Curve Founder Calls for DeFi Safety Standards Amid Hacking Surge

CRV0,61%
ETH3,7%
ZRO-1,5%
AAVE3,78%

Michael Egorov, founder of Curve Finance, publicly raised concerns about structural vulnerabilities in the DeFi industry on April 21, 2026, stating that “preventable hacks” stemming from centralized single points of failure are damaging industry trust and cannot be ignored any longer.

Recent DeFi Incident and Responsibility Concerns

On April 18, Kelp DAO’s cross-chain bridge vulnerability was exploited, resulting in the theft of approximately 116,500 rsETH (restaked Ethereum), valued at approximately $292 million. LayerZero handled the cross-chain movement in this incident. Following the attack, major DeFi lending protocols including Aave froze the rsETH market and restricted related deposits and borrowing.

Egorov criticized the interconnected nature of multiple infrastructure components—Aave, rsETH, and LayerZero—and the resulting structure that diffuses accountability. He noted that “despite users being unable to withdraw their assets, each project claims to be operating normally,” emphasizing that “ultimately, only users bear the losses.”

Proposed Solutions: Prevention Over Response

Egorov argued that addressing these issues requires prevention rather than post-incident response. He advocated for:

  • Reducing single points of failure in DeFi infrastructure
  • Designing systems that distribute trust when centralized solutions are unavoidable
  • Sharing best practices across the industry
  • Strengthening code verification standards

Industry-Wide Safety Standards and Governance

Egorov called for collaborative action across the DeFi sector to establish safety standards applicable to the entire industry. He proposed that projects, auditors, and risk assessment groups work together to establish safe design principles and verification criteria.

He further suggested that major ecosystem institutions—specifically the Ethereum Foundation and Solana Foundation—should take the lead in establishing industry standards. Egorov also referenced the need to learn from traditional finance’s risk management approaches.

Warnings on Adoption and Trust

While expressing confidence that “DeFi will ultimately prevail,” Egorov warned that failure to address current structural vulnerabilities could result in serious erosion of trust during the path to mainstream adoption.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

The UK Financial Conduct Authority launches its first crackdown on illegal peer-to-peer cryptocurrency trading

The FCA’s first wave of enforcement actions, working together with HMRC and the South West Regional Organised Crime Unit, raided multiple London locations suspected of running unregistered P2P cryptocurrency trading venues, issuing stop orders and bringing the matters into a criminal investigation. Experts say such unregistered platforms are illegal and carry high risk, and regulators will strengthen oversight gaps with regulations such as those on anti-money laundering. The UK is gradually building a cryptocurrency regulatory framework, with full implementation expected by 2027; in 2026, a registration application channel will be opened, and investors should carefully assess risks.

ChainNewsAbmedia6h ago

Hyperliquid Launches Policy Center in U.S. to Advance Decentralized Derivatives Regulation

Gate News message, April 22 — Hyperliquid has established the Hyperliquid Policy Center (HPC) in the United States, funded by the Hyper Foundation. The initiative aims to secure legal clarity and protections for U.S. users and developers, with a focus on on-chain perpetual futures contracts. HPC wi

GateNews8h ago

Major CEX Urges U.S. Congress to Implement Crypto Tax Exemption Threshold and Allow Staking Reward Tax Timing Choice

Major CEX urges Congress to set a minimum tax-exemption for crypto transactions and offer flexible staking-report timing, citing IRS forms show most trades under thresholds and heavy reporting burden. The article reports that a major centralized exchange is urging U.S. Congress to establish inflation-adjusted minimum exemption thresholds for crypto transactions and to allow taxpayers to choose when to report staking rewards. It cites CoinDesk data showing 56 million crypto tax forms filed for 2025, with most transactions valued under $50, illustrating the administrative burden of current reporting rules and the need for policy changes.

GateNews10h ago

North Carolina Passes Digital Asset Law Allowing Banks to Custody Crypto

Gate News message, April 22 — North Carolina has officially introduced House Bill 1029, the Digital Asset and Stablecoin Act, marking the state's entry into crypto regulation. The bill, developed following recommendations from a dedicated blockchain committee, aims to integrate digital assets into t

GateNews10h ago

UK FCA Conducts Coordinated Raids on Illegal P2P Crypto Trading Sites in London

FCA raids eight London sites tied to unregistered P2P crypto trading, issuing cease-and-desist notices. Evidence points to money-laundering and terror-financing probes; no P2P platform is FCA-registered; enforcement signals a tougher AML crackdown. Abstract: The FCA, with tax authorities and police, conducted surprise raids at eight London sites linked to unregistered peer-to-peer crypto trading, issuing cease-and-desist notices. The operation underpins ongoing money-laundering and terrorist-financing probes. No P2P platform is FCA-registered in the UK. Analysts view the action as a shift from statements to enforcement, signaling potential broader crackdowns under AML and financial-promotion rules for crypto assets, which remain high-risk investments.

GateNews10h ago

Bank of Korea Prioritizes CBDCs Under New Governor Shin, Maintains 2.5% Rate Amid Regional Uncertainty

Gate News message, April 22 — South Korea's central bank has entered a new monetary phase with newly appointed governor Shin Hyun-song placing central bank digital currencies (CBDCs) at the forefront of the country's financial system. In his inaugural address, Shin positioned CBDCs and bank-issued d

GateNews14h ago
Comment
0/400
RationalRugCheckervip
· 3h ago
The biggest pain point in DeFi is actually "the cascading risk caused by composability," where one flaw can propagate a chain reaction, requiring more systematic risk control.
View OriginalReply0
SlippageAfterTheRainvip
· 04-21 10:15
Collaboration security standards + accountability mechanisms are very important; otherwise, users will just continue to use centralized hosting for convenience.
View OriginalReply0
GasFeesAfterTheRainvip
· 04-21 09:46
Who should set the standards? The foundation, the auditing firm, or the protocol alliance? Don't let it end up with everyone doing their own thing again.
View OriginalReply0
ChaintraceAuntievip
· 04-21 05:55
That's right, safety must come before growth.
View OriginalReply0
0XNightRunvip
· 04-21 05:51
Accountability sounds good, but how can anonymous on-chain teams be implemented? At least make permissions, delays, and emergency procedures open and transparent.
View OriginalReply0
NonceNomadvip
· 04-21 05:49
I would prefer to see the upfront security budget: higher bug bounties, continuous monitoring, formal verification before launch—don't rely solely on a single audit.
View OriginalReply0
BetaTestHumanvip
· 04-21 05:41
Can we establish "Accident Review Standards" and "Safety Ratings" similar to traditional industries? So that ordinary users can easily understand the risks at a glance.
View OriginalReply0
OrigamiMountainsAndRiversvip
· 04-21 05:38
Restoring trust depends on two points: the compensation mechanism and ongoing transparency. When an issue occurs, disclose immediately, review, and improve—don't delay.
View OriginalReply0
GateUser-3d750846vip
· 04-21 05:32
I support industry-level security alliances, but we must prevent being hijacked by large projects' rules; small teams should also have channels for participation and appeals.
View OriginalReply0
YieldCartographervip
· 04-21 05:32
Don't blame the hackers entirely; many issues stem from internal process and permission design problems, especially with admin keys, upgrade logic, and oracle dependencies.
View OriginalReply0
View More