Until April 17, lending stablecoins on Aave yielded 2.32% APY, despite the Federal Reserve's overnight rate being 3.64%. This suggested the market viewed DeFi as a lower credit risk than the US Treasury. However, this perception changed dramatically over 48 hours. The hierarchy of dollar-credit options by yield made no sense, with Treasury overnight yields at 3.64%, Ledn's investment-grade Bitcoin-backed ABS senior tranche at 6.84%, and Aave at 2.32%.

This mispricing had to be corrected, and the market did so in real-time. The incident began with an attacker exploiting Kelp DAO's cross-chain bridge, minting unbacked rsETH tokens worth around $292 million. The attacker then used these tokens as collateral on Aave, borrowing an estimated $190-230 million in real assets.

The protocol functioned as designed, but the shortfall was structural, not technical. The contagion was instant, with DeFi protocols being interoperable by design.

Approximately 20% of Aave's historical borrow volume came from recursive leverage, and within 48 hours, $6-10 billion in net outflows left Aave. Utilization on WETH, USDT, and USDC pools hit 100%, and depositors couldn't withdraw while borrowers couldn't source stablecoin liquidity.

Rates responded accordingly, with Aave stablecoin deposit APYs rising from 3-6% pre-exploit to 13.4% within two days. The Total DeFi TVL across the top 20 chains fell by more than $13 billion. Unlike traditional lenders, DeFi protocols lack bankruptcy laws, and there is no process for recovery or accountability. This has direct consequences for risk sizing, as estimating total loss is possible, but predicting its distribution is not.

DeFi is not risk-free and carries a premium over regulated equivalents. The recent events serve as a reminder that permissionless markets have always existed and have never been risk-free. Institutional allocators should take this signal seriously, as the 2.32% Aave APR before last weekend did not reflect the underlying risk, and the market has now adjusted.