Crypto lending rebounds 55%, but protocol links and AI-era exploits keep risks in focus

Crypto lending rebounds 55%, but protocol links and AI-era exploits keep risks in focus

N
News Editor
2026-10-08 13:30:00
Crypto lending has rebounded sharply since July, with total value locked climbing more than 55% to about $56 billion, according to figures cited in Cointelegraph Magazine. The recovery follows a weak second quarter, when Galaxy data showed $11.33 billion left the sector, partly after the April Kelp DAO incident shook confidence in lending markets and left Aave users temporarily unable to access ETH tied to the event. The episode exposed a broader problem for DeFi lenders: even if a protocol’s own smart contracts are not breached, risks can still arrive through bridges, wrapped assets, verifier networks, oracles, governance systems, and other external dependencies. After the Kelp DAO cross-chain route was exploited, 116,500 unbacked rsETH worth roughly $290 million at the time was created, and much of it was used as collateral on Aave. Aave later froze its rsETH and wrsETH markets, while deposits fell by about $15 billion in the following days. Executives from Aave, Spark, Ledn, Maple, and SALT Lending said risk management now has to extend beyond code audits to include collateral quality, operational security, liquidity controls, key management, and response procedures. They also said AI can help with testing and code review, but current tools still produce a high number of false positives, leaving human judgment central to security work.

Crypto lending has picked up again after a weak second quarter, with total value locked in the sector rising more than 55% since the start of July to roughly $56 billion. The rebound has brought capital back into DeFi lending markets, but it has also enlarged the target. As protocols become more interconnected, a failure in one part of the stack can spread well beyond the point where an exploit begins.

Crypto lending rebounds 55%, but protocol links and AI-era exploits keep risks in focus 2

Figures from Galaxy, cited in the report, show that $11.33 billion left the crypto lending sector in Q2. The pullback was attributed in part to a loss of confidence after the April Kelp DAO hack, which left users on Aave, described in the piece as the most trusted protocol, unable to access their ETH tied to the incident.

That event remains central to how major lending platforms now think about security. Stani Kulechov, founder and chief executive of Aave Labs, told Cointelegraph Magazine that the issue is now at the top of the agenda.

An attack surface that extends beyond the contract

In April, hackers exploited a Kelp DAO cross-chain route and created 116,500 unbacked rsETH, worth about $290 million at the time. A large share of those tokens was then posted as collateral to borrow other assets on Aave markets.

Aave’s own contracts were not breached. Even so, the protocol still suffered heavy fallout. Deposits fell by around $15 billion in the days after the exploit, and Aave froze its rsETH and wrsETH markets.

Galaxy data showed the lending market contracted 16.78% in Q2. Kulechov said Aave has since rebuilt its security approach around a wider view of risk.

“We rebuilt our approach around that wider view,” he said. “Our starting point is that security can’t stop at the smart contract.” He added that traditional reviews “missed the risk sitting in the bridges, verifier networks and other infrastructure an asset depends on.”

That same logic applies to users trying to assess lending protocols. Thomas Wu, chief financial officer of Bitcoin-backed lender Ledn, said every wrapper, bridge, and oracle between the lender and the underlying asset creates another place where a loan can fail.

Sid Powell, co-founder and chief executive of crypto credit platform Maple, told Magazine that serious lenders should begin with the assumption that a borrower can fail at any time, then build their controls from there.

Containment matters when prevention is not enough

Sam MacPherson, chief executive of DeFi lender Spark, said his team reviews more than smart contracts. Its process also covers governance design, operational security, collateral quality, liquidity management, and dependencies across the broader ecosystem.

Spark started phasing out rsETH on SparkLend in January, before the April Kelp exploit. MacPherson said the team concluded that the asset’s “low usage and revenue” did not justify the “additional risk” involved in supporting it.

Kulechov said Aave has introduced similar mechanisms. Each asset is reviewed every quarter and then reviewed again after any material change. He also said the protocol has already begun “an orderly wind-down” on six networks that did not meet its chain-level standards.

Data from DeFiLlama showed lending TVL has risen more than 55% from the end of Q2. Kulechov said no protocol can control the whole ecosystem, but each one can decide how much risk it accepts and how quickly it reacts when trouble appears.

MacPherson made a similar point from the response side. Preventing failures is the goal, he said, but protocols also need procedures ready for the moment something does go wrong.

Crypto lending rebounds 55%, but protocol links and AI-era exploits keep risks in focus 3

Human error still sits near the center of the problem

Shawn Owen, founder and chief executive of SALT Lending, said human error remains one of the biggest vulnerabilities in crypto lending, and one of the easiest to miss.

“A lot of the biggest losses have come down to key management, access controls or someone getting socially engineered, and a smart contract audit won’t catch any of that,” Owen said.

Risk also rises when customer assets are deployed elsewhere to earn yield. The industry learned that painfully during the 2022 market unwind, when lenders including Celsius, Voyager, and BlockFi collapsed after taking on risks that customers either did not understand or did not expect.

Ledn’s answer is to keep client Bitcoin with qualified custodians instead of lending it out for extra yield. Wu said every transaction adds another point of possible failure, so reducing the number of steps lowers the chance of a breach.

Powell warned that another pressure point appears when deposits arrive faster than managers can find sound lending opportunities. In that situation, the push to preserve yields can lead to poor decisions.

AI can help, but it also creates new exposure

Recent headlines have focused on AI-assisted hacks, exploits, and agents acting outside human control. Even so, AI may also improve security in crypto lending if it is used carefully.

Aave is already using AI-assisted testing alongside its standard security process. In one exercise, it used mutation testing to deliberately inject bugs into V4 contracts, and its test suites caught 271 of 304 injected vulnerabilities.

In a recent review of Aave’s V3 and V4 codebases, three AI security tools produced 71 findings. After manual review, 20 were considered valid. The remaining 51 findings showed the limits of current tooling and why human reviewers still matter.

“AI is very good at breadth and speed,” Kulechov said, “but around 70% of the raw findings were false positives, so expert judgment stays essential.”

He also described AI as a double-edged sword. As AI agents begin managing capital onchain, their permissions, inputs, and decision logic become part of the attack surface.

“As AI agents start managing capital onchain,” Kulechov said, “their permissions, inputs and decision logic become things that need to be secured just like a contract.”

With crypto lending growing again, the core issue is no longer limited to whether code passes review. The harder task is understanding every dependency a protocol takes on, monitoring those links in real time, and containing damage when one of them breaks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.