Via cryptonews.com
Veda CEO says key management, not smart contract bugs, is the real threat to onchain vaults
Sun Raghupathi argues that operational security now matters more than code audits as DeFi vaults handle billions in deposits
The crypto industry has spent years obsessing over smart contract exploits. Sun Raghupathi, CEO of onchain vault infrastructure provider Veda, thinks it’s time to update the threat model. In his view, the biggest risk facing onchain vaults today isn’t a rogue line of Solidity. It’s who holds the keys.
Raghupathi’s argument is straightforward: as smart contract code matures and gets battle-tested through repeated audits and real-world usage, the attack surface shifts. The weakest link is increasingly the humans and processes managing access controls, not the contracts themselves.
From code exploits to operational failures
But Raghupathi is pointing to a different pattern. Several high-profile incidents in recent memory didn’t involve exploiting a vulnerability in a protocol’s smart contracts at all. They involved compromised private keys, insider threats, or sloppy operational security that gave attackers a backdoor into systems that were technically sound.
Veda, founded in 2024, has routed more than $16 billion through its vault infrastructure without a reported security incident on its smart contracts.
Veda’s growing footprint
Veda builds standardized infrastructure that lets developers and institutions create and distribute yield products with built-in risk and compliance controls.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Its most prominent client is Kraken, whose Earn vaults run on Veda’s infrastructure. Those vaults alone have accumulated more than $600 million in deposits, with over $100 million in inflows arriving since June 2025. The firm has also attracted more than 80,000 users across its vault products and closed an $18 million funding round led by CoinFund in June 2025.
Why this matters for institutional DeFi
A hedge fund or asset manager evaluating an onchain yield product isn’t just going to read the smart contract audit report. They’re going to ask who has admin keys, how those keys are stored, what multisig configurations are in place, and what happens if a key holder goes rogue or gets compromised.
Veda’s approach of integrating compliance and risk controls directly into its vault infrastructure appears designed to answer exactly those questions. The $600 million sitting in Kraken’s Earn vaults is evidence that this positioning is working. Kraken, as a regulated exchange, wouldn’t park that kind of capital on infrastructure it hadn’t vetted extensively, and inflows have continued accelerating with $100 million arriving since June 2025.