The crypto lending sector is experiencing a robust recovery, with total value locked (TVL) rising more than 55% since early July to reach approximately $56 billion. This rebound follows a dismal second quarter during which $11.33 billion exited the sector, driven largely by a crisis of confidence stemming from the April Kelp DAO hack. That exploit resulted in the creation of 116,500 unbacked rsETH tokens, worth about $290 million at the time, which were subsequently posted as collateral on Aave markets. Although Aave’s own contracts remained secure, the protocol saw deposits drop by around $15 billion and was forced to freeze its rsETH and wrsETH markets.

In response to these vulnerabilities, major lending platforms are adopting more holistic security frameworks that extend beyond smart contract audits to include bridge, oracle, and infrastructure risks. Aave founder Stani Kulechov noted that traditional reviews often missed risks sitting in dependent infrastructure, prompting a quarterly re-review process for all assets and an orderly wind-down of six networks that failed chain-level standards. Similarly, Spark began phasing out rsETH in January, prior to the April exploit, due to low usage and revenue not justifying the additional risk. Ledn CFO Thomas Wu emphasized that every wrapper, bridge, and oracle represents another potential point of failure, while SALT Lending CEO Shawn Owen highlighted human error, such as key management failures and social engineering, as critical vulnerabilities that automated audits cannot catch.