Encrypted lending has rebounded, but the attacks on AI and the associated chain risks remain.
Cointelegraph
47m ago
Ai Focus
Since July, encrypted lending has rebounded by over 55%, with a total locked-up value of approximately $56 billion. However, cross-dependencies between protocols, AI assisted attacks, and human errors continue to increase risks. Institutions such as Aave, Spark, Ledn, and Maple have stated that security audits, asset isolation, and risk mitigation mechanisms are more important than ever.
Helpful
No.Help

Since July, encrypted lending has risen by 55%, but now it also has to face the threat of AI-assisted hacker attacks, as well as the risk of risks spreading in a chain reaction between interrelated protocols. Here’s how to maintain security as much as possible.

As the charts turned from red to green, after a particularly sluggish performance in the second quarter, crypto lending has once again attracted attention.

Data from Galaxy shows that in the second quarter, $11.33 billion in funds flowed out of this sector. Part of the reason was the Kelp DAO hacking incident in April, which triggered a crisis of confidence among borrowers and even prevented users of one of the most trusted protocols, Aave, from withdrawing their ETH.

However, since the beginning of July, the total locked value in the lending sector has grown by more than 55%, and is currently around 56 billion US dollars.

But this also means that the "honey pot" has become even larger. In the era of AI auxiliary hackers, if one protocol is exploited, it could have a series of devastating effects on other protocols connected to it. Can users still trust the interwoven DeFi lending protocols?

Aave Labs Founder and CEO Stani Kulechov told Magazine, that this issue has now become a focal point of attention.

"When a protocol accepts a certain token as collateral, it also accepts the bridge for that token, the validator configuration, the oracle, as well as the operational security of the issuer."

And that is precisely why Aave has gotten into trouble.

The attack surface continues to expand.

When hackers took advantage of a cross-chain path involving Kelp DAO in April, they created 116,500 uncollateralized rsETH tokens (worth approximately $290 million at the time). Many of these tokens were subsequently used as collateral to borrow other assets on the Aave market.

Although the Aave contract itself was not compromised, the protocol still saw a decrease of about $15 billion in deposits within a few days after the vulnerability was exploited, and was forced to freeze its rsETH and wrsETH markets.

The lending market contracted by 16.78% in the second quarter. Source: Galaxy

Kulechov indicates that Aave has now adopted a more holistic approach to security.

"We have rebuilt our approach from a broader perspective," he said. "Our starting point is that security cannot be limited to smart contracts alone." He added that traditional audits "ignore the risks lurking in bridges, verifier networks, and other infrastructure upon which assets depend."

Users of lending protocols also need to assess the extent to which a protocol is exposed to external and internal risks.

Bitcoin-backed Lending Institution Ledn Chief Financial Officer Thomas Wu stated: "Every wrapper, bridge, and oracle between the lender and the underlying assets is another potential point for errors in the loan."

The co-founder and CEO of the encrypted lending platform Maple, Sid Powell, told Magazine that so-called "serious lenders" should assume that borrowers may fail at any time and base their decisions on that premise.

"What do I hold? Where is it placed? Can I see it in real time? If there is a problem, how fast can I get it back?"

When security fails, the ability to contain is very important.

DeFi Borrower Spark CEO Sam MacPherson stated that in addition to smart contracts, the team will also review governance design, operational security, collateral quality, liquidity management, as well as dependencies within the broader ecosystem.

Before the Kelp vulnerability occurred in April, Spark had already begun to gradually stop supporting rsETH on SparkLend as early as January. This was because their assessment was that the “lower usage rate and revenue” of rsETH were not sufficient to offset the “additional risks” associated with supporting it.

Kulechov indicates that Aave has also introduced a similar mechanism, where each asset will be re-evaluated on a quarterly basis and again after any significant changes. He mentioned that the protocol has already begun the "orderly exit" of 6 networks that do not meet the chain-level standards.

Lending ( TVL ) increased by over 55% compared to the end of the second quarter. Source: DeFiLlama

"No protocol can control the entire ecosystem, but it can control how much risk it is willing to take and how quickly it can respond when problems arise," said Kulechov.

MacPherson indicates that although preventing failure is the goal, the protocol also needs to have a contingency plan in place in case of issues.

Preventing losses is just part of the challenge. The protocol also needs to prove how losses will be contained in the event that real problems do arise.

Human error margin

SALT Lending Founder and CEO Shawn Owen stated that human error remains one of the biggest vulnerabilities and is also the most easily overlooked.

When assets are deployed elsewhere to earn interest, additional risks emerge. Crypto lending institutions suffered during the brutal market crash in 2022, when institutions such as Celsius, Voyager, and BlockFi collapsed one after another due to taking on risks that customers did not understand or anticipate.

To minimize the potential impact of attacks, Ledn entrusts customers' Bitcoin to qualified custodians instead of lending it out to generate additional profits.

Wu indicates that each transaction represents another potential point for error, 'so the fewer transactions there are, the lower the risk of encountering vulnerabilities.'

