Aave Faces $6 Billion Deposit Exodus After Kelp Hack Exposes DeFi Lender's Structural Vulnerabilities
Aave has witnessed a staggering $6.6 billion exodus, not due to a direct hack, but rather a consequence of the Kelp bridge exploit. The protocol's total value locked plummeted from $26.4 billion to nearly $20 billion, with the AAVE token experiencing a 16% decline to $92 and daily fees surging to $1.99 million amidst widespread liquidations. Depositors are fleeing as Aave grapples with a crisis not of its own making, stemming from attackers' exploitation of Kelp's bridge, resulting in the theft of 116,500 rsETH, which was then used as collateral on Aave V3 to borrow wrapped ether. On-chain trackers estimate the Aave-specific borrow to be around $196 million, with total positions across Aave, Compound, and Euler nearing $236 million. As the largest lending protocol in DeFi, Aave enables users to deposit crypto and earn yield, while others borrow against collateral. However, the recent hack has exposed a structural risk, with Aave now forced to quantify its bad debt. The attack involved tricking Kelp's cross-chain bridge into releasing 116,500 rsETH, worth approximately $292 million, which was then deposited onto Aave V3 as collateral to borrow wrapped ether. Aave's initial response indicated that the Umbrella reserve would cover any deficit, but the language has since softened to exploring paths to offset the deficit. The concentration of Aave's loan book on Ethereum, with $14.24 billion of the $17.82 billion in outstanding borrows, has exacerbated the damage. Stani Kulechov, Aave's founder, emphasized that the exploit was external and the protocol's contracts were not compromised. Nevertheless, Aave's acceptance of liquid restaking tokens as collateral has left depositors vulnerable, highlighting the fragility of the DeFi system.