Crypto Coalition Unveils Technical Proposal to Mitigate Aave Token Exploit

Typically, a $300 million shortfall doesn't come with a straightforward solution. However, the group leading the Kelp DAO recovery effort is attempting to devise one. DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem stakeholders, has devised a detailed, step-by-step proposal to restore rsETH backing following this month's Kelp DAO hack, which sent shockwaves through DeFi lending markets and released over 116,000 unaccounted tokens. The proposal, shared on Aave's official X account, resembles a coordinated cleanup operation, relying heavily on Aave's infrastructure to rectify the damage and stabilize markets. The incident originated on April 18, when an attacker exploited a vulnerability in rsETH's bridge, forging a message that appeared legitimate and tricking the Ethereum side of the system into releasing 116,500 rsETH, creating a large batch of rsETH without backing. These tokens were then dispersed across multiple wallets and deployed across DeFi, with a significant portion used as collateral on Aave and other lending platforms. As a result, protocols like Aave found themselves holding collateral that was temporarily under-backed. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in active positions across Aave and Compound. This presents two concurrent challenges: restoring rsETH's actual backing and unwinding the loans created using those extra tokens. DeFi United's proposal aims to address both aspects simultaneously. To restore backing, the group has secured sufficient ETH commitments to fully re-collateralize rsETH, which will be fed back into the system in stages, converting it to rsETH and depositing it back into the system to ensure the token is fully backed. Concurrently, attention will shift to the lending markets where the damage is most visible. Rather than allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A key aspect of this involves dealing with the positions the attacker opened on Aave, which are essentially loans backed by rsETH that should not have existed. Instead of waiting for these loans to collapse, the proposal suggests nudging the system to enable their closure in a more controlled manner. By temporarily adjusting rsETH's valuation within the system, those bad positions can be liquidated or closed more smoothly, allowing the underlying assets, such as ETH, to be recovered. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the resulting hole. Although the process is not without risk, relying on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind, the plan represents a more coordinated response than DeFi has often managed previously. If executed as intended, the ultimate goal is straightforward: 'rsETH backing is fully restored, and all affected markets are stabilized,' as the proposal states.