Crypto Coalition Unveils Plan to Mitigate Aave Token Exploit
Typically, a $300 million shortfall doesn't come with a straightforward solution. However, the group leading the Kelp DAO recovery effort is attempting to create one. DeFi United, a coalition comprising multiple blockchain projects and crypto ecosystem individuals, has devised a detailed, step-by-step plan to reestablish the backing of rsETH following this month's Kelp DAO hack, which had a profound impact on DeFi lending markets and resulted in the release of over 116,000 unaccounted tokens. The proposal, shared on Aave's official X account, resembles a coordinated cleanup operation that relies heavily on Aave's infrastructure to rectify the damage and stabilize the markets. The incident originated on April 18, when an attacker exploited a vulnerability in rsETH's bridge, forging a message that appeared legitimate and tricking the Ethereum side of the system into releasing 116,500 rsETH, thereby creating a large batch of rsETH without backing. These tokens were dispersed across multiple wallets and utilized across DeFi, with a significant portion used as collateral on Aave and other lending platforms. This is where the issue became systemic, as protocols like Aave found themselves holding collateral that was, at least temporarily, not fully backed. According to the proposal, the majority of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in positions across Aave and Compound. This presents two problems to be solved simultaneously: restoring the actual backing of rsETH and unwinding the loans created using the extra tokens. DeFi United's proposal aims to address both aspects of the equation. To reestablish the backing, the group claims to have secured sufficient ETH commitments to fully re-collateralize rsETH. The plan involves feeding this ETH back into the system in stages, converting it to rsETH, and depositing it back into the system to ensure the token is once again fully backed. Concurrently, attention shifts to the lending markets where the damage is most evident. Rather than allowing the situation to unfold chaotically, the plan is to intervene and carefully unwind the mess. A significant part of this involves dealing with the positions the attacker opened on Aave, which are essentially loans backed by rsETH that should not have existed in the first place. Instead of waiting for these loans to collapse, the proposal suggests taking a more controlled approach to close them out. By temporarily adjusting how rsETH is valued within the system, those bad positions can be liquidated or closed more smoothly, enabling the recovery of underlying assets like ETH. The proposal estimates that this could free up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the hole left behind. Although the process carries risks, it hinges on governance approvals across multiple chains, the successful deployment of committed funds, and a smooth execution of the unwind. Nevertheless, the plan reflects a more coordinated response than DeFi has often achieved previously. If executed as intended, the ultimate goal is straightforward: the backing of rsETH is fully restored, and all affected markets are stabilized, as stated in the proposal.