Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit
A recent bridge exploit targeting Kelp DAO has put lending protocol Aave at risk of incurring significant losses, potentially up to $230 million, as the situation continues to unfold. According to a report published by Aave Labs and LlamaRisk on the Aave governance forum, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker took advantage of this setup by creating a fake transfer message, resulting in the creation of new, unbacked tokens. The attacker then used these tokens as collateral to borrow roughly $190 million in ETH and related assets from Aave, leaving the protocol exposed to potentially impaired collateral. Aave Labs quickly responded by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp DAO handles the shortfall, with two possible scenarios: spreading losses across all rsETH holders, resulting in an estimated 15% depegging and around $124 million in bad debt for Aave, or isolating losses to Layer 2 networks, which would lead to a more severe impact of roughly $230 million in bad debt. The exploit was made possible by weaknesses in Kelp's verification process using LayerZero, allowing the attacker to manipulate cross-chain messages and extract value from the system. This incident has raised concerns about the potential for undercollateralized loans and has led to a significant withdrawal of total value locked from Aave, with around $6 billion being pulled out following the incident. As the situation continues to evolve, Aave's ultimate exposure remains uncertain, with discussions underway with ecosystem participants to address potential losses and the Kelp DAO treasury holding approximately $181 million in assets.