Crypto Coalition Unveils Plan to Mitigate Aave Token Exploit
Unlike typical massive financial shortfalls, this one may have a viable repair strategy. DeFi United, an alliance of prominent blockchain projects and crypto ecosystem players, has devised a meticulous, step-by-step plan to revive the backing of rsETH after a recent Kelp DAO breach, which released over 116,000 unaccounted-for tokens into the market. The detailed proposal, shared on Aave's official X account, outlines a coordinated effort to utilize Aave's infrastructure and rectify the damage, thereby stabilizing the markets. This incident originated from an exploit of rsETH's bridge on April 18, where an attacker manipulated the system into releasing 116,500 rsETH by forging a legitimate message, resulting in a large batch of rsETH being created without proper backing. These tokens were not dormant; they were dispersed across multiple wallets and integrated into various DeFi platforms, with a significant portion being used as collateral on Aave and other lending platforms. This is where the issue became systemic: protocols like Aave found themselves holding collateral that was not fully backed, at least temporarily. According to the proposal, the majority of the exploited funds are still active, with approximately 107,000 of the original 116,500 rsETH remaining tied to active positions across Aave and Compound. This presents two concurrent challenges: restoring the actual backing of rsETH and unwinding the loans created using those extra tokens. DeFi United's proposal aims to address both aspects of the problem simultaneously. On the backing side, the group claims to have secured sufficient ETH commitments to fully re-collateralize rsETH. The plan involves gradually feeding this ETH back into the system, converting it to rsETH, and depositing it back into the system to ensure the token is once again fully backed. Concurrently, attention is focused on the lending markets where the damage is most pronounced. Rather than allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A significant aspect of this involves dealing with the positions the attacker opened on Aave, essentially loans backed by rsETH that should not have existed. Instead of waiting for these loans to collapse, which could cause further market disruption, the proposal suggests guiding the system to enable these bad positions to be liquidated or closed more smoothly. In practice, temporarily adjusting how rsETH is valued within the system will facilitate the liquidation or closure of these positions, allowing the recovery of underlying assets like ETH. The proposal estimates this could release around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the gap left behind. Although the process is not without risk, relying on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind, the plan represents a more coordinated response than DeFi has often achieved in the past. If executed as intended, the ultimate goal is clear: 'rsETH backing is fully restored, and all affected markets are stabilized,' as stated in the proposal.