Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities
Aave has witnessed a staggering $6.6 billion withdrawal, not due to a direct hack, but rather as a consequence of a security breach in the Kelp bridge. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion, with the AAVE token experiencing a 16% decline to $92 and daily fees surging to $1.99 million amidst intense liquidations over the weekend. Depositors are fleeing due to Aave's unintended exposure to a hole created by the Kelp hack, where attackers drained 116,500 rsETH and used them as collateral to borrow wrapped ether on Aave V3, resulting in a potential bad debt of approximately $196 million. As the largest lending protocol in DeFi, Aave enables users to deposit crypto and earn yield, while others borrow against collateral. The Kelp protocol, which facilitates liquid restaking, was breached, allowing attackers to steal rsETH tokens and utilize them on Aave, highlighting the protocol's vulnerability to external exploits. Aave's loan book, spanning 22 chains, is heavily concentrated on Ethereum, with WETH being the dominant loan type, making it susceptible to such attacks. The incident has raised concerns about the fragility of the DeFi system, with the AAVE token price reflecting the uncertainty surrounding the Umbrella reserve's ability to cover the potential losses.