TL;DR
- The crypto lending market has grown by more than 55% since July, reaching approximately $56 billion in total value locked.
- The Kelp DAO exploit exposed vulnerabilities across interconnected DeFi protocols and triggered a $15 billion decline in Aave deposits.
- Aave has started using artificial intelligence to detect vulnerabilities, although nearly 70% of the initial findings were false positives.
The crypto lending market has rebounded by more than 55% since July, reaching approximately $56 billion in total value locked (TVL), according to data from DeFiLlama.
The recovery followed a second quarter in which the sector lost $11.33 billion, according to Galaxy. Part of that decline was linked to the Kelp DAO exploit, which affected Aave users and exposed the risks associated with interconnected protocols.
The recovery also brings new security challenges, particularly as artificial intelligence is increasingly used to identify and exploit vulnerabilities.
Kelp DAO Exploit Exposed Risks in Crypto Lending
In April, an exploit targeting Kelp DAO’s cross-chain infrastructure allowed attackers to create 116,500 unbacked rsETH tokens, worth approximately $290 million at the time.
Some of these tokens were used as collateral to borrow funds on Aave. Although its smart contracts were not directly compromised, the protocol experienced a decline of nearly $15 billion in deposits and had to freeze its rsETH and wrsETH markets.
Stani Kulechov, founder of Aave Labs, explained that security in the crypto industry must also cover the bridges, oracles, and external systems on which assets accepted as collateral depend.
Aave began reviewing each asset quarterly and announced the gradual wind-down of operations across six networks that failed to meet its standards.
The Double-Edged Sword of Artificial Intelligence
Aave has incorporated artificial intelligence tools into its security processes to identify potential flaws in its smart contracts.
During a test of its V4 version, the systems detected 271 of the 304 deliberately introduced vulnerabilities.
In another review of the V3 and V4 versions, three AI tools identified 71 potential issues, but only 20 were deemed valid following a manual assessment.
Kulechov warned that approximately 70% of the initial findings were false positives, making human oversight essential.
Meanwhile, Shawn Owen, CEO of SALT Lending, noted that key management, access controls, and social engineering remain major sources of cryptocurrency losses.
Thomas Wu, chief financial officer of Ledn, recommended keeping clients’ Bitcoin in segregated custody and reducing unnecessary transfers to limit exposure to potential attacks.







