Cronje: DeFi shifting to for-profit teams, adds circuit breaker

Andre Cronje says many DeFi projects now run as for-profit teams with upgradeable contracts and off‑chain controls. Flying Tulip added a withdrawal circuit breaker after April exploits.

Andre Cronje, founder of Flying Tulip, said much of decentralized finance has moved from immutable public protocols to teams operating for-profit businesses that use upgradeable contracts, off‑chain infrastructure and active operational controls. Flying Tulip added a withdrawal circuit breaker this week after a series of exploits in April; the tool delays or queues withdrawals during abnormal outflows to give the team time to investigate and respond.

Cronje argued the security model for newer DeFi systems is no longer defined by deployed smart contract code alone. He pointed to proxy upgrades that allow contract logic to change after deployment, multisignature signers that approve actions, external infrastructure providers and administrative processes that can alter protocol behavior.

The circuit breaker implemented by Flying Tulip is intended as a temporary pause rather than a permanent blockade on withdrawals. The protocol’s system provides roughly six hours for the team to assess an unusual outflow; Cronje said smaller or less distributed teams might need 12 to 24 hours. He described the mechanism as a response window to investigate events, not as a way to prevent incidents outright.

In April, attacks on a decentralized exchange known as Drift Protocol and a restaking platform called Kelp produced estimated losses of about $280 million and $293 million, respectively. One episode affecting the rsETH token and interactions with Aave traced the vulnerability to off‑chain infrastructure and compromised signers rather than to bugs in deployed contract code.

Michael Egorov, founder of Curve Finance and Yield Basis, warned that many recent exploits have stemmed from centralization and off‑chain single points of failure rather than from smart contract errors. He cautioned that emergency controls such as circuit breakers can create new attack surfaces if they grant humans the authority to change code or block withdrawals; compromised signers could turn a safeguard into a drainer or a centralized freeze mechanism.

Both founders called for layered security. They recommended clear checks on who can upgrade contracts, formal approval processes, timelocks and distributed signing. Egorov said longer‑term designs should reduce human‑centric points of failure so systems can operate safely without manual intervention.

A bank research note from Standard Chartered described the April incidents as growing pains and highlighted more than $300 million raised by a DeFi coalition to recover funds and support affected projects. The note also cited planned protocol upgrades and coordination among projects, including changes to lending architectures, as steps aimed at reducing reliance on vulnerable components such as cross‑chain bridges.

Protocol teams and governance communities are weighing tradeoffs between emergency operational controls that provide time to respond and the goal of minimizing human control over live contracts. Options under consideration include refined access controls, stricter multisignature governance and protocol designs that limit the need for post‑deployment intervention.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author