
The DeFi vault landscape has experienced significant contraction, with net TVL across all defined vault categories totaling $120.4 billion, down about 50% from the peak of $241 billion around October last year. According to the latest DeFi Vault 2026 Annual Report, this downward trend was driven by the 'October liquidation event,' which triggered a cascading liquidation across DeFi. The vault ecosystem has evolved into eight structural categories: lending vaults, liquid collateral, recollateralized collateral, risk curation vaults, vault infrastructure providers, yield optimizer RWA credit vaults, perpetual contract LP vaults, and options vaults. Despite the overall decline, RWA Vaults showed resilience with 37.8% growth against the trend, while other categories experienced significant pullbacks.
OpenZeppelin CEO Manuel Aráoz has escalated his security warnings, now declaring 'all of DeFi unsafe' in a post on X Wednesday, citing the transformative impact of artificial intelligence on hacking capabilities. Aráoz explained that 'coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric', with defenders needing to fix every bug while attackers need just one exploit to steal funds. His concerns have intensified as Anthropic's restricted Claude Mythos AI model can autonomously discover software vulnerabilities and develop working exploits at a level that surpasses existing automated tools. This technological advancement raises uncomfortable questions for DeFi, whose core security model was designed around human attackers operating at human speed, as machine systems can now scan publicly available smart contract code, identify weaknesses, and weaponize them faster than defenders can patch them.
Aráoz highlighted the critical security imbalance facing DeFi protocols. As reported by The Block, he explained that 'coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric'. The fundamental issue lies in the fact that defenders need to fix every bug while attackers need just one exploit to steal funds, creating an inherently unbalanced security environment. Recent events have reinforced this asymmetry, with three major incidents between October 2025 and May 2026 (the Stream Finance, Resolv, and Kelp hacks) providing a good stress test window that has affected the entire DeFi ecosystem. The concentration of losses came largely from bridge-related weaknesses, privileged access failures, and operational mistakes instead of isolated coding bugs alone.
April 2025 marked a devastating month for DeFi security, with nearly $630 million stolen from DeFi protocols, according to DefiLlama's data. This represented the worst month for DeFi hacks and exploits since February 2025, when Bybit was hacked for approximately $1.5 billion. The month featured two major attacks: the $285 million exploit of Drift Protocol, where attackers reportedly used a six-month social engineering campaign, and the $293 million exploit of Kelp DAO tied to vulnerabilities in its cross-chain bridge infrastructure. Security researchers and blockchain investigators have widely linked both attacks to North Korean state-backed hacking groups. Among the smaller attacks, Wasabi Protocol lost roughly $5.5 million across multiple networks, while Sweat Economy reported losses of about $3.46 million after attackers drained nearly 65% of its liquidity pool in under 30 seconds. On the Sui blockchain, Aftermath Finance lost nearly $1.1 million in USDC from its perpetuals platform in 11 transactions over approximately 36 minutes.
The security concerns have significantly impacted DeFi adoption metrics. According to DefiLlama's data, DeFi TVL is down about 14% since mid-April, falling from approximately $172 billion to $148 billion. May has continued the trend with 25 DeFi exploits reported so far, though on a smaller scale, including notable incidents such as Verus Network's Ethereum bridge exploited for $11.6 million and Polymarket's $573,200 security breach that may have involved a compromised private key. The latest DeFi Vault 2026 Annual Report confirms this trend, showing that categories such as lending, liquid staking, and restaking were hit the hardest because they have the largest exposure to on-chain assets and drive the on-chain economy, while RWA Vaults, having no exposure to crypto assets, continued to show unrelated growth. Despite the overall decline, DeFi exploits crossed $600 million in April alone, making it the worst month for crypto-related hacks in more than a year.