Aave Faces $6 Billion Deposit Withdrawal Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities

Aave has witnessed a massive exodus of $6.6 billion in deposits, not due to a direct hack on the protocol itself, but as a consequence of a security breach in Kelp's bridge. The total value locked in Aave dropped significantly from $26.4 billion on April 18 to approximately $20 billion by Sunday morning, according to DefiLlama. This sharp decline was accompanied by a 16% fall in the AAVE token's value to $92 and a spike in daily fees to $1.99 million, as the protocol underwent a wave of liquidations over the weekend. Depositors are fleeing because Aave has been left to grapple with a financial hole it did not create. The crisis began when attackers drained 116,500 rsETH from Kelp's bridge on Saturday, which they then used as collateral on Aave V3 to borrow wrapped ether. On-chain data indicates that the borrowed amount on Aave is roughly $196 million, with total positions across Aave, Compound, and Euler reaching around $236 million. Aave, as the largest lending protocol in DeFi, allows users to deposit cryptocurrency to earn yields, while others borrow against collateral. Kelp, a liquid restaking protocol, takes already staked ether on Ethereum and channels it through EigenLayer, a separate yield-generating system, issuing rsETH in exchange. This rsETH is tradable and, critically, was used by some users as collateral on Aave to borrow against. The exploit occurred when attackers tricked Kelp's cross-chain bridge into releasing 116,500 rsETH, valued at about $292 million, to a controlled address. They then deposited this stolen rsETH onto Aave V3 as collateral and borrowed wrapped ether against it. Aave initially stated that the Umbrella reserve would cover any resulting deficit but later softened its stance to exploring paths to offset the deficit. The reason for this significant impact lies in the concentration of Aave's loan book, which spans 22 chains but has $14.24 billion of its $17.82 billion in outstanding borrows on Ethereum alone, with WETH constituting 39.49% of all loans. The attack directly hit the dominant collateral-to-WETH pair in Aave's book. Stani Kulechov, Aave's founder, clarified that the exploit was external and did not compromise the protocol's contracts. However, Aave's acceptance of a liquid restaking token as collateral, whose backing vanished due to a bridge exploit outside of Aave's control, places depositors at risk of loss. The whitelisting of liquid restaking tokens across major lending protocols was based on their yield and representation of Ethereum's locked value, with risk models assuming they would hold peg under normal conditions. None of these models accounted for a scenario where the collateral's value drops to zero due to a bridge exploit on an unrelated chain. A trader noted that AAVE, being the backbone of DeFi with billions invested and serving as a model for new DeFi infrastructure on other chains, faces contagion risk, highlighting the fragility of the entire system. The current token price reflects concerns over whether the Umbrella reserve is sufficient to cover the resulting hole and whether stkAAVE holders backing this reserve will absorb the loss.