Kelp DAO Vulnerability Triggers Exodus of Hundreds of Billions; Two Major DeFi Lending Pathologies Clash Head-On

marsbit2026-05-29 tarihinde yayınlandı2026-05-29 tarihinde güncellendi

Özet

Title: Kelp DAO Exploit Triggers $15 Billion Exodus, Exposing a Clash Between Two DeFi Lending Models. In April 2026, a hacker exploited a LayerZero bridge vulnerability in the Kelp DAO project, minting $292 million in fake rsETH tokens. These were deposited into Aave as collateral to borrow real Ethereum, draining the protocol's liquidity. Within three and a half days, Aave saw $15 billion in deposits flee, forcing a costly $160 million bailout. The root cause was identified as Aave's governance, which had previously voted to set rsETH's loan-to-value ratio to a risky 93%, leaving minimal safety margin. This incident starkly contrasts with the experience of Morpho, the second-largest DeFi lending protocol. Some fake rsETH also flowed into Morpho, but the exposure was limited to $1 million across isolated, pre-configured markets, preventing systemic contagion. The event highlights a fundamental divergence in DeFi lending architectures. Aave employs a shared liquidity pool model, where all deposits back all approved collateral assets, governed by DAO vote. This creates systemic risk, as seen when even users who never interacted with rsETH faced frozen funds. Furthermore, Aave's governance, influenced by leveraged borrowers, prioritized their interests during the crisis, even lowering borrowing rates for frozen markets at the expense of safer depositors. Its supplemental insurance mechanism, Umbrella, also failed as providers withdrew capital when needed. Morpho operates on...

Author: Vaidik Mandloi

Compilation: Saoirse, Foresight News

The underlying principles of all lending protocols in DeFi are largely similar: users deposit stablecoins or Ethereum into a shared liquidity pool, and borrowers draw funds from it after pledging assets; decentralized autonomous organizations (DAOs) vote to decide which assets can serve as collateral and their corresponding loan-to-value (LTV) ratios. Aave has developed a deposit scale of $500 billion precisely by relying on this model. For most of DeFi's development, this has been the industry's sole operating model, and its rationality has never been truly questioned.

However, on April 18, 2026, a hacker exploited a vulnerability in the LayerZero cross-chain bridge of the Kelp DAO project to forge rsETH tokens worth $292 million. The hacker deposited these counterfeit tokens into Aave as collateral to borrow real Ethereum. Within hours, the utilization rates of Aave's major mainstream lending markets reached 100%, meaning all available funds within the protocol had been fully borrowed. Over the next three and a half days, the platform lost $15 billion in deposits. Ultimately, Aave had to collaborate with various ecosystem parties to conduct a rescue, raising $160 million to cover the losses.

Although this vulnerability originated from the Kelp DAO project, the root cause of such massive losses lies in Aave's governance mechanism. As early as January of this year, a community vote decided to raise the collateral factor for rsETH to 93%, leaving only a 7% safety margin for such assets. It was this single decision that brewed one of the largest bank runs in the history of DeFi lending.

On the same day, some of the forged rsETH tokens also flowed into Morpho, the second-largest DeFi lending protocol. However, the risk exposure was only $1 million and dispersed across two independent, small isolated markets, failing to trigger a chain-reaction crisis.

Upon conducting in-depth research into this incident, I discovered that behind this event lies far more than a simple security attack.

Core Differences Between the Two Models

To understand why Aave hemorrhaged billions while Morpho remained largely unscathed, we must first clarify the fund placement and operational logic of the two protocol types.

When you deposit USDC into Aave, the funds flow into a single master liquidity pool, supporting lending activities for all community-approved assets like Ethereum and staked tokens. Depositors cannot choose the type of collateral asset their funds correspond to; all related rules are set by DAO votes. Therefore, when rsETH faced collapse risk, even ordinary users who had only deposited USDC and never touched rsETH found their assets frozen—everyone's funds were in the same risk pool, suffering collective losses.

Source: BingX

More critically, while the market was halted and users couldn't withdraw, Aave's governance layer actually lowered the borrowing rates for the frozen Ethereum markets, aiming to protect borrowers who had leveraged rsETH. Since deposit rates are directly linked to borrowing rates, depositors with the lowest risk and principal security saw their deposit yields shrink further.

In traditional credit systems, lenders with the lowest risk enjoy priority in repayment. However, Aave completely inverted this rule. The reason is that borrowers engaged in rsETH leveraged trading are also the most active voting group in community governance. When risk erupts, high-risk participants holding governance power naturally prioritize protecting their own interests.

