DeFi's Ghost Chain Problem: A Necessary Evil or Hasty Retreat?
The DeFi space has been hit hard by exploits in H2 2026, with losses totaling $1.3B. Two major incidents, KelpDAO and Drift Protocol, accounted for over 40% of this loss, each losing $292M and $285M respectively. Both breaches were due to operational and infrastructure security flaws rather than typical smart contract bugs.
Aave and LayerZero, two prominent DeFi protocols, have responded by targeting 'ghost chains', or low-activity networks that are often vulnerable to attacks. Aave has shut down its V3 lending deployments on six networks, including Sonic and Aptos, while LayerZero has axed support for 32 chains, citing a focus on more secure options.
However, experts are divided on the effectiveness of this approach. Joe Armstrong, Growth and Partnerships Director at node operator LinkPool, believes that the purge will not significantly reduce DeFi exploits, as most losses come from off-chain signing and bridging attacks rather than ghost chains. In contrast, HashKey Group's Tim Sun sees the purge as a necessary step for the industry to improve security.
The issue of ghost chains has been highlighted by recent incidents, including the KelpDAO hack, which was made possible due to a single verifier signing off cross-chain messages. This vulnerability can be mitigated with more robust security measures, such as multi-verifier configurations.