Aave’s 15 September 2026 account explainer describes password-based access, device recovery and optional biometric recovery. The important questions are who can recover access, which permissions exist and how withdrawals are authorized.
Aave Labs introduced its official MCP server on 8 September 2026. It supports protocol queries and unsigned transaction preparation across V3 and V4. The key distinction is between reading data, preparing an action and signing it.
On 25 August 2026 a thin Pendle YT-reUSD tape moved PT-reUSD about 3% and Morpho liquidated roughly $36 million of looped debt in 14 minutes. Lenders were made whole. The lesson is oracle window, LLTV and looping — not a hack.
A $292 million bridge exploit on KelpDAO on April 18, 2026 sent shockwaves through DeFi, triggering a $13 billion TVL outflow across the ecosystem. Here is what happened, how it was exploited, and what the response revealed about DeFi's composability risk.
Chainlink's Cross-Chain Interoperability Protocol saw weekly volume surge 260% to over $1.3 billion in late April 2026. Exchange outflows hit a single-day record of 970,430 LINK, cumulative spot ETF inflows crossed $111.5 million, and CCIP v1.5 enters its final security audit before mainnet.
DeFi's total value locked has rebounded to approach $93 billion in early May 2026, recovering from a sharp decline following KelpDAO's $292 million exploit on 18 April. The recovery reflects stabilising market sentiment and renewed confidence in major protocols including Aave, Lido, and Curve.
The $292M Kelp DAO rsETH exploit spilled across chains as Kamino Finance on Solana saw USDC lending pools reach 100% utilization, with lenders racing to exit before bad debt from bridged rsETH collateral materialized.
Security researchers sounded emergency alerts warning DeFi users to stop interacting with any dApps built on Vercel infrastructure after stolen GitHub and NPM keys raised the possibility of compromised JavaScript served directly to user wallets.
AAVE token fell 16% and $6 billion fled the protocol after attackers used drained rsETH to borrow wrapped ether, leaving Aave assessing its bad debt exposure from one of DeFi's most damaging contagion events.
Firepan HQ has removed the paywall on its professional DeFi vulnerability scanner, citing a dramatic increase in AI-generated smart contract exploits and urging developers to secure codebases before LLM-driven attacks identify weaknesses first.
MetaMask published an extensive threat report documenting a new generation of AI-automated attacks against crypto users, including fake Google security pages, malware targeting 850 browser extensions, and AI agents autonomously generating exploits against DeFi wallets.
Polymarket has posted a $5 million bug bounty on Cantina security marketplace, opening its entire infrastructure — smart contracts, UMA oracle adapters, and web application — to public vulnerability disclosure in one of the largest bug bounties in DeFi history.
Zerion detailed an AI-driven security breach that was contained within 2.5 hours without any user fund losses, then announced a multi-firm security partnership with Blockaid for transaction simulation, ZeroShadow for fund tracing, and ChainPatrol for domain monitoring.
Aave V4 went live on Ethereum on 30 March 2026 with Hub & Spoke accounting, a new liquidation engine, and a user risk premium on borrows. V3 did not disappear. This is the launch recap and who should not migrate yet — not a click-path.
We cover decentralized lending, stablecoins, protocol infrastructure, regulation and security. Each briefing separates reported facts from analysis and links to research that explains the underlying mechanisms.
How can I follow new DeFi articles?
Subscribe to the news RSS feed for newly published stories, browse a topic, or search the publication. Publication dates describe our articles; event dates and source links appear within each report.
How do you verify protocol and regulatory announcements?
We prefer original protocol announcements, governance proposals and official legislative records. We identify issuer claims, distinguish proposals from live changes, and update earlier coverage when a development changes its conclusion.