Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit
A devastating bridge exploit targeting Kelp DAO and LayerZero has put lending protocol Aave at risk of suffering losses of up to $230 million. The incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker manipulated this setup by forging a valid-looking transfer message, resulting in the creation of new, unbacked tokens. The perpetrator then deposited a significant portion of these tokens into Aave as collateral and borrowed approximately $190 million in ETH and related assets. In response, Aave swiftly contained the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now hinges on how Kelp handles the shortfall, with potential losses ranging from $124 million if spread across all rsETH holders to $230 million if confined to Layer 2 networks. The exploit exposed weaknesses in Kelp's cross-chain message verification process using LayerZero, allowing the attacker to extract value from the system. This incident has raised concerns about the potential for undercollateralized loans and highlighted Aave's indirect exposure to external systems, leading to a significant decline in deposits as users reassess the safety of interconnected DeFi infrastructure.