Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do institutions hesitate to use DeFi protocols…
Cyber Security

Why do institutions hesitate to use DeFi protocols directly instead of only holding digital assets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

Institutions hesitate because direct DeFi participation introduces smart contract risk, uncertain insurance coverage, and weaker regulatory clarity than traditional custody models. They also face greater accountability when managing other people’s money, which raises the bar for due diligence. For that reason, many institutions start with asset holding and only expand into DeFi once controls, oversight, and risk transfer mechanisms are stronger.

Why institutions stop at custody instead of touching DeFi directly

For an institution, “using DeFi” is not just a trade decision, it is an operating model decision. Direct protocol participation exposes the institution to smart contract failure, oracle and bridge dependency, and fast-moving governance or parameter changes that are harder to bound than a custody-only posture. It also creates a higher evidentiary burden for approvals, monitoring, and client accountability when the capital belongs to others.

The custody-first approach preserves optionality. Institutions can hold digital assets, then decide whether any protocol interaction is justified after they have mapped the contract risk, the operational controls, and the legal basis for acting on behalf of clients. That is why the debate is often less about “can we use DeFi?” and more about “can we justify the control and accountability model that direct use requires?”

That distinction matters because direct participation changes the risk surface in ways custody alone does not. A custody model concentrates risk in storage, segregation, and key management, while protocol use adds execution risk, on-chain failure modes, and dependence on code that may be difficult to unwind once deployed. For institutions, the practical question is whether those extra dependencies are material enough to outweigh the yield, access, or product-design benefit.

What actually changes when an institution goes on-chain

Direct DeFi use adds three material layers on top of simple asset holding. First, there is contract and protocol risk, including logic bugs, upgradeability surprises, governance capture, and integration assumptions that can fail under stress. Second, there is accountability risk, because asset managers, trustees, and fiduciaries need to explain why a particular protocol, pool, or routing path was acceptable at the time of use. Third, there is regulatory and legal uncertainty, especially where asset classification, custody obligations, disclosures, and client suitability vary by jurisdiction.

Institutions also face a control mismatch. Traditional custody models are built around segregated accounts, established counterparties, and documented recovery paths. DeFi execution can require wallet signing, real-time transaction approval, and dependency on external infrastructure such as RPC endpoints, bridges, oracles, and third-party front ends. Each of those adds a possible point of failure that can affect both losses and auditability.

For practitioners comparing protocol access with holding only, the operational issue is not whether one control is “better,” but whether the institution can bound blast radius. If the institution cannot reliably limit exposure per strategy, venue, or client mandate, direct participation tends to be treated as a premium-risk activity rather than a default operating posture. The broader the mandate, the more conservative the initial entry point usually becomes.

Risk and Threat Considerations

Direct DeFi exposure can fail in ways that custody-only holdings do not. Smart contract defects, oracle manipulation, bridge compromise, and governance attacks can convert an ordinary transaction into an irreversible loss event. For an institution, the issue is amplified by fiduciary duty and the need to show that the selected protocol, controls, and permissions were reasonable before the loss occurred.

Failure mechanism: A protocol dependency breaks, a contract behaves unexpectedly, or a connected service is compromised, and the institution has limited ability to reverse or contain the position once funds have been moved on-chain.

Impact: Losses can include direct asset loss, forced impairment, client claims, reporting complications, and a higher threshold for future approval of on-chain strategies.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.2 — Risk Management StrategyDeFi entry changes enterprise risk strategy and tolerance.
GV.4 — Cybersecurity Risk Management StrategyDirect protocol use introduces contract and operational risk needing formal treatment.
ID.RA — Risk AssessmentThe question centers on assessing contract, regulatory, and accountability risk.
Recommendation — Define DeFi participation limits through explicit risk appetite and governance approval. Align DeFi exposure decisions to documented cyber risk management criteria. Assess protocol, governance, and legal risks before direct on-chain use.
CIS Controls v86 — Access Control ManagementProtocol interaction depends on tightly bounded transaction and wallet access.
3 — Data ProtectionInstitutions need to protect signing material, transaction data, and client records.
Recommendation — Restrict DeFi transaction authority to approved users and use cases. Protect wallet secrets, signing workflows, and sensitive transaction artifacts.
NIST AI RMFGOVERN — GovernInstitutions need governance for AI-like autonomous or algorithmic decision workflows in DeFi operations.
MAP — MapProtocol use requires mapping business purpose, stakeholders, and risk context.
Recommendation — Establish governance for any automated or model-assisted DeFi decision process. Map DeFi use cases, dependencies, and accountability before deployment.

Practitioner Guidance

What to verify: Before any direct DeFi use, verify whether the institution can evidence protocol due diligence, pre-trade approval, transaction-level controls, and post-trade monitoring. The minimum bar is not just “did we understand the protocol,” but “can we prove who approved the risk, what limits applied, and how exceptions are handled.”

Decision rule: If the activity cannot be bounded by mandate, liquidity profile, and counterparty analysis, treat it as an experimental or restricted strategy rather than a routine treasury function. If the institution is managing client money, require a stronger review standard than would be used for proprietary capital.

Practitioner takeaway: Institutions usually hesitate because direct DeFi use converts a holding decision into an execution, governance, and accountability problem, so adoption should follow control maturity, not precede it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org