Coalition Unveils Plan to Mitigate $300 Million Token Exploit Affecting Aave Users

A $300 million deficit is not typically accompanied by a straightforward repair guide. However, the group leading the Kelp DAO recovery effort is attempting to create one. DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem individuals, has outlined a step-by-step plan to restore the backing of rsETH following this month's Kelp DAO hack, which sent shockwaves through DeFi lending markets after releasing over 116,000 unaccounted-for tokens. The proposal, shared on Aave's official X account, resembles a coordinated cleanup operation, relying heavily on Aave's infrastructure to rectify the damage and stabilize markets. The incident originated on April 18 when an attacker exploited a vulnerability in rsETH's bridge by forging a message that appeared legitimate, tricking the Ethereum side of the system into releasing 116,500 rsETH, making the system believe the funds had moved when they hadn't, and allowing a large batch of rsETH to be created without backing. These tokens were not idle; they were dispersed across multiple wallets and deployed across DeFi, with a significant portion used as collateral on Aave and other lending platforms. This is where the issue became systemic: protocols like Aave found themselves holding collateral that was not fully backed, at least temporarily. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in active positions across Aave and Compound. This presents two problems that need to be addressed simultaneously: restoring the actual backing of rsETH and unwinding the loans created using those extra tokens. DeFi United's proposal aims to tackle both aspects of the equation. On the backing side, the group claims to have secured enough ETH commitments to fully re-collateralize rsETH. The plan involves feeding this ETH back into the system in stages, converting it to rsETH, and depositing it back into the system so the token is once again fully backed. At the same time, attention shifts to the lending markets where the damage is most visible. Instead of allowing things to unfold chaotically, the plan is to intervene and carefully unwind the mess. A significant part of this involves dealing with the positions the attacker opened on Aave, which are essentially loans backed by rsETH that should not have existed in the first place. Rather than waiting for those loans to collapse on their own, which could cause further market disruption, the proposal suggests nudging the system to allow these bad positions to be closed out in a more controlled manner. In practice, temporarily adjusting how rsETH is valued within the system will enable those positions to be liquidated or closed more smoothly. As these positions are unwound, the underlying assets, such as ETH, can be recovered. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it is converted into ETH and used to cover the shortfall created by the exploit, essentially filling the hole left behind. The process is not without risk, as it depends on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind. Nevertheless, the plan reflects a more coordinated response than DeFi has often managed previously. If executed as intended, the ultimate goal is straightforward: 'rsETH backing is fully restored, and all affected markets are stabilized,' as stated in the proposal.