Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities
Aave has witnessed a massive exodus of $6.6 billion in deposits, not due to a direct hack, but as a result of a vulnerability in its ecosystem. The protocol's total value locked plummeted from $26.4 billion on April 18 to approximately $20 billion by Sunday morning, according to DefiLlama. This significant decline was accompanied by a 16% drop in the AAVE token to $92 and a spike in daily fees to $1.99 million, as liquidations swept through the weekend. Depositors are fleeing because Aave is now carrying a debt it did not create. Attackers had drained 116,500 rsETH from Kelp's bridge on Saturday, which they then used as collateral on Aave V3 to borrow wrapped ether. On-chain trackers estimate the Aave-specific borrow to be around $196 million, with total positions across Aave, Compound, and Euler totaling approximately $236 million. Aave, as the largest lending protocol in DeFi, allows users to deposit cryptocurrency to earn yields, while others borrow against collateral. Kelp, a liquid restaking protocol, takes ether already staked on Ethereum and routes it through EigenLayer, issuing an rsETH receipt token in exchange. This rsETH is tradable and was used by some users as collateral on Aave to borrow against. On Saturday, attackers exploited Kelp's cross-chain bridge, tricking it into releasing 116,500 rsETH, worth about $292 million, to a controlled address. They then deposited this stolen rsETH onto Aave V3 as collateral and borrowed wrapped ether against it. Aave initially stated that the Umbrella reserve would cover any deficit but later softened its stance to exploring paths to offset the deficit. The damage is concentrated because Aave's loan book, spanning 22 chains, has a significant portion of its outstanding borrows on Ethereum, with WETH making up 39.49% of all loans. Stani Kulechov, Aave's founder, noted that the exploit was external and the protocol's contracts were not compromised. However, Aave's acceptance of a liquid restaking token as collateral, which had its backing vanish due to a bridge exploit outside Aave's control, puts depositors at risk. The risk models for such tokens, whitelisted across major lending protocols for their yield and growing share of Ethereum's locked value, did not account for a scenario where the collateral's value drops to zero due to an external bridge exploit. As trader Altcoin Sherpa pointed out, AAVE's contagion risk highlights the fragility of the entire DeFi system. The current token price reflects concerns over whether the Umbrella reserve is sufficient to cover the resulting hole and whether stkAAVE holders backing this reserve will absorb the loss.