Aave launched an insurance mechanism called Umbrella in late 2025, attempting to address such bad debt risks. Users could stake Ethereum; if the protocol incurred bad debts, the staked assets would be used for compensation. However, after the Kelp DAO crisis erupted, 18,922 out of 23,507 staked aWETH positions entered an unstaking waiting period, with nearly 80% of the insurance pool's funds withdrawing collectively.

This mechanism ultimately failed completely. On-chain insurance relies on voluntary user participation, and capital providers inevitably choose to exit when real risk materializes—after all, their assets only face substantial loss when a crisis occurs. This leads to such insurance often existing during peaceful times but becoming ineffective precisely when protection is needed.

Morpho's operational model is entirely different. It abandons the unified shared liquidity pool. Anyone can create an independent, isolated lending market, pre-setting the loan asset, collateral asset, price oracle, and interest rate model. Once parameters are deployed, they cannot be modified. To adjust risk levels, one can only create a new market.

Differences in underlying architecture between the traditional DeFi lending model (represented by Aave) and Morpho's "Morphological" model.

Furthermore, Morpho introduces independent risk management institutions (Stewards), such as Gauntlet and Steakhouse Financial. These entities establish vaults, allocate funds to different markets based on their own analysis, and charge performance fees; if losses occur, they are confined within their own vaults. Gauntlet also provided risk advice for Aave, but in Aave's system, its professional opinions were often overruled by token holders seeking high yields through voting, a situation Morpho prevents at its root.

The Overlooked Hidden Cost

Aave and Morpho are currently the two most widely applied lending models in the crypto space: Aave uses the shared liquidity pool model where all deposits are aggregated, with risk rules set by community votes; Morpho advocates the isolated market model, where each lending pair is independent, with risks managed autonomously by professional institutions.

The Kelp DAO vulnerability exposed the flaws and weaknesses of the shared pool model. But even during stable periods without security incidents, this model harbors a long-overlooked hidden cost. Aave's three core markets on Ethereum (Ethereum, USDT, USDC) contribute 89% of the platform's lending volume. In these three markets, deposit rates are consistently 25% to 35% lower than borrowing rates. This spread essentially represents idle funds lying dormant in the liquidity pool; depositors cannot profit from them, yet borrowers still bear the full borrowing cost.

The interest rate mechanism adjusted based on utilization rates can push rates higher when risk increases but cannot activate idle funds when lending demand is low, leaving large amounts of assets stranded in the pool generating no yield. In these three markets alone, the annual value erosion due to idle funds amounts to approximately $52 million, close to a quarter of Aave's annualized revenue for one quarter. Even zeroing out the reserve ratio and canceling platform fees cannot solve the idle fund issue—it's an inherent shortcoming of the shared pool architecture.

Morpho's interest rate model aims to maintain a utilization rate of around 90%, significantly higher than Aave's 60% to 80% range. This model can sustain high utilization because deposits within the platform are not re-used as collateral for other loans, avoiding chain-liquidation risks at the source and thus eliminating the need to reserve large amounts of capital as a risk buffer. When lending demand is strong and funds are heavily borrowed, rates automatically increase, attracting more depositors; when lending demand is weak, rates decrease, stimulating borrowing. The entire system achieves dynamic balance without requiring community votes.

Source: Gate.com

Actual data confirms its advantage: even after deducting Steward fees, the yield offered to depositors by Morpho's top USDC vaults still exceeds that of Aave and Compound. Currently, Morpho's deposit-to-loan ratio is 41%, while Aave's is 39%, and the former's scale reaches tens of billions of dollars, meaning the yield advantage benefits all depositors on the platform day after day.

Institutional Choice: Which is More Trustworthy?

Surprisingly, all of Coinbase's crypto asset lending services are built on Morpho. The related loan scale has now surpassed $2 billion, and over 100 million platform users are indirectly enjoying the returns provided by Morpho.

Most users aren't even aware they are using DeFi services. Coinbase did not develop its own lending system nor choose another platform. The core reason is that Morpho's underlying architecture allows the platform to independently set risk parameters, select partner risk institutions, and maintain full control over the entire product experience.

Apollo Global Management, a global asset manager with over $1 trillion in assets under management and 30 years of experience in private credit, recently signed a four-year cooperation agreement, planning to acquire up to 90 million MORPHO tokens, accounting for 9% of the total token supply. The institution is connecting its tokenized fund assets to Morpho as collateral, with Gauntlet responsible for vault management and market stress testing.

Beyond that, Anchorage Digital, the first federally chartered native crypto bank in the US, has connected its institutional clients managing hundreds of billions to Morpho vaults; SG-FORGE, the compliant arm of French banking giant Société Générale, is the first licensed bank to implement DeFi lending business through Morpho.

