Some crypto borrowers are reconsidering decentralized finance (DeFi) lending after a security breach at Kelp DAO exposed vulnerabilities in how cross-chain bridges verify messages. The incident, which occurred in April 2026, resulted in estimated losses of $292 million, a figure later attributed to North Korea's Lazarus Group. For borrowers, the key issue is that the attack did not target the lending protocols' code but rather the upstream infrastructure they rely on.

Security firm Halborn reported that attackers knocked offline honest data nodes and forced the system onto nodes they controlled. This allowed them to push through a fake cross-chain packet that minted 116,500 unbacked rsETH, representing about 18% of the token's circulating supply. Because some of this stolen rsETH was posted as collateral for loans on Aave and other major lending markets, those platforms froze their rsETH markets to avoid bad debt. Although Aave's core contracts were never touched, its users remained exposed to the risk. Data cited by Halborn indicates that more than $13 billion in total value left DeFi platforms in the two days following the incident.

The event highlighted that the "trustless" nature of DeFi encompasses many moving parts, including wrapped assets, bridges, oracles, and governance. A borrower depends on smart contracts, but also on these peripheral systems, any of which can fail while the lending code functions as intended. For Bitcoin holders, using assets on Ethereum-based protocols generally requires wrapping them first, adding another point of failure. In the Kelp case, rsETH is a wrapped derivative claim on restaked ETH, and it was this derivative layer that the attackers forged. Native Bitcoin collateral avoids this step entirely, as there is no wrapping or bridging involved.

Advances in artificial intelligence are adding another layer to this calculation. AI agents are becoming more capable of identifying smart-contract flaws and generating working exploits in testing environments. While these same tools improve auditing and monitoring, they indicate that code-based systems face a constantly evolving threat landscape. This development contrasts with centralized finance (CeFi), where borrowers trust a company rather than a contract.

CeFi offers a different risk profile characterized by slower processes and added counterparty risk but provides legal agreements, support lines, and defined paths for resolution. Centralized lenders are not inherently safe; past failures like Celsius and BlockFi demonstrate significant counterparty risks. However, CeFi can offer native Bitcoin as collateral without wrapping, third-party custody, and set liquidation terms. The suitability of a CeFi lender depends on specific factors such as whether collateral is held directly or lent out for yield, if reserves can be independently verified, and whether liquidation thresholds are clearly defined before borrowing.

Ledn, a CeFi lender founded in 2018, operates in this space offering Bitcoin-backed loans and savings products in more than 100 countries. The company states it keeps 100% of Bitcoin loan collateral in custody and does not lend it out. It was the first digital-asset lender to complete a formal proof-of-reserves attestation by an outside accountant. Mauricio Di Bartolomeo, Ledn's co-founder and chief sales officer, noted that every borrowing model requires trust in some component. He emphasized that the critical questions involve what is being trusted, whether it can be verified, and what happens if it fails.

The shift in crypto borrowing reflects a move away from asking which system removes trust entirely to determining which specific risks a borrower is willing to hold.