Aave TVL remains 43% below pre-hack level after KelpDAO exploit

Aave TVL remains 43% below pre-hack level after KelpDAO exploit

N
News Editor
2026-08-18 18:13:51
Aave has yet to regain the liquidity it had before the April 18 hack of KelpDAO, according to Protos. The report says the lending protocol now holds about $14.9 billion in assets, down 43% from the $26.4 billion on the day of the attack and 67% below its 52-week high of $45.9 billion in October 2025. Although Aave said its contracts, oracles, and liquidation system functioned as intended, the platform was still hit after attackers used stolen rsETH as collateral to borrow ETH. Protos said that move left Aave and Compound with an estimated $246 million in combined bad debt. The report also notes that Aave’s deposits fell by more than $8 billion within two days of the exploit, while stablecoin pools hit 100% utilization. Aave later liquidated the attacker’s positions and said by late May that markets had returned to normal, but TVL kept falling into June before partially recovering. Investigators cited in the report linked the operation to North Korean actors, including Lazarus Group and a cluster identified by LayerZero as TraderTraitor.

Aave still has not recovered from the April 18 hack of KelpDAO, with the total value of assets in its smart contracts down 43% from the day of the exploit, according to Protos. The protocol now holds about $14.9 billion, compared with $26.4 billion just before the attack. That figure is also 67% below Aave’s 52-week high of $45.9 billion reached in October 2025.

Even before the exploit, Aave was already below that October peak. After the attack, however, the decline deepened and never fully reversed.

Aave absorbed losses through its lending markets

Protos said North Korean hackers looted KelpDAO in mid-April. Because Aave accepted KelpDAO-linked tokens as collateral for loans, the incident left Aave facing a nine-figure loss. The protocol itself was not hacked, based on its own report, but the event still cost it the long-held position of DeFi’s largest platform by this measure.

Four months later, depositors have yet to return in full. LayerZero, the software provider for the KelpDAO bridge, blamed North Korea within 48 hours of the attack, a conclusion that Protos said outside investigators later confirmed.

KelpDAO takes ETH deposits, stakes them on Ethereum for yield, and issues a tradable receipt token known as rsETH. The attackers placed stolen rsETH on Aave and borrowed real ETH against it. Protos said that maneuver left Aave and fellow lender Compound with an estimated $246 million in combined bad debt.

Markets normalized, but liquidity did not

Aave forcibly liquidated the attacker’s positions, while industry allies restored the missing collateral. By late May, Aave had declared that every market was back to normal.

Still, the dollar value of its liquidity pools never recovered. Protos said Aave remains roughly two-thirds below its October peak. The report also referenced Aave’s dismissal of a restraining notice tied to rescued funds, describing the stance as “finders keepers.”

The pullback has mattered beyond Aave itself. Protos described the protocol as a non-custodial lending app that ended 2025 with $55 billion in TVL, accounting for more than half of the DeFi lending sector’s TVL. For borrowers, that number directly reflects how much inventory and deposited capital is available to draw from. A pool that is 43% smaller has that much less capacity to lend, while price swings become harder to absorb.

Aave TVL remains 43% below pre-hack level after KelpDAO exploit 3

Investigators pointed to North Korean links

According to investigators at Chainalysis, North Korea’s Lazarus Group was probably helping the KelpDAO attackers. In LayerZero’s own post-mortem, the operation was attributed to a North Korean-linked cluster identified as TraderTraitor. Protos also said it had reported alleged on-chain links to the Bybit and BTC Turk hacks.

Deposits dropped sharply after the theft

AAVE fell about 20% in the day after the theft, dropping from roughly $115 to below $92. It now trades near $89, still slightly below its pre-hack level.

Within two days of the attack, deposits on Aave had fallen by more than $8 billion. Its stablecoin pools also reached 100% utilization, leaving billions of dollars in crypto effectively stuck, with no room for other users to withdraw stablecoins.

On April 27, Aave said a new coalition called DeFi United had pledged enough ETH to restore full backing for rsETH. The protocol then liquidated the attacker’s positions on Ethereum and Arbitrum on May 6. Replacement collateral moved into the bridge’s reserves in tranches through late May.

The outflows did not stop in May. Protos said TVL kept draining into June, bottoming near $11.9 billion before staging a partial recovery. Aave now sits near $14.9 billion, still 43% below the level recorded on hack day.

In Aave’s own account, its contracts, oracles, and liquidation mechanics worked exactly as designed. Even so, Protos said North Korea was still able to pull funds using phony collateral.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
30

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.