These heavily regulated traditional financial institutions collectively chose Morpho, with a highly consistent core demand: the isolated market model allows them to meet their own compliance and risk control requirements without relying on DAO decisions. In contrast, all market rules in Aave inevitably involve community voting, completely incompatible with institutions' need for autonomous control.

Changes in the regulatory environment have further amplified this trend. The US "GENIUS Act" stipulates that stablecoin issuers cannot directly distribute investment returns, meaning stablecoin institutions require neutral underlying infrastructure to activate vast amounts of idle assets. US-related projections show that by 2028, the scale of stablecoin reserves invested in US Treasury bonds will surge from the current $120 billion to over $1 trillion. This massive pool of capital urgently needs a lending foundation that allows asset custodians to control their own risks, and Morpho is currently the most fitting choice.

İlgili Sorular

QWhat was the root cause of the massive $15 billion deposit outflow from Aave following the Kelp DAO exploit?

AThe root cause was Aave's governance mechanism. Earlier, the community had voted to increase the loan-to-value (LTV) ratio for rsETH to 93%, leaving a very thin safety margin of 7%. When fake rsETH tokens were deposited as collateral, it quickly drained the shared liquidity pool, causing the massive withdrawal.

QWhat is the fundamental difference in the operational models between Aave and Morpho as described in the article?

AAave uses a shared liquidity pool model where all deposits are pooled together to back all approved assets, with rules set by DAO governance. Morpho uses an isolated market model, where each lending market is separate with its own parameters set at creation, managed independently by professional risk stewards.

QWhy did Aave's Umbrella insurance mechanism fail during the crisis, according to the article?

AThe mechanism failed because it relies on voluntary participation. When the crisis hit, nearly 80% of the staked insurance funds (aWETH) entered the unstaking period and were withdrawn. Participants were incentivized to leave to avoid losses, rendering the insurance pool ineffective when it was needed most.

QWhat 'hidden cost' does the shared pool model like Aave's incur during normal market conditions?

AA significant hidden cost is idle capital due to low capital efficiency. In Aave's top three markets, the spread between deposit and borrow rates (25-35%) represents idle funds that earn no yield for depositors but whose cost is still borne by borrowers, leading to an estimated annual value drain of $52 million.

QWhy are regulated traditional financial institutions like Coinbase and Apollo Global Management choosing Morpho over Aave for their DeFi lending operations?

AThey choose Morpho because its isolated market model allows them to set their own risk parameters and choose their risk stewards, giving them full control and compliance. This is essential for meeting regulatory requirements, unlike Aave's model where all market rules are subject to community DAO votes.

İlgili Okumalar

Xiaomi MiMo's 99% Price Cut is Not Marketing! Luo Fuli Posts on X to Refute Critics

The price of Xiaomi's MiMo-V2.5 series API has been permanently reduced by up to 99%, specifically for the "Input (Cache Hit)" cost, which covers users re-reading historical context in long conversations. MiMo's head, Luo Fuli, published a detailed technical blog to clarify that this drastic price cut stems from genuine engineering breakthroughs, not a marketing stunt or a simple price war. The core of the achievement lies in six key engineering optimizations. First, the model architecture adopts a Hybrid Sliding Window Attention (SWA), reducing the memory footprint (KVCache) to 1/7th of a traditional model. Second, a dual-pool memory management system actually utilizes these savings, allowing a single GPU to handle over 5 times more concurrent users. Third, an upgraded prefix caching mechanism achieves a cache hit rate of 93-95% for repeated reads, meaning most such requests bypass GPU computation entirely. Fourth, a self-developed distributed cache (GCache) utilizes idle SSD space on existing GPU servers, eliminating additional storage costs. Fifth, an intelligent scheduling system (LLM-Router) efficiently routes requests to maximize cache reuse and performance. Sixth, Multi-Token Prediction (MTP) accelerates the model's text generation ("output") side. Together, these systemic optimizations dramatically lower the real computational cost per request, enabling the 99% price reduction for cached inputs while reportedly maintaining positive gross margins. Luo Fuli's disclosure aims to shift the narrative from "price war" to a demonstration of substantive AI engineering progress.

marsbit1 saat önce

Xiaomi MiMo's 99% Price Cut is Not Marketing! Luo Fuli Posts on X to Refute Critics

marsbit1 saat önce

$26 Billion: An 'All-Chinese Team' Backs the World's Highest-Valued AI Programming Company

