Coalition Unveils Plan to Mitigate $300 Million Token Exploit Impact on Aave Users

The aftermath of a $300 million exploit typically doesn't come with a straightforward solution. However, the group driving the Kelp DAO recovery effort is attempting to devise one. DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem individuals, has put forth a detailed, step-by-step proposal to restore the backing of rsETH following this month's Kelp DAO hack, which significantly impacted DeFi lending markets. The proposal, shared on Aave's official X account, resembles a coordinated cleanup operation, heavily reliant on Aave's infrastructure to rectify the damage and stabilize markets. The incident originated on April 18, when an attacker exploited a vulnerability in rsETH's bridge, tricking the Ethereum side into releasing 116,500 rsETH by forging a legitimate message, thus creating a large batch of rsETH without backing. These tokens were dispersed across multiple wallets and utilized across DeFi, with a substantial portion used as collateral on Aave and other lending platforms. This is where the issue became systemic, as protocols like Aave found themselves holding collateral that wasn't fully backed. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in positions across Aave and Compound. This presents two pressing issues: restoring the actual backing of rsETH and unwinding the loans created using those extra tokens. DeFi United's proposal aims to address both aspects simultaneously. On the backing side, the group claims to have secured enough ETH commitments to fully re-collateralize rsETH, planning to feed that ETH back into the system in stages, converting it to rsETH and depositing it to ensure the token is once again fully backed. Concurrently, attention shifts to the lending markets where the damage is most apparent. Instead of allowing the situation to unfold chaotically, the plan involves carefully unwinding the mess. A significant part of this process entails dealing with the positions the attacker opened on Aave, essentially loans backed by rsETH that shouldn't have existed. Rather than waiting for those loans to collapse, which could cause further market disruption, the proposal suggests intervening to close them in a more controlled manner. By temporarily adjusting how rsETH is valued within the system, those bad positions can be liquidated or closed more smoothly, allowing the underlying assets, such as ETH, to be recovered. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once the collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the hole left behind. The process carries risks, depending on governance approvals across multiple chains, the successful deployment of committed funds, and the smooth execution of the unwind. Nonetheless, the plan represents a more coordinated response than DeFi has often achieved previously. If executed as intended, the ultimate goal is clear: 'rsETH backing is fully restored, and all affected markets are stabilized,' as the proposal states.