Close Menu
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
What's Hot

Bitcoin Mining Generates 90% of HIVE’s $1M Daily Revenue

September 11, 2026

IREN Stock Drops as Investors Question AI Promises

September 11, 2026

Jeremy Siegel Urges Fed Rate Hike Despite Selloff Risk

September 11, 2026

Nasdaq, Boerse Stuttgart Ask EU to Raise Tokenization Trial Cap

September 11, 2026

Sam Bankman-Fried Appeals FTX Conviction to Supreme Court

September 11, 2026

Analyst Warns Anthropic IPO May Distract From Bitcoin Rally

September 11, 2026

Polygon Network Unveils Ambitious ‘Gigagas’ Roadmap

September 11, 2026

US Lawmakers Consider AI System “Kill Switches”

September 11, 2026

XRP Price Projection Hits $60 Amid Regulatory Hurdle

September 11, 2026

Pumpfun Mobile App Temporarily Removed from US, India iOS Stores

September 11, 2026
Facebook X (Twitter) Instagram
Daily Crypto News
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
Dashboard
Daily Crypto News
Home»News»Aave Still Has an $8 Billion Hole Five Months After the Kelp Hack
White Aave logo centered on a solid black background
White Aave logo centered on a solid black background
News

Aave Still Has an $8 Billion Hole Five Months After the Kelp Hack

Luiza NunesBy Luiza NunesSeptember 11, 20264 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Five months after the Kelp hack, Aave still has a balance-sheet-sized reminder of what went wrong: deposits remain about $8 billion below where they stood before the exploit.

Aave held roughly $26.1 billion in deposits on April 17, the day before the attack. By September 10, that figure had fallen to $18.1 billion, according to DefiLlama.

That gap is striking for another reason. Aave’s own lending software did not break.

The problem arrived from somewhere else: a token used as collateral carried a claim that had already been compromised before it ever reached the lending market. In other words, Aave’s contracts were functioning normally while the thing they were being asked to trust was not.

What the Kelp attack actually changed for Aave

The April 18 attack targeted Kelp DAO’s cross-chain bridge, rather than Aave’s lending infrastructure. Kelp is a liquid restaking protocol, and its rsETH token represents a claim on staked ether rather than ether itself.

Attackers manipulated the information used by the bridge to validate incoming messages. That allowed them to create a counterfeit claim and release 116,500 rsETH, worth about $292 million at the time.

That haul represented nearly 18% of rsETH’s total supply.

The investigation by security firm Halborn pointed to a single-verifier design and compromised data nodes. Chainalysis also attributed the attackers to North Korea’s Lazarus Group.

The important part for Aave came next.

The newly created rsETH did not stay isolated inside the bridge system. Attackers brought 89,567 rsETH into Aave and used it as collateral to borrow approximately $193 million.

Suddenly, the lending protocol was sitting underneath a problem it had not created.

Aave moved quickly. It froze rsETH markets across 11 markets within an hour and later froze WETH two days after the exploit. BeInCrypto warned WETH suppliers to withdraw that same evening, before those pools reached full utilization.

Aave’s own incident report made the distinction explicit: “Aave’s smart contracts were not compromised at any point during this event. All protocol logic, including supply, repayment, and liquidation mechanisms, continued to function as designed.”

The losses, however, were real.

Aave initially estimated bad debt at $123.7 million if the losses were distributed across the affected markets. Once the exposure to bridged rsETH was isolated, the figure rose to $230.1 million.

Why Aave’s $8 billion deposit gap matters

The immediate damage was partially contained by a recovery effort involving rival protocols and other participants.

A coalition-backed plan collected about 69,570 ETH in pledges against a 75,081 ETH shortfall. Arbitrum’s Security Council also froze 30,765 ETH connected to the exploit, and Arbitrum’s DAO released that amount to Aave in June.

There is still legal uncertainty around those funds. A US court order sought by creditors with judgments against North Korea remains in the picture.

The bigger story, though, is what happened to user deposits.

Aave had about $12.5 billion at the end of June. By September 10, deposits had climbed back to $18.1 billion. That is a substantial recovery, but it is still roughly 31% below the pre-hack level.

AAVE, meanwhile, was trading near $124, down 3.8% on the day.

The episode exposes an awkward reality of decentralized lending: the code can work exactly as intended and still inherit someone else’s security failure.

Bridged assets, wrapped tokens and other receipt-style assets all introduce another layer between a lender and the underlying asset. Every extra layer creates another place where assumptions can go bad.

The same question applies well beyond rsETH.

Before treating one of these assets as collateral, users have to know how the bridge is secured, how many independent parties can authorize a transfer, and whether a lending market keeps its risks isolated or allows losses to spread across neighboring pools.

There is another question that is easier to miss: whether the collateral is actually an asset at all, or simply a claim on another claim.

The Kelp exploit made that distinction painfully concrete for Aave. The lending machinery kept running. The collateral underneath it had already become something else.

aave Crypto Market Crypto Security kelp dao
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

World Prediction Markets Hit Solana With a 1 Million-User Waitlist

September 11, 2026

Bitcoin $400,000 by 2030 Is Still a “Reasonable Target,” Coinbase CEO Says

September 11, 2026

Bitcoin Quantum Threat Gets More Real as IonQ Unveils 256-Qubit Machine

September 11, 2026

Solana Tokens Hit a Record as More Than 263,000 Are Minted in One Day

September 10, 2026

Recent Posts

  • Bitcoin Mining Generates 90% of HIVE’s $1M Daily Revenue
  • IREN Stock Drops as Investors Question AI Promises
  • Jeremy Siegel Urges Fed Rate Hike Despite Selloff Risk
  • Nasdaq, Boerse Stuttgart Ask EU to Raise Tokenization Trial Cap
  • Sam Bankman-Fried Appeals FTX Conviction to Supreme Court
Top Posts

World Prediction Markets Hit Solana With a 1 Million-User Waitlist

September 11, 2026

Bitcoin $400,000 by 2030 Is Still a “Reasonable Target,” Coinbase CEO Says

September 11, 2026

Bitcoin Quantum Threat Gets More Real as IonQ Unveils 256-Qubit Machine

September 11, 2026

Stay updated with the latest crypto news, market trends, and expert insights. We provide accurate and timely information to help you make better decisions.

Facebook X (Twitter) Instagram Pinterest YouTube
Our Resources
  • About Us
  • Privacy Policy
  • Editorial Policy
  • Legal Disclaimer
  • Contact us
Categories
  • Altcoins
  • Prediction
  • Opinion
  • Guides
  • Reviews
  • Bitcoin
  • Ethereum
Recent Posts
  • Bitcoin Mining Generates 90% of HIVE’s $1M Daily Revenue
  • IREN Stock Drops as Investors Question AI Promises
  • Jeremy Siegel Urges Fed Rate Hike Despite Selloff Risk
  • Nasdaq, Boerse Stuttgart Ask EU to Raise Tokenization Trial Cap
© 2026 Daily Crypto News

Type above and press Enter to search. Press Esc to cancel.