Understanding the evolving risk structure facing DeFi through "two incidents"

2026/05/29 10:00 (Updated 2026/05/29 16:46)
Yuki Aoki
SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
Understanding the evolving risk structure facing DeFi through "two incidents"

Summary

1. Vulnerabilities in Trust Design and Massive Losses

The exploits targeting Drift and Kelp in April 2026 resulted in a combined drain of approximately $600 million in assets. Notably, the root cause did not stem from smart contract vulnerabilities, but rather from flaws in "off-code" trust design—specifically, misplaced human trust and dependencies on external systems.

2. Case Studies of Sophisticated, Multi-Stage Attacks

  • Drift: Administrative privileges were compromised via social engineering.
  • Kelp: Attackers exploited integration flaws in external communication systems alongside a server takeover.

Both incidents share a common pattern: rather than relying on a single bug, attackers executed bold, sophisticated, multi-stage campaigns that weaponized operational blind spots.

3.Shifting Risk Landscapes and Defense-in-Depth

The DeFi risk paradigm is shifting away from simple code exploits toward comprehensive trust-design vulnerabilities encompassing operations and data verification. Moving forward, standard configuration audits alone are insufficient. Implementing a defense-in-depth (multi-layered) strategy—including EDR deployment, device isolation, and security awareness training—is imperative to eliminate any openings for attackers.


In April 2026, two hacking incidents that shook the DeFi ecosystem occurred in quick succession. "Drift" and "Kelp" were attacked, each resulting in the loss of approximately $300 million in assets.

Many readers might immediately think of flaws in smart contracts when hearing about such incidents. However, what stood out in these cases was that "DeFi still relies on human trust and dependence on external systems." The problem extended beyond the code itself to the operational aspects and the design of the connections.

This article will examine where the focus of risks facing DeFi today has shifted, based on the Drift and Kelp incidents.

The article is for members only. Please sign up to continue reading.

SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
Side Banner
Side Banner
MAGAZINE
Iolite Vol.21

Iolite Vol.21

September 2026 issueReleased on 2026/07/30

Interview Richard Teng, Co-CEO, Binance Taisuke Isono, Head of Nikko Open Innovation Lab & DeFi Technology Department, SMBC Nikko Securities Inc. Hiroshi Kamiwaki, Director & Head of Crypto Asset Finance Business, Fintertech Co., Ltd. PHOTO & INTERVIEW Yusaku Nakano Feature Story: "Survival Strategies for Crypto Exchanges — The New Order Post-FIEA Transition" Interview Tomoyuki Isaka, President & Representative Director, CEO, Coincheck, Inc. Takaaki Fujiwara, Executive Vice President & Director, Mercury Inc. [Dialogue Series] The NISHI Talk: Crypto Conversations "Social Implementation Beyond Merely Holding Bitcoin" Kasou NISHI × Rintaro Kawai, President & Representative Director, ANAP HOLDINGS Co., Ltd. Series: Tech and Future Toshinao Sasaki ...and more

MAGAZINE

Iolite Vol.21

September 2026 issueReleased on 2026/07/30
Interview Richard Teng, Co-CEO, Binance Taisuke Isono, Head of Nikko Open Innovation Lab & DeFi Technology Department, SMBC Nikko Securities Inc. Hiroshi Kamiwaki, Director & Head of Crypto Asset Finance Business, Fintertech Co., Ltd. PHOTO & INTERVIEW Yusaku Nakano Feature Story: "Survival Strategies for Crypto Exchanges — The New Order Post-FIEA Transition" Interview Tomoyuki Isaka, President & Representative Director, CEO, Coincheck, Inc. Takaaki Fujiwara, Executive Vice President & Director, Mercury Inc. [Dialogue Series] The NISHI Talk: Crypto Conversations "Social Implementation Beyond Merely Holding Bitcoin" Kasou NISHI × Rintaro Kawai, President & Representative Director, ANAP HOLDINGS Co., Ltd. Series: Tech and Future Toshinao Sasaki ...and more