A compromised bridge drained nearly $294 million in unbacked rsETH from KelpDAO on April 18. Most DeFi lending protocols scrambled. SparkLend, run by CEO Sam MacPherson, barely flinched.
The reason comes down to something unsexy but effective: rate limits. SparkLend had pre-built caps on how much capital could flow in or out during any given period, a mechanism designed specifically for moments like this one. Those guardrails, combined with reduced rsETH exposure and an oracle killswitch, meant the protocol avoided material losses entirely while competitors watched their balance sheets catch fire.
What happened with KelpDAO
The exploit targeted a LayerZero bridge connected to KelpDAO, siphoning approximately 116,500 rsETH. At the time, that stash was worth between $292 million and $294 million.
Aave, the largest decentralized lending protocol by most measures, was holding substantial rsETH positions when the exploit hit. The result was roughly $195 million in bad debt from unbacked collateral. Aave was forced to freeze markets as a reactive measure, and its total value locked took a sharp hit before partially recovering.
SparkLend, by contrast, had already lowered its rsETH exposure ahead of the incident, maintaining a loan-to-value ratio of 72% on those positions. The protocol’s rate-limited deposit and borrow caps meant that even if market conditions deteriorated rapidly, the damage would be mechanically contained.
How rate limits actually work
MacPherson has described these controls as predetermined risk measures, not reactive patches applied after something goes wrong. The distinction matters. Aave’s market freeze was a manual intervention, a fire alarm pulled after the smoke was already thick. SparkLend’s rate limits were structural, built into the protocol’s architecture before anyone knew KelpDAO would be exploited.
The oracle killswitch added another layer. If price feeds for rsETH became unreliable, SparkLend could halt operations tied to that asset without disrupting the rest of the protocol.
The aftermath told the real story
In the weeks following the exploit, SparkLend accumulated between $1 billion and $1.7 billion in new deposits. The SPK token reflected that sentiment with short-term gains ranging from 50% to 78% after the hack.
Aave’s situation was more painful. Beyond the $195 million in bad debt, the protocol faced a credibility challenge. Aave’s TVL declined significantly before staging a partial recovery.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
13









English (US) ·