DeFi lending protocols processed an estimated $13 billion in deposit outflows over 48 hours in April 2026 after the KelpDAO bridge exploit exposed structural fragility in the collateralized-debt-position (CDP) model that underpins the sector. On June 1, Ethereum co-founder Vitalik Buterin publish...
"Real-time oracles can only rely on a small number of automated actors watching live price feeds, and they leave no room for dispute resolution." — Vitalik Buterin, Co-founder, Ethereum
DeFi lending protocols processed an estimated $13 billion in deposit outflows over 48 hours in April 2026 after the KelpDAO bridge exploit exposed structural fragility in the collateralized-debt-position (CDP) model that underpins the sector. On June 1, Ethereum co-founder Vitalik Buterin published a research proposal on ethresearch.ch to replace CDPs with an options-based architecture that eliminates forced liquidations entirely. Within 10 days, at least two teams had shipped working code, including testnet exchange Cleave, which bills itself as "DeFi's third pillar alongside Uniswap for spot and Hyperliquid for perpetuals."
The proposal arrives at a specific moment. Combined DeFi TVL across six major chains stood at $57.9 billion as of June 23, according to DefiLlama, down from roughly $99.5 billion before the April crisis. Aave, the sector's largest lender, saw its TVL fall 44% during April. The question Buterin's model poses is not theoretical: can DeFi lending be rebuilt without the liquidation cascades that periodically drain billions from the ecosystem?
The CDP model works as follows: a user deposits collateral (typically ETH), borrows against it (typically a stablecoin), and faces forced liquidation if the collateral-to-debt ratio falls below a protocol-defined threshold. The mechanism is designed to keep lending protocols solvent. In practice, it produces cascading failures during sharp market moves.
The April 2026 KelpDAO incident offers the clearest recent case study. A $292 million LayerZero bridge exploit, attributed by Quantstamp to North Korea's Lazarus Group, created unbacked rsETH collateral on Aave. The stolen assets were deposited as collateral and used to borrow funds, generating roughly $196 million in bad debt on the sector's largest lender. Over the following 48 hours, depositors pulled $8.45 billion from Aave, according to DefiLlama data. Pool utilization for ETH, USDT, and USDC hit 100%, trapping remaining depositors. Those stranded users then borrowed approximately $300 million against their own locked deposits at steep losses — a textbook bank run on decentralized rails.
Total DeFi TVL fell from $99.5 billion to $86.3 billion in two days, according to DefiLlama. Binance Research tallied more than 20 exploits across April 2026, the highest monthly attack count on record.
Even routine market volatility triggers damage. In March 2026, a misconfigured parameter in Aave's Collateral Asset Protection Oracle (CAPO), an external risk management tool, erroneously flagged positions for liquidation, producing a $27 million cascade. Aave founder Stani Kulechov attributed the incident to "third-party dependencies that are related to more traditional security."
The pattern is consistent across DeFi's history. Flash loan attacks constituted 58% of total DeFi losses in 2025, according to Immunefi. Oracle manipulation accounted for 31% of early-2025 losses. The liquidation mechanism, designed as a safety valve, functions as an amplifier during stress events.
Buterin's June 1 research post, titled "Building index-tracking assets on top of options instead of debt," proposes replacing the CDP architecture with a structure rooted in options contracts. The core claim: by eliminating debt and collateral ratios from the system, forced liquidation becomes structurally impossible.
In his model, one ETH is split into two paired claims — designated P (positive/upside) and N (negative/downside) — that always sum back to one ETH regardless of price movement. Because the two payoffs are complementary, no position can become undercollateralized. There is no debt. There is no margin call. There is no liquidation trigger.
At the end of a set maturity period, an oracle determines the final price, and payouts are distributed accordingly. The P holder receives exposure to price appreciation above a strike. The N holder receives a floor return. Both claims are fully backed by the underlying ETH at all times.
This is structurally distinct from perpetual futures or CDP-based synthetics. The closest analogy in traditional finance is a covered call paired with a cash-secured put — two instruments whose combined payoffs replicate the underlying asset with no net leverage.
Consider one ETH worth $4,000 at inception, with a maturity of 30 days and a strike price of $4,000:
P + N always equals ETH_final. The vault holds 1 ETH throughout. No external collateral is needed. No ratio can breach a threshold because there is no ratio — the system is fully reserved by construction.
Users seeking leveraged upside buy P tokens. Users seeking dollar-denominated yield sell their P tokens and hold N tokens, which behave like a short-dated principal-protected note. The N token is not a stablecoin, but its payoff profile — capped upside, protected downside — resembles one within the maturity window.
The proposal's second structural change may prove more consequential than the first. CDP-based protocols require real-time price oracles to monitor collateral ratios and trigger liquidations. These oracles are a persistent attack surface. OWASP ranked oracle manipulation as the second most damaging smart contract vulnerability in 2025.
Buterin's model settles once, at maturity. This means the system does not need continuous price feeds. It can use what he calls "slow oracles" — mechanisms resembling prediction market resolution, where prices are established through a dispute period rather than a live feed.
