Four months after North Korea's Lazarus Group drained $292 million through KelpDAO, Aave's total value locked remains 43 percent below pre-hack levels.
Four months after North Korea's Lazarus Group drained $292 million through KelpDAO, Aave's total value locked remains 43 percent below pre-hack levels.

Aave's TVL sits at $14.9 billion, down 43 percent from $26.4 billion before the April 18 KelpDAO hack. According to DefiLlama data, the protocol's TVL peaked at $45.9 billion in October 2025 and ended last year with $55 billion, representing more than half of the DeFi lending sector's total value locked.
North Korea's Lazarus Group exploited a 1-of-1 DVN configuration in KelpDAO's LayerZero bridge integration on April 18, minting 116,500 unbacked rsETH tokens worth approximately $292 million. The attacker deposited roughly 89,567 rsETH — about $221 million — into Aave V3 markets on Ethereum and Arbitrum as collateral, then borrowed approximately 82,650 WETH worth $191 million.
Within two days, Aave's deposits collapsed by more than $8 billion and stablecoin pools hit 100 percent utilization, freezing billions in crypto dollars. TVL bottomed near $11.9 billion in June before partially recovering to current levels.
Aave and partners launched the DeFi United coalition on April 27 to address the shortfall and prevent bad debt propagation. The recovery effort secured commitments including 2,500 stETH from Lido Finance, 5,000 ETH from EtherFi, 5,000 ETH from Aave founder Stani Kulechov, up to 30,000 ETH from Mantle as a three-year credit facility, and 25,000 ETH from the Aave DAO treasury. By April 25, DeFi United had raised approximately $160 million, with industry reports indicating commitments of up to $303 million pending governance approval.
Aave force-liquidated the attacker's positions on Ethereum and Arbitrum on May 6, and replacement collateral flowed into the bridge's reserves in tranches through late May. The AAVE token declined approximately 20 percent on the day after the theft, falling from roughly $115 to below $92. The token currently trades near $89, still slightly below pre-hack levels.
Aave published an official postmortem tracing the exploit to a LayerZero bridge verification failure rather than a bug in its smart contracts. The protocol announced a sweeping review of every asset listed on V3 and a rewrite of its listing standards. Collateral assessments will now evaluate bridges, oracle dependencies, custodians, and operational security alongside traditional financial and smart-contract risks.
The KelpDAO exploit exposed a new class of systemic risk in DeFi: the vulnerability of bridge-dependent collateral. Aave's smart contract security remained intact, yet the protocol incurred significant losses because it accepted collateral whose value derived from an external bridge infrastructure. An exploit in one protocol's bridge can propagate through the broader DeFi sector when that protocol's tokens serve as collateral on other platforms.
Aave's TVL decline from $26.4 billion to $14.9 billion represents an $11.5 billion reduction in available lending liquidity. This contraction affects not only Aave but the broader DeFi lending market that depends on its liquidity base. Compound, the next-largest lending protocol, holds just $1.2 billion in TVL by comparison.
Four months post-exploit, Aave has achieved technical recovery — bad debt has been addressed, markets have reopened, and lending functions operate normally. However, the 43 percent TVL deficit indicates that depositor confidence has not returned to pre-hack levels. The liquidity crunch that followed the attack, more than the bad debt itself, appears to have driven depositors toward exits.
This article is for informational purposes only and does not constitute investment advice.