Aave still has not recovered from the April 18 hack of KelpDAO, with the total value of assets in its smart contracts down 43% from the day of the exploit, according to Protos. The protocol now holds about $14.9 billion, compared with $26.4 billion just before the attack. That figure is also 67% below Aave’s 52-week high of $45.9 billion reached in October 2025.
Even before the exploit, Aave was already below that October peak. After the attack, however, the decline deepened and never fully reversed.
Aave absorbed losses through its lending markets
Protos said North Korean hackers looted KelpDAO in mid-April. Because Aave accepted KelpDAO-linked tokens as collateral for loans, the incident left Aave facing a nine-figure loss. The protocol itself was not hacked, based on its own report, but the event still cost it the long-held position of DeFi’s largest platform by this measure.
Four months later, depositors have yet to return in full. LayerZero, the software provider for the KelpDAO bridge, blamed North Korea within 48 hours of the attack, a conclusion that Protos said outside investigators later confirmed.
KelpDAO takes ETH deposits, stakes them on Ethereum for yield, and issues a tradable receipt token known as rsETH. The attackers placed stolen rsETH on Aave and borrowed real ETH against it. Protos said that maneuver left Aave and fellow lender Compound with an estimated $246 million in combined bad debt.
Markets normalized, but liquidity did not
Aave forcibly liquidated the attacker’s positions, while industry allies restored the missing collateral. By late May, Aave had declared that every market was back to normal.
Still, the dollar value of its liquidity pools never recovered. Protos said Aave remains roughly two-thirds below its October peak. The report also referenced Aave’s dismissal of a restraining notice tied to rescued funds, describing the stance as “finders keepers.”
The pullback has mattered beyond Aave itself. Protos described the protocol as a non-custodial lending app that ended 2025 with $55 billion in TVL, accounting for more than half of the DeFi lending sector’s TVL. For borrowers, that number directly reflects how much inventory and deposited capital is available to draw from. A pool that is 43% smaller has that much less capacity to lend, while price swings become harder to absorb.

Investigators pointed to North Korean links
According to investigators at Chainalysis, North Korea’s Lazarus Group was probably helping the KelpDAO attackers. In LayerZero’s own post-mortem, the operation was attributed to a North Korean-linked cluster identified as TraderTraitor. Protos also said it had reported alleged on-chain links to the Bybit and BTC Turk hacks.
Deposits dropped sharply after the theft
AAVE fell about 20% in the day after the theft, dropping from roughly $115 to below $92. It now trades near $89, still slightly below its pre-hack level.
Within two days of the attack, deposits on Aave had fallen by more than $8 billion. Its stablecoin pools also reached 100% utilization, leaving billions of dollars in crypto effectively stuck, with no room for other users to withdraw stablecoins.
On April 27, Aave said a new coalition called DeFi United had pledged enough ETH to restore full backing for rsETH. The protocol then liquidated the attacker’s positions on Ethereum and Arbitrum on May 6. Replacement collateral moved into the bridge’s reserves in tranches through late May.
The outflows did not stop in May. Protos said TVL kept draining into June, bottoming near $11.9 billion before staging a partial recovery. Aave now sits near $14.9 billion, still 43% below the level recorded on hack day.
In Aave’s own account, its contracts, oracles, and liquidation mechanics worked exactly as designed. Even so, Protos said North Korea was still able to pull funds using phony collateral.

