Four of the ten largest DeFi lending venues hold enough reserves for an average year. Coverage ranges from 1.9x at Venus Core Pool to 7x at Compound V3, yet reaches roughly 5% of the capital needed in a 1-in-1000 year. The asymmetry remains after the two checks that undo much of the paper: changing the severity family and changing the confidence level. Its 18%-of-TVL capital estimate does not.

The paper's setup

DeFi earn products, including lending-pool supply positions, DEX liquidity provision and yield vaults, resemble deposits and pay a yield. Suppliers bear operational risk in the Basel sense: contract exploits, rugpulls, oracle manipulation and deployment errors. Bundi prices that loss process in a market where protocols have no capital requirement. When a protocol holds no reserve, depositors carry the residual risk and receive only the supply yield above the risk-free rate as compensation.

The framing comes from the bank market-discipline channel in Flannery and in Egan, Hortaçsu and Matvos, where uninsured creditors demand a spread for institutional risk. Bundi treats the protocol buffer and the depositor premium as alternative ways to fund the same tail, then asks whether either one is large enough.

His yardstick begins with seven public hack feeds: DefiLlama, rekt.news, DeFiHackLabs, kismp123, BlockSec, de.fi (4,030 raw records) and SlowMist (2,100). Deduplication has two passes. The first clusters names inside a 21-day window. The second matches events on the same date when reported losses are within 10%, after which each loss becomes the median across sources.

Every retained event receives a DeFi sub-sector label and a Basel Level-1 event type. The latter is the banking taxonomy for loss causes, covering internal fraud, external fraud, client and product practices, business disruption and execution errors. The two categories without an on-chain analogue are removed. From 2020-02-11 through 2026-05-29, the resulting sample contains 1,075 depositor-facing events and USD 9.45B in gross losses. Mean event loss is USD 8.79m, the median is USD 0.50m, and the maximum is USD 624m from Ronin. Cross-source confirmation exists for half the events (536). I have seen no equal to this dataset in the DeFi-security literature, and it is the paper's strongest contribution.

Bundi then applies a textbook loss-distribution approach by sector: peaks-over-threshold GPD severity, negative-binomial monthly counts and 200,000 simulated years. Each simulated event is capped at the largest single-protocol exposure for its sector. The reported output is VaR at 99.9% as a share of trailing-365-day TVL.

Lending requires 18.0%, DEX 14.1%, Yield 15.3%, Stablecoin 16.1% and Bridge 32.5%. Measured against the Lending estimate, the four disclosed buffers fund 2% at Venus through 9% at Aave V3 of their allocated tail. Across the six unbuffered venues, the average supply-yield premium is +54 bps over the 3.70% T-bill. Estimated per-protocol tail-risk premiums span 3,905 to 8,131 bps.

How Lending reaches 18%

The first fault line is the severity family. Bundi compares GPD with lognormal on the same exceedances using the Vuong test. All seven sectors produce a tie: |V| is at most 1.37 against a 5% critical value of 1.96, while p is at least 0.17. He reports the tie plainly, then keeps the GPD.

That choice bears directly on the headline. The banking study he cites, by de Fontnouvelle and co-authors, found aggregate VaR changing by an order of magnitude across severity choices. Bundi's central claim also says the buffers miss the target by an order of magnitude. Model uncertainty and the claimed funding gap therefore occupy the same scale.

The quantile creates the next break. Moving from 99.9% to 99% lowers Lending capital from 18% of TVL to 5%. Mean coverage among buffered venues rises from 5% to 31%. Bundi includes this sensitivity and argues that, even at 99%, the buffers cover only about a third of a requirement that remains an order of magnitude above bank operational-risk capital. Fair enough. A three-to-one shortfall makes a materially different claim from the twenty-to-one shortfall printed in the abstract.

Very few observations support the Lending tail. Sector exceedance counts range from 20 to 51. For Lending, the bootstrap CI around xi-hat of 0.75 is [-0.28, +1.50]. Removing the single largest event lowers the estimate from 0.75 to 0.35. Its bootstrap IQR for VaR runs from [3.2%, 18.9%] of TVL, and the point estimate lands at the upper edge.

The 18% estimate comes mainly from the largest venue's at-risk funds and the exposure cap, rather than unusual tail thickness. Across the four core sectors, xi falls in [0.61, 0.75]. Moscadelli's banking band is heavier at [0.85, 1.39]. The point estimates remain below that band, although their confidence intervals overlap it and the Lending CI contains the whole range. Bridge (1.87), Derivatives (1.45) and Other (1.58) carry the heavy tails. Each exceeds the infinite-mean boundary at xi = 1, leaving the cap to hold the estimates together.

Without the cap, Bridge jumps from 32.5% to 67,326% of TVL.

Bundi describes this as the same instability that led Basel to retire the Advanced Measurement Approach, its internal-model option, in 2017.

Fluid holds up the average

Buffered venues show a median premium of -86 bps, compared with +39 bps for unbuffered venues. The gap is 125 bps. A one-sided Mann-Whitney test across four buffered and six unbuffered venues returns p = 0.01. Extending the test to all 19 lending venues above USD 100m in net TVL preserves the direction, with p = 0.03.

Composition matters. The +54 bps unbuffered average combines Fluid at +257, Jupiter at +94 and Morpho at +90 with JustLend at -28, Euler at -11 and Kamino at -79. Once Fluid is removed, that average drops from +54 bps to +13 bps. Fluid determines this average alone. The median difference and rank-based p = 0.01 remain unchanged. The paper also says supply APY includes incentives, and Bundi argues that yields below the USD 100m cutoff are driven by airdrops rather than market clearing.

Both group medians hover below or near zero. The finding is therefore that large, established venues pay 86 bps below the T-bill, while smaller venues pay 39 bps above it. Bundi acknowledges the confound in his limitations. Buffered venues are also the largest and oldest, so brand may explain the spread. The reduced-form proxy also absorbs utilization and rate governance, while a controlled panel regression is deferred to future work.

On that evidence, the claim that markets discriminate in the right direction asks too much of a single June 2026 cross-section covering ten venues. The tail-coverage finding avoids that inference.

The finding worth keeping

The shape of the failure matters more than the estimated magnitude. Each of the four disclosed buffers covers expected annual loss at least once: Venus 187%, Aave V3 475% and Compound V3 700%. Tail coverage stays between 2% and 9%. The deficiency belongs squarely to the tail.

That result survives a switch between GPD and lognormal, as well as movement away from the 99.9% quantile. Code audits also leave the internal-fraud and deployment-error categories untouched, and those categories account for 26% of Lending losses. The case for disclosure stands without the more fragile capital estimate.

We could not test any of these claims with our own data. Doing so requires protocol-level histories for supply APY, TVL and governance reserve balances, together with the labeled incident set. Our crypto coverage consists of spot price series. Trading tokens would examine a different mechanism because the premium studied here appears in supply yields. A related mismatch arose in our note on the correlation rotation premium, where no traded instrument spanned the priced object.

A panel with venue fixed effects and utilization controls could change my view of the yield result, provided the buffer coefficient survives after absorbing size and age. Bundi has already assembled the loss dataset. The yield panel still needs collection because the paper's yields, TVL and buffers are a June 2026 snapshot of ten venues, with the extension reaching only 19.