"The only way to eliminate these risks is to keep the client's bitcoins in isolated custody, implement strict controls, and minimize the number of transfers as much as possible."

Powell warns that when the inflow of deposits is so rapid that managers do not have time to find suitable borrowers, the pressure to maintain profits may lead to wrong decisions.

So they are willing to take on a bit more risk in order to achieve their goals. Perhaps the collateral requirements will be relaxed, or they might lend money to borrowers who would have been rejected just a year ago... Managers who are able to hold on during a downturn are usually those who are willing to say no to capital when there is no suitable place to invest it.

AI Can it make lending safer?

Despite the recent news about AI hackers, vulnerability exploits, and out-of-control agents, AI could actually help to enhance the security of encrypted lending.

Aave has been using AI for auxiliary testing outside of the regular security process. This protocol employs mutation testing, deliberately introducing vulnerabilities into the V4 contract, and the test suite identified 271 out of 304 injection vulnerabilities.

In recent reviews of their V3 and V4 codebases, three AI security tools identified a total of 71 issues. After manual verification, 20 of these were deemed valid. The remaining 51 issues also indicate that human security experts will continue to have a role to play in the foreseeable future.

AI Assistance for Aave V3 and V4 security review. Source: Aave

Kulechov indicates that: “AI is outstanding in terms of breadth and speed, but approximately 70% of the initial findings are false positives; therefore, expert judgment remains crucial.”

As the permissions, protocol knowledge, and decision-making processes of AI continue to strengthen, it itself will also become another potential point of attack.

"When AI intelligents start managing capital on the chain," said Kulechov, "their permissions, inputs, and decision-making logic also need to be protected just like contracts."

Therefore, as encrypted lending grows again, the challenge is not only to ensure the security of the code but also to make sure that every new part of this "puzzle" is understood, monitored, and can be contained in case of problems.

《Magazine》: Stablecoins can flow out of banks and countries like lightning.

DeFi

Lending

Hacker attack

Private Key

Self-hosted

Industry

More related content

Here are the events that occurred in today's crypto market.

The U.S. government transferred $770 million in seized bitcoins to Coinbase Prime.

Standard Chartered Bank plans to offer institutional crypto custody services in Singapore

Here are the events that occurred in today's crypto market.

The U.S. government transferred $770 million in seized bitcoins to Coinbase Prime.

Standard Chartered Bank plans to offer institutional crypto custody services in Singapore

Tip
$0
Like
0
Save
0
Views 25
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
The shift to "hedge mode" in encryption forces custodian institutions to rethink multi-chain key management
Project Eleven and Quantus plan to launch Quantus custody support for institutions in the first quarter of 2027, allowing institutions to manage keys and approve transactions through hardware security modules, internal policies, and audit systems. The article points out that as different blockchain networks may adopt various post-quantum cryptography standards, the key issue faced by banks and custodian institutions is whether their key management, approval, and audit systems can adapt to this multi-chain migration.
CoinDesk
·2026-10-08 22:50:51
7
S-Bank will initiate the redemption process for the remaining minority shares of Oma Savings Bank.
S-Bank indicates that after completing the tender offer for Oma Savings Bank, it holds approximately 96.79% of the shares. Therefore, it will initiate the redemption process for the shares of the remaining minority shareholders in accordance with Finnish company law, and plans to facilitate the delisting of Oma Savings Bank from NASDAQ Helsinki when conditions permit and it is reasonable and feasible.
GlobeNewswire
·2026-10-08 22:50:48
7
Waymo receives a $5 billion loan from Blackstone, PIMCO, etc., to expand its Robotaxi business
Alphabet's autonomous driving technology company, Waymo, has completed a $5 billion loan financing, with lenders including PIMCO, Blackstone, and Sixth Street. This is Waymo's first debt financing, and the company says this move will enhance the flexibility of its balance sheet and support its expansion of Robotaxi business in the United States, Europe, and Japan.
TechCrunch
·2026-10-08 22:40:48
8
Tesla's patent for an "electric fan car" adds a lot of suspense to the Roadster launch event
Tesla has postponed the launch event for its new generation of Roadster to October 15th, and a patent for an "electric fan vehicle" disclosed by the United States Patent and Trademark Office has sparked increased speculation about the design and powertrain of this car.
The Block
·2026-10-08 22:40:47
9
Counterpoint Data: Wafer Foundry 2.0 Revenues Reached $96.6 Billion in Q2 2026, a Year-on-Year Increase of 25%
According to Counterpoint Research, the global wafer foundry 2.0 market achieved revenue of $96.6 billion in the second quarter of 2026, a year-on-year increase of 25% and a month-on-month increase of 11%. TSMC contributed 42% of this revenue, with its revenue increasing by 34% year-on-year; institutions also expect that demand for advanced packaging will continue to drive growth in computing-related revenues.
The Block
·2026-10-08 22:40:45
9
View More