The history of cross-chain bridges getting hacked can basically be summed up in one sentence: if there's money in the pool, hackers are gonna show up.

Ronin got hit for 625 million, Wormhole was breached for 320 million, and Nomad lost 190 million. Each incident tells the same story: the funds locked in the bridge turned into a giant honeypot.

Alex's thread is about security, but what he really wants to highlight isn't 'we're doing security well'; it's a more fundamental issue: you shouldn't be fortifying the honeypot, you should make the honeypot disappear.

The 0-TVL structure of deBridge embodies this idea. The protocol locks no funds; users only express intent, and market makers cover the execution with their own capital.

No shared pool, no TVL, and when hackers come, they find the vault is empty. This flips the security logic of most projects on its head.

The industry still revolves around who has done more audits, who monitors faster, and who offers higher bounties, but all of this assumes 'the pool is definitely going to exist' and just slaps on patches.

Alex is spot on; audits and monitoring are downstream measures, and architecture is upstream. Of course, 0-TVL isn't without its costs. You need enough solvers willing to front the capital, and the market maker network has to be deep enough. This isn't a model every team can pull off.

But in terms of direction, removing 'things that need protection' from the protocol could be the biggest paradigm shift in DeFi security.

AI making attacks cheaper only solidifies this judgment.