Aave Loses $6.6 Billion in Deposits After Kelp Hack Exposes DeFi Lending Risk

Aave Loses $6.6 Billion in Deposits After Kelp Hack Exposes DeFi Lending Risk

N
News Editor 01
2026-07-22 16:50:13
Aave’s TVL fell from $26.4 billion to nearly $20 billion after stolen rsETH from Kelp was posted on Aave V3 as collateral to borrow WETH, exposing a key weakness in DeFi risk models.
AaveKelpDeFi lendingrsETHcross-chain bridge

Aave saw a sharp weekend exodus as its total value locked dropped from $26.4 billion on April 18 to nearly $20 billion by Sunday morning in the U.S., according to DefiLlama. That wiped out $6.6 billion in deposits in a short span. The AAVE token fell 16% to $92, while daily fees climbed to $1.99 million as liquidations accelerated.

The protocol itself was not hacked. The pressure came after attackers drained 116,500 rsETH from Kelp’s cross-chain bridge on Saturday, an amount the report valued at about $292 million. They then moved the stolen rsETH onto Aave V3 as collateral and borrowed wrapped ether against it. On-chain trackers estimated the Aave-specific borrow at roughly $196 million, with total exposure across Aave, Compound, and Euler near $236 million.

How a Kelp bridge failure reached Aave

Aave is the largest lending protocol in DeFi, where depositors supply crypto and borrowers take loans against posted collateral. Kelp operates as a liquid restaking protocol: users route already staked ether into EigenLayer and receive rsETH in return. That receipt token can be traded, and some users also used it as collateral on lending markets such as Aave.

This is where the weakness became visible. Aave accepted rsETH as collateral, but the asset backing that token disappeared through a bridge Aave does not control. Aave founder Stani Kulechov said the exploit was external and that Aave’s own contracts were not compromised. Even so, depositors were still exposed once the posted collateral lost integrity.

Concentration in Ethereum and WETH amplified the damage

Aave’s loan book spans 22 chains, yet Ethereum carries most of the weight. Of the protocol’s $17.82 billion in outstanding borrows, $14.24 billion sits on Ethereum alone. WETH also accounts for 39.49% of all loans on the platform. That concentration meant the attack hit the collateral-to-WETH pairing at the center of Aave’s lending activity, not a marginal market.

The report notes that liquid restaking tokens had been whitelisted by major lending protocols because they generated yield and represented a growing share of Ethereum’s locked capital. Existing risk models assumed these assets would hold their peg under ordinary market stress. They did not account for a case in which collateral could effectively collapse because a bridge on another chain was exploited over a weekend.

Attention turns to the Umbrella reserve

Aave initially said the Umbrella reserve would cover any deficit. By Saturday afternoon, that language shifted to saying the protocol would “explore paths to offset the deficit.” The softer wording raised fresh questions about whether the reserve is large enough and whether stkAAVE holders backing it could end up absorbing losses.

Trader Altcoin Sherpa wrote on X that AAVE is the backbone of DeFi and that much of the infrastructure launched on new chains is based on forks of it. In that view, contagion risk at Aave points to fragility across the wider system. In this episode, the market is not only repricing Aave. It is also reassessing how much trust DeFi lenders can place in liquid restaking collateral and cross-chain bridge assumptions.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.