The DeFi dilemma in the wake of the $200M KuCoin exploit.

By Paul Claudius, co-founder of oracle provider DIA

Following the recent hack of Hong Kong-based centralised crypto exchange KuCoin, many DeFi projects were quick to freeze their smart contracts and initiate a token swap to do damage control and undermine the hacker’s ability to monetise on his actions. Others rejected using centralized infrastructure to exert this power. The difference in responses brings up an age-old question in the realm of DLT: How much decentralization do we really want?

Catching Up

On Friday, September 25, a malicious actor or actors routed an estimated USD 200 million worth of digital assets from the exchange to an external address, affecting hundreds of thousands of users and well over 100 projects. The hack, which affected projects of all sizes, posed a looming threat of massive token dumps, potentially crashing token prices and investor morale. The community watched the event unfold in real-time via the hacker’s wallet on Etherscan and Ethplorer.

As of Saturday, September 26, smaller tranches of tokens from a broad range of projects were being sold off. This compelled projects to take mostly discretionary decisions that would potentially impact thousands of KuCoin clients and entire communities.

Pressure to Act

As the situation unfolded, the impacted projects took the initiative to support and coordinate among each other, while KuCoin was requesting projects to unilaterally initiate a fork or pause contracts.

Projects were evaluating this course of action when the hacker increased pressure by moving over two million of Ocean tokens to liquidate on Uniswap from his master wallet. The swift progression of the situation painfully highlighted the risks borne both by the vulnerabilities of centralized infrastructure as well as the continuous nature of DEXs:

Centralised infrastructure creates opportunities for hackers and decentralized infrastructure allows them to monetize on it.

DeFi-Defining Moment

The way that we deal with such situations and the decisions we take to mitigate them and what we expect from decentralized organizations and decision-making processes is – at least in part – what defines the projects themselves as well as the wider DeFi community.

Do we prefer benevolent dictators that take swift and decisive action in the interest of the community? Are we OK with surrendering the ultimate power to just one or a handful of people? Was this the root of the entire debacle in the first place? Or do we prefer the other extreme – absolute decentralization at all costs that might not reflect communities’ current sentiment and cause them to suffer an immediate adverse financial impact?