According to Buterin's research post, slow oracles "leave room for dispute resolution and verification" rather than requiring instant price accuracy. The April 2026 Polymarket incident, where a trader allegedly extracted $34,000 by manipulating a Paris weather sensor with a hair dryer, illustrated the fragility of real-time oracle systems even outside DeFi lending.
The trade-off is temporal: users cannot exit positions instantly. They must wait for maturity or trade their P/N tokens on secondary markets. This introduces different risks — notably liquidity risk and basis risk — but eliminates the specific failure mode of oracle-triggered liquidation cascades.
By June 11, ten days after publication, multiple developer teams had shipped working implementations. The development velocity suggests the idea addresses a recognized structural need.
Cleave is the most visible implementation. Operating on testnet at testnet.cleave.market, it splits ETH into a "cash half" and an "upside half" with one-click Earn and Boost products. Settlement uses a median of three Uniswap time-weighted average prices (TWAPs), removing dependency on external oracle infrastructure. Cleave describes its system as offering "no margin, no funding, and nothing to liquidate."
A separate unnamed team deployed a physically settled P/N construction live on Base (Coinbase's Layer 2 network), supporting full lifecycle operations: minting paired claims from WETH, transferring claims between parties, exercising against USDC strike prices, and settling vaults through underlying asset movement. The Base deployment removes the oracle from the critical settlement path entirely by moving underlying assets rather than reading prices.
Buterin has urged caution on mainnet deployment. Per his forum comments: "Anything moving toward mainnet should be formally verified — mathematically checked to behave as specified — before it handles real funds."
The proposal has drawn specific technical criticism. Ben Lilly, analyst at Brownstone Research, identified the maturity date as the core design limitation in a June 15 analysis. CDP-based lending allows users to maintain positions indefinitely — a borrower deposits ETH, draws a stablecoin loan, and holds as long as the collateral ratio holds. Buterin's model requires borrowers to "roll into a fresh contract every cycle, which means slippage and no set-it-and-forget-it mode," according to Lilly.
This is a material constraint. Rolling options positions incurs transaction costs (gas fees, spread, potential slippage) at every expiration. For retail users on mainnet Ethereum, where gas fees averaged $2-5 per transaction in June 2026 according to Etherscan, frequent rolls could erode returns on smaller positions.
Lilly also flagged the user experience gap: "Most borrowers don't understand strikes, expirations, and rolls — they simply want collateral-pledging and stablecoin-borrowing buttons." Abstracting options mechanics into a simple interface is a design challenge that DeFi options protocols have historically struggled to solve; the on-chain options market remains a fraction of DeFi lending's $57.9 billion TVL.
Buterin acknowledged this limitation in his original post, noting that "it remains unclear whether those adjustments can be made cheaply and efficiently enough to avoid excessive trading costs or slippage." He also noted the model is "not suitable for accounting stablecoins, where price drift creates problems that the options structure cannot absorb cleanly."
The proposal addresses barriers that institutional risk committees have flagged repeatedly. The April 2026 Aave crisis — where $8.45 billion exited the protocol in 48 hours — is precisely the contagion scenario that compliance teams model when evaluating on-chain credit exposure.
A system where positions cannot be liquidated by construction eliminates the specific cascade risk that caused the April drawdown. The slow oracle design reduces manipulation surface. Full reserve backing by underlying assets (rather than fluctuating collateral ratios) simplifies the risk disclosure that regulated entities require.
Aave's own response to the April crisis points toward similar structural conclusions. Under its forthcoming V4 architecture, a modular "hub-and-spoke" system will replace traditional token pooling, enabling the core protocol to levy localized risk premiums and freeze specific collateral lines before contagion reaches primary reserves. As Kulechov stated at a June conference: "When you have a completely auditable and public system, anyone can actually inspect the code and also do different kinds of risk analysis based on that. I think that is the key to building resilient software."
The approaches are different — Aave V4 retains CDPs but adds isolation; Buterin's model removes CDPs entirely — but both recognize that the current architecture does not contain contagion adequately.
The options-based DeFi model does not solve every problem that CDP lending addresses. It introduces maturity risk, roll costs, and user complexity. It cannot replace stablecoins backed by debt positions. The on-chain options market is nascent and illiquid relative to lending.
What it does is remove, by construction, the specific failure mode that drained $13 billion from DeFi in April 2026. Forced liquidation cascades are a structural feature of the CDP model — not a bug, not a misconfiguration, but an inherent consequence of maintaining collateral ratios with real-time oracles during periods of stress.
The speed of developer adoption — testnet to live deployment in under two weeks — indicates the DeFi development community views liquidation risk as a top-tier structural problem rather than a theoretical concern. Whether the options-based model can achieve the capital efficiency and user simplicity required for mainstream adoption remains unproven. The code exists. The economics are under stress test. The question is whether DeFi users will accept maturity constraints in exchange for the elimination of liquidation risk.