Crypto lending rises again… but have they solved the risks?
Crypto lending activity has rebounded since July, with total value locked rising more than 55% to about $56 billion after a sharp contraction in Q2. The sector faces renewed scrutiny over interconnected DeFi risks and new threats such as AI-assisted exploits following high-profile incidents like the April Kelp DAO cross-chain attack that affected Aave users.

Why It Matters
Rising deposits enlarge the potential impact of any future exploit because liquidity and collateral are increasingly interlinked across protocols; that makes systemic vulnerabilities — in bridges, verifiers, oracles and custody — a material concern for lenders and users. How protocols adapt operationally and technically will shape whether the market can grow without repeating past failures.
Key Facts
- Q2 outflows: $11.33 billion left crypto lending in Q2 (Galaxy)
- Post-July recovery: Total value locked in lending up more than 55% to around $56 billion
- Kelp DAO exploit (April): Attackers created 116,500 unbacked rsETH (≈ $290 million at the time)
- Impact on Aave deposits: Aave saw deposits fall by about $15 billion after the Kelp exploit
- Lending market contraction in Q2: 16.78% contraction (Galaxy)
After a weak second quarter that saw $11.33 billion exit crypto lending, the sector has staged a notable recovery: total value locked in lending protocols has climbed by more than 55% since the start of July to roughly $56 billion. The rebound follows a period of shaken confidence triggered in part by an April cross-chain exploit of Kelp DAO that produced a large quantity of unbacked rsETH and disrupted markets tied to that asset.
The Kelp incident highlighted how vulnerabilities outside a protocol’s own smart contracts can cascade through the ecosystem. Attackers minted 116,500 unbacked rsETH (about $290 million at the time), and many of those tokens were used as collateral on Aave, prompting roughly $15 billion of deposits to leave the protocol and forcing Aave to freeze rsETH and wrsETH markets. Industry leaders now stress that custody, bridges, verifier configurations and oracle feeds are all potential failure points when a token is accepted as collateral.
Protocol teams say they have adjusted security practices to reflect that wider attack surface. Aave’s founder Stani Kulechov says the project rebuilt its security posture to go beyond smart-contract reviews and now re-evaluates every asset quarterly and after material changes; Aave has already begun an orderly wind-down on six networks that failed to meet chain-level standards. Other lenders have taken similar steps: Spark began removing rsETH from SparkLend in January citing low usage and excess risk, and firms such as Ledn emphasize keeping client bitcoin with qualified custodians and minimizing on-chain movements to reduce exposure.
Operational failures and human error remain prominent concerns. Executives point to key management, access controls and social engineering as recurring causes of losses that audits may not catch. Lenders also warn against the pressures created when deposit inflows outpace safe deployment opportunities, which can lead managers to lower collateral standards or accept riskier borrowers. At the same time, some teams are turning to AI tools to augment security: Aave reported using AI-assisted mutation testing that flagged most deliberately injected bugs in its V4 tests, and a review of V3/V4 codebases produced 71 findings from three AI security tools prior to manual review.
Keep Reading
Tokenized Stocks Grew 395% in a Year While DeFi Use Stayed Under 3%

Bitcoin Sinks Below $84,000 in Sudden Sell-Off

Greece plans 10% capital gains tax on cryptocurrencies
