Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities
Aave has experienced a significant exodus of deposits, with $6.6 billion withdrawn, not due to a direct hack on the protocol itself, but rather as a consequence of a security breach in Kelp's bridge. This breach led to the drainage of 116,500 rsETH, which was then used as collateral on Aave V3 to borrow wrapped ether, resulting in a substantial loss for the protocol. The AAVE token price dropped by 16% to $92, while daily fees surged to $1.99 million amidst a wave of liquidations over the weekend. The total value locked in Aave decreased from $26.4 billion on April 18 to approximately $20 billion by Sunday morning, according to DefiLlama. The hackers' ability to exploit Kelp's bridge and utilize the stolen rsETH on Aave highlights the potential risks associated with the use of liquid restaking tokens as collateral. Aave, as the largest lending protocol in DeFi, allows users to deposit cryptocurrency to earn yields, while others borrow against collateral. The concentration of Aave's loan book, with Ethereum holding $14.24 billion of the $17.82 billion in outstanding borrows, and WETH accounting for 39.49% of all loans, exacerbates the impact of the attack. The founder of Aave, Stani Kulechov, has stated that the exploit was external and did not compromise the protocol's contracts. However, the acceptance of liquid restaking tokens as collateral has introduced a vulnerability, as the backing of these tokens can vanish if a bridge on an unrelated chain is exploited. This incident has sparked concerns regarding the fragility of the DeFi system, with the token price now reflecting the uncertainty surrounding the ability of the Umbrella reserve to cover the resulting deficit.