Aave faces $230M potential bad debt after Kelp DAO bridge exploit

Aave faces $230M potential bad debt after Kelp DAO bridge exploit

N
News Editor 01
2026-07-24 07:35:17
Aave could sustain up to $230 million in losses after a bridge exploit involving Kelp DAO and LayerZero. An attacker deposited 89,567 fake rsETH into Aave and borrowed $190M. The outcome hinges on how Kelp allocates the shortfall, with two scenarios exceeding $124M.

Aave is staring at potential losses of up to $230 million after a cross-chain bridge exploit targeting Kelp DAO and LayerZero sent shockwaves through DeFi. According to a report from Aave Labs and risk service provider LlamaRisk posted on Aave's governance forum, the incident revolves around rsETH, a liquid restaking token issued by Kelp DAO. The token relies on a bridge mechanism that locks tokens on the origin chain and issues corresponding copies on the destination chain.

Forged message freed 116,500 rsETH

The attacker exploited this setup by crafting a fraudulent transfer message that appeared valid. The system approved the transfer even though no tokens were ever moved from the sending chain, effectively creating 116,500 unbacked rsETH from the Ethereum-side bridge. Instead of selling on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed roughly $190 million in ETH and related assets across Ethereum and Arbitrum. This left Aave exposed to collateral whose backing was severely impaired.

Aave Labs moved quickly. Within hours, the protocol froze rsETH markets across all deployments, set loan-to-value ratios to zero, and halted new borrowing against the asset. But the ultimate damage depