Coalition Unveils Technical Plan to Mitigate Aave Token Exploit

Unlike typical scenarios where massive financial shortfalls emerge, this instance has prompted a concerted effort to devise a restoration plan. DeFi United, an alliance of blockchain projects and crypto stakeholders, has put forth a meticulous, step-by-step proposal to revive the rsETH token's backing after a recent Kelp DAO hack sent shockwaves through the DeFi lending ecosystem, releasing over 116,000 unaccounted tokens. The detailed proposal, shared on Aave's official X account, resembles a coordinated recovery operation, heavily reliant on Aave's infrastructure to rectify the damage and stabilize the markets. The incident is traced back to April 18, when an attacker exploited a vulnerability in rsETH's bridge, tricking the Ethereum side into releasing 116,500 rsETH by forging a legitimate message, thus creating a large batch of rsETH without backing. These tokens were not idle; they were dispersed across multiple wallets and utilized across DeFi, with a significant portion used as collateral on Aave and other lending platforms. This is where the issue became systemic: protocols like Aave found themselves holding collateral that was not fully backed, at least temporarily. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in active positions across Aave and Compound. This presents two pressing issues: restoring the actual backing of rsETH and unwinding the loans created using those extra tokens. DeFi United's proposal aims to address both aspects of the equation simultaneously. On the backing side, the group claims to have secured sufficient ETH commitments to fully re-collateralize rsETH. The plan involves feeding this ETH back into the system in stages, converting it to rsETH, and depositing it back into the system so the token is once again fully backed. Meanwhile, attention is focused on the lending markets where the damage is most visible. Instead of allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A significant part of this involves dealing with the positions the attacker opened on Aave, essentially loans backed by rsETH that should not have existed in the first place. Rather than waiting for those loans to collapse on their own, which could cause further market disruption, the proposal suggests nudging the system to enable those bad positions to be liquidated or closed more smoothly. Temporarily adjusting how rsETH is valued inside the system will facilitate the liquidation or closure of these positions, allowing the recovery of underlying assets like ETH. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, essentially filling the hole left behind. The process is not without risk, as it hinges on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind. Nevertheless, the plan reflects a more coordinated response than DeFi has often managed previously. If executed as intended, the ultimate goal is straightforward: the rsETH backing is fully restored, and all affected markets are stabilized, as stated in the proposal. Read more: Industry leaders are investing hundreds of millions into a rescue plan for Aave users after a massive crypto hack.