Sunand Raghupathi, the founder and CEO of Veda, wants DeFi users to stop treating vaults like they’re FDIC-insured checking accounts. His core message is blunt: onchain vaults are structurally closer to hedge funds than savings products, and the sooner users internalize that, the fewer people get hurt.
The warning comes at a time when vault infrastructure is quietly becoming the backbone of institutional DeFi. Veda’s own vaults power Kraken’s DeFi Earn product, which has pulled in over $600 million in deposits with more than $100 million in inflows since mid-2025. That kind of capital flow makes the “is this safe?” question considerably more expensive to get wrong.
The risk model has shifted
Raghupathi’s argument centers on a subtle but important evolution in where DeFi risk actually lives. For years, the nightmare scenario was a smart contract exploit: a bug in the code that lets an attacker drain a protocol overnight. That hasn’t disappeared, but it’s no longer the primary threat vector for well-audited vault systems.
Instead, the risks have migrated to the operational layer. Think key management, multisig governance setups, and the human decisions around how strategies get deployed and modified. The more relevant questions involve who controls the keys, how governance decisions get made, and what safeguards exist against a rogue operator or compromised signer.






