Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerability

Aave has experienced a massive exodus of $6.6 billion in deposits, not due to a direct hack, but as a result of a security breach in the Kelp protocol. The total value locked in Aave dropped from $26.4 billion to nearly $20 billion, with the AAVE token falling 16% to $92 and daily fees surging to $1.99 million amidst a wave of liquidations over the weekend. Depositors are fleeing due to Aave's unintended exposure to bad debt. When attackers drained 116,500 rsETH from Kelp's bridge, they used the stolen tokens as collateral on Aave V3 to borrow wrapped ether. On-chain data estimates the Aave-specific borrow to be around $196 million, with total positions across Aave, Compound, and Euler totaling $236 million. Aave, the largest DeFi lending protocol, allows users to deposit crypto to earn yield, while others borrow against collateral. Kelp, a liquid restaking protocol, had its cross-chain bridge exploited, resulting in the theft of 116,500 rsETH, valued at approximately $292 million. The stolen rsETH was then deposited onto Aave V3 as collateral to borrow wrapped ether. The attack has raised concerns about the concentration of Aave's loan book, with Ethereum holding $14.24 billion of the $17.82 billion in outstanding borrows, and WETH accounting for 39.49% of all loans on the protocol. Aave's founder, Stani Kulechov, stated that the exploit was external and did not compromise the protocol's contracts. However, the acceptance of liquid restaking tokens as collateral has exposed Aave to unforeseen risks. The incident has sparked worries about the fragility of the DeFi system, with the AAVE token price reflecting concerns over the Umbrella reserve's ability to cover the resulting deficit.