Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit

A recent exploit of the Kelp DAO and LayerZero bridge has put lending protocol Aave at risk of losses totaling up to $230 million, contingent upon the resolution of the situation. According to a report published by Aave Labs and LlamaRisk on the Aave governance forum, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker exploited this setup by creating a forged transfer message that appeared legitimate, resulting in the creation of new tokens without backing, with 116,500 rsETH being released from the Ethereum-side bridge. Instead of selling the assets, the attacker used 89,567 rsETH as collateral to borrow approximately $190 million in ETH and related assets across Ethereum and Arbitrum, leaving Aave vulnerable to collateral with potentially impaired backing. Aave Labs responded swiftly to mitigate the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on Kelp's handling of the shortfall, with estimated losses ranging from $124 million if spread across all rsETH holders to $230 million if isolated to Layer 2 networks. The exploit was made possible by weaknesses in Kelp's verification of cross-chain messages using LayerZero, allowing the attacker to manipulate the process and extract value from the system. This incident has raised concerns about the potential for undercollateralized loans and has led to a significant withdrawal of around $6 billion in total value locked from Aave, highlighting the platform's indirect exposure to external systems and the need for robust risk management.