Coalition Unveils Plan to Mitigate Aave Token Exploit
The aftermath of a $300 million exploit typically doesn't come with a straightforward repair guide. However, DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem stakeholders, is attempting to create one. This coalition has outlined a detailed, step-by-step proposal to restore the backing of rsETH following the Kelp DAO hack earlier this month. The incident triggered the release of over 116,000 unaccounted-for tokens, disrupting DeFi lending markets. The plan, shared on Aave's official X account, resembles a coordinated cleanup effort. It relies heavily on Aave's infrastructure to rectify the damage and stabilize the markets. The exploit was made possible by an attacker who manipulated a vulnerability in rsETH's bridge on April 18. By forging a legitimate-looking message, the attacker deceived the Ethereum side of the system into releasing 116,500 rsETH, creating a large batch of tokens without backing. These tokens were not idle; they were distributed across multiple wallets and utilized across DeFi, with a significant portion used as collateral on Aave and other lending platforms. The issue became systemic when protocols like Aave found themselves holding collateral that was not fully backed. According to the proposal, most of the exploited funds are still active, with approximately 107,000 of the original 116,500 rsETH tied up in positions across Aave and Compound. This presents two pressing issues: restoring the actual backing of rsETH and unwinding the loans created using the extra tokens. DeFi United's proposal aims to address both problems simultaneously. To restore backing, the group claims to have secured sufficient ETH commitments to fully re-collateralize rsETH. The plan is to feed this ETH back into the system in stages, converting it to rsETH and depositing it to ensure the token is fully backed once more. Meanwhile, attention is focused on the lending markets where the damage is most evident. Rather than allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A significant part of this process involves dealing with the positions the attacker opened on Aave – essentially loans backed by rsETH that should not have existed. Instead of waiting for these loans to collapse, the proposal suggests guiding the system to close them in a more controlled manner. By temporarily adjusting how rsETH is valued within the system, those bad positions can be liquidated or closed more smoothly. As these positions are unwound, the underlying assets, such as ETH, can be recovered. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, essentially filling the hole left behind. The process is not without risk, as it depends on governance approvals across multiple chains, the successful deployment of committed funds, and the smooth execution of the unwind. Despite the challenges, the plan represents a more coordinated response than DeFi has often managed in the past. If executed as intended, the ultimate goal is clear: 'rsETH backing is fully restored, and all affected markets are stabilized,' as the proposal states.