Crypto Coalition Unveils Technical Proposal to Mitigate Aave Token Exploit

Typically, a $300 million shortfall doesn't come with a straightforward repair guide. However, the group leading the Kelp DAO recovery effort is attempting to create one. DeFi United, a coalition of multiple blockchain projects and crypto ecosystem individuals, has devised a detailed, step-by-step proposal to restore the backing of rsETH after this month's Kelp DAO hack disrupted DeFi lending markets, releasing over 116,000 unaccounted-for tokens. The plan, shared on Aave's official X account, resembles a coordinated cleanup operation, relying heavily on Aave's infrastructure to rectify the damage and stabilize markets. The incident originated on April 18, when an attacker exploited a vulnerability in rsETH's bridge, tricking the Ethereum side into releasing 116,500 rsETH by forging a legitimate-looking message, thus creating a large batch of rsETH without backing. These tokens were not idle; they were dispersed across multiple wallets and utilized across DeFi, with a significant portion used as collateral on Aave and other lending platforms. This is where the issue became systemic: protocols like Aave found themselves holding collateral that was temporarily unbacked. According to the proposal, most of the exploited funds remain active, with approximately 107,000 of the original 116,500 rsETH still tied up in positions across Aave and Compound. This presents two concurrent problems: restoring rsETH's backing and unwinding the loans created using those extra tokens. DeFi United's proposal aims to address both issues simultaneously. To restore backing, the group has secured enough ETH commitments to fully re-collateralize rsETH, planning to feed this ETH back into the system in stages, converting it to rsETH, and depositing it back into the system to ensure the token is fully backed. Concurrently, attention shifts to the lending markets where the damage is most visible. Instead of allowing a chaotic outcome, the plan involves carefully unwinding the mess. A key aspect of this involves dealing with the positions the attacker opened on Aave, essentially loans backed by rsETH that should not have existed. Rather than waiting for these loans to collapse, the proposal suggests temporarily adjusting rsETH's valuation within the system to enable these bad positions to be liquidated or closed more smoothly. As these positions are unwound, the underlying assets, such as ETH, can be recovered, potentially freeing up around 13,000 ETH from Aave alone. Once this collateral is recovered, it will be converted into ETH and used to cover the shortfall created by the exploit, effectively filling the hole left behind. The process carries risks, depending on governance approvals across multiple chains, the successful deployment of committed funds, and the smooth execution of the unwind. Nonetheless, the plan represents a more coordinated response than DeFi has often managed previously. If executed as intended, the ultimate goal is clear: 'rsETH backing is fully restored, and all affected markets are stabilized,' as the proposal states.