Let’s address the risks of decentralization

Let’s address the risks of decentralization

Mads Eberhardt 400x400
Mads Eberhardt

Cryptocurrency Analyst

Summary:  Decentralization is the key value proposition of crypto. It enables trust and services without intermediaries. However, there is no such thing as a free lunch, as decentralization comes with severe risks, stressed last week by the $320mn Wormhole exploit. This may reduce trust in decentralized applications and give incentive to further regulation.


In August, Certus One owned by leading market maker Jump Crypto, a subsidiary of Jump Trading, launched Wormhole, an interoperability protocol allowing users to transfer tokens and use applications across various cryptocurrencies such as Ethereum, Solana, and Terra. Such an application is also known as a bridge. The most used Wormhole bridge is from Ethereum to Solana. This particular bride was targeted last week in what evolved into one of the largest decentralized finance protocol exploits in crypto.

Wormhole exploited for 120,000 Ether

On Wednesday, a hacker managed to exploit the Wormhole bridge between Ethereum and Solana for 120,000 Ether, worth around $320mn at the time. In brief, the hacker was able to mislead the protocol into assuming that the person in question deposited Ether into the contract to issue an equal amount in wETH, which is tokenized Ether on Solana collateralized with actual Ether through Wormhole. With the wETH at hand on Solana, the hacker returned to Wormhole to redeem the majority to actual Ether on Ethereum. The problem, though, as the hackers wETH was not collateralized, it was Ether collateralizing others wETH. The hacker traded the remaining wETH into other assets on decentralized exchanges on Solana to quickly get rid of the undercollateralized wETH.

Wormhole quickly offered the hacker a $10mn bug bounty if returning the funds. However, the hacker did not seem interested since Jump Crypto promptly funded Wormhole with an equivalent 120,000 Ether from their own book, saying on Twitter: “Jump Crypto believes in a multichain future and that Wormhole is essential infrastructure. That’s why we replaced 120k ETH to make community members whole and support Wormhole now as it continues to develop.” The hacker has not moved the stolen Ether yet, and to cash out such an amount will be severely challenging, as the few exchanges, brokers, and OTC desks able to liquidate such an amount will freeze it instantly if it suddenly hits their Ethereum wallet, as they know the source of the funds.

The Wormhole exploit stresses the risk of decentralization

In 2021, $1.3bn was lost in decentralized application exploits, which was more than double the amount of 2020 upon an increasing value locked in decentralized applications. Hence, the Wormhole exploit is surely not the first and most critically, it is presumably not the last exploit. The latter stresses that decentralized applications are fragile and that they will likely continue to be that for years to come. This is further enhanced upon the fact that Wormhole was not developed by a teenager living in his or her parents’ basement. It was virtually developed by Jump Trading, one of the largest market makers within equities, options, futures, and cryptocurrencies. If a protocol developed by a corporation of that size can be exploited, imagine how challenging it is for a minor start-up to develop safeguarded decentralized applications. Moreover, imagine if an exploit in fact happens for a minor start-up, it is immediately game over as they cannot in this case fund the protocol with over $300mn worth in Ether in under 24 hours. This ultimately limits innovation within crypto as fewer want to risk their start-up and reputation in the space.
7_MAEB_1
Source: Defi Llama

Here, decentralization enters the equation. While decentralization is the key value proposition of crypto because it empowers services normally facilitated by various intermediaries such as international transfers and decentralized trading of non-fungible tokens (NFTs), it is also a notable shortcoming of crypto. This is the case with decentralized exploits, as developers and users cannot recover funds when exploits occur, compared to a centralized system where the company behind can often reverse the transaction. This means that exploits and cyberattacks can have proportionally much worse consequences when dealing decentralized.

Does crypto learn from it?

Whenever an exploit takes place, the community often makes a u-turn and presents it as somewhat positive with the main argument being that the protocol in question alongside other protocols learn from the particular exploit to develop future-proof protocols. The learning view is likely true, however, imagine in how many ways various decentralized applications can be exploited, so to potentially develop safeguarded decentralized applications through a learning phase will not be a quick fix.

One might argue that decentralized applications will experience the same learning phase and development as e.g., crypto wallets. In the early days of Bitcoin, there were no great wallets, which meant that many Bitcoins were lost forever in the first years of its lifetime. At the time, it was likely hard to imagine that institutions would ever trust crypto companies to custody billions worth of value. This is not unimaginable anymore. Quite the contrary, it is the case today. As Søren Kierkegaard said: “Life can only be understood backwards, but it must be lived forwards”.

It is important to remember that the first decentralized applications launched in 2018, so it is somewhat of a new phenomenon. This means the industry is still quite early in its learning phase. Furthermore, over the past years, several consultancies have launched making audits in the code of decentralized applications, such as OpenZeppelin, which further enhances security. Besides doing audits, OpenZeppelin has released a framework of battle-tested smart contracts intended to be used by new decentralized applications. This effectively means that as the industry matures there will perchance be various frameworks and infrastructure to be leveraged in making applications more secure.

