the cross-chain messaging protocol (LayerZero): KelpDAO used the lowest security setup available, effectively creating a single point of failure. Redundancies and decentralization could help mitigate this risk.

Ineffective risk management in DeFi protocols can amplify the impact of security risks. Minting unauthorized tokens is of limited value to an attacker unless they can monetize them. In the KelpDAO case, the rsETH tokens the attacker created were relatively illiquid: the attacker could not sell them without significant loss through slippage. However, they were eligible as collateral on a major DeFi lending protocol, Aave. The attacker borrowed about $300 million of wrapped ether (WETH) and was able to realize a significant financial gain.

S&P Global Ratings believes risk control parameters must be used effectively on permissionless DeFi protocols to contain risk and contagion effects. When onboarding assets as collateral, lending protocols need to consider asset-level operational risks but also concentration risks, to allow the protocol to withstand the impact of any asset-level tail risk event. In the KelpDAO case, risk treatment for rsETH was driven by that asset’s correlation with Ethereum, failing to account for its status as a distinct asset with its own unique risk profile. As a result, Aave took on a large exposure to this asset, despite its complexities and short track record. Aave’s supply cap for rsETH was greater than the total supply of rsETH, and in the immediate aftermath of the attack, the protocol lent out more against this single asset than its entire reserve dedicated to covering losses across the whole protocol.

DeFi lending protocols have risk parameters to mitigate loss severity and contagion risks……but in the KelpDAO case, Aave’s risk limits for rsETH were poorly calibrated.

The fallout from the Resolv episode was less severe but highlighted another contagion pathway in DeFi lending. The amounts at stake were lower, and the attacker simply traded out of the affected tokens. The market value of the tokens collapsed as news broke of the attack. However, these tokens were eligible as collateral in some curated vaults on the Morpho lending protocol, where their price was hard-coded at $1. This created an arbitrage: market participants could buy depreciated tokens through a decentralized exchange and use them as collateral to borrow USDC, a stablecoin. In the immediate aftermath, some vault curators lent a massive amount against the affected collateral relative to previous market liquidity, the event likely caused by automated allocation mechanisms seeking to optimize yield, without sufficient guardrails against concentration risk.

Sophisticated social engineering attacks highlight the importance of governance to support cyber resilience. The Drift attack was a six-month long operation in which the hackers posed as representatives of a quantitative trading protocol to earn the Drift team’s trust. This social engineering ultimately allowed the attacker to take over administrative powers and to drain most of Drift’s liquidity. Preventing similar incidents requires a multilayered defense: moving beyond simple trust-based interactions toward a “Zero Trust” architecture (operating under the assumption that no user, device, or network can be trusted by default and needs to be continuously verified); implementing rigorous identity verification protocols for all personnel, partners, and temporary workers; and ensuring that decentralized, multiparty authorization processes govern critical administrative functions.

What Comes Next

The adoption of tokenization and maturation of the DeFi ecosystem require robust risk
management. Bad actors will continue to seek vulnerabilities from which they can gain financially. Ensuring operational security around token minting and burning is key. It is also critical to recognize that individual asset-level risks can materialize, and therefore adapting concentration limits to the risk profile of specific assets is a key risk management tool.

See also:

DTCC Advances Development of New Tokenization Service, Convenes 50+ Firms to Drive Digital Assets Adoption | Disruption Banking

IOSCO Issues Final Report on Updated Liquidity Risk Management Recommendations for Collective Investment Schemes | Disruption Banking

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Related Posts

Write your email to verify subscription

Loading...

Sign up for our free newsletter and receive the latest banking and fintech stories, straight to your inbox - every week