Aave Faces $6 Billion Deposit Exodus After Kelp Hack Exposes DeFi Vulnerabilities
Aave witnessed a staggering $6.6 billion exodus, not due to a direct hack, but as a result of a vulnerability exposed by an attack on Kelp's bridge. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion. The AAVE token's value dropped 16% to $92, with daily fees surging to $1.99 million as liquidations swept through the weekend. Depositors fled due to Aave's unintended burden. Attackers had drained 116,500 rsETH from Kelp's bridge and used them as collateral on Aave V3 to borrow wrapped ether. On-chain trackers estimated the Aave-specific borrow to be around $196 million, with total positions across Aave, Compound, and Euler at approximately $236 million. Aave, the largest DeFi lending protocol, allows users to deposit crypto to earn yield, while others borrow against collateral. Kelp, a liquid restaking protocol, issues rsETH tokens, which some users posted as collateral on Aave. On Saturday, attackers exploited Kelp's cross-chain bridge, releasing 116,500 rsETH, worth about $292 million, to their control. They then deposited the stolen rsETH onto Aave V3 as collateral and borrowed wrapped ether against it. The concentration of Aave's loan book on Ethereum, with $14.24 billion of the $17.82 billion in outstanding borrows, exacerbated the damage. Aave's founder, Stani Kulechov, stated that the exploit was external and the protocol's contracts were not compromised. However, Aave's acceptance of liquid restaking tokens as collateral, which had their backing vanished due to a bridge exploit, puts depositors at risk. The incident highlights the fragility of the DeFi system, with the AAVE token price reflecting concerns over the Umbrella reserve's ability to cover the resulting deficit.