Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit

A recent bridge exploit involving Kelp DAO and LayerZero has put lending protocol Aave at risk of significant losses, potentially up to $230 million. The incident occurred when an attacker manipulated the bridge mechanism, creating unbacked tokens by forging a transfer message. As a result, approximately 116,500 rsETH were released from the Ethereum-side bridge, with the attacker depositing a substantial portion into Aave as collateral to borrow around $190 million in ETH and related assets. Aave swiftly responded by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The extent of the losses now depends on how Kelp DAO handles the shortfall, with two possible outcomes: a 15% depegging of the rsETH token, resulting in approximately $124 million in bad debt for Aave, or a more severe impact of around $230 million in bad debt if losses are isolated to Layer 2 networks. The exploit highlights weaknesses in Kelp's verification process for cross-chain messages using LayerZero, allowing the attacker to extract value from the system. In response to the incident, users have withdrawn around $6 billion in total value locked from Aave, reflecting a broader pullback as participants reassess the safety of interconnected DeFi infrastructure. Discussions are underway to address potential losses, with Aave's ultimate exposure remaining uncertain as the situation continues to unfold.