Aave Overhauls Collateral and Listing Standards After KelpDAO Exploit
Aave is an overcollateralized decentralized lending protocol, making asset quality and liquidation liquidity critical to depositor safety. An April exploit targeting KelpDAO's rsETH cross-chain bridge affected about $230 million in assets and exposed Aave to hundreds of millions of dollars in potential bad debt. The incident showed that assessments limited to price and liquidity fail to capture technical risks.
After the incident, Aave temporarily tightened Ether borrowing caps and restricted affected markets. Its WETH markets returned to normal only after progress was made in recovering rsETH. Aave has now announced a comprehensive overhaul of its collateral and listing standards, expanding reviews beyond financial risk to include cybersecurity, cross-chain bridge dependencies and technical architecture. Its CEO also stressed the protocol's resilience after it came under pressure from withdrawals of about $8.45 billion.
All Coverage
5 original reportsThe Backstory
The history behind this eventAave Deploys V4 on Avalanche, Laying Groundwork for Tokenized Credit
Leading decentralized lending protocol Aave has moved aggressively into lending against tokenized real-world assets (RWAs) since deploying V4 on Ethereum in March 2026. As financial institutions seek more onchain infrastructure, the tokenization of assets such as US Treasuries and private credit has become central to the convergence of decentralized finance (DeFi) and traditional finance. Blockchain technology can also improve the liquidity and capital efficiency of those assets.
Aave deployed V4 on Avalanche on July 15, 2026, marking its first expansion beyond Ethereum. The new version introduces a Hub & Spoke architecture designed to improve liquidity. The Avalanche ecosystem is also providing $15 million in performance incentives, to be distributed based on metrics including total value locked, to accelerate the development of lending markets for tokenized real-world assets.
Aave Withstands More Than $8 Billion in Withdrawals, Raising DeFi Risk Concerns
Aave is a major decentralized finance, or DeFi, lending protocol that allows users to deposit assets or borrow against collateral. The stress did not stem from a hack of Aave's smart contracts, but from a vulnerability in an external KelpDAO rsETH bridge. The risk spread through links among collateral, lending and liquidity, highlighting the potential for contagion across DeFi protocols.
In April 2026, a hacker stole about $292 million in rsETH from KelpDAO's LayerZero bridge. Aave subsequently faced about $8.45 billion in withdrawals, but its core protocol remained operational and funds were not frozen across the board. Utilization in some markets nevertheless reached 100%, prompting administrators to urgently freeze individual markets and adjust risk parameters.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →