Until April 17, lending stablecoins on Aave yielded 2.32% APY, despite the Federal Reserve's overnight rate being 3.64%. This discrepancy implied that the market viewed an unregulated, open-source smart contract as a lower credit risk than the US Treasury. However, this mispricing was corrected within 48 hours. The catalyst for this change was an exploit on Kelp DAO's LayerZero-powered cross-chain bridge, which led to the minting of unbacked rsETH tokens worth around $292 million.

These tokens were used as collateral on Aave, resulting in a structural shortfall. The incident report acknowledged that the protocol functioned as designed, but the configuration made the exploit possible. The contagion was instantaneous, with DeFi protocols being interoperable by design. Roughly 20% of Aave's historical borrow volume came from recursive leverage, and within 48 hours, $6-10 billion in net outflows left Aave.

Utilization on WETH, USDT, and USDC pools hit 100%, and depositors couldn't withdraw, while borrowers couldn't source stablecoin liquidity. Rates responded accordingly, with Aave stablecoin deposit APYs increasing from 3-6% pre-exploit to 13.4% within two days.

The incident highlights the lack of bankruptcy law within DeFi protocols, meaning that there is no process for recovery, and no one to hold accountable. This has direct consequences for risk sizing, as the total loss can be estimated, but the distribution of losses cannot be predicted.

DeFi is not going away, but the architecture carries a premium over regulated equivalents, and institutional allocators should take the signal seriously when sizing DeFi exposure for the coming year.