Aave Details rsETH Exploit Response as Recovery Commitments Near $300 Million

Aave Details rsETH Exploit Response as Recovery Commitments Near $300 Million

N
News Editor 01
2026-07-24 10:20:15
Aave said a forged bridge message released 116,500 rsETH, which attackers used on Aave to borrow WETH and wstETH. Emergency freezes, partner coordination, and recovery commitments of about $300 million helped restore full backing of 116,131.72 rsETH by May 26, 2026.
AaversETHbridge exploitDeFisecurity

Aave has published a full post-mortem on the April 18, 2026 rsETH bridge exploit that hit several Aave V3 markets. The incident began at 17:35 UTC, when Kelp’s rsETH LayerZero V2 bridge accepted a forged cross-chain message and released 116,500 rsETH on Ethereum without a matching burn on Unichain. The attacker later spread those tokens across multiple addresses, then deposited part of the balance into Aave and borrowed WETH and wstETH against it.

Bridge verifier design sat at the center of the exploit

Aave said the failure came from third-party bridge infrastructure, not from the lending protocol itself. The bridge used a one-of-one Decentralized Verifier Network setup, meaning inbound messages were approved by a single verifier. According to Aave, an RPC-poisoning attack distorted the verifier’s view of source-chain activity. That allowed the Ethereum adapter to release rsETH that did not have backing on the originating chain.

From there, the exposure moved into Aave markets. Aave said 89,567 rsETH was supplied into eight Aave V3 positions across Ethereum Core and Arbitrum. Those positions were then used to borrow 82,650 WETH and 821 wstETH. Reported health factors stayed between 1.01 and 1.03, leaving the positions very close to liquidation levels.

Emergency protections expanded across markets and chains

Once the scope became clear, Aave’s Protocol Guardian and Risk Steward turned on emergency controls. The protocol froze rsETH and wrsETH reserves, cut loan-to-value ratios to zero, and later froze WETH on several deployments. Kelp also paused the affected rsETH tied to the exploit. On April 21, the Arbitrum Security Council froze more than 30,765 ETH linked to the attacker.

Containment continued on multiple fronts. LlamaRisk issued an incident report, while Aave paused rsETH reserves on Ethereum Core, Arbitrum, Base, Mantle, and Linea. The response was not limited to a single pool or network.

Five refill tranches helped restore full backing

Aave Labs also coordinated DeFi United, a recovery effort involving Lido, EtherFi Foundation, Ethena, Mantle, Compound, Consensys, Joseph Lubin, LayerZero, KelpDAO, and others. Aave said recovery commitments topped $160 million by April 25 and later reached roughly $300 million.

The technical recovery process included liquidating attacker-linked positions, burning recovered rsETH, and refilling the LayerZero adapter in five separate tranches. By May 26, 116,131.72 rsETH had been redeposited, restoring full backing. Aave said the WETH and rsETH markets are now operating normally, while reviews of asset listings, bridge dependencies, risk frameworks, and security standards are still in progress.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.