Aave has published a full post-mortem on the April 18, 2026 rsETH bridge exploit that hit several Aave V3 markets. The incident began at 17:35 UTC, when Kelp’s rsETH LayerZero V2 bridge accepted a forged cross-chain message and released 116,500 rsETH on Ethereum without a matching burn on Unichain. The attacker later spread those tokens across multiple addresses, then deposited part of the balance into Aave and borrowed WETH and wstETH against it.
Bridge verifier design sat at the center of the exploit
Aave said the failure came from third-party bridge infrastructure, not from the lending protocol itself. The bridge used a one-of-one Decentralized Verifier Network setup, meaning inbound messages were approved by a single verifier. According to Aave, an RPC-poisoning attack distorted the verifier’s view of source-chain activity. That allowed the Ethereum adapter to release rsETH that did not have backing on the originating chain.
From there, the exposure moved into Aave markets. Aave said 89,567 rsETH was supplied into eight Aave V3 positions across Ethereum Core and Arbitrum. Those positions were then used to borrow 82,650 WETH and 821 wstETH. Reported health factors stayed between 1.01 and 1.03, leaving the positions very close to liquidation levels.
Emergency protections expanded across markets and chains
Once the scope became clear, Aave’s Protocol Guardian and Risk Steward turned on emergency controls. The protocol froze rsETH and wrsETH reserves, cut loan-to-value ratios to zero, and later froze WETH on several deployments. Kelp also paused the affected rsETH tied to the exploit. On April 21, the Arbitrum Security Council froze more than 30,765 ETH linked to the attacker.
Containment continued on multiple fronts. LlamaRisk issued an incident report, while Aave paused rsETH reserves on Ethereum Core, Arbitrum, Base, Mantle, and Linea. The response was not limited to a single pool or network.
Five refill tranches helped restore full backing
Aave Labs also coordinated DeFi United, a recovery effort involving Lido, EtherFi Foundation, Ethena, Mantle, Compound, Consensys, Joseph Lubin, LayerZero, KelpDAO, and others. Aave said recovery commitments topped $160 million by April 25 and later reached roughly $300 million.
The technical recovery process included liquidating attacker-linked positions, burning recovered rsETH, and refilling the LayerZero adapter in five separate tranches. By May 26, 116,131.72 rsETH had been redeposited, restoring full backing. Aave said the WETH and rsETH markets are now operating normally, while reviews of asset listings, bridge dependencies, risk frameworks, and security standards are still in progress.

