Why some crypto borrowers are rethinking DeFi Crypto News

A single forged message moved through some of crypto’s largest lending markets in April 2026 without breaking any of the lending protocols’ own code. For borrowers, that detail is the whole story.

It started with Kelp DAO, a liquid restaking protocol. According to security firm Halborn, the attackers didn’t target Kelp’s lending logic; they went after how its cross-chain bridge verified messages.

They knocked the honest data nodes offline, forced the system onto nodes they controlled, and pushed through a fake cross-chain packet that minted 116,500 unbacked rsETH, about 18% of the token’s circulating supply. It was part of an estimated $292 million in losses, later attributed to North Korea’s Lazarus Group.

Related: Billionaire has 5-word response to Elon Musk’s Tesla chart

“Trustless” still has dependencies

The knock-on effects are what borrowers noticed. Some of the stolen rsETH was posted as collateral for loans on Aave and several major lending markets, and each froze its rsETH market to avoid taking on bad debt. Aave’s core contracts were never touched, but its users were still exposed. More than $13 billion in total value left DeFi platforms over the next two days, per data cited by Halborn.

The takeaway isn’t that DeFi failed. It’s that “trustless” covers a lot of moving parts. A borrower on a DeFi protocol depends on smart contracts, but also on wrapped assets, bridges, oracles, and governance, any of which can break while the lending code works exactly as intended.

Bitcoin holders inherit an extra step: using BTC on Ethereum-based protocols generally means wrapping it first, which adds another point of failure. That extra step is exactly what failed at Kelp. rsETH isn’t Ethereum, but a wrapped, derivative claim on restaked ETH, and that derivative layer is what the attackers forged. Native BTC collateral skips that step entirely: no wrapping, no bridging, no derivative token standing between the borrower and the asset. There’s nothing there to fake.

AI is now part of the calculation. AI agents are getting better at finding smart-contract flaws, and in some cases generating working exploits in testing. The same tools also improve auditing and monitoring, so it’s not one-directional. But it’s a reminder that code-based systems are up against a moving target.

Weighing the trade-offs

It helps to lay the two side by side. DeFi’s pull is real: anyone can borrow without permission or paperwork, funds move in minutes, and rates are often lower because there’s no company taking a cut in the middle. The cost is that you’re trusting code and everything it plugs into, and when something upstream breaks, as it did with Kelp, there’s no one to call and no contract to fall back on. CeFi inverts that.

A centralized lender is a company you’re trusting instead of a contract, which means slower processes, added counterparty risk, and less transparency, but also a legal agreement, a support line, and a defined path if something goes wrong, and typically, a higher rate: the premium that pays for those things. Neither removes risk. They just relocate it.

Centralized lenders aren’t a safe harbor by default. CeFi carries counterparty risk, and Celsius and BlockFi are recent enough to make the point on their own. What CeFi can offer is a different risk profile: native Bitcoin as collateral without wrapping, a legal contract, third-party custody, human support, and set liquidation terms. Whether that’s a better deal depends entirely on the lender.

Not all CeFi lenders offer that risk profile equally, and the gap is worth checking before borrowing. Does the lender hold your collateral directly, or lend it back out to generate yield? Can reserves be independently verified, or is it their word against nothing? Are liquidation thresholds spelled out before you borrow, or discovered after? And is there an actual legal agreement behind the product, something enforceable, not just a terms-of-service page? Those four questions separate a durable CeFi lender from a fragile one faster than any marketing claim will.

Ledn is one CeFi lender in this space. Founded in 2018, it offers Bitcoin-backed loans and dollar and Bitcoin savings products in more than 100 countries, and was the first digital-asset lender to complete a formal proof-of-reserves attestation, in which an outside accountant checks that client assets are accounted for.

The company says it keeps 100% of Bitcoin loan collateral in custody rather than lending it out, ring-fences that collateral from its funding partners, and gives borrowers tools like loan-to-value alerts, automatic top-ups, and partial repayments.

Mauricio Di Bartolomeo, Ledn’s co-founder and chief sales officer, puts the decision in plain terms. Every borrowing model asks you to trust something,” he said. “The important questions to ask are what you are trusting, whether you can verify it and what happens when it fails.”
That’s roughly where crypto borrowing has landed. The question is shifting from which system removes trust to which risks a borrower is willing to hold.