Crypto Lending Rebounds—Focus Shifts to Risk Controls Now
0
0

Crypto lending is rebounding after a painful Q2 marked by collapsing confidence in parts of the DeFi ecosystem. Data cited by Galaxy shows the sector shed $11.33 billion in total value locked (TVL) during Q2 2026, after the Kelp DAO hack in April disrupted access to Aave’s users’ ETH.
Since the start of July, however, lending TVL has climbed more than 55%, reaching roughly $56 billion according to DeFiLlama. The recovery is welcome—but it also raises a sharper question for investors and builders: as lending rails become more interconnected, how do protocols contain damage when one exploited component compromises others?
Key takeaways
- Galaxy estimates crypto lending TVL fell by $11.33 billion in Q2 2026, following the April Kelp DAO incident that affected users on Aave.
- From early July, lending TVL rose more than 55% to about $56 billion, signaling renewed appetite for onchain credit.
- Aave’s founder Stani Kulechov argues that modern lending security can’t stop at smart-contract audits because bridges, verifiers, oracles, and issuers introduce additional risk.
- Executives interviewed emphasize containment: preventing losses is not enough if procedures and dependencies aren’t designed to limit blast radius.
- AI-assisted testing is being used in lending security workflows, but experts warn it still depends heavily on human judgment due to false positives and new attack surfaces.
From Q2 contraction to July rebound
Galaxy’s research, referenced in the report, frames Q2 2026 as a period of accelerated contraction for crypto lending. The $11.33 billion outflow was linked partly to the Kelp DAO hack in April, which led to users of Aave’s most trusted protocol being unable to access their ETH.
That episode didn’t just stress one set of contracts; it exposed how collateral behavior can ripple across interconnected systems. With lending TVL now back above roughly $56 billion—around 55% higher than at the end of Q2, based on DeFiLlama—the sector’s rebound suggests market participants are willing to re-engage. The question, though, is whether lenders and liquidity providers can manage the expanded “attack surface” that interdependence creates.
The Kelp DAO episode highlighted dependency risk
According to Cointelegraph’s earlier coverage, hackers exploited a Kelp DAO cross-chain route in April. The incident produced 116,500 unbacked rsETH tokens (valued at about $290 million at the time), and many of those tokens were used as collateral to borrow assets across Aave markets.
Even though Aave’s own contracts were not directly breached, the protocol experienced substantial fallout. Cointelegraph reported that deposits fell by around $15 billion in the days after the exploit, and Aave froze its rsETH and wrsETH markets in response.
Stani Kulechov, founder and chief executive of Aave Labs, described how the problem extends beyond code. He argued that when a protocol accepts a token as collateral, it is effectively accepting the token’s broader infrastructure—its bridge, its verifier configuration, oracle dependencies, and the operational security of the issuer.
That framing matters for users because it shifts what “security” means in DeFi lending. Rather than treating a protocol’s risk as isolated to its smart contracts, lenders are increasingly evaluated on the reliability of the entire dependency chain that moves value from one system to another.
Containment, governance, and operational readiness
In interviews cited in the piece, multiple lending executives emphasized that robust processes are as important as vulnerability prevention.
Thomas Wu, chief financial officer of Bitcoin-backed lender Ledn, highlighted the practical reality that each wrapper, bridge, and oracle between a lender and the underlying asset creates another place a loan can go wrong. In his view, reducing the number of moving parts can directly reduce exposure, particularly because each additional interaction increases the likelihood of failure.
Ledn’s approach, as described, keeps client Bitcoin with qualified custodians rather than lending it out to generate additional yield. Wu argued that fewer transactions mean fewer opportunities for breaches. His warning was blunt: the only way to remove certain risks is to keep client assets in segregated custody with tight controls and minimal movement.
Maple co-founder and chief executive Sid Powell offered another lens: “serious lenders” should plan as if a borrower can fail at any time, working backward from questions about real-time visibility, asset location, and the speed of response if something breaks. Spark CEO Sam MacPherson similarly pointed to broader responsibility beyond smart contracts—reviewing governance design, operational security, collateral quality, liquidity management, and ecosystem dependencies.
Several examples in the report suggest this is already changing how specific assets are treated. Spark began phasing out rsETH on SparkLend in January, before the April Kelp exploit, after concluding that the token’s low usage and revenue didn’t justify the additional risk of supporting it.
Kulechov said Aave has introduced similar mechanisms, including re-reviewing assets quarterly and again after material changes. He also described an “orderly wind-down” on six networks that didn’t meet chain-level standards, tying the response to measurable operational requirements rather than ad hoc reaction.
Where AI fits—and where it can complicate security
As headlines around AI-driven exploits continue to circulate, the report argues that AI could also help improve crypto lending security—at least when used as a tool inside a disciplined testing and review pipeline.
According to details attributed to Aave, the protocol is using AI-assisted testing alongside conventional security processes. It reportedly used mutation testing to deliberately introduce bugs into V4 contracts, with test suites catching 271 of 304 injected vulnerabilities.
In a recent review of Aave V3 and V4 codebases, three AI security tools reportedly generated 71 findings; after manual review, 20 were considered valid. The remainder—51 items—were presented as examples of why expert oversight is likely to remain essential, because AI is described as strong on breadth and speed but not reliable enough to stand alone.
Kulechov also warned that AI can be a double-edged sword. As AI agents are granted permissions and begin managing capital onchain, their permissions, inputs, and decision logic become additional components that need securing like any other contract element.
That creates a new challenge for the next phase of lending growth. The sector isn’t only trying to keep existing code secure; it must ensure every new “piece of the puzzle”—including automation and AI-assisted decision-making—can be monitored and contained if something goes wrong.
For readers watching the market closely, the next test won’t just be whether lending TVL continues rising, but whether protocols increasingly quantify and manage interdependency risk—especially around bridges, oracles, governance changes, and operational controls—and whether they can demonstrate containment plans when external failures propagate across connected systems.
This article was originally published as Crypto Lending Rebounds—Focus Shifts to Risk Controls Now on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
0
0
Securely connect the portfolio you’re using to start.






