Aave Still Down $8 Billion After Kelp Hack
The hack did not hit Aave’s code, but Kelp’s bridge behind rsETH. According to DefiLlama, deposits are still well below the level before April 18.

Key Takeaways
- Five months after the Kelp hack, Aave is still at $18.1 billion in deposits, 31% below the level before the attack.
- The hack did not hit Aave’s smart contracts, but Kelp DAO’s cross-chain bridge, which released 116,500 rsETH.
- Aave estimated the bad debt at $123.7 million to $230.1 million, while bridged assets and cross-chain bridges expose broader DeFi risks.
Five months after the Kelp hack, Aave is still far below its pre-incident level. Deposits stood at $18.1 billion (€15.5 billion), about 31% lower than the $26.1 billion (€22.4 billion) from the day before the hack, according to DefiLlama. The protocol itself stayed technically intact, but the damage ran through the collateral backing the loans.
What Went Wrong at Kelp
The April 18 attack did not target Aave’s lending code, but Kelp DAO’s cross-chain bridge. Kelp is a liquid restaking protocol, and rsETH is its receipt token. Anyone holding rsETH does not own ether directly, but has a claim on staked ether, and that exact claim was exploited through the bridge.
Attackers manipulated the data feeds the bridge trusted and sent a fake message. That released 116,500 rsETH, worth about $292 million (€251 million), nearly 18% of the total supply. Security firm Halborn linked the breach to a single-verifier setup and hijacked data nodes. Chainalysis attributed the attack to North Korea’s Lazarus Group. So this was not a broken smart contract, but weak security around the bridge.
Impact on Aave
Those unsecured tokens then ended up in lending markets. Attackers deposited 89,567 rsETH on Aave and borrowed about $193 million (€166 million) against it. Aave disabled rsETH in 11 markets within an hour and froze WETH two days later. The protocol itself said its smart contracts were never compromised.
In its incident report, Aave estimated the bad debt at $123.7 million (€106 million) if losses were split evenly. If only the bridged rsETH is counted, that rose to $230.1 million (€197 million). Rival protocols and a recovery plan later filled much of the gap, but depositors came back more slowly than the balance sheet suggested.
Why This Matters More Broadly
The case shows how vulnerable cross-chain setups still are in DeFi. In 2026, hacks on cross-chain bridges have already caused more than $328 million (€281 million) in losses, highlighting the risks around this kind of infrastructure. For European crypto users, that matters because receipt tokens and bridged assets are being used more and more as collateral in lending markets.
That question also keeps coming up outside Aave. Wrapped Bitcoin and similar tokens always add an extra layer between the borrower and the underlying asset. So anyone using those tokens as collateral needs to look not just at the price, but also at the bridge, the number of signers, and whether they are dealing with a claim on another claim.