Aave Faces Potential Losses of Up to $230 Million Due to Kelp DAO Bridge Exploit
A recent bridge exploit involving Kelp DAO and LayerZero has put Aave, a lending protocol, at risk of losing up to $230 million, depending on the resolution. The incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to transfer tokens between blockchains. An attacker manipulated this setup by forging a valid transfer message, resulting in the creation of new tokens without backing, and releasing 116,500 rsETH from the Ethereum-side bridge. Instead of selling the assets, the attacker used 89,567 rsETH as collateral to borrow approximately $190 million in ETH and related assets across Ethereum and Arbitrum, exposing Aave to potentially impaired collateral. Aave Labs swiftly contained the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on Kelp's handling of the shortfall. If losses are spread across all rsETH holders, the token would face an estimated 15% depegging, resulting in around $124 million in bad debt for Aave. However, if losses are isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million, primarily affecting networks like Arbitrum and Mantle. The exploit stemmed from weaknesses in Kelp's cross-chain message verification using LayerZero, allowing the attacker to manipulate the process and extract value from the system. The incident has raised concerns about mispriced or undercollateralized loans and has led to a significant withdrawal of around $6 billion in total value locked from Aave. The report highlights Aave's indirect exposure to external systems, resulting in increased collateral risk, pressure on lending positions, and a decline in deposits. Discussions are underway with ecosystem participants to address potential losses, with Aave's ultimate exposure uncertain as the situation continues to unfold.