Five months after the April hack of Kelp DAO, Aave has still not recovered the deposits it lost. Total value locked on the lending protocol stood at 18.1 billion USD this week, roughly 31 percent below the 26.1 billion USD it held the day before the attack, according to DefiLlama. The gap of about 8 billion USD has narrowed since summer, when deposits bottomed around 12.5 billion USD at the end of June, but the recovery is clearly incomplete.
The strange part of the story is that Aave’s own code never failed. What failed was the collateral behind its loans, in a place its loan contracts could not check.
## What the Kelp hack actually broke
On April 18, attackers went after how Kelp DAO’s cross-chain bridge verified incoming messages, not at any lending logic. Kelp is a liquid restaking protocol, and rsETH is its receipt token. An rsETH holder does not hold ether directly; they hold a claim on staked ether, and that claim crossed a bridge before it reached a lending market.
The attackers corrupted the data feeds the bridge trusted and pushed a fake message through it. The result was the release of 116,500 rsETH, worth about 292 million USD and close to 18 percent of the token’s supply, with nothing behind it. Security firm Halborn traced the theft to a single-verifier setup and hijacked data nodes. Chainalysis linked the attackers to North Korea’s Lazarus Group. No Aave contract was broken at any point; supply, repayment and liquidation mechanisms kept functioning as designed.
The unbacked tokens then walked into lending markets. The attackers supplied 89,567 rsETH on Aave and borrowed roughly 193 million USD against it. Aave froze rsETH across eleven markets within the hour and froze WETH two days later. AAVE dropped around 20 percent in a day amid whale selling and a record spike in ETH utilization across the protocol.
Aave’s incident report put the bad debt at 123.7 million USD if losses were spread evenly across positions. Isolating the bridged rsETH pushed the estimate to 230.1 million USD.
## How the hole got filled
Rival protocols covered much of the shortfall. A coalition-funded recovery plan gathered about 69,570 ETH in pledges against a 75,081 ETH shortfall. Arbitrum’s Security Council froze 30,765 ETH of the stolen proceeds, and the Arbitrum DAO released that sum to Aave in June. One complication remains: a US court order sought by creditors holding judgments against North Korea still hangs over part of the money.
The balance sheet has healed faster than depositor trust. From 12.5 billion USD at the end of June, deposits climbed to 18.1 billion USD this week, meaning most of the flight has reversed. But the last 8 billion USD is the hardest, because those are the depositors who watched a supply-side asset turn out to be a bridge counterparty in disguise, and who now price that risk into every receipt token they post.
AAVE trades near 124 USD, down 3.8 percent on the day, and remains well below pre-incident levels.
## The receipt token problem is bigger than Aave
The uncomfortable lesson is that the same structure sits throughout DeFi. Wrapped Bitcoin, liquid staking tokens and other receipt assets all place something between a borrower and the underlying asset. Aave itself just activated new emergency powers that let it freeze markets in seconds, a direct response to how fast the rsETH incident moved. But freezing is a blunt instrument, as the protocol’s own community noted when debating whether those powers should ever be used to unfreeze.
Three questions are worth asking before posting any receipt token as collateral. How many independent parties must sign off on the token’s bridge, and is the answer one? Whether the lending market is isolated or shares losses with its neighbors. And whether the collateral is a claim on another claim, which doubles the number of things that must not break.
April answered none of those questions for the borrowers who lost access. It demonstrated the cost of not asking.
## What recovery looks like from here
Aave’s slow rebound is arguably the healthier signal for DeFi than a quick one. Deposits returning to within 31 percent of the pre-hack level, after an incident that put nine figures of bad debt on the books, shows a market that distinguishes between a protocol failure and a collateral failure. The protocol’s contracts did their job, the freeze worked, rivals and the Arbitrum DAO backstopped the gap, and the token still trades with real liquidity.
The 8 billion USD that has not come back functions as a standing price on bridge risk. Every new restaking token, every wrapped asset and every cross-chain receipt now competes against a memory of what a single verifier and a few hijacked nodes could do to the largest lender in DeFi. Until that discount closes, Aave’s recovery is real but unfinished.
Prices at the time of writing: BTC 78,500 USD, ETH 2,496 USD, SOL 104 USD.
18.1b tvl and they call this a recovery lol. still 8 billion short of where aave sat the day before kelp got drained
exactly. people blame aave like auditors can somehow verify collateral on every remote protocol it hooks into
auditors cannot verify remote collateral, sure, but Aave could have capped bridged LST exposure earlier. isolation was the fix that arrived one hack late
69,570 ETH pledged against 75,081 needed, covered mostly by rival protocols. that part deserves more attention than the TVL chart honestly
wildest part is Aaves code worked exactly as written. the bridge feed lied and the lending market believed it. oracles and bridges are the real attack surface, not the lending logic
single verifier plus hijacked data nodes, and the industry response was more audits of lending contracts. the bridge was the weak link in april and it still is
bridge-verified messages feeding collateral data is exactly the failure mode people flagged in the march oracle postmortems. nobody changed anything
What everyone misses: Aave itself never failed. The collateral broke somewhere its loan contracts could not even inspect. Hard to patch what you cannot see.
18.1B TVL and still 8B short of the pre-attack 26.1B. people frame the recovery curve as a victory lap when its mostly inertia drifting back
26.1b included a lot of Kelp-looped leverage that can never come back the same way. 18.1b might be the honest number, not a failure state
honest number is doing a lot of work there lol. if the 26.1b was fake leverage then every pre-hack TVL chart we quote is inflated too, cant have it both ways
31 percent under the pre-attack number and people post the TVL chart like a comeback story. the sticky 8B left when trust did
bounced from 12.5b at the june lows to 18.1b, that is real inflows, but most of it is mercenary yield farmers rotating back. the sticky deposits are still gone
116,500 rsETH minted off one fake message, worth 292M, and it took months for anyone to call this a bridge problem instead of an Aave problem. headline game is wild