On the other hand, even if the industry can present a near-zero exploit risk in the future, the question is whether everyday people will trust decentralized applications with their history of exploits. Not to mention that the potential consequences of exploits are rapidly intensified upon increasing usage and value locked in decentralized applications. This may enforce tough regulation by regulators before the industry proves that it is safe to interact with.

Outrageous Predictions 2026

01 /

  • Executive Summary: Outrageous Predictions 2026

    Outrageous Predictions

    Executive Summary: Outrageous Predictions 2026

    Saxo Group

    Read Saxo's Outrageous Predictions for 2026, our latest batch of low probability, but high impact ev...
  • A Fortune 500 company names an AI model as CEO

    Outrageous Predictions

    A Fortune 500 company names an AI model as CEO

    Charu Chanana

    Chief Investment Strategist

    Can AI be trusted to take over in the boardroom? With the right algorithms and balanced human oversi...
  • Despite concerns, U.S. 2026 mid-term elections proceed smoothly

    Outrageous Predictions

    Despite concerns, U.S. 2026 mid-term elections proceed smoothly

    John J. Hardy

    Global Head of Macro Strategy

    In spite of outstanding threats to the American democratic process, the US midterms come and go cord...
  • Dollar dominance challenged by Beijing’s golden yuan

    Outrageous Predictions

    Dollar dominance challenged by Beijing’s golden yuan

    Charu Chanana

    Chief Investment Strategist

    Beijing does an end-run around the US dollar, setting up a framework for settling trade in a neutral...
  • Obesity drugs for everyone – even for pets

    Outrageous Predictions

    Obesity drugs for everyone – even for pets

    Jacob Falkencrone

    Global Head of Investment Strategy

    The availability of GLP-1 drugs in pill form makes them ubiquitous, shrinking waistlines, even for p...
  • Dumb AI triggers trillion-dollar clean-up

    Outrageous Predictions

    Dumb AI triggers trillion-dollar clean-up

    Jacob Falkencrone

    Global Head of Investment Strategy

    Agentic AI systems are deployed across all sectors, and after a solid start, mistakes trigger a tril...
  • Quantum leap Q-Day arrives early, crashing crypto and destabilizing world finance

    Outrageous Predictions

    Quantum leap Q-Day arrives early, crashing crypto and destabilizing world finance

    Neil Wilson

    Investor Content Strategist

    A quantum computer cracks today’s digital security, bringing enough chaos with it that Bitcoin crash...
  • SpaceX announces an IPO, supercharging extraterrestrial markets

    Outrageous Predictions

    SpaceX announces an IPO, supercharging extraterrestrial markets

    John J. Hardy

    Global Head of Macro Strategy

    Financial markets go into orbit, to the moon and beyond as SpaceX expands rocket launches by orders-...
  • Taylor Swift-Kelce wedding spikes global growth

    Outrageous Predictions

    Taylor Swift-Kelce wedding spikes global growth

    John J. Hardy

    Global Head of Macro Strategy

    Next year’s most anticipated wedding inspires Gen Z to drop the doomscrolling and dial up the real w...
  • China unleashes CNY 50 trillion stimulus to reflate its economy

    Outrageous Predictions

    China unleashes CNY 50 trillion stimulus to reflate its economy

    Charu Chanana

    Chief Investment Strategist

    Having created history’s most epic debt bubble, China boldly bets that fiscal stimulus to the tune o...

Content disclaimer

None of the information provided on this website constitutes an offer, solicitation, or endorsement to buy or sell any financial instrument, nor is it financial, investment, or trading advice. Saxo Bank A/S and its entities within the Saxo Bank Group provide execution-only services, with all trades and investments based on self-directed decisions. Analysis, research, and educational content is for informational purposes only and should not be considered advice nor a recommendation.

Saxo’s content may reflect the personal views of the author, which are subject to change without notice. Mentions of specific financial products are for illustrative purposes only and may serve to clarify financial literacy topics. Content classified as investment research is marketing material and does not meet legal requirements for independent research.

Before making any investment decisions, you should assess your own financial situation, needs, and objectives, and consider seeking independent professional advice. Saxo does not guarantee the accuracy or completeness of any information provided and assumes no liability for any errors, omissions, losses, or damages resulting from the use of this information.

Please refer to our full disclaimer and notification on non-independent investment research for more details.

Saxo Bank A/S (Headquarters)
Philip Heymans Alle 15
2900 Hellerup
Denmark

Contact Saxo

Select region

International
International

All trading and investing comes with risk, including but not limited to the potential to lose your entire invested amount.

Information on our international website (as selected from the globe drop-down) can be accessed worldwide and relates to Saxo Bank A/S as the parent company of the Saxo Bank Group. Any mention of the Saxo Bank Group refers to the overall organisation, including subsidiaries and branches under Saxo Bank A/S. Client agreements are made with the relevant Saxo entity based on your country of residence and are governed by the applicable laws of that entity's jurisdiction.

Apple and the Apple logo are trademarks of Apple Inc., registered in the US and other countries. App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC.