After the $16.5 billion in exploits, DeFi is now being forced toward the controls it once resisted
The rsETH crisis resulted in $200 million in bad debt on Aaves books, despite not a single line of its contracts misbehaving. On Apr. 18, attackers that Chainalysis preliminarily linked to Lazarus compromised RPC infrastructure, forced a failover to poisoned nodes via DDoS, and injected false data into a 1-of-1 DVN configuration on KelpDAOs rsETH bridge. The forged message released approximately 116,500 rsETH, and Aaves incident report confirmed that Ethereum accepted nonce 308 while the Unichain source endpoint never advanced past 307. The attacker supplied the compromised rsETH to Aave and borrowed against it, resulting in bad debt and serving as a frame for the current state of DeFis security. Exploiters extracted over $635 million across 28 incidents in April, the worst monthly total in over a year. DefiLlama puts the cumulative historical cost of hacks at $16.5 billion, with $7.7 billion specifically targeting DeFi. The high-profile exploits on Drift and the KelpDAO bridge resulted in DeFi losing nearly $11 bilion in total value locked last month. That contraction occurred as stablecoin rails, tokenized treasuries, and regulated settlement layers gained institutional traction in the same capital markets. DeFi exploiters extracted $635 million across 28 incidents in April, the sectors worst monthly loss in over a year, while