Aave faced record withdrawals after KelpDAO exploit, raising scrutiny over DeFi risk

Aave faced record withdrawals after KelpDAO exploit, raising scrutiny over DeFi risk

Aave has proposed a stricter protocol-wide risk framework for token listings, bridges, chain deployments and automated monitoring after the $292 million KelpDAO exploit exposed cross-protocol contagion risks.

AAVE
WETH
RSETH

Fact Check
All key claim elements are corroborated across multiple independent sources. CoinDesk (the originating piece) and crypto.news report the $8.45B withdrawal figure and Kulechov's Proof of Talk remarks. Chainalysis's forensic blog independently confirms the $292M KelpDAO LayerZero bridge exploit on April 18, 2026. Cryptobriefing's contemporaneous April 20, 2026 report independently confirms the $8.45B drop in Aave TVL. LlamaRisk's ~$123.7M bad debt figure (cited in crypto.news and BlockBeats) supports the claim that independent data pointed to bad debt and risk architecture concerns.
Summary

Aave, the largest DeFi lending platform, has proposed a stricter risk framework after KelpDAO’s LayerZero-powered bridge was exploited for about $292 million in April, an event that triggered as much as $8.45 billion in deposit withdrawals from Aave within 48 hours. The attack spilled into Aave V3 when the exploiter deposited a significant portion of the stolen 116,500 rsETH tokens as collateral and borrowed substantial amounts of WETH, heightening the risk of bad debt on the protocol; independent data said about $123.7 million in wETH bad debt was left on Aave V3. Prepared by LlamaRisk and now open to Aave governance review, the proposal would tighten standards for asset listings, bridges, chain deployments and automated monitoring across Aave V3, V4 and Aave Horizon.

Terms & Concepts
  • bad debt: Losses a protocol cannot recover after collateral and other protections fail to cover obligations.
  • Aave V3: The third major version of Aave’s decentralized lending market.
  • bridging risk: The possibility that vulnerabilities in cross-chain transfer systems could cause losses or spread stress between protocols.