by John Gray
A line has been drawn under the Kelp DAO exploit: the post-mortems have been published, the op-eds have dried up, and the DeFi news cycle has moved on. In this sense, it feels like the right moment to follow up on our recent breakdown of the exploit with an article exploring some of the broader lessons that DeFi could draw from April’s $300m heist.
New attack surfaces, new sources of risk
As Alec Zebrick, Senior Manager, Global Services at Chainalysis, highlighted to The InterSection, the major takehome is that the exploit wasn’t due to a smart contract bug, but rather to a sophisticated attack on off-chain bridge verification infrastructure. In other words, it was an illustration of the fact it is no longer enough to audit the contract and assume you’re safe. Bridges, verifiers, oracles, governance systems, administrators and even human operators may now be equally important attack surfaces. This is particularly true for collateral used in lending markets, which typically requires a degree of management overhead.
But Kelp was far more than a cybersecurity issue. The exploit exposed the growing importance of risk management around the assets themselves. Lending protocols are not responsible for securing another project’s infrastructure, but they are responsible for deciding whether an asset should be listed at all, how much users can borrow against it, whether it should sit in an isolated market, and what supply caps, debt ceilings and liquidation parameters should apply.
“Detection needs to happen at the invariant level,” Zebrick argued, “continuously verifying that cross-chain accounting adds up, and single points of failure in verification infrastructure need to be treated as active and not theoretical risks.” Zebrick pointed to another key consideration. “The composability that makes DeFi powerful also means a major exploit creates immediate contagion risk across protocols.”
Of course, this is precisely what happened in the case of the Kelp exploit: once the supposedly legitimate rsETH entered the ecosystem, the damage rippled through the network. In this way, despite the fact its own systems were not violated, Aave came to be the principal victim of the exploit.
Composability and its discontents
For Michael Lewellen – cybersecurity expert and security advisor to the Compound Foundation – this is one of the most important lessons of Kelp. The exploit, as Lewellen told The InterSection earlier this week, was an example of a broader question, “one that I think a lot of people probably should have been looking closer at.”
Kelp, he said, is “a relatively exotic collateral” with a decent but not stellar reputation, far from being a blue-chip style asset such as stETH or similar. This type of liquid restaking token has become popular because they enable people to earn yield and generate additional revenue.
However, the more of these collaterals you add, Lewellen explained, “the more your risk expands. And a monolithic model like Aave is especially vulnerable to this because those assets are existing in the same pool as many of the others.” Increasingly, protocols need to underwrite the operational risks of the collateral they accept, not just its market volatility. In light of this, “what we’re realizing now is that DeFi is not going to necessarily insulate you from systemic risk”, unless you go for a very particular DeFi protocol, such as Morpho, which has certain limitations. Even then, however, “you’re usually just picking different risks. I mean, USDC is a systemic risk. If anything happens to USDC all of DeFi is effectively screwed. “Going forward, people will probably need to think more frankly about where their yield is coming from and what are the risks behind it. I think there’s still very strong cases to use DeFi protocols, but I think what Kelp DAO did was destroy the narrative that passive yield equivalent to a short-term treasury was the right risk factor.
“The yield has to justify the risk.”
DeFi united?
One notable characteristic of the Kelp exploit was the speed and effectiveness of the initial response to it. For Chainalysis’ Zebrick, “perhaps the most consequential action was the Arbitrum Security Council’s freeze of over 30,000 ETH in attacker funds within days, coordinated with law enforcement and supported by Chainalysis. This demonstrated what credible L2 governance can accomplish when it moves quickly.”
Further to this, the weeks after the initial incident saw an interesting and unprecedented development: the coming together of an informal coalition known as DeFi United, spearheaded by Aave, which worked to restore rsETH’s backing and, effectively, make everyone whole. For Zebrick, “DeFi United’s speed in organizing a coalition to restore rsETH’s backing was impressive, and it reflects a maturing ecosystem.”
However, to many it looked like DeFi United was redolent of the worst of TradFi: a bailout to save an institution that had become “too big to fail”. As David Phelps of Confetti said at the time, it was “a solution that just depends on trust. You’re just trusting that Daddy Warbucks is gonna come in with his billions of dollars and give it back to you to try to help you out. I don’t think this instills a lot of confidence.”
Did DeFi United really introduce an element of moral hazard into DeFi? If protocols, investors and users know that the ecosystem may intervene to absorb the consequences of catastrophic failures, does that weaken the incentive to build secure systems?
Michael Lewellen thinks this is not an issue. For him, DeFi United was really the “save Aave” fund. The Kelp DAO exploit was critical to Aave, as it would have had the largest hole out of anyone. “The test would be if we see another incident, and Aave is not not the one that’s actually the most at risk, will we see another DeFi United? I would be surprised.”
Apart from anything else, even DeFi United was touch-and-go, with a lot of legal limbo and voting processes. The money may have been committed fairly quickly, but it took some time to be accessed. While this was going on, Aave had to find ways to ensure that the protocol could remain solvent. “If a few things had fallen through,” Lewellen said, “it could have ended badly.”
Considering this, Lewellen underlined the importance of individual protocols being able to stand on their own two feet. “They need to be thinking more about their own insurance, their own reserves, their own way to cover risk. At Compound we have reserves that can help cover losses. We ended up being made whole through DeFi United, which was great, but we could have used a pretty large amount of our reserves to make our users whole, and the protocol could have kept functioning after the initial pause was over.”
This is particularly important because DeFi lacks FDIC insurance, or any comparable statutory resolution process. Users will likely be at the back of the line when it comes to a recovery. For individual protocols, the key learning from Kelp DAO should not be that the system will come to their rescue, but, again, that they must do everything they can to mitigate their risk of being caught up in a similar contagion. Lewellen suggested that such mitigation could look like boosting their ability to pause; to delist collateral more effectively; or to isolate “exotic” collateral from more “conservative” deposits.
Isolated markets or monolithic pools
Are there any risks Lewellen feels DeFi is still underestimating? What structural changes would he make, were he the demiurge of the system? “My cypherpunk brain would say, find a way to make ETH a stable asset or find ways to have natively on-chain assets backing protocols and creating stablecoins – kind of like the old MakerDAO model.
“The problem is that you always struggle with maintaining stability and liquidity in those events. So I understand the natural push towards centrally issued stablecoins and/or RWAs to have better, safer sources of yield.”
One response to the possibility of contagion exemplified by Kelp would be to build markets to be more isolated, somewhat along the lines of Morpho or Comet. “You can have different markets for different flavours of risk,” Lewellen noted. “I do like the isolation model over the monolith model. I think the monolith model has its advantages, especially in that it does not fragment liquidity, but it comes with pooling your risk, which means that it’s really on the person managing these large pools of many different assets to think through every asset that’s being added.
“It's a very difficult balance. You want to go after new sources of revenue and new collateral, but not all of them are maybe worthy, or at least are worth the potential risk increase that they introduce.” In terms of procedure, he would recommend building fast, capable emergency response controls. This would give emergency responders – the people that sit on multisigs or security councils – more options to deal with crises, although, he conceded, “it’s always a balancing act between giving more control and then maintaining the right level of permissionlessness and non-custodial nature.”