Key Takeaways
A new wave of banking startups is trying to bridge the gap between crypto and traditional finance, promising faster payments and smoother interoperability along the way.
Erebor is one of them — a stablecoin-powered bank backed by Palantir’s Joe Lonsdale and Oculus founder Palmer Luckey. It’s betting that blockchain rails and digital dollars can rewire how banking works.
But not everyone’s ready to buy the hype. Mitchell Amador, CEO of Web3 security firm Immunefi, sees the potential, but also some serious risks.
He’s warning that blending crypto infrastructure with legacy systems could create vulnerabilities we’re not fully prepared for.
According to Amador, Erebor’s approach, while innovative, introduces fresh layers of risk.
“If they’re truly building on blockchain rails with stablecoins as their primary assets—which is the natural evolution I see for fintech—then this represents a huge improvement over traditional neobanks,” said Amador.
“Being blockchain-native means that every transaction, every account balance, and every financial product is interoperable with the broader DeFi ecosystem,” the exec added.
That interoperability, he said, could unlock unprecedented speed and transparency. But it also exposes new vulnerabilities—attack surfaces that legacy systems never had to contend with.
Amador warns that relying entirely on stablecoins exposes Erebor to a deeper web of technical dependencies.
“When you build your entire banking infrastructure on stablecoins, you’re inheriting all the risks of those underlying protocols,” he told CCN.
“If there’s a smart contract vulnerability or an issue with the underlying bridge for a major stablecoin, it could compromise your entire bank,” Amador highlighted.
He points to the collapse of Terra-Luna, which wiped out $40 billion in value, as a cautionary tale.
At Immunefi, Amador’s team has helped avert over $25 billion in damages through its bug bounty platform.
Many of the most critical vulnerabilities involved cross-chain bridges, one of the foundational components of stablecoin interoperability.
While public codebases may offer transparency, they also come with exposure. “Smart contract vulnerabilities can be exploited instantly and irreversibly,” Amador noted.
“The attack surface includes not just your smart contracts but every protocol you interact with, every bridge you use, and every stablecoin you support.”
The security calculus is shifting in this new model. “The average hack costs $16 million, but a critical bug bounty might cost you $1-2 million,” Amador said.
For stablecoin banks like Erebor to succeed, Amador emphasizes the need for structured security incentives and real-time monitoring.
“Establishing a robust security framework starts with a well-structured bug bounty program,” he said. “We recommend that bounties for critical vulnerabilities scale up to 10% of the funds at risk.”
He said proactive tools like Safe Harbor agreements—which protect ethical hackers during live exploits—and anomaly detection systems are also key to building resilience.
Amador also criticized underfunded security programs. “We’re already seeing the consequences of misaligned white-hat incentives, as evident in the Cork Protocol breach, where a $100,000 bounty sat alongside $12 million in risk. That’s not security, that’s optics.”
Even with rigorous defenses, systemic fragility remains a risk.
“With stablecoins, there needs to be monitoring of the underlying collateral, proper key management for treasury operations, and, most critically, an understanding of the potential cascade effects,” Amador said.
He warns that a single failure can create cross-protocol liquidity shocks. Platforms need to implement proper circuit breakers or pause mechanisms.
Amador believes the transparent nature of blockchain transactions may work in stablecoin banks’ favor as regulators increase scrutiny.
“Stablecoin-based banking offers unprecedented transparency because every transaction is on-chain and auditable,” he said.
However, transparency challenges conventional financial oversight. “The key is to be proactive with regulators and demonstrate that their security practices exceed traditional banking standards,” he added.
Ultimately, Erebor’s long-term success may hinge less on technology than on execution.
“Never assume your code is bug-free,” Amador cautioned. “Hacked projects typically lose 3 months recovering and see sustained price depression for at least 6 months.”
He urged the team behind Erebor not to rush growth: “Have a clear incident response plan and ensure you can intervene or pause operations if needed.”
As stablecoin banking pushes into uncharted territory, Amador’s message to fintech builders is simple: security must evolve as quickly as the innovation it protects.