Coalition Unveils Technical Proposal to Mitigate Aave Token Exploit
Typically, a $300 million deficit doesn't come with a straightforward repair guide. However, the group leading the Kelp DAO recovery effort is attempting to create one. DeFi United, a coalition of multiple blockchain projects and crypto ecosystem individuals, has developed a detailed, step-by-step plan to restore the backing of rsETH following this month's Kelp DAO hack, which sent shockwaves through DeFi lending markets and released over 116,000 unaccounted-for tokens. The proposal, shared on Aave's official X account, resembles a coordinated cleanup operation that relies heavily on Aave's infrastructure to rectify the damage and stabilize markets. The incident originated on April 18 when an attacker exploited a vulnerability in rsETH's bridge, forging a message that appeared legitimate and tricking the Ethereum side of the system into releasing 116,500 rsETH, creating a large batch of rsETH without backing. These tokens were then distributed across multiple wallets and deployed throughout DeFi, with a significant portion used as collateral on Aave and other lending platforms. As a result, protocols like Aave found themselves holding collateral that was temporarily under-backed. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in active positions across Aave and Compound. DeFi United's proposal aims to address both the restoration of rsETH's backing and the unwinding of loans created using the extra tokens. The group claims to have secured sufficient ETH commitments to fully re-collateralize rsETH and plans to feed this ETH back into the system in stages, converting it to rsETH and depositing it back into the system to ensure the token is fully backed. Simultaneously, the plan focuses on the lending markets where the damage is most visible, seeking to carefully unwind the mess rather than allowing it to play out chaotically. A key aspect of this involves dealing with the positions the attacker opened on Aave, which are essentially loans backed by rsETH that shouldn't have existed. Instead of waiting for these loans to collapse, the proposal suggests temporarily adjusting how rsETH is valued inside the system to enable these bad positions to be liquidated or closed more smoothly. As these positions are unwound, the underlying assets, such as ETH, can be recovered, potentially freeing up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the hole left behind. Although the process carries risks, including the need for governance approvals across multiple chains and the successful deployment of committed funds, the plan represents a more coordinated response than DeFi has often managed previously. If executed as intended, the ultimate goal is to fully restore rsETH backing and stabilize all affected markets.