2025 Crypto Lending Safety: Assessing $17.78B in CeFi Loans Risks & Security

7 min read

VerifiedX Explained: Building a Self-Custodial Ecosystem Around Bitcoin and Beyond

Back in 2022, the crypto lending sector faced a significant crisis, nearly leading to its collapse. Prominent platforms such as Celsius, BlockFi, and Voyager, which had assured users of their stability, disintegrated within a matter of months. This turmoil resulted in the disappearance of billions of dollars in user funds, severely undermining trust in centralized lending systems. Many observers believed the experiment in centralized finance (CeFi) was over. However, three years later, CeFi lending has made a subtle resurgence. The landscape is now characterized by fewer players, stricter regulations, and more cautious ambitions. Recent research from Galaxy indicates that the sector currently represents $17.78 billion in active loans, approximately 40% of the global crypto credit market. While this seems like a recovery, the lingering question remains: what level of control do users truly have when they entrust their crypto assets to these platforms?

Key Insights

– CeFi lending has revived to reach $17.78 billion in 2025, yet issues surrounding transparency and rehypothecation risks remain.
– Tether, Nexo, and Galaxy Digital are now major players, collectively dominating up to 89% of the CeFi lending market.
– Institutions are drawn to CeFi due to its regulatory transparency and quick transactions, but the lack of visibility raises systemic risk concerns.
– Platforms like CoinRabbit advocate for greater transparency by avoiding rehypothecation and ensuring all client funds are kept separate.

Revival of CeFi Lending

The recovery of CeFi lending began gradually but has since gained momentum. According to Galaxy’s Q2 2025 data, the total outstanding loans reached $44.25 billion, excluding collateralized debt positions (CDPs), and $53.09 billion when including them. These figures are approaching the record levels seen in 2021. Decentralized finance (DeFi) played a crucial role in this rebound, capturing nearly 60% of the market with $26.47 billion in active loans, marking an impressive 42% growth over the previous quarter. For example, Aave’s performance has been remarkable, with its cumulative deposits surpassing $3 trillion by August 2025, and active loans exceeding $29 billion, alongside a total value locked (TVL) above $40 billion. Users naturally gravitated towards platforms that offered transparency. In DeFi, on-chain visibility of transactions and collateral movements allows users to assess risk rather than assume it, thereby helping to restore confidence that CeFi has yet to fully regain. In contrast, CeFi has approached its recovery with caution. Following the 2022 crisis, only a few firms remained, redirecting their focus towards compliance, risk management, and enhancing brand credibility. This shift resulted in a smaller yet more resilient sector, which has seen a quarter-over-quarter growth rate of 14.66%, culminating in the current $17.78 billion figure. Nevertheless, even with this newfound discipline, old vulnerabilities persist. The practice of rehypothecation—where client collateral is reused—continues to be widespread. When platforms redeploy user assets for their own strategies, it amplifies overall exposure. In the event of a market downturn, this interconnectedness can lead to a domino effect of liquidations. While trust may be gradually reinstated, transparency has not yet caught up.

The New Landscape of Lenders

Today’s CeFi ecosystem is predominantly controlled by three entities: Tether, Nexo, and Galaxy Digital. Collectively, these firms hold a staggering 74-89% market share in centralized lending, depending on the source of the data. Specifically, Tether commands 57.02% with $10.14 billion in loans, followed by Nexo at 11% ($1.96 billion), and Galaxy Digital at 6.23% (approximately $1.11 billion). This level of market concentration qualifies as an oligopoly, as indicated by a Herfindahl-Hirschman Index ranging from 3,450 to 3,500. Such concentration creates potential risks; should a leading player face a liquidity issue, the entire market could experience a freeze within days. Furthermore, the lack of transparency in CeFi means users cannot verify loan books, collateral ratios, or internal protocols. This consolidation of power allows these major firms to dictate lending and deposit rates, potentially stifling competition and innovation. Smaller lenders find themselves in a challenging position; unable to compete with the larger firms’ scale, they must rely on speed and user experience, which shifts security from a baseline expectation to a selling point. This shift is ironic, given that the industry initially emerged from the promise of safety.

