Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit

A recent exploit of the Kelp DAO and LayerZero bridge has put lending protocol Aave at risk of losing up to $230 million, contingent on the resolution of the situation. According to a report by Aave Labs and LlamaRisk, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker manipulated this setup by creating a forged transfer message, resulting in the creation of new tokens without backing, and releasing 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets, the attacker used 89,567 rsETH as collateral to borrow approximately $190 million in ETH and related assets across Ethereum and Arbitrum, leaving Aave vulnerable to collateral with potentially impaired backing. Aave Labs acted swiftly to mitigate the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall, with two possible scenarios: if losses are spread across all rsETH holders, the token may face a 15% depegging, resulting in around $124 million in bad debt for Aave, or if losses are isolated to Layer 2 networks, the impact could be more severe, with bad debt rising to approximately $230 million. The exploit stemmed from weaknesses in Kelp's verification of cross-chain messages using LayerZero, allowing the attacker to make certain assets appear fully backed when they were not. This incident has raised concerns about the potential for undercollateralized loans and has led to a significant withdrawal of around $6 billion in total value locked from Aave. The episode highlights Aave's indirect exposure to external systems, with increased collateral risk, pressure on lending positions, and a decline in deposits as users reassess the safety of interconnected DeFi infrastructure.