BlockBeats reported on June 19 that Aave experienced about $8.45 billion in fund withdrawals after KelpDAO’s rsETH cross-chain bridge was attacked in April 2026. Despite the scale of the outflows, the protocol’s core functions did not fail, making the episode one of the largest liquidity stress tests DeFi has faced to date. The event has been framed by supporters as evidence that on-chain lending infrastructure can keep operating under extreme pressure, while also reopening discussion over the limits of DeFi risk management.
The rsETH Bridge Attack Triggered Collateral Concerns
The crisis began with an attack on KelpDAO’s LayerZero bridge, in which around $292 million worth of rsETH was stolen. After the exploit, market participants raised concerns over the value of rsETH as collateral and over its solvency. Because rsETH had been widely used as collateral in protocols including Aave, the risk quickly spread into lending markets. Users moved to withdraw funds in large numbers, utilization in some markets temporarily reached 100%, and some users were unable to withdraw immediately.
In response to the liquidity strain, Aave’s risk management team activated emergency freezes and parameter adjustments designed to limit the spread of risk. Aave founder Stani Kulechov described the incident as proof of DeFi’s growing maturity. In his view, the protocol continued to function as designed under extreme stress, showing the resilience of an on-chain system built around transparency and rule-based execution.
Risk Controls Worked, but the Debate Continues
Several independent analysts noted that Aave avoided a systemic collapse, but the episode exposed ongoing weaknesses in DeFi lending systems. These include concentration risk, liquidity risk and contagion risk created by a high degree of interconnection between protocols. The behavior of large borrowers can affect the stability of the overall system in ways that exceed model assumptions, making that issue a central part of the post-crisis discussion.
Aave currently manages risk through multiple layers of controls, including loan-to-value limits, liquidation thresholds, supply caps, borrow caps, Isolation Mode, E-Mode and governance mechanisms. These tools broadly functioned during the crisis. However, observers said governance response speed and risk models still need further optimization to deal with future unknown systemic shocks. The episode showed that DeFi protocols can withstand large-scale runs without external rescue, but a single stress test does not fully prove system safety. As composability between protocols continues to increase, a problem involving one external asset or bridge can still develop quickly into a liquidity crisis across the wider ecosystem.

