Surge in Blockchain Lending
The blockchain lending industry grew 55% since early July, re‑emerging after a tough second quarter. This rebound, however, also magnifies risks, especially as AI‑facilitated attacks spread quickly through tightly linked DeFi protocols. The key question remains: can users trust these complex systems today?
Breaking news
Ripple Moves 200 Million XRP Ahead of XRPL Privacy Upgrade
Bitcoin Declines Amid Middle East Tensions and Rising US Treasury Yields
Bitcoin Price Holds Above $82K Despite Mounting Bearish Pressure
Chainlink, Cardano and Solana slide below key support levels after failed ralliesGalaxy Data Highlights Outflows
Galaxy reports that about $11.33 billion left the market in Q2, a sharp drop fueled partly by the Kelp DAO protocol exploit in April. That incident left users of top platforms like Aave unable to access their Ethereum (ETH), shocking the market. Although charts have shifted from red to green, the total value of locked loans rose over 55%, reaching roughly $56 billion now. This financial „leverage” attracts more predators, raising concerns about a potential domino effect across connected protocols.
Aave’s Security Priorities
Stani Kulechov, founder and CEO of Aave Labs, stresses that security has become the top priority. He explains that when a protocol accepts a token as collateral, it implicitly accepts the integrity of the cross‑chain bridge, verifier configuration, oracle, and the token issuer’s operational security. This was why Aave found itself in a delicate situation. When hackers exploited a cross‑chain route in Kelp DAO in April, they created 116,500 uncovered rsETH units, worth about $290 million at the time. Many of these tokens were used as collateral to borrow other assets on Aave. Although Aave’s own contracts were not directly compromised, deposit volume fell by about $15 billion in the days following the incident, forcing the platform to freeze rsETH and wrsETH markets. The overall lending market contracted 16.78% in Q2, according to Galaxy.
Aave’s Holistic Security Approach
Kulechov notes that Aave now adopts a more holistic security approach, rebuilding its strategy around this broad perspective. The starting point is the idea that security does not stop at smart‑contract level. Traditional reviews often miss hidden risks in dependent infrastructure, such as verifier networks or bridges. Thomas Wu, CFO of Ledn, a Bitcoin‑backed lender, adds that users must assess how exposed protocols are to external and internal risks. He stresses that every wrapper, bridge, or oracle between a lender and the underlying asset represents a new potential failure point.
Maple’s Risk Management Advice
Sid Powell, co‑founder and CEO of crypto‑credit platform Maple, suggests serious lenders should assume any loan could default at any moment and plan retroactively from there. She constantly questions what is held, where it is stored, whether it can be visualized in real time, and how quickly it can be accessed in an emergency.
Spark’s Comprehensive Review
Sam MacPherson, CEO of DeFi lender Spark, states that technical teams review not only smart contracts but also governance design, operational security, collateral quality, liquidity management, and ecosystem dependencies. Spark began gradually eliminating rsETH on SparkLend in January, before the April exploit, after assessing that low usage and revenue did not justify the added risk.
Aave’s Ongoing Risk Management
Aave introduced similar mechanisms, re‑evaluating each asset quarterly and restarting the process after any substantial change. The protocol has already initiated an „ordered shutdown” on six networks that did not meet cross‑chain standards. While no protocol can control the entire ecosystem, Kulechov believes it can manage how much risk it accepts and how quickly it responds. MacPherson adds that beyond preventing losses, protocols must demonstrate how losses would be contained in an incident.
Human Error Remains a Major Vulnerability
Shawn Owen, founder of SALT Lending, notes that human error remains one of the biggest vulnerabilities, often overlooked. Many major losses stem from key management issues, access controls, or social engineering—issues that smart‑contract audits cannot detect. Additional risks arise when assets are distributed elsewhere to generate yields, expanding the attack surface.

