Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit

A recent bridge exploit involving Kelp DAO and LayerZero has put lending protocol Aave at risk of losing up to $230 million, with the outcome dependent on how the situation is resolved. The incident revolves around rsETH, a liquid restaking token issued by KelpDAO, which relies on a bridge mechanism to move tokens between blockchains. An attacker exploited this setup by creating a forged transfer message, resulting in the creation of new tokens without backing. The attacker then used these tokens as collateral to borrow approximately $190 million in ETH and related assets, leaving Aave exposed to potentially impaired collateral. Aave Labs took swift action to contain the risk, freezing rsETH markets and halting new borrowing against the asset. The outcome now depends on how Kelp handles the shortfall, with two possible scenarios: a 15% depegging of rsETH if losses are spread across all holders, resulting in $124 million in bad debt for Aave, or a more severe impact if losses are isolated to Layer 2 networks, resulting in $230 million in bad debt. The exploit highlights weaknesses in Kelp's verification process using LayerZero, which allowed the attacker to manipulate cross-chain messages and extract value from the system. In response, users withdrew around $6 billion in total value locked from Aave, reflecting a broad pullback due to uncertainty. The incident has raised concerns about the safety of interconnected DeFi infrastructure and Aave's indirect exposure to external systems.