The April 18, 2026 exploit of KelpDAO ranks as the most expensive DeFi hack of the year. North Korea’s Lazarus Group executed the attack through a vulnerability in KelpDAO’s LayerZero bridge integration.
The attack vector targeted LayerZero’s Omnichain Fungible Token adapter, which was configured with a 1-of-1 DVN (Decentralized Verifier Network) configuration—a single verifier approving cross-chain messages without additional validation. This configuration deviated from LayerZero’s recommended 2-of-2 standard.
The attacker submitted a forged inbound data packet that minted 116,500 unbacked rsETH tokens, valued at approximately $292 million at the time of the exploit. The minting occurred without corresponding token burns or locks on the source chain.
The attacker deposited approximately 89,567 rsETH—worth roughly $221 million—into Aave V3 markets on Ethereum and Arbitrum as collateral. The attacker then borrowed approximately 82,650 WETH (about $191 million) and smaller amounts of wstETH against this impaired collateral. These positions maintained health factors between 1.01 and 1.03, indicating low probability of full repayment.
The exploit did not compromise Aave’s smart contracts. Aave’s report confirmed that oracles, liquidation mechanisms, and lending logic operated as designed. The damage stemmed entirely from Aave’s acceptance of a bridge-dependent asset whose backing became compromised through an external vulnerability.
Aave’s TVL stood at $26.4 billion immediately prior to the April 18 attack. As of August 18, 2026, Aave’s TVL sits at $14.9 billion, representing a 43% decline from pre-hack levels.
The current TVL stands 67% below the 52-week high of $45.9 billion reached in October 2025. Aave ended 2025 with $55 billion in TVL, representing more than half of the entire DeFi lending sector’s TVL at that time.
Within two days of the hack, Aave’s deposits collapsed by more than $8 billion. Stablecoin pools reached 100% utilization, effectively freezing billions in crypto dollars with no capacity for additional stablecoin withdrawals.
TVL continued to drain through May and into June, bottoming near $11.9 billion before a partial recovery began. The protocol has recovered approximately $3 billion from that June low, a 5.6% gain over the past 30 days, but remains far below pre-hack levels. A pool worth 43% less has proportionally less available for borrowers to draw against, with increased volatility in remaining liquidity.
Aave and partners launched the “DeFi United” coalition on April 27, 2026, to address the shortfall and prevent bad debt propagation.
The recovery effort secured commitments including:
Lido Finance: 2,500 stETH (approximately $5.7 million)
EtherFi: 5,000 ETH
Stani Kulechov (Aave founder): 5,000 ETH
Mantle: Up to 30,000 ETH as a three-year credit facility based on Lido staking yield plus 1%
Aave DAO: 25,000 ETH from treasury (subject to governance vote)
By April 25, DeFi United had raised approximately $160 million. Industry reports indicated commitments of up to $303 million, with much of the capital pending governance approval.
Aave force-liquidated the attacker’s positions on Ethereum and Arbitrum on May 6. Replacement collateral flowed into the bridge’s reserves in tranches through late May. By late May, Aave declared all markets back to normal. However, the trust deficit persisted beyond the technical resolution.
The AAVE token declined approximately 20% on the day following the theft, falling from roughly $115 to below $92. The token currently trades near $89, remaining slightly below pre-hack levels.
Aave published an official postmortem tracing the exploit to a LayerZero bridge verification failure rather than a bug in Aave’s smart contracts.
The protocol announced a sweeping review of every asset listed on V3 and a rewrite of its listing standards. Going forward, collateral assessments will evaluate bridges, oracle dependencies, custodians, and operational security alongside traditional financial and smart-contract risks.
Aave has implemented hundreds of parameter changes to curb exposure and plans to add automated defenses that can instantly strip collateral of borrowing power.
The KelpDAO exploit exposed a new class of systemic risk in DeFi: the vulnerability of bridge-dependent collateral. Aave’s smart contract security remained intact, yet the protocol incurred significant losses because it accepted collateral whose value derived from an external bridge infrastructure.

The incident demonstrates that DeFi composability creates risk vectors beyond individual protocol security. An exploit in one protocol’s bridge can propagate through the ecosystem when that protocol’s tokens serve as collateral on other platforms.
Aave’s TVL decline from $26.4 billion to $14.9 billion represents a $11.5 billion reduction in available lending liquidity. This contraction affects not only Aave but the broader DeFi lending market that depends on its liquidity base.
Four months post-exploit, Aave has achieved technical recovery—bad debt has been addressed, markets have reopened, and lending functions operate normally.
However, the 43% TVL deficit indicates that depositor confidence has not returned to pre-hack levels. The liquidity crunch that followed the attack, more than the bad debt itself, appears to have driven depositors toward exits.
Aave’s position as DeFi’s largest lending protocol by TVL remains intact, with TVL approximately $14.8 billion compared to Compound’s $1.2 billion. However, the protocol has not recovered the deposits it lost, and most withdrawn funds have not returned.
The risk framework overhaul and DeFi United recovery mechanism represent structural changes that may strengthen Aave’s resilience against future bridge-related exploits. Whether these changes restore depositor confidence remains an open question, as TVL recovery has lagged significantly behind technical remediation.