Aave Faces $8.45B in Withdrawals After rsETH Bridge Attack Without Core Failure

Aave Faces $8.45B in Withdrawals After rsETH Bridge Attack Without Core Failure

N
News Editor
2026-06-19 18:00:51
Aave experienced about $8.45 billion in withdrawals after KelpDAO’s rsETH bridge was attacked in April 2026. The protocol’s core functions did not fail, but the episode exposed liquidity, concentration and contagion risks across DeFi lending markets.
AaveKelpDAOrsETHDeFiLayerZeroLiquidity Risk

ChainCatcher reported that Aave experienced roughly $8.45 billion in withdrawals after KelpDAO’s rsETH cross-chain bridge was attacked in April 2026. Despite the scale of the outflows and the pressure on liquidity, Aave’s core protocol functions did not suffer a failure. The episode has been described as one of the largest liquidity stress tests in DeFi to date, with the main focus falling on how a problem involving an external asset and bridge could spread rapidly into a major lending protocol.

rsETH theft triggered collateral and solvency concerns

The crisis originated from an attack on KelpDAO’s LayerZero bridge, in which about $292 million worth of rsETH was stolen. After the attack, market participants became concerned about the value of rsETH as collateral and about solvency tied to that asset. Because rsETH had been widely used as collateral in protocols including Aave, the risk quickly moved beyond the bridge itself and reached DeFi lending markets.

As users moved to withdraw funds, some markets saw utilization briefly reach 100%. During that period, some users were unable to withdraw funds immediately, reflecting the direct liquidity stress created by the rush for exits. In response to the pressure, Aave’s risk management team activated emergency freezes and parameter adjustments designed to limit further risk transmission across the protocol.

Aave founder Stani Kulechov described the event as evidence of growing DeFi maturity. In his view, the protocol continued to operate as designed under extreme stress, showing the resilience of an on-chain, transparent and rules-based system. The fact that Aave avoided a breakdown in core functionality became one of the central points in the discussion following the incident.

Risk controls worked, but model and governance questions remain

Several independent analysts said that although Aave avoided a systemic collapse, the event exposed ongoing weaknesses in DeFi lending architecture. These include concentration risk, liquidity risk and contagion risk created by the high degree of interconnection between protocols. The behavior of large borrowers can have an effect on system stability that exceeds model expectations, especially when confidence in collateral and user liquidity demand deteriorate at the same time.

Aave currently manages risk through multiple layers of controls, including loan-to-value limits, liquidation thresholds, supply caps, borrowing caps, Isolation Mode, E-Mode and governance mechanisms. These protections broadly functioned during the crisis, but observers said governance response speed and risk models still need further optimization to address unknown future systemic shocks.

The incident shows that DeFi protocols can withstand large-scale runs without outside rescue, but a single stress test cannot fully prove that a system is secure. As composability between protocols continues to increase, a problem involving one external asset or cross-chain bridge can still turn quickly into a liquidity crisis across the broader ecosystem.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.