Cognition AI, the company behind the AI programmer "Devin," has raised over $1 billion in new funding at a valuation of $26 billion, just eight months after reaching a $10.2 billion valuation. The round was led by Lux Capital, General Catalyst, and 8VC. Founded by three young Chinese entrepreneurs with strong competitive programming backgrounds, Cognition initially gained fame with Devin, marketed as the world's first AI software engineer capable of handling tasks from start to finish. While its early demos were impressive, real-world usage revealed reliability and cost-effectiveness issues, leading to a significant price cut for Devin in 2025. A pivotal moment came when Cognition acquired the assets of AI IDE company Windsurf after a failed acquisition by OpenAI. This move gave Cognition a crucial developer-facing tool, allowing it to pursue a two-pronged strategy: Devin for autonomous task execution and Windsurf for integrated, collaborative coding within an IDE. This shift helped the company move away from the controversial "AI replacement" narrative towards a model of augmenting human engineers, particularly for repetitive or maintenance tasks. This strategic pivot is backed by strong commercial metrics. The company reports a 10x increase in enterprise usage this year, with an annual revenue run-rate of $492 million and a 50% month-over-month growth in enterprise Devin usage over the past six months. Its client list now includes major corporations like Goldman Sachs and Mercedes-Benz, as well as government agencies like NASA and the U.S. Army. Investors are betting on Cognition becoming a foundational piece of next-generation software engineering infrastructure, positioning it at the center of a hybrid future where AI agents and human developers work in tandem.

marsbit1 saat önce

$26 Billion: An 'All-Chinese Team' Backs the World's Highest-Valued AI Programming Company

marsbit1 saat önce

The Hottest 00s Generation on Wall Street

"Wall Street's Hottest '00s Phenom: The 25-Year-Old Fund Manager Who Bet on AI's 'Boring' Backbone" At just 25, Leopold Aschenbrenner, once fired by OpenAI, now runs a hedge fund worth $13.7 billion. His strategy? Betting against the consensus. While others chased AI chips, he invested early in the physical infrastructure powering the AI boom: electricity, data centers, and energy. Expelled from OpenAI's safety team in 2024, Aschenbrenner foresaw the coming bottleneck. He argued that AI progress would be limited not by algorithms, but by power, chip capacity, and space. Acting on this, he founded Situational Awareness LP to go long on these "old economy" assets. His bets have paid off spectacularly. His fund's assets soared from $255 million in late 2024 to $13.7 billion by Q1 2026. His portfolio is a direct reflection of his thesis: major long positions in fuel cell company Bloom Energy and data center/bitcoin mining firms like CleanSpark and Riot Platforms, which control critical land and power resources. Conversely, he holds massive put options against overheated semiconductor giants like NVIDIA and AMD. A notable exception was his bullish bet on storage company SanDisk, which surged ~160% in Q2. Aschenbrenner's vision is materializing. Tech giants like Amazon, Alphabet, and Meta are ramping up colossal capital expenditure on data centers. Global data center power consumption is projected to skyrocket, with AI accounting for over half by 2030. The demand for enabling technologies like optical fiber and modules is also exploding. His story underscores a fundamental truth of the AI era: the ethereal intelligence of algorithms rests on a very physical, heavy, and power-hungry foundation. The future is being built not just in code, but in concrete, copper, and kilowatts.

marsbit3 saat önce

The Hottest 00s Generation on Wall Street

marsbit3 saat önce

Review of Cathie Wood's Masterstroke Operation on Circle

A Recap of Cathie Wood's Masterful Trading in Circle's IPO This article analyzes the strategic moves made by ARK Invest's Cathie Wood around the IPO of Circle (CRCL). Despite her typical long-term, narrative-driven investment style, Wood executed a textbook "buy low, sell high" trade. Wood secured a core position of approximately 4.49 million shares at the $31 IPO price. The stock debuted at $69, surged to a high of $299 in June 2025 fueled by stablecoin regulatory news (the GENIUS Act), and then entered a prolonged decline. During this rally, ARK systematically sold around 1.7 million shares at an average price near $210, driven partly by internal fund rebalancing rules triggered by the stock's soaring weight. This move locked in substantial profits. As the stock later fell due to lockup expirations, new share issuance, and interest rate concerns—even dipping below $50—Wood began repurchasing shares. Starting in November 2025 around $86, she continued buying on the way down, eventually rebuilding her position to roughly the original size by Q1 2026. Key takeaways include: 1) Having a strong, independent long-term thesis (viewing Circle as critical digital dollar infrastructure). 2) Trading in tranches instead of trying to time exact tops or bottoms. 3) Maintaining strict position-sizing discipline, using rules to force profit-taking and preserve buying power. For most retail investors, chasing the dramatic "pop" at open is dangerous, as the subsequent 83% drawdown showed. Wood's success hinged on pre-IPO access, a clear investment thesis, and disciplined execution.

