Coalition Unveils Plan to Mitigate Aave Token Exploit

In a rare instance, a $300 million shortfall has prompted the creation of a detailed recovery plan. DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem stakeholders, has devised a step-by-step approach to reestablish the backing of rsETH following the Kelp DAO hack that sent shockwaves through DeFi lending markets, resulting in the release of over 116,000 unaccounted-for tokens. The proposal, shared on Aave's official X account, resembles a coordinated recovery effort, relying heavily on Aave's infrastructure to rectify the damage and stabilize the markets. The incident originated on April 18, when an attacker exploited a vulnerability in rsETH's bridge by forging a message that appeared legitimate, tricking the Ethereum side of the system into releasing 116,500 rsETH, creating a large batch of rsETH without backing. These tokens were not dormant; they were distributed across multiple wallets and utilized across DeFi, with a significant portion used as collateral on Aave and other lending platforms. The issue became systemic when protocols like Aave found themselves holding collateral that was not fully backed. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in positions across Aave and Compound. This presents two challenges: restoring the actual backing of rsETH and unwinding the loans created using the extra tokens. DeFi United's proposal aims to address both issues simultaneously. To reestablish backing, the group has secured sufficient ETH commitments to fully re-collateralize rsETH, planning to introduce this ETH into the system in stages, converting it to rsETH, and depositing it back into the system to ensure the token is fully backed. Concurrently, attention shifts to the lending markets where the damage is most evident. Rather than allowing the situation to unfold chaotically, the plan involves carefully unwinding the mess. A significant aspect of this involves addressing the positions the attacker opened on Aave, essentially loans backed by rsETH that should not have existed. Instead of waiting for these loans to collapse, the proposal suggests adjusting the system to enable the closure of these positions in a more controlled manner. Temporarily adjusting rsETH's valuation within the system will facilitate the smooth liquidation or closure of these positions, allowing the recovery of underlying assets like ETH. The proposal estimates this could release around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the resulting gap. The process carries risks, dependent on governance approvals across multiple chains, the successful deployment of committed funds, and the smooth execution of the unwind. However, the plan represents a more coordinated response than DeFi has often achieved in the past. If executed as intended, the ultimate goal is clear: the full restoration of rsETH backing and the stabilization of all affected markets, as stated in the proposal. Further reading: Industry leaders are investing hundreds of millions into a rescue plan for Aave users following a massive crypto hack.