Lessons from the Past

The collapse of Celsius in June 2022 serves as a cautionary tale. At its peak, Celsius managed $20 billion in assets across 1.7 million accounts. The company failed due to fundamental flaws: rehypothecation, reckless pursuit of high yields, and inadequate liquidity planning. By lending customer deposits into long-term, illiquid projects while guaranteeing short-term withdrawals, Celsius’s model collapsed overnight when market conditions shifted. Alarmingly, many of the same structural weaknesses still persist in the current CeFi landscape. While lenders now emphasize compliance and caution, rehypothecation continues to be a common practice, often disclosed only in fine print. The concentration of the market does not diminish systemic risk; instead, it redistributes it among a smaller number of players. If another large lender repeats the mistakes of Celsius, the repercussions could be significantly magnified this time, given the reduced number of competitors to absorb the impact.

Institutional Preference for CeFi

Despite its inherent risks, CeFi continues to appeal to institutional investors. This attraction is driven by operational familiarity rather than emotional considerations. Institutions are accustomed to working with centralized counterparties and place high value on regulatory clarity, with Know Your Customer (KYC) and Anti-Money Laundering (AML) protocols integrated into every transaction. They rely on recognized custodians, such as BitGo and Zodia/Fireblocks, to protect their assets within licensed frameworks. Additionally, institutions favor flexible loan structures that are not yet possible with DeFi’s rigid smart contracts. Speed is crucial for these investors, who require swift execution to facilitate large transactions without delays caused by block confirmations. For corporate treasuries and hedge funds, CeFi mimics traditional finance, but with enhanced speed and yield potential. However, this perceived comfort can be deceptive. The same lack of transparency that drove retail users away from CeFi in 2022 still exists for institutional clients today.

User Expectations from CeFi

As the market landscape has evolved since the last crisis, user expectations have shifted dramatically. The emphasis has transitioned away from yield chasing towards securing access, speed, safety, and clarity. At the core of user concerns is security, with rehypothecation posing the greatest risk. This practice allows lenders such as Nexo, Salt Lending, Strike, and Ledn to openly state that they may reuse deposited assets. Conversely, some platforms, like CoinRabbit, have committed to avoiding rehypothecation entirely, maintaining a policy of keeping client funds separate and untouched. CoinRabbit emphasizes that this approach is not just a choice but a fundamental principle of trust. “The absence of rehypothecation is vital for the entire market,” the company notes. “User assets must remain secure.” This sentiment is echoed by clients, who increasingly prioritize asset segregation and transparent custody as essential requirements. Without these assurances, the credibility of CeFi could erode with each negative news story.

Speed and User Experience

DeFi platforms such as Aave and Compound can issue loans in seconds, while CeFi still struggles with average processing times ranging from 24 to 48 hours due to manual KYC checks and liquidity assessments. In rapidly changing markets, even a brief delay can mean the difference between profit and loss. For instance, CoinRabbit claims to have reduced issuance time to about ten minutes, providing nearly instant liquidity without sacrificing verification processes. While Strike has also enhanced its processing capabilities, many competitors remain hindered by outdated systems. In this environment, efficiency is no longer just a luxury for CeFi; it has become essential for survival. Users now correlate response times with credibility.

Challenges of Opacity and Lending Clarity

The lack of transparency remains a fundamental weakness within CeFi. Few platforms disclose critical information such as loan-to-value ratios, liquidation procedures, or fee structures. Before its downfall, BlockFi exemplified the pitfalls of failing to communicate changes in rates clearly. In stark contrast, DeFi platforms operate on a transparent, on-chain basis, making every transaction public and auditable. In CeFi, however, users must place their trust in press releases rather than verifiable code. This growing disparity in transparency leaves users increasingly impatient. Without open reporting, even minor fluctuations can trigger panic withdrawals. Individuals do not withdraw funds merely out of fear of losses; they withdraw because they lack visibility into the situation.

