It's Not Destruction, It's Reinventing: Hacking and Regulation Are Pushing DeFi to Realism

Author: Gu Yu, ChainCatcher
Original title: Are Hacking and Regulation Ruining DeFi?
In April 2026, a series of security disasters once again brought DeFi to the forefront of public opinion. The Kelp DAO and Drift Protocol attacks collectively caused losses of more than US$575 million. The total locked value (TVL) of DeFi plummeted from about US$172 billion to US$148 billion, and the TVL of the lending sector alone collapsed from US$53 billion to US$40 billion.
In recent days, well-known security audit firmsopenZeppelinCo-founder Manuel Aráoz said bluntly on the X platform: “I don't think all DeFi is secure anymore.” He even said that he has begun privately advising family and friends to clear all DeFi positions, including Aave, MakerDAO, and Compound, which are known as “low-risk blue chip” agreements.
Although this judgment is particularly harsh, it is worth pondering. After all, OpenZeppelin has long been one of the most important security infrastructure builders in the DeFi world, and its smart contract standards and security tools have evolved almost throughout the industry. If even those most familiar with smart contract security systems are beginning to question the risks of DeFi and withdraw decisively, then this certainly means that some deeper problem is surfacing.
Whenever DeFi has experienced setbacks over the past few years, people have been able to quickly find a specific reason. When the market is sluggish, people blame the macro environment; when hacking occurs, people think it is due to technical flaws; when regulators act, people also attribute the problem to policy pressure.
However, if you lengthen the time dimension, people will discover an increasingly clear fact: the plight of DeFi today is not caused by an attack, a regulatory policy, or a failed project, but rather the two sets of core logic that it was originally founded on are being challenged at the same time.
A set of logic comes from the world of technology: code can replace trust. Another set of logic comes from the institutional world, that is, an open network can bypass the constraints of traditional financial systems.
However, hacking and regulation have hit these two pillars separately.
I. The deep evolution of the DeFi security crisis
In ten years, the core paradox of DeFi security hasn't changed. Web3 security researchers have already identified this fatal asymmetry: defenders must close every possible gap that can be exploited, and attackers only need to succeed in one step.
On the face of it, the attack methods are nothing more than cliché routines such as cross-chain bridge exploits, multi-signature privilege hijacking, and oracle manipulation. But the Kelp DAO and Drift Protocol incidents revealed an even harsher trend: the most fatal bugs are often not in the smart contract code.
On April 18, the Ethereum liquidity heavy staking protocol Kelp DAO was attacked. The attackers used the DVN (Decentralized Verification Network) configuration vulnerability of the LayerZero cross-chain bridge, falsified cross-chain messages, and removed 116,500 rSetH from the cross-chain bridge within a few hours, which was about US$293 million at the price at the time.
The nature of this disaster was a misconfiguration, not a code flaw. Kelp DAO chose “1-of-1” for LayerZero's cross-chain verification network — only one DVN node is required to confirm, and cross-chain messages are considered legitimate. When the attackers attacked the two RPC nodes that provided authentication data and launched a DDoS attack, the entire bridging system was in vain
On April 1, Drift Protocol, one of the largest perpetual contract DEXs in the Solana ecosystem, was attacked and lost 285 million US dollars, making it the biggest single DeFi attack so far in 2026, and the second largest hacking case in Solana history.
It's also not a smart contract bug. The attackers attacked at least two of the three signers of the multi-signature wallet through social engineering, using Solana's durable nonce feature to force them to pre-sign malicious transactions. Once the attackers obtained administrator rights, they completed the theft of funds in less than 12 minutes.
The root cause of the attack is a complete failure of operational security (OpSec): improper configuration of multi-signature wallets, blind spots in key management, and flawed social engineering defenses.
These two incidents revealed the deep evolution of the DeFi security crisis: the breakthrough of attacks is systematically shifting from traditional smart contract code bugs to the configuration layer and humanity/OpSec layer.
Manuel Aráoz pinpointed the crux of the problem: “Smart contract security is essentially an extremely asymmetrical game — the defender must fix all the bugs, and the attackers only need to find one to steal the money.” After AI began to exponentially increase attack efficiency, this asymmetry was rapidly unbalanced.
