Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit
A recent exploit of the Kelp DAO and LayerZero bridge has put lending protocol Aave at risk of losing up to $230 million, contingent upon the resolution of the situation. According to a report by Aave Labs and LlamaRisk, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker exploited this setup by creating a forged transfer message, resulting in the creation of new tokens without backing, and the release of 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets, the attacker used 89,567 rsETH as collateral to borrow approximately $190 million in ETH and related assets across Ethereum and Arbitrum, leaving Aave vulnerable to impaired collateral. Aave Labs promptly contained the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now hinges on Kelp's handling of the shortfall, with two possible scenarios: a 15% depegging of rsETH if losses are spread across all holders, resulting in around $124 million in bad debt for Aave, or a more severe impact of roughly $230 million in bad debt if losses are isolated to Layer 2 networks. The exploit stemmed from weaknesses in Kelp's cross-chain message verification using LayerZero, which allowed the attacker to manipulate the process and extract value from the system. The incident has raised concerns about the safety of interconnected DeFi infrastructure and the potential for undercollateralized loans, prompting users to reduce their exposure and withdraw around $6 billion in total value locked from Aave.