On April 18, attackers exploited a weakness in Kelp’s LayerZero bridge and minted roughly $293M of unbacked rsETH. Rather than just cashing out, they dumped the fake rsETH straight into Aave as collateral and borrowed real assets against it.
Aave responded by freezing deposits and withdrawals of rsETH. But this didn’t contain the damage, it instead spread the contagion. rsETH depositors realized that even with their own funds frozen, they could still use that same collateral to borrow unaffected assets like USDT and USDC. So they did exactly that, in their minds with rsETH potentially going to 0, any recourse they could get was worth it, so they borrowed whatever stablecoin they could, with no intention of ever reclaiming back their collateral. Stablecoin utilization on Aave then shot up to 100%, and yields spiked above 10%, even though stablecoins had zero exposure to the actual exploit.
The situation eventually subsided and utilization normalized. But it exposed something uncomfortable about pooled lending design generally: contagion isn’t contained to the affected asset. Any asset sharing a liquidity pool with a compromised one can get dragged into a liquidity crunch, even if it has nothing to do with the exploit itself.
That’s the part that seems to have actually done the lasting damage. Users saw that their funds could be affected by risk they had no direct exposure to, and that fear triggered a broader exodus from Aave, and DeFi lending more generally, that a simple freeze couldn’t undo.
Aave’s TVL in numbers:
April 17 (day before the exploit): $25.93B April 19 (two days after): $21.80B July 21 (three months later): $14.40BAave lost over $11.5B in TVL, a 44.5% decline from pre-hack levels. The immediate 2-day fall is clearly hack-driven. What’s more alarming is that it didn’t stop there, TVL kept sliding for months instead of finding a bottom, this is likely the structural damage. Worth being upfront that this stretch also overlapped with a broader crypto downturn, so not all of that continued bleed can be pinned on Kelp specifically. But the fact that Aave never even stabilized, let alone recovered, four months out is notable regardless of how much is directly attributable.
Context on timing: the Kelp exploit also happened just 17 days after a separate $295M hack on Drift Trade (April 1), also allegedly linked to North Korean state hackers. Between the two, April alone accounted for $644.9M in hack losses, more than half of everything lost to hacks across the first seven months of 2026.
The uncomfortable part for lending protocols broadly: this attack vector, mint fake wrapped or liquid-staking tokens, deposit as collateral, borrow real assets, doesn’t require finding a bug in the lending protocol at all. It only requires a bug somewhere upstream in whatever bridge or minting mechanism issues the collateral asset. Aave’s contracts did exactly what they were designed to do, and it still took what looks like a permanent TVL hit because of a design property (shared liquidity pools) rather than a code flaw.
Full data and methodology, not just on the Aave/Kelp fallout but crypto hacks in general: https://www.coingecko.com/learn/crypto-hacks-and-exploits-2016-to-2026
submitted by /u/khai0001 [link] [comments]r/CryptoCurrencyRead More
You might also be interested in reading This Indicator Predicts Potential Decline Ahead For Bitcoin Price.
