Curve Founder Calls for DeFi Safety Standards Amid Hacking Surge

CRV3,33%
ETH1,25%
ZRO4,19%
AAVE1,4%

Michael Egorov, founder of Curve Finance, publicly raised concerns about structural vulnerabilities in the DeFi industry on April 21, 2026, stating that “preventable hacks” stemming from centralized single points of failure are damaging industry trust and cannot be ignored any longer.

Recent DeFi Incident and Responsibility Concerns

On April 18, Kelp DAO’s cross-chain bridge vulnerability was exploited, resulting in the theft of approximately 116,500 rsETH (restaked Ethereum), valued at approximately $292 million. LayerZero handled the cross-chain movement in this incident. Following the attack, major DeFi lending protocols including Aave froze the rsETH market and restricted related deposits and borrowing.

Egorov criticized the interconnected nature of multiple infrastructure components—Aave, rsETH, and LayerZero—and the resulting structure that diffuses accountability. He noted that “despite users being unable to withdraw their assets, each project claims to be operating normally,” emphasizing that “ultimately, only users bear the losses.”

Proposed Solutions: Prevention Over Response

Egorov argued that addressing these issues requires prevention rather than post-incident response. He advocated for:

  • Reducing single points of failure in DeFi infrastructure
  • Designing systems that distribute trust when centralized solutions are unavoidable
  • Sharing best practices across the industry
  • Strengthening code verification standards

Industry-Wide Safety Standards and Governance

Egorov called for collaborative action across the DeFi sector to establish safety standards applicable to the entire industry. He proposed that projects, auditors, and risk assessment groups work together to establish safe design principles and verification criteria.

He further suggested that major ecosystem institutions—specifically the Ethereum Foundation and Solana Foundation—should take the lead in establishing industry standards. Egorov also referenced the need to learn from traditional finance’s risk management approaches.

Warnings on Adoption and Trust

While expressing confidence that “DeFi will ultimately prevail,” Egorov warned that failure to address current structural vulnerabilities could result in serious erosion of trust during the path to mainstream adoption.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Unit Labs Requests Meeting with U.S. CFTC

Gate News reports Unit Labs, parent of Unitxyz and Tradexyz, filed a request to meet the CFTC on April 7; the meeting's nature and outcome remain undisclosed. Abstract: The article notes that Unit Labs, parent company of Unitxyz and Tradexyz, requested a meeting with the U.S. Commodity Futures Trading Commission (CFTC) on April 7. The record provides no information on the purpose or outcome of the meeting.

GateNews18m ago

Korean National Tax Service Launches Crypto Tax-Evasion Crackdown in July: Even Self-Custody Wallets and Mixing Services Can Be Traced

According to a report by ZDNet Korea, South Korea’s National Tax Service (NTS) issued on April 15 a procurement notice for a “virtual asset tax evasion response and transaction tracking software,” with plans to complete system selection by the end of May, deploy it in June, and officially launch it in July. The new system will be able to track self-custodied (non-custodial) wallets such as MetaMask and Phantom, and will include “demixing” technology to enforce tax evasion against offenders who use mixers to conceal the flow of funds. This is the third upgrade to South Korea’s crypto tax investigation tracking system since 2024. In conjunction with new tax legislation that, starting in 2026, will formally bring crypto assets under taxation under the “Other Income” category of the comprehensive income tax, enforcement tools are being upgraded at the same time to improve collection efficiency. Procurement scope: Chainalysis and TRM

ChainNewsAbmedia1h ago

South Korea's Tax Authority Introduces Crypto Tracking Software to Monitor Tax Evasion, Including Non-Custodial Wallets

Gate News message, April 21 — South Korea's National Tax Service announced on April 15 that it plans to deploy crypto asset tracking software from firms including Chainalysis and TRM Labs to monitor cryptocurrency transactions in real time, trace hidden assets of suspected tax evaders, and combat mo

GateNews1h ago

Sberbank Prepares Crypto Trading Rollout for 110M Users

Sberbank prepares crypto trading and custody services, awaiting regulatory approval to launch for 110M users. Proposed rules may allow retail access with limits, a shift toward regulated crypto participation in Russia. Bank built infrastructure and tested services, positioning for fast

CryptoFrontNews1h ago

U.S. CLARITY Act stablecoin bill faces May delay amid bank pushback

U.S. CLARITY Act faces a May delay as banks fight stablecoin yields, clashing with a White House report that says the lending impact is just 0.02%. Summary U.S. CLARITY Act's April committee review hangs in the balance as Senate

Cryptonews2h ago

Bank for International Settlements Warns: Stablecoins Are More Like Securities, Redemption Flaws Could Trigger a Bank Run

International Settlements Bank (BIS) Managing Director Pablo Hernández de Cos warned on Monday at a Bank of Japan conference in Japan that the global stablecoin market has surpassed $315.9 billion, but its operating mechanism is closer to investment products such as ETFs rather than true money. The BIS said that if large-scale redemptions occur, it would trigger a chain-reaction effect similar to the run on Silicon Valley Bank in 2023.

MarketWhisper2h ago
Comment
0/400
ChaintraceAuntievip
· 3h ago
That's right, safety must come before growth.
View OriginalReply0
0XNightRunvip
· 3h ago
Accountability sounds good, but how can anonymous on-chain teams be implemented? At least make permissions, delays, and emergency procedures open and transparent.
View OriginalReply0
NonceNomadvip
· 3h ago
I would prefer to see the upfront security budget: higher bug bounties, continuous monitoring, formal verification before launch—don't rely solely on a single audit.
View OriginalReply0
BetaTestHumanvip
· 3h ago
Can we establish "Accident Review Standards" and "Safety Ratings" similar to traditional industries? So that ordinary users can easily understand the risks at a glance.
View OriginalReply0
OrigamiMountainsAndRiversvip
· 3h ago
Restoring trust depends on two points: the compensation mechanism and ongoing transparency. When an issue occurs, disclose immediately, review, and improve—don't delay.
View OriginalReply0
GateUser-3d750846vip
· 3h ago
I support industry-level security alliances, but we must prevent being hijacked by large projects' rules; small teams should also have channels for participation and appeals.
View OriginalReply0
YieldCartographervip
· 3h ago
Don't blame the hackers entirely; many issues stem from internal process and permission design problems, especially with admin keys, upgrade logic, and oracle dependencies.
View OriginalReply0
ThinkForThreeSecondsBeforevip
· 3h ago
To achieve large-scale adoption of DeFi, it must have "security enabled by default," hide complexity, and let users avoid pitfalls without having to learn a bunch of things.
View OriginalReply0
BluePeonyPrincipalProtectionvip
· 3h ago
Every incident serves as a reminder: don't equate TVL with strength; safety margin is the real moat.
View OriginalReply0
LimeLeverageAlertvip
· 3h ago
If the collaboration standards are just slogans, they are useless. It's best to have an actionable checklist: least privilege, multi-signature thresholds, timelock, monitoring and alerts.
View OriginalReply0
View More