- Aave’s total value locked (TVL) plunged 43% since the April 18 KelpDAO hack, falling to $14.9 billion — 67% below its 52-week high.
- North Korean Hackers drained KelpDAO and deposited stolen rsETH on Aave as collateral, borrowing real ETH and leaving the protocol with nine-figure bad debt.
- Despite Aave liquidating attacker positions and a coalition restoring collateral by late May, depositor confidence has not returned and TVL continues to lag.
Aave, one of crypto’s largest lending protocols, still has not recovered from the April 18 hack of KelpDAO. The value of all crypto assets in its smart contracts is down 43% since the attack and 67% below its 52-week high, data shows.
KelpDAO users had entrusted $26.4 billion to Aave just prior to the hack, down sharply from the October 2025 peak of $45.9 billion. Only $14.9 billion worth of assets remain in the ecosystem today.
North Korean hackers looted KelpDAO in mid-April, and by accepting KelpDAO tokens as collateral for loans, Aave was left nursing a nine-figure loss. LayerZero, the KelpDAO bridge’s software provider, blamed North Korea within 48 hours — an early call that outside investigators later confirmed.
KelpDAO takes deposits of ETH, stakes on Ethereum‘s blockchain for yield, and issues a tradeable receipt token called rsETH. The thieves parked stolen rsETH on Aave and DeFi/aave-posts-plan-to-restore-rseth-backing/” rel=”noreferrer noopener”>borrowed real ETH against it, leaving Aave and fellow lender Compound with an estimated $246 million of combined bad debt.
Aave forcibly liquidated the attacker’s positions, industry allies rebuilt the missing collateral, and by late May, Aave had declared every market back to normal. Nevertheless, the dollar value of its liquidity pools never recovered.
Aave ended 2025 with $55 billion in TVL, worth more than half of the DeFi lending sector’s total. For a borrower, TVL is not an abstraction — a pool worth 43% less has that much less to lend and much higher volatility.
According to investigators at Chainalysis, North Korea‘s Lazarus Group was probably helping the attackers, while LayerZero’s own post-mortem attributed the operation to a cluster known as TraderTraitor. Within two days of the hack, Aave’s deposits collapsed by more than $8 billion and its stablecoin pools hit 100% utilization, leaving billions of crypto dollars effectively frozen.
On April 27, Aave announced that a new coalition, DeFi United, had pledged enough ETH to restore rsETH’s full backing. It then liquidated the attacker’s positions on Ethereum and Arbitrum on May 6, and replacement collateral flowed into the bridge’s reserves in tranches through late May.
The panic continued even into June, with TVL draining to roughly $11.9 billion before partially recovering. According to its own report, Aave’s contracts, oracles and liquidation mechanics worked exactly as designed, yet North Korea was still able to withdraw money using phony collateral.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- Kraken Launch Crypto-Fiat Debit Card with up to 2% Bitcoin Cashback
- City Forum campaign steals data via Salesforce, ServiceNow guest access
- Citi Bank to Launch Bitcoin Custody+ Service for Clients
- Metaplanet Seeds US Bitcoin Treasury with $132M BTC Deal
- Jane Street Boosts Bitcoin, XRP ETF Holdings in Q2 Filing
