Crypto lending has picked up again after a weak second quarter, with total value locked in the sector rising more than 55% since the start of July to roughly $56 billion. The rebound has brought capital back into DeFi lending markets, but it has also enlarged the target. As protocols become more interconnected, a failure in one part of the stack can spread well beyond the point where an exploit begins.

Figures from Galaxy, cited in the report, show that $11.33 billion left the crypto lending sector in Q2. The pullback was attributed in part to a loss of confidence after the April Kelp DAO hack, which left users on Aave, described in the piece as the most trusted protocol, unable to access their ETH tied to the incident.
That event remains central to how major lending platforms now think about security. Stani Kulechov, founder and chief executive of Aave Labs, told Cointelegraph Magazine that the issue is now at the top of the agenda.
An attack surface that extends beyond the contract
In April, hackers exploited a Kelp DAO cross-chain route and created 116,500 unbacked rsETH, worth about $290 million at the time. A large share of those tokens was then posted as collateral to borrow other assets on Aave markets.
Aave’s own contracts were not breached. Even so, the protocol still suffered heavy fallout. Deposits fell by around $15 billion in the days after the exploit, and Aave froze its rsETH and wrsETH markets.
Galaxy data showed the lending market contracted 16.78% in Q2. Kulechov said Aave has since rebuilt its security approach around a wider view of risk.
“We rebuilt our approach around that wider view,” he said. “Our starting point is that security can’t stop at the smart contract.” He added that traditional reviews “missed the risk sitting in the bridges, verifier networks and other infrastructure an asset depends on.”
That same logic applies to users trying to assess lending protocols. Thomas Wu, chief financial officer of Bitcoin-backed lender Ledn, said every wrapper, bridge, and oracle between the lender and the underlying asset creates another place where a loan can fail.
Sid Powell, co-founder and chief executive of crypto credit platform Maple, told Magazine that serious lenders should begin with the assumption that a borrower can fail at any time, then build their controls from there.
Containment matters when prevention is not enough
Sam MacPherson, chief executive of DeFi lender Spark, said his team reviews more than smart contracts. Its process also covers governance design, operational security, collateral quality, liquidity management, and dependencies across the broader ecosystem.
Spark started phasing out rsETH on SparkLend in January, before the April Kelp exploit. MacPherson said the team concluded that the asset’s “low usage and revenue” did not justify the “additional risk” involved in supporting it.
Kulechov said Aave has introduced similar mechanisms. Each asset is reviewed every quarter and then reviewed again after any material change. He also said the protocol has already begun “an orderly wind-down” on six networks that did not meet its chain-level standards.
Data from DeFiLlama showed lending TVL has risen more than 55% from the end of Q2. Kulechov said no protocol can control the whole ecosystem, but each one can decide how much risk it accepts and how quickly it reacts when trouble appears.
MacPherson made a similar point from the response side. Preventing failures is the goal, he said, but protocols also need procedures ready for the moment something does go wrong.

Human error still sits near the center of the problem
Shawn Owen, founder and chief executive of SALT Lending, said human error remains one of the biggest vulnerabilities in crypto lending, and one of the easiest to miss.
“A lot of the biggest losses have come down to key management, access controls or someone getting socially engineered, and a smart contract audit won’t catch any of that,” Owen said.
Risk also rises when customer assets are deployed elsewhere to earn yield. The industry learned that painfully during the 2022 market unwind, when lenders including Celsius, Voyager, and BlockFi collapsed after taking on risks that customers either did not understand or did not expect.
Ledn’s answer is to keep client Bitcoin with qualified custodians instead of lending it out for extra yield. Wu said every transaction adds another point of possible failure, so reducing the number of steps lowers the chance of a breach.
Powell warned that another pressure point appears when deposits arrive faster than managers can find sound lending opportunities. In that situation, the push to preserve yields can lead to poor decisions.
AI can help, but it also creates new exposure
Recent headlines have focused on AI-assisted hacks, exploits, and agents acting outside human control. Even so, AI may also improve security in crypto lending if it is used carefully.
Aave is already using AI-assisted testing alongside its standard security process. In one exercise, it used mutation testing to deliberately inject bugs into V4 contracts, and its test suites caught 271 of 304 injected vulnerabilities.
In a recent review of Aave’s V3 and V4 codebases, three AI security tools produced 71 findings. After manual review, 20 were considered valid. The remaining 51 findings showed the limits of current tooling and why human reviewers still matter.
“AI is very good at breadth and speed,” Kulechov said, “but around 70% of the raw findings were false positives, so expert judgment stays essential.”
He also described AI as a double-edged sword. As AI agents begin managing capital onchain, their permissions, inputs, and decision logic become part of the attack surface.
“As AI agents start managing capital onchain,” Kulechov said, “their permissions, inputs and decision logic become things that need to be secured just like a contract.”
With crypto lending growing again, the core issue is no longer limited to whether code passes review. The harder task is understanding every dependency a protocol takes on, monitoring those links in real time, and containing damage when one of them breaks.

