Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit
A recent exploit of the Kelp DAO and LayerZero bridge has put lending protocol Aave at risk of losing up to $230 million. The incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to move tokens between blockchains. An attacker manipulated this setup by creating a forged transfer message, resulting in the creation of new, unbacked tokens. The attacker then used these tokens as collateral to borrow approximately $190 million in ETH and related assets from Aave, exposing the protocol to potentially impaired collateral. Aave swiftly responded by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now hinges on how Kelp DAO addresses the shortfall, with potential losses estimated at $124 million if spread across all rsETH holders, or $230 million if confined to Layer 2 networks. The exploit highlights weaknesses in Kelp's cross-chain message verification process using LayerZero, allowing the attacker to extract value from the system. In response to the incident, users have withdrawn around $6 billion in total value locked from Aave, reflecting a broader pullback due to uncertainty. The episode underscores Aave's indirect exposure to external systems, with increased collateral risk, pressure on lending positions, and a decline in deposits. Discussions are ongoing with ecosystem participants to address potential losses, with Aave's ultimate exposure remaining uncertain.