
Aave has proposed a stricter protocol-wide risk framework for token listings, bridges, chain deployments and automated monitoring after the $292 million KelpDAO exploit exposed cross-protocol contagion risks.
Aave, the largest DeFi lending platform, has proposed a stricter risk framework after KelpDAO’s LayerZero-powered bridge was exploited for about $292 million in April, an event that triggered as much as $8.45 billion in deposit withdrawals from Aave within 48 hours. The attack spilled into Aave V3 when the exploiter deposited a significant portion of the stolen 116,500 rsETH tokens as collateral and borrowed substantial amounts of WETH, heightening the risk of bad debt on the protocol; independent data said about $123.7 million in wETH bad debt was left on Aave V3. Prepared by LlamaRisk and now open to Aave governance review, the proposal would tighten standards for asset listings, bridges, chain deployments and automated monitoring across Aave V3, V4 and Aave Horizon.