Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities

Aave has witnessed a staggering $6.6 billion exodus, not due to a direct hack, but rather a consequence of the Kelp bridge exploit. The protocol's total value locked plummeted from $26.4 billion to approximately $20 billion, with the AAVE token shedding 16% to $92 and daily fees surging to $1.99 million amidst a flurry of liquidations. Depositors are fleeing as Aave grapples with a hole it did not create. Attackers drained 116,500 rsETH from Kelp's bridge, leveraging the stolen tokens as collateral on Aave V3 to borrow wrapped ether. On-chain trackers estimate the Aave-specific borrow at around $196 million, with total positions across Aave, Compound, and Euler nearing $236 million. As the largest lending protocol in DeFi, Aave enables users to deposit crypto for yield, while others borrow against collateral. However, the recent Kelp hack has exposed a critical vulnerability, with the stolen rsETH being used as collateral to borrow against. Aave initially stated that the Umbrella reserve would cover any deficit, but later softened its stance to 'exploring paths to offset the deficit.' The concentration of loans on Ethereum, with $14.24 billion of the $17.82 billion in outstanding borrows, has exacerbated the damage. Stani Kulechov, Aave's founder, emphasized that the exploit was external and the protocol's contracts were not compromised. Nevertheless, Aave's acceptance of liquid restaking tokens as collateral has left depositors vulnerable. The risk models had priced these tokens as if they would maintain their peg under normal conditions, but failed to account for a scenario where the collateral's value evaporates due to a bridge exploit on an unrelated chain. The token price now reflects the market's attempt to gauge whether the Umbrella reserve is sufficient to cover the resulting hole and whether stkAAVE holders will bear the loss.