Aave Faces Potential $230 Million Loss Following Kelp DAO Bridge Exploit

A recent bridge exploit involving Kelp DAO and LayerZero has put lending protocol Aave at risk of incurring significant losses, potentially up to $230 million, contingent upon the resolution of the situation. The incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker exploited this setup by creating a forged transfer message, resulting in the creation of new tokens without backing and the release of 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets on the open market, the attacker used 89,567 rsETH as collateral to borrow approximately $190 million in ETH and related assets across Ethereum and Arbitrum, leaving Aave vulnerable to collateral with potentially impaired backing. Aave Labs promptly took measures to mitigate the risk, freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall, with estimated losses ranging from $124 million if spread across all rsETH holders to $230 million if isolated to Layer 2 networks. The exploit was made possible by weaknesses in Kelp's verification of cross-chain messages using LayerZero, allowing the attacker to manipulate the process and extract value from the system. In response to the incident, users withdrew around $6 billion in total value locked from Aave, reflecting a broad pullback due to uncertainty. The episode highlights Aave's indirect exposure to external systems, with increased collateral risk, pressure on lending positions, and a decline in deposits as users reassess the safety of interconnected DeFi infrastructure.