Aave Faces $6 Billion Deposit Exodus After Kelp Hack Exposes DeFi Lender's Structural Vulnerabilities

Aave has witnessed a staggering $6.6 billion withdrawal, not due to a direct hack, but as a result of a vulnerability exposed by the Kelp hack. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion, with the AAVE token experiencing a 16% decline to $92 and daily fees surging to $1.99 million amidst widespread liquidations over the weekend. Depositors are fleeing due to Aave's unintentional acquisition of a significant liability. Following the theft of 116,500 rsETH from Kelp's bridge, the attackers utilized the stolen tokens as collateral on Aave V3 to borrow wrapped ether, resulting in an estimated $196 million in Aave-specific borrowing and approximately $236 million in total positions across Aave, Compound, and Euler. As the largest lending protocol in DeFi, Aave enables users to deposit cryptocurrency to earn yield, while others borrow against collateral. Kelp, a liquid restaking protocol, routes previously staked ether on Ethereum through a separate yield-generating system called EigenLayer, issuing a receipt token, rsETH. This rsETH is traded by users and, crucially, used as collateral on Aave to borrow against. On Saturday, attackers deceived Kelp's cross-chain bridge into releasing 116,500 rsETH, valued at approximately $292 million, to a controlled address. They then deposited the stolen rsETH onto Aave V3 as collateral, borrowing wrapped ether against it. Initially, Aave stated that the Umbrella reserve would cover any deficit, but later shifted to exploring paths to offset the deficit. The damage is concentrated due to Aave's loan book being predominantly based on Ethereum, with $14.24 billion of the $17.82 billion in outstanding borrows. The WETH pair, which dominates Aave's book, was directly impacted by the attack. Stani Kulechov, Aave's founder, emphasized that the exploit was external and the protocol's contracts were not compromised. However, Aave accepted a liquid restaking token as collateral, which lost its backing when the bridge it was on was exploited. Depositors are at risk of losing their funds either way. Liquid restaking tokens were widely accepted as collateral due to their yield and growing share of Ethereum's locked value, but their risk models did not account for a scenario where the collateral's value drops to zero due to a bridge exploit on an unrelated chain. The current token price reflects concerns over whether the Umbrella reserve is sufficient to cover the resulting hole and whether stkAAVE holders, who back the reserve, will absorb the loss.