Aave, one of DeFi’s largest lending protocols, is managing a liquidity crisis and an estimated $177 million to $200 million in bad debt after attackers siphoned 116,500 rsETH from KelpDAO’s bridge on April 18, 2026. The attackers deposited the stolen tokens on Aave V3 as collateral and borrowed wrapped ether (WETH) against them. Once KelpDAO paused rsETH contracts in response to the exploit, the collateral backing those borrow positions became worthless, leaving Aave holding bad debt across its WETH reserves.
Aave Freezes rsETH Markets, WETH Pool Utilization Hits 100%
Aave confirmed that its own contracts were not exploited. “Aave’s contracts have not been exploited,” the project’s X account stated. “rsETH has been frozen on Aave V3 and V4, the asset does not have any borrowing power as a measure due to KelpDAO bridge exploit that happened outside of Aave. Both Aave V3 and V4 does not have further exposure to rsETH,” added founder Stani Kulechov.
Despite the freeze, a wave of withdrawals hit Aave’s ETH and WETH pools, with outflows reportedly reaching $5.4 billion within hours. As capital drained, WETH pool utilization climbed to 100%, meaning no liquidity remains for suppliers to redeem. Stablecoin pools also saw elevated utilization as users rushed to exit, causing failed and delayed withdrawals across USDC and USDT markets.
Aave’s total value locked (TVL) dropped from approximately $26.4 billion to $19.776 billion, a 24.11% decline. The AAVE token fell 17.7% on April 19 as the market priced in bad debt uncertainty and potential impacts from the Umbrella backstop mechanism.
Umbrella Backstop Activated to Cover Bad Debt
Aave’s Umbrella system is the protocol’s built-in backstop designed to cover such events. If bad debt is confirmed, the mechanism can draw on reserves and may involve slashing staked AAVE to cover the deficit. The precise impact on depositors is still being determined. Other protocols connected to overlapping liquidity pools, including Sparklend, reported rate spikes and temporary pauses as capital shifted away from affected markets.
As of April 19, no new exploits have been reported. ETH pool utilization remains elevated, and full withdrawal access depends on either panic subsiding or the Umbrella mechanism settling the bad debt and restoring confidence. Aave’s next steps include completing a bad debt review, issuing a formal Umbrella resolution, and monitoring outflows as the market absorbs the full impact of the KelpDAO exploit.
This incident underscores the cascading risk in DeFi: a bridge exploit can propagate through collateralized positions to the largest lending market, causing billions in liquidity to vanish within minutes.

