Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit

A recent bridge exploit targeting Kelp DAO and LayerZero has put lending protocol Aave at risk of losing up to $230 million, contingent upon the resolution of the situation. According to a report published by Aave Labs and LlamaRisk on the Aave governance forum, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker manipulated this setup by creating a forged transfer message, resulting in the creation of new tokens without backing. The attacker then deposited these tokens into Aave as collateral and borrowed approximately $190 million in ETH and related assets, leaving Aave vulnerable to collateral with potentially impaired backing. In response, Aave Labs swiftly contained the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now depends largely on how Kelp handles the shortfall, with potential losses ranging from $124 million if spread across all rsETH holders to $230 million if isolated to Layer 2 networks. The exploit was made possible by weaknesses in Kelp's verification of cross-chain messages using LayerZero, allowing the attacker to manipulate the process and extract value from the system. As a result, concerns have been raised about the potential for undercollateralized loans, prompting users to reduce their exposure and withdraw around $6 billion in total value locked from Aave. The incident highlights Aave's indirect exposure to external systems, with increased collateral risk, pressure on lending positions, and a decline in deposits. Discussions are underway to address potential losses, with the report stating that the DAO treasury holds approximately $181 million in assets.