marsbit5 saat önce

Review of Cathie Wood's Masterstroke Operation on Circle

marsbit5 saat önce

Sharplink CEO: Ethereum's Future is Unfolding Now

In an article titled "Sharplink CEO: Ethereum's Future is Unfolding," Joseph Chalom, a former BlackRock executive and current Sharplink CEO, argues that the current debates surrounding the Ethereum Foundation (EF) and ETH price miss the bigger picture. He asserts that Ethereum's long-term institutional adoption is secured by its foundational strengths: trust, security, and liquidity. Chalom highlights Ethereum's dominance in settling stablecoin value, tokenizing real-world assets (RWA), and facilitating high-value DeFi transactions as evidence of its winning position. He defends the Ethereum Foundation's focus on rigorous protocol development and a decade-long track record of major upgrades (The Merge, EIP-1559, Dencun, etc.), viewing its upcoming technical roadmap as the most ambitious in the industry. Contrary to critics, Chalom posits that Ethereum's decentralization and reliable neutrality are core strengths for institutional adoption, not weaknesses, as they prevent control by any single entity. Drawing a parallel to Amazon's early days, he suggests that ETH's intrinsic value is tied to the expansion of its network, which is poised for a step-change in transaction volume across stablecoins, RWAs, DeFi, and agentic finance. Chalom advocates for a "be greedy when others are fearful" approach, citing historical examples from Warren Buffett and his own experience at BlackRock during the crypto winter. He concludes that while the EF should remain focused on core protocol attributes (CROPS: Censorship Resistance, Capture Resistance, Open Source, Privacy, Security), there is a leadership gap in market outreach. Chalom calls for ecosystem participants, including Sharplink and other key players, to become more vocal advocates to support the coming institutional adoption supercycle, asserting that "Ethereum's future is unfolding now."

marsbit5 saat önce

Sharplink CEO: Ethereum's Future is Unfolding Now

marsbit5 saat önce

İşlemler

Spot
Futures

Popüler Makaleler

DAO Nasıl Satın Alınır

HTX.com’a hoş geldiniz! DAO Maker (DAO) satın alma işlemlerini basit ve kullanışlı bir hâle getirdik. Adım adım açıkladığımız rehberimizi takip ederek kripto yolculuğunuza başlayın. 1. Adım: HTX Hesabınızı OluşturunHTX'te ücretsiz bir hesap açmak için e-posta adresinizi veya telefon numaranızı kullanın. Sorunsuzca kaydolun ve tüm özelliklerin kilidini açın. Hesabımı Aç2. Adım: Kripto Satın Al Bölümüne Gidin ve Ödeme Yönteminizi SeçinKredi/Banka Kartı: Visa veya Mastercard'ınızı kullanarak anında DAO Maker (DAO) satın alın.Bakiye: Sorunsuz bir şekilde işlem yapmak için HTX hesap bakiyenizdeki fonları kullanın.Üçüncü Taraflar: Kullanımı kolaylaştırmak için Google Pay ve Apple Pay gibi popüler ödeme yöntemlerini ekledik.P2P: HTX'teki diğer kullanıcılarla doğrudan işlem yapın.Borsa Dışı (OTC): Yatırımcılar için kişiye özel hizmetler ve rekabetçi döviz kurları sunuyoruz.3. Adım: DAO Maker (DAO) Varlıklarınızı SaklayınDAO Maker (DAO) satın aldıktan sonra HTX hesabınızda saklayın. Alternatif olarak, blok zinciri transferi yoluyla başka bir yere gönderebilir veya diğer kripto para birimlerini takas etmek için kullanabilirsiniz.4. Adım: DAO Maker (DAO) Varlıklarınızla İşlem YapınHTX'in spot piyasasında DAO Maker (DAO) ile kolayca işlemler yapın.Hesabınıza erişin, işlem çiftinizi seçin, işlemlerinizi gerçekleştirin ve gerçek zamanlı olarak izleyin. Hem yeni başlayanlar hem de deneyimli yatırımcılar için kullanıcı dostu bir deneyim sunuyoruz.

172 Toplam GörüntülenmeYayınlanma 2024.12.11Güncellenme 2025.03.21

DAO Nasıl Satın Alınır

Tartışmalar

HTX Topluluğuna hoş geldiniz. Burada, en son platform gelişmeleri hakkında bilgi sahibi olabilir ve profesyonel piyasa görüşlerine erişebilirsiniz. Kullanıcıların DAO (DAO) fiyatı hakkındaki görüşleri aşağıda sunulmaktadır.

活动图片