DeFi under siege: how one exploit wiped out $13 billion in a single weekend

DeFi under siege: how one exploit wiped out $13 billion in a single weekend

By Cyberlife | CryptoMagazine | 21 Apr 2026


The decentralized finance sector is waking up to one of its worst crises in years. What began as a targeted attack on Kelp DAO's bridge infrastructure on Saturday April 18 has rapidly evolved into a systemic shock, with losses rippling across multiple protocols and chains in ways that are still being fully tallied.

The mechanics were straightforward but devastating. An attacker managed to mint and extract 116,500 rsETH tokens worth roughly $290 million, then immediately deployed them as collateral across several major lending platforms to borrow liquid assets. The problem: the rsETH used as collateral was essentially worthless, backed by nothing. The borrowed assets, however, were very real.

Aave took the biggest hit. Around 53,000 rsETH were deposited on Aave V3 on Ethereum Mainnet, draining approximately 52,458 WETH in loans. A further 30,700 rsETH landed on Aave's Arbitrum markets, generating another $72 million in toxic exposure. Compound was also targeted, absorbing 17,400 rsETH and a potential $40 million loss. The pattern was consistent: hit every money market that accepted rsETH, extract as much liquidity as possible, leave the bad debt behind.

The market reaction was swift and brutal. Aave's token dropped 20% in 48 hours while over $8.4 billion fled the platform. Across DeFi lending as a whole, total TVL collapsed from $99.5 billion to $86.3 billion, a drawdown of $13.2 billion in a matter of hours. The contagion reached Solana too, with protocols like Kamino Finance hitting 100% borrow utilization, effectively freezing withdrawals for liquidity providers.

Three paths forward are being debated. The first involves distributing the loss across all rsETH holders through an 18.5% haircut, with residual bad debt of around $216 million absorbed by Aave's Umbrella buffer and treasury, potentially requiring a sale of $AAVE tokens. The second is a full rsETH collapse, letting the token go to zero and leaving Aave to absorb the entire $341 million shortfall alone. The third, and most complex, would be a pre-attack rollback, reconstructing token distribution via snapshot and reimbursing users based on their pre-hack balances. Given how widely the funds have already moved across chains and protocols, this last option looks more theoretical than practical.

Kelp DAO has yet to issue any formal statement. rsETH redemptions remain frozen. The silence is not helping.

Zooming out, this incident fits an uncomfortable pattern. DeFi in 2026 is experiencing a frequency and severity of exploits that mirrors the bleak landscape of 2022. Attribution to state-sponsored actors like Lazarus Group may be accurate, but naming the attacker does nothing to fix the underlying vulnerabilities. The sector needs deeper security audits, more careful code review, and a slower approach to deployment. That last point matters more than ever as a growing number of teams are now shipping DeFi infrastructure built substantially with AI-generated code, introducing subtle flaws that may not surface until it is too late.

The money can potentially be recovered. The trust is harder to rebuild.

How do you rate this article?

9



CryptoMagazine
CryptoMagazine

All the most important crypto news, before anyone else!

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?