More than $5.4 billion in digital assets exited a major decentralized lending protocol on April 19 after an attacker used falsified rsETH tokens as collateral to borrow large amounts of ether (ETH), according to on-chain analytics firm EmberCN. Among those pulling funds was Justin Sun, who withdrew 65,584 ETH worth about $154 million.
The rapid withdrawals cut the platform’s total value locked (TVL) by more than 60% within hours, sparked a sharp liquidity crunch across connected applications, and drove the protocol’s governance token down more than 50% in 24 hours.
How the exploit worked
The incident did not stem from a direct breach of the lending protocol’s smart contracts.
Instead, the attacker exploited weaknesses in the design and support mechanism of rsETH, a token that appeared legitimate on the platform but lacked reliable, verifiable backing. By using these falsified rsETH tokens as collateral, the exploiter was able to borrow valid ETH against effectively unbacked assets.
This created an imbalance between the value of collateral and the value of borrowed funds, raising the risk of substantial bad debt if the loans are not repaid. Market participants quickly began to question the platform’s solvency in a default scenario.
Flight to other defi platforms
The perceived risk triggered an immediate rush to exit. Large holders moved to cut exposure before any losses could be socialized across remaining liquidity providers.
Capital rotated quickly into other decentralized finance platforms, with much of the demand flowing to Spark. As inflows surged, Spark’s ETH deposit rate briefly spiked to around 130% before easing back toward 18% later in the day, highlighting the extreme stress in borrowing markets as users hunted for alternative venues.
On-chain data showed a significant acceleration in transactions between protocols, underscoring how fast liquidity can reallocate under pressure when confidence in a single platform breaks.
Governance token selloff and repricing
Alongside the outflows, the protocol’s governance token suffered a steep selloff, dropping more than 50% over the 24 hours following the event.
That reaction is broadly in line with historical patterns: tokens hit by major exploits tend to see a median price drop of around 60% over six months and rarely return to previous levels. The decline signals that holders are marking down expectations for the protocol’s future fee income and growth, as a smaller asset base typically translates into lower long‑term revenue.
The selling by large capital holders, including the more than $150 million moved by Sun, reflects a defensive strategy: exit before liquidity thins further and before any unresolved bad debt—estimated around $200 million—ends up being absorbed by those who stay.
Systemic risk and echoes of earlier exploits
The speed and scale of the outflows mirror the reaction to the Drift Protocol exploit earlier this year, when TVL dropped from $550 million to under $300 million in less than an hour.
Both episodes highlight how quickly confidence can evaporate in interconnected defi markets when participants fear socialized losses. A single weak point in collateral quality can force a chain reaction across multiple platforms that accept the same or related assets.
Following the Drift incident, at least a dozen other protocols experienced related stress or exploits, underscoring the risk of contagion when synthetic or derivative assets are widely used as collateral.
Collateral quality moves to the forefront
The event has renewed scrutiny of how defi platforms vet and manage collateral, especially tokens that represent synthetic, off‑chain, or cross‑protocol value.
Key design measures now under discussion in the sector include:
- Lower collateral ratios for complex or less transparent assets
- Tighter borrowing limits and caps on exposure to any single collateral type
- Additional risk-layer mechanisms, such as insurance funds or segregated lending markets for higher‑risk tokens
- Stricter verification standards for assets whose backing cannot be fully confirmed on-chain
The core issue is that asset legitimacy is often inferred from integration—being widely supported and usable as collateral—rather than from transparent, verifiable backing. This creates openings for sophisticated exploits that weaponize trust in integrated assets.
What traders are watching now
For those active in defi, the episode reinforces several practical signals and risk checks:
- TVL is not enough: a high TVL can reflect concentration risk as much as strength. Platforms with large, clustered exposures to newer or opaque collateral types may be more attractive targets for attackers.
- Collateral composition matters: reviewing the share of synthetic, derivative, and cross‑chain assets in a protocol’s collateral mix is becoming as important as headline TVL.
- On-chain flows as early warning: unusual capital concentrations, sudden rate spikes (such as Spark’s 130% ETH deposit rate), and rapid shifts in liquidity between platforms can provide earlier signals of stress than traditional news channels.
- Diversification across applications: spreading activity across multiple platforms with different collateral frameworks can reduce the impact of a single protocol failure or collateral design flaw.
Outlook for the affected protocol and wider defi
The affected lending platform now faces three immediate challenges: managing or resolving the bad debt, restoring confidence in its collateral framework, and stabilizing its governance token.
In the broader market, the incident is likely to accelerate moves toward:
- More conservative collateral acceptance policies
- Segmented markets that isolate riskier assets
- Wider use of third‑party or on-chain proof mechanisms to verify backing
As defi continues to integrate increasingly complex assets, the central question is shifting from how much value a protocol holds to how robust and verifiable that value actually is under stress.
Worried about similar exploits? Learn how to protect yourself by understanding crypto security breaches and hacking lessons in depth.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

