Aave Faces $6 Billion Deposit Exodus Following Kelp Hack, Exposing DeFi Lender's Structural Vulnerabilities
Aave witnessed a staggering $6.6 billion exodus, not due to a direct hack, but as a consequence of a vulnerability in the DeFi ecosystem. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion, with the AAVE token experiencing a 16% decline to $92 and daily fees surging to $1.99 million amidst widespread liquidations over the weekend. Depositors are fleeing due to Aave's exposure to a hole created by an external exploit. Attackers drained 116,500 rsETH from Kelp's bridge, utilizing the stolen tokens as collateral on Aave V3 to borrow wrapped ether. On-chain trackers estimate the Aave-specific borrow to be around $196 million, with total positions across Aave, Compound, and Euler at approximately $236 million. As the largest lending protocol in DeFi, Aave allows users to deposit crypto to earn yield, while others borrow against collateral. The exploited rsETH, used as collateral by some users, has put Aave at risk. The attack involved tricking Kelp's cross-chain bridge into releasing the stolen rsETH, which was then used to borrow wrapped ether on Aave V3. Initially, Aave stated that the Umbrella reserve would cover any deficit, but later softened its stance to exploring paths to offset the deficit. The concentration of Aave's loan book on Ethereum, with $14.24 billion of the $17.82 billion in outstanding borrows, and the dominance of the WETH pair, has exacerbated the damage. Aave's founder, Stani Kulechov, confirmed that the exploit was external and the protocol's contracts were not compromised. However, the acceptance of liquid restaking tokens as collateral has introduced unforeseen risks. The token's backing vanished due to a bridge exploit on a chain Aave does not control, leaving depositors vulnerable to losses. The risk models had priced these tokens based on their yield and growth potential, but failed to account for a scenario where the collateral's value would plummet to zero due to a bridge exploit. The incident highlights the fragility of the DeFi system, with Aave's contagion risk posing a significant threat to the entire ecosystem. The current token price reflects the market's uncertainty about whether the Umbrella reserve is sufficient to cover the resulting hole and whether stkAAVE holders will bear the loss.