Predictability of Liquidations

Liquidation policies vary significantly among CeFi platforms, and this inconsistency often leaves users unprepared for sudden margin calls. Some borrowers have faced losses due to abrupt notifications with inadequate advance warning. Liquidation thresholds can differ widely, with some requiring 12-hour notices and others extending to 48 hours, resulting in uncertainty during volatile market conditions. Platforms like CoinRabbit are addressing this issue by enhancing communication. They employ multi-channel alerts via email, SMS, and Telegram, along with real-time monitoring for larger accounts. They also commit to contacting clients directly as risk thresholds are approached to minimize the occurrence of avoidable liquidations. While proactive oversight remains uncommon in CeFi, it is increasingly becoming an expectation among users.

Regulatory and Jurisdictional Risks

Regulation continues to pose a significant challenge for CeFi’s full recovery. The sector navigates a fragmented regulatory landscape, with different frameworks such as MiCA in Europe and SEC oversight in the U.S., each interpreting custody, lending, and digital assets differently. Complying with multiple jurisdictions is both costly and complex, favoring larger firms while disadvantaging smaller ones, leading to increased market consolidation. Some platforms fail to disclose vital information about their rehypothecation practices, leaving users uncertain about the status of their assets. This mixture of vague disclosures and inconsistent regulations makes the promise of stability in CeFi conditional. For users worldwide, the associated risks now depend as much on geographic location as on the specific platform utilized.

Implications of Market Concentration

The concentration within CeFi does more than restrict choices; it reshapes the entire market. Fewer participants result in diminished incentives for innovation, slower product development cycles, and a lack of pressure to enhance transparency. Limited innovation: Dominant players like Tether and Nexo see no reason to revamp profitable systems, while smaller firms lack the necessary capital to compete. Risk homogenization: Similar business models among leading lenders create correlated vulnerabilities. A liquidity crisis for one could expose others to identical risks. High entry barriers: The costs associated with regulation and capital reserves deter new entrants, decreasing diversity in operational models and risk tolerance. Restricted credit supply: Institutions seeking substantial liquidity have no viable alternatives, forcing them to rely on the same three providers, which can unilaterally adjust rates.

The Path Towards Safer CeFi

In summary, while the resurgence of CeFi is tangible, resilience does not equate to safety. The market appears healthier due to its reduced size, increased regulation, and numerical growth. However, these indicators obscure lingering structural issues. The ideal path for CeFi is to rebuild trust from the foundation up. This could involve eliminating rehypothecation, enforcing strict segregation of user assets, and adopting transparent lending metrics that reflect the clarity found in DeFi. It also necessitates the development of liquidation systems that prioritize client protection over surprise outcomes. CoinRabbit exemplifies a possible future: maintaining funds offline in cold storage, prohibiting collateral reuse, and ensuring real-time access to withdrawals. This model demonstrates that security and accessibility can coexist harmoniously. Conversely, many in the industry still view rehypothecation as essential for profitability. Until this perspective shifts, every market rally carries the potential for another downturn. CeFi has shown it can endure; the next challenge is to prove it is worthy of trust.

Frequently Asked Questions

Rehypothecation allows lending platforms to repurpose client collateral for additional yield generation. While this can enhance returns, it exposes customers to hidden risks if the platform’s investments falter, making asset withdrawals reliant on external liquidity. Once collateral is reused, users lose some control over their assets. DeFi platforms utilize public smart contracts, allowing visibility into all collateral, loans, and liquidations. In contrast, CeFi manages assets off-chain, preventing users from verifying how their funds are utilized, which diminishes accountability. The transparency of DeFi transactions inherently promotes better risk management practices. The high concentration and lack of clear risk management in CeFi render it more fragile, as a small number of platforms dominate the market, amplifying systemic risks. Disruptions at a leading provider can trigger broader liquidity crises across the sector. Yes, an increasing number of CeFi lenders are now focusing on fully segregating user assets, avoiding the reuse of client funds altogether. CoinRabbit is one such example, adhering to a policy that keeps collateral secure and untouched. This shift reflects a growing trend towards transparency and self-custody principles within centralized lending.

Stay on top of Crypto Trends

Subcribe to our newsletter to get the latest crypto news in your inbox