Kelp DAO Exploit Sparks Aave Liquidity Crunch, $6.2 Billion Withdrawal Panic

4 weeks ago 21

In brief

  • Aave users struggled to retreat funds from Aave aft attackers borrowed with stolen rsETH connected the platform, spiking a halfway market’s alleged utilization rate.
  • The funds were plundered from a LayerZero-powered bridge, successful what onlookers described arsenic DeFi’s biggest exploit truthful acold this year.
  • Early Sunday, DefiLlama’s 0xngmi said Aave had faced $6.2 cardinal successful nett withdrawals, portion Spark’s monetsupply.eth pointed to “negative secondary effects.”

Less than a time aft attackers drained $291 cardinal successful crypto from infrastructure linked to decentralized finance task Kelp DAO, users connected Aave, 1 of DeFi’s astir battle-tested protocols, struggled to retreat funds amid a liquidity crunch.

A span that typically allows users to determination an plus called rsETH from 1 web to different was exploited connected Saturday, prompting Aave to frost markets tied to the token, which attackers had utilized to get funds from the platform, the lending protocol said successful an X post.

Meanwhile, Kelp DAO said successful an X station that it had “paused rsETH contracts” crossed Ethereum’s mainnet and respective layer-2 scaling networks arsenic it investigates suspicious activity.

Earlier contiguous we identified suspicious cross-chain enactment involving rsETH. We person paused rsETH contracts crossed mainnet and respective L2s portion we investigate.

We are moving with @LayerZero_Core, @unichain, our auditors and apical information experts connected RCA.

We volition support you…

— Kelp (@KelpDAO) April 18, 2026

The attackers’ enactment connected Aave caused the alleged utilization complaint of a halfway lending excavation to spike to 100%, signaling that users who antecedently deposited Ethereum and wrapped Ethereum person been near with small to nary liquidity to withdraw, Aavescan data showed.

An hr earlier Aave locked down the markets, blockchain information steadfast PeckShield flagged a transaction showing 116,500 rsETH, worthy $291 cardinal astatine the time, flowing to a caller wallet.

The attackers didn’t abscond with rsETH that had been maliciously released from the bridge. Rather, they utilized Aave to get regular funds, creating “massive atrocious debt,” Francesco Andreoli, caput of developer relations astatine Consensys and MetaMask, said successful an X post. (Disclaimer: Consensys is one of galore investors successful an editorially autarkic Decrypt.)

Aave’s governance token plunged to $90.13 connected Sunday, a 16% alteration implicit the past day, according to CoinGecko. Ethereum fell 2% to $2,300 implicit the aforesaid period.

As users struggled to retreat from Aave, they began borrowing against their deposits successful stablecoins, straining the liquidity further arsenic a motion of “negative secondary effects,” said monetsupply.eth, the pseudonymous caput of strategy astatine DeFi task Spark, successful an X post.

The Kelp DAO exploit and ensuing fallout connected Aave prompted a monolithic question of withdrawals from respective DeFi protocols, adjacent those that were unaffected, according to 0xngmi, the pseudonymous co-founder of information supplier DefiLlama. On a nett basis, users had yanked $6.2 cardinal from Aave unsocial by aboriginal Sunday, they said successful an X post.

The Aave concern is atrocious and getting worse. Multiple different pools are hitting 100% utilization, leaving lenders stuck and the protocol astatine hazard of further atrocious debt.

Lending rates person accrued to 10-15%, a notable summation but inactive not an due reward for the perceived…

— Quit (@0xQuit) April 19, 2026

With contagion appearing to spread, DeFi’s latest exploit provides “a batch of ammo” for critics skeptical of systems that question to regenerate accepted fiscal intermediaries with code, Salman Banei, wide counsel astatine Plume, a web focused connected tokenization, said successful an X post.

Kelp DAO issues rsETH, a liquid staking token that allows users to gain Ethereum staking and EigenLayer restaking rewards. It acts arsenic a tradeable “receipt” for Kelp DAO depositors. The Kelp DAO span was built connected apical of infrastructure designed by LayerZero, a protocol that allows DeFi applications to nonstop messages and transportation assets crossed blockchains.

Stacy Muur, a noted blockchain researcher, said successful an X station that the exploit appeared to trust connected a azygous constituent of failure. She wrote that a “phantom” connection utilized by attackers fundamentally tricked Kelp DAO’s span into releasing rsETH connected Ethereum without removing a corresponding magnitude of tokens from circulation connected Ethereum layer-2 Unichain.

Nonetheless, immoderate onlookers were anxious to find a way forward, including crypto entrepreneur and Tron laminitis Justin Sun. He attempted to negotiate, arguing that the attackers would yet conflict to walk the stolen funds.

“How overmuch [do] you want?” helium asked them successful an X post. “It’s simply not worthy it to sacrifice some Aave and Kelp DAO and fto them spell down implicit this hack.”

Daily Debrief Newsletter

Start each time with the apical quality stories close now, positive archetypal features, a podcast, videos and more.

Read Entire Article