3 min read
Add as a preferred source on Google

Crypto Lending Contracts as External Risks Reach Beyond Smart Contracts

Crypto-collateralized lending fell 16.78% in the second quarter to $56.16 billion, while the Kelp DAO bridge exploit exposed Aave markets to risks outside protocol code.

Mentioned assets
Bridge and vault separated by a damaged verification gate / TokenPost.ai
Bridge and vault separated by a damaged verification gate / TokenPost.ai

Crypto lending contracted in the second quarter as risks tied to bridges, verification networks, price oracles, governance, custody and operational controls continued to shape the sector beyond smart-contract code.

Crypto-collateralized lending fell by $11.33 billion, or 16.78%, during the second quarter to $56.16 billion. Outstanding decentralized-finance borrowing stood at $21.94 billion on July 31, 2026, down 53.45% from its all-time high of $47.13 billion.

The available figures do not confirm a claim that lending total value locked rose more than 55% from the beginning of July to about $56 billion. Lending TVL declined 36% over the comparison period examined in July 2026.

The broader risk became clear on April 18, 2026, when an attacker exploited Kelp DAO’s LayerZero V2 route between Unichain and Ethereum. The route relied on a single decentralized-verification-network attestation and released 116,500 rsETH without a corresponding burn on the source chain.

The tokens were valued at approximately $292 million. The attacker supplied rsETH as collateral on Aave V3 and borrowed other assets. Aave began freezing rsETH and wrsETH reserves at about 3 p.m. ET (19:00 UTC), after the exploit occurred at 1:35 p.m. ET (17:35 UTC).

The incident did not compromise Aave’s smart contracts. The issue originated with the rsETH asset and its bridge configuration, but the resulting tokens entered Aave markets and required emergency freezes and additional risk controls.

The episode shows how lending protocols can inherit weaknesses from assets they accept as collateral. A bridge can create or transfer an asset incorrectly, a verifier can approve an invalid message, an oracle can provide a misleading price, or an issuer can face an operational failure. Each component can affect the value and availability of collateral even when the lending protocol’s own code is functioning as designed.

Aave Labs is also expanding automated security testing alongside conventional reviews and other defensive measures. Testing of Aave V3 and V4 with three artificial-intelligence security tools produced 71 findings. Manual review validated 20 of them, all at low or informational severity, with none confirmed as critical or high severity.

A separate mutation test introduced 304 deliberate code changes into selected V4 contracts. Existing tests detected 271 of the changes, while 33 results were inconclusive because of test-suite timeouts.

Those results show the limits of automated testing as well as its value. The tools can examine a broad range of code quickly, but the findings still require expert review to determine whether they represent valid vulnerabilities or false positives. The available security evidence concerns defensive testing and does not establish that artificial intelligence was used in a successful crypto-lending exploit.

Aave selected six smaller deployments for an orderly wind-down after activity no longer justified continued support. The decision adds to efforts to manage the number of markets that require monitoring, risk parameters and technical maintenance.

For lenders, the key operational questions are whether collateral can be identified, monitored in real time and recovered quickly when an external component fails. The answer depends not only on the lending protocol’s smart contracts, but also on the bridge, verifier, oracle, custodian and issuer connected to the collateral.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…