As the charts flip from red to green, crypto lending has seen a resurgence of interest after a particularly dismal second quarter.
Figures from Galaxy show that $11.33 billion left the sector in Q2 — partly due to the crisis of confidence in lenders caused by the Kelp DAO hack in April that left users of the most trusted protocol, Aave, unable to access their ETH.
Since the beginning of July, however, total lending value locked has gained more than 55% to sit around $56 billion today.
But that also means the honeypot has grown larger. Can users trust interlinked DeFi lending protocols in the age of AI-assisted hacks, when an exploit from any one protocol can have a series of devastating effects for other protocols connected to it?
Stani Kulechov, founder and chief executive of Aave Labs, tells Magazine the problem is now top of mind.
“When a protocol accepts a token as collateral, it is also accepting that token’s bridge, its verifier configuration, its oracle and its issuer’s operational security.”
And that’s exactly what landed Aave in trouble.
An expanding attack surface
When hackers exploited a Kelp DAO cross-chain route in April, they created 116,500 unbacked rsETH (worth about $290 million at the time), and many of those tokens were posted as collateral to borrow other assets on Aave markets.
Even though Aave’s own contracts were not breached, the protocol still saw deposits fall by around $15 billion in the days after the exploit, and it had to freeze its rsETH and wrsETH markets.
The lending market contracted by 16.78% in Q2. Source: Galaxy
Kulechov says that Aave now takes a more holistic approach to security.
“We rebuilt our approach around that wider view,” he says. “Our starting point is that security can’t stop at the smart contract.” He adds that traditional reviews “missed the risk sitting in the bridges, verifier networks and other infrastructure an asset depends on.”
Related: MiCA is coming for DeFi vaults, but regulation will be difficult
Users of lending protocols will similarly need to judge how exposed a protocol is to external and internal risks.
“Every wrapper, bridge and oracle between the lender and the underlying asset is another place a loan can go wrong,” says Thomas Wu, chief financial officer of Bitcoin-backed lender Ledn.
Sid Powell, co-founder and chief executive of crypto credit platform Maple, tells Magazine that “serious lenders” should assume a borrower can fail at any time and work backward from there.
“What am I holding, where is it, can I see it in real time, and how quickly can I get to it if something breaks?”
When security fails, containment matters
DeFi lender Spark chief executive Sam MacPherson says that beyond smart contracts, the team also reviews governance design, operational security, collateral quality, liquidity management and dependencies across the wider ecosystem.
Spark began phasing out rsETH on SparkLend in January, before the April Kelp exploit, after assessing that “its low usage and revenue” did not justify the “additional risk” created by supporting it.
Kulechov says Aave has introduced similar mechanisms, and every asset is re-reviewed quarterly and “again after any material change.” He says the protocol has already started “an orderly wind-down” on six networks that didn’t meet the chain-level standards.

Lending (TVL) is up over 55% from the end of Q2. Source: DeFiLlama
“No protocol can control the entire ecosystem, but it can control how much of that risk it takes on and how quickly it responds,” Kulechov says.
While preventing failures is the aim, protocols also need procedures in place to respond if something happens, says MacPherson.
“Preventing losses is only part of the challenge. Protocols also need to demonstrate how a loss would be contained if something does go wrong.”
The margin for human error
Shawn Owen, founder and chief executive of SALT Lending, says that human error remains one of the biggest vulnerabilities — and it’s the easiest to overlook.
“A lot of the biggest losses have come down to key management, access controls or someone getting socially engineered, and a smart contract audit won’t catch any of that,” Owen says.
Additional risks materialize when assets are deployed elsewhere to generate interest. Crypto lenders learned that lesson the hard way during 2022’s brutal market unwind, when lenders like Celsius, Voyager and BlockFi all imploded after taking on risks customers either didn’t understand or weren’t expecting.
To minimize the attack surface, Ledn keeps client Bitcoin with qualified custodians rather than lending it out to generate additional yield.
Related: S&P Global brings risk assessments to growing crypto lending vault sector
Wu says every transaction is an additional point where something can go wrong, “so the fewer there are, the lower the risk of a breach.”
“The only way to take those risks off the table is to keep client Bitcoin in segregated custody, with tight controls and as few movements as possible.”
Powell warns that when deposits start coming in faster than a manager can find good places to lend, the pressure to maintain yields can lead to bad choices.
“So they take on a little more risk to get there. Maybe the collateral standards get looser, or they lend to a borrower they’d have turned down a year ago. […] The managers who hold up in a downturn are usually the ones who were willing to say no to capital when they didn’t have a good place to put it.”
Can AI make lending safer?
For all the recent headlines about AI hacks and exploits and agents escaping human control, AI may actually be able to assist in making crypto lending safer.
Aave is already using AI-assisted testing alongside its conventional security processes. It used mutation testing to deliberately introduce bugs into V4 contracts, and its test suites caught 271 of 304 injected vulnerabilities.
In a recent review of its V3 and V4 codebases, three AI security tools generated 71 findings, of which, after manual review, 20 were considered valid. The other 51 showed why human security experts will likely remain employed for some time to come.
AI-Assisted Security Review of Aave V3 & V4. Source Aave
“AI is very good at breadth and speed,” Kulechov says, “but around 70% of the raw findings were false positives, so expert judgment stays essential.”
AI is something of a double-edged sword as its permissions, protocol knowledge and decision-making processes become another potential attack surface.
“As AI agents start managing capital onchain,” Kulechov says, “their permissions, inputs and decision logic become things that need to be secured just like a contract.”
So, as crypto lending grows again, the challenge isn’t just keeping the code secure, but making sure every new part of the puzzle is understood, monitored and contained when something goes wrong.
Magazine: Stablecoins can drain from banks and nations at lightning speed
Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.
Read the full article here


