Veda CEO Highlights Key Management Risks in Onchain Vaults Over Smart Contract Bugs
Sun Raghupathi, CEO of Veda, a provider of onchain vault infrastructure, argues that the crypto industry needs to reassess its focus on security threats. He believes that the most significant risk facing onchain vaults today is not the smart contract bugs that have dominated discussions, but rather the individuals and processes managing access controls.
Raghupathi points out that as smart contract code matures and undergoes rigorous audits, the vulnerabilities shift from the code itself to the human factors involved in key management. Recent high-profile incidents have often stemmed from compromised private keys or operational security failures rather than direct exploits of smart contracts.
Veda has successfully routed over $16 billion through its vault infrastructure without any reported security incidents related to its smart contracts. The company’s infrastructure supports major clients, including Kraken, whose Earn vaults have accumulated over $600 million in deposits since their launch.
Raghupathi warns that DeFi users should not treat onchain vaults as if they are FDIC-insured accounts. Instead, he likens them more to hedge funds, underscoring the importance of understanding the risks involved in operational management and governance. As institutional interest in DeFi grows, Veda's approach to integrating compliance and risk controls into its vault infrastructure aims to address these critical concerns.
With the increasing flow of capital into products like Kraken's DeFi Earn, the stakes for misjudging safety are high. Veda's focus on operational security and governance structures is becoming increasingly relevant as the landscape of DeFi evolves.
Updated 18:30 UTC
Key Insights from Andre Cronje on Onchain Finance
- Decentralization is no longer the sole operating model for most DeFi protocols; the industry is evolving.
- Modern protocols require identifiable teams for maintenance, risk management, and value creation.
- Upgradeability is recommended for complex financial systems, but it introduces significant operational risks.
- Audits are essential but should be part of a broader security strategy that includes infrastructure security and real-time monitoring.
- Separation of authority in financial systems is crucial to mitigate risks associated with emergency controls.
- Users must understand their actual exposure in onchain finance, which often involves multiple counterparties beyond just smart contracts.
- Transparency and compliance standards similar to those in regulated markets should be applied to token trading.
- Flying Tulip’s margin accounts utilize an equity-based model to better manage risk compared to traditional LTV models.
- The design of ftUSD allows for leveraging staked ETH while maintaining a balanced collateral structure.
FAQ
What is the main risk associated with onchain vaults according to Veda's CEO?
Sun Raghupathi, CEO of Veda, argues that the most significant risk facing onchain vaults today is not smart contract bugs, but rather the individuals and processes managing access controls.
How has Veda performed in terms of security incidents?
Veda has successfully routed over $16 billion through its vault infrastructure without any reported security incidents related to its smart contracts.
What does Raghupathi compare onchain vaults to?
Raghupathi compares onchain vaults to hedge funds, emphasizing the importance of understanding the risks involved in operational management and governance.
What is the significance of operational security in DeFi according to Veda?
As institutional interest in DeFi grows, Veda's focus on operational security and governance structures is becoming increasingly relevant to address critical concerns related to risk management.
What should DeFi users be cautious about regarding onchain vaults?
DeFi users should not treat onchain vaults as if they are FDIC-insured accounts, as the risks involved are more akin to those of hedge funds.
Comments
Comments are moderated before publish.
No comments yet — be the first.