Crypto Coalition Unveils Technical Plan to Mitigate Aave Token Exploit

The aftermath of a $300 million exploit typically doesn't come with a straightforward repair guide. However, DeFi United, a coalition of multiple blockchain projects and crypto ecosystem individuals, has outlined a detailed, step-by-step plan to restore the backing of rsETH following the recent Kelp DAO hack, which released over 116,000 unaccounted-for tokens and disrupted DeFi lending markets. The proposal, shared on Aave's official X account, resembles a coordinated recovery effort, relying heavily on Aave's infrastructure to rectify the damage and stabilize the markets. The incident began on April 18, when an attacker exploited a vulnerability in rsETH's bridge, forging a legitimate-looking message that tricked the Ethereum side into releasing 116,500 rsETH, creating a large batch of tokens without backing. These tokens were not idle; they were distributed across multiple wallets and used across DeFi, with a significant portion used as collateral on Aave and other lending platforms, causing the problem to become systemic: protocols like Aave found themselves holding collateral that was temporarily unbacked. According to the proposal, most of the exploited funds remain active, with roughly 107,000 of the original 116,500 rsETH still tied up in positions across Aave and Compound. This leaves two problems to solve: restoring rsETH's backing and unwinding the loans created using the extra tokens. DeFi United's proposal aims to tackle both issues simultaneously. To restore backing, the group claims to have secured enough ETH commitments to fully re-collateralize rsETH, which will be fed back into the system in stages, converting it to rsETH and depositing it back into the system to ensure the token is fully backed. Meanwhile, attention shifts to the lending markets where the damage is most visible. Instead of allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A key part of this involves addressing the positions the attacker opened on Aave, which are essentially loans backed by rsETH that should not have existed. Rather than waiting for these loans to collapse on their own, potentially causing further market disruption, the proposal suggests adjusting the system to enable these bad positions to be closed out in a more controlled manner. By temporarily adjusting rsETH's valuation within the system, those positions can be liquidated or closed more smoothly, allowing the underlying assets, such as ETH, to be recovered. The proposal estimates this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the hole left behind. The process is not without risk, as it depends on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind. Nevertheless, the plan represents a more coordinated response than DeFi has often managed in the past. If executed as intended, the ultimate goal is clear: "rsETH backing is fully restored, and all affected markets are stabilized," as the proposal states. Read more: Industry leaders are investing hundreds of millions into a rescue plan for Aave users following a massive crypto hack