Aave Faces $6 Billion Deposit Exodus After Kelp Hack Exposes DeFi Lender's Vulnerability

Aave has witnessed a staggering $6.6 billion withdrawal, not due to a direct hack but as a result of an external exploit. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion, with the AAVE token experiencing a 16% decline to $92 and daily fees surging to $1.99 million amidst widespread liquidations over the weekend. Depositors are fleeing due to Aave's unforeseen exposure to a hole not of its creation. Attackers drained 116,500 rsETH from Kelp's bridge, using the stolen tokens as collateral on Aave V3 to borrow wrapped ether. On-chain data indicates Aave-specific borrowings amount to roughly $196 million, with total positions across Aave, Compound, and Euler nearing $236 million. As the largest DeFi lending protocol, Aave enables users to deposit crypto for yield while others borrow against collateral. Kelp, a liquid restaking protocol, issues rsETH tokens, which some users posted as collateral on Aave. The rsETH tokens were stolen from Kelp's cross-chain bridge and then used on Aave, leading to a significant deficit. Initially, Aave stated the Umbrella reserve would cover any shortfall, but later shifted to exploring paths to offset the deficit. The concentration of Aave's loan book on Ethereum, with $14.24 billion of $17.82 billion in outstanding borrows, exacerbates the issue. Founder Stani Kulechov confirmed the exploit was external, but Aave's acceptance of liquid restaking tokens as collateral has introduced unforeseen risk. These tokens were whitelisted across major lending protocols due to their yield and growing share of Ethereum's locked value, but risk models failed to account for a scenario where the collateral's value evaporates due to an external bridge exploit. The incident highlights the fragility of the DeFi system, with the AAVE token price now reflecting concerns over whether the Umbrella reserve can cover the resulting hole and potential losses for stkAAVE holders.