AI coding agents can automatically compress issues that previously took weeks for top white hat teams to discover into minutes, and can even autonomously generate attack scripts based on publicly available protocol code. As one of the most mainstream security audit firms in the industry, OpenZeppelin's co-founder made such a pessimistic judgment, more like a sign — the security industry itself is aware that the existing defense framework is facing a systemic failure.
II. Continued spread of regulatory pressure
While the security crisis continues to deepen, regulatory forces also continue to exert pressure on both on-chain and off-chain levels.
On May 26, the British government added the cryptocurrency exchange HTX to the Russian sanctions list and used regulation 17A to sanction crypto asset exchanges for the first time. The UK alleges that HTX handled $3.3 trillion in transactions in 2025, allegedly providing financial services to the sanctioned A7 payment network and Russian exchange Garantex.
The chain reaction caused by the sanctions spread rapidly. As several mainstream AML companies added HTX exchange addresses to the dangerous address list, many exchanges using their AML system immediately tightened transaction reviews with HTX related addresses, and a large number of HTX users were unable to withdraw their assets to other exchanges.
The HTX incident revealed a deeper dilemma: under a complex geopolitical landscape, a sanction order initiated by regulation can trigger an expanding chain effect on the chain, which ultimately affects the transfer of funds from countless ordinary users. An HTX user holds assets completely innocently, but due to the platform's potential compliance risks, withdrawals to other exchanges may be blocked by the entire AML system's “firewall”, and funds may be frozen or delayed indefinitely.
In fact, the HTX incident is just the tip of the iceberg of regulatory pressure. What really deeply restricts DeFi innovation is the regulatory agency's legal characterization of the underlying business model of the agreement.
Over the past two years, the US SEC has launched investigations into “blue chip” DeFi agreements such as Compound, Uniswap, and Curve, focusing on whether governance tokens constitute unregistered securities. The more direct crackdown comes from the field of income tokens — SEC enforcement actions against products such as Gemini Earn show that as long as an agreement is made to pay passive interest based on deposits to users, it can easily be recognized as an investment contract, thus triggering registration and disclosure obligations under the Securities Law.
This qualitative ambiguity and pressure of the law directly stifles DeFi's most imaginative innovation direction: from liquidity mining to structured income products, developers always have to worry about whether their token economy model is stepping on the red line of regulation.
In a sense, DeFi's initial emphasis on “no license required” is gradually evolving into another form of “licensing system.” This “license” does not come from a single company or agreement, but from every link in the regulatory compliance chain: AML lists, exchange risk control engines, the long-range jurisdiction of securities laws, etc.
3. DeFi has entered a stage of realism
Looking back on the ups and downs of DeFi over the past few years, DeFi's security woes and regulatory pressure do not exist independently. The lack of a clear regulatory framework makes it difficult to establish industry consensus on safety standards; frequent safety incidents in turn provide the most direct reason for global regulators to tighten enforcement; and the accelerated security asymmetry in the AI era and gradually tightening compliance thresholds eventually intertwined, pushing countless ordinary users to the center of the storm.
Essentially, the boundaries of security audits and the rigidity of regulatory compliance are continuing to erode the two core assumptions on which DeFi is based — “code is law” and “freedom without permission.”
Today, users take on higher technical risks than traditional finance, yet they may not have more freedom than traditional finance. This is the reason many market players are confused today. They discovered that DeFi is neither as secure as banks nor as fully open as initially promised.
And when a system loses both a safety premium and a free premium, its growth logic will naturally be challenged. So the question probably shouldn't be “are hackers and regulation ruining DeFi?”
More accurately, hacking and regulation just forced the industry to face reality. Hackers make people realize that code doesn't naturally create trust; regulation makes people realize that the on-chain world has never been a parallel universe operating outside of the real world.
That doesn't mean DeFi is failing. On the contrary, it meant that the experiment was moving from an idealistic phase to a realistic phase.
DeFi is not destroyed by hackers, nor is it destroyed by the regulatory network. It is being redefined by the rules of existence that the two have co-shaped: DeFi in the future will either move towards a stricter framework of industry security self-discipline and compliance, and be forced to compromise on the principles of decentralization; or it will gradually lose market confidence and become marginalized for a long time amid ongoing offensive and defensive imbalances.
Twitter:https://twitter.com/BitpushNewsCN
Compare the TG exchange group:https://t.me/BitPushCommunity
Compare TG subscriptions:https://t.me/bitpush



