Aave faced one of DeFi’s sharpest liquidity shocks in April 2026. After the $292 million exploit of KelpDAO’s LayerZero-powered bridge, the decentralized lending protocol saw $8.45 billion in withdrawals over 48 hours, turning the incident into a major stress event for onchain credit markets.
Speaking at the Proof of Talk event in Paris, Aave Labs founder and CEO Stani Kulechov defended the protocol’s performance. He said Aave’s V3 infrastructure had already lived through multiple market cycles and described the protocol as resilient during turbulent periods. His remarks focused on the durability of the system rather than the operational strain exposed by the liquidity crunch.
The trigger sat outside Aave’s core code
Kulechov argued that core smart contracts should be separated from failures in external infrastructure. In his view, DeFi smart contract development generally has very few issues, while third-party dependencies and more conventional security weaknesses are often what spill over into the broader market.
According to the report, the April incident started with an RPC-spoofing and DDoS attack on LayerZero verifier nodes tied to KelpDAO, not with a flaw in Aave’s own code. That distinction is technically important. Still, risk analysts said it leaves a harder point unanswered: breakdowns in connected infrastructure can transmit stress into lending protocols just as fast as a native exploit.
Bad debt mounted and emergency support followed
LlamaRisk later said the attackers minted worthless collateral, posted it to Aave, and withdrew genuine wrapped Ether, or wETH. The result was an estimated $123.7 million in bad debt on Aave V3. Analysts at the Bank Policy Institute also said Aave’s limited insurance coverage showed how exposed DeFi platforms can be to bank-run dynamics, with users bearing the consequences.
Aave remained operational, but not through automation alone. The recovery effort described in the report centered on a roughly $300 million emergency response led by people rather than code. That package included a 25,000 ETH pledge from the Aave DAO and a personal contribution of 5,000 ETH from Kulechov, valued in the article at about $8.4 million.
V4 is being framed as the structural fix
Kulechov said Aave Labs is using the upcoming V4 upgrade to redesign risk management at the architectural level. The stated goal is to stop future bridge failures from triggering another system-wide withdrawal wave.
Under the plan he described, Aave V4 will move to a modular “hub-and-spoke” structure instead of relying on traditional token pooling. That setup would let the protocol apply localized risk premiums on its own and freeze specific collateral lines before stress reaches primary lending reserves. Kulechov also said that public, auditable systems allow anyone to inspect code and run risk analysis, which he called central to building resilient software.
Aave is presenting the $8.45 billion withdrawal event as evidence of endurance. Critics are reading the same episode as a warning about dependency risk, weak insurance buffers, and the limits of isolation in DeFi lending. The debate is likely to stay active until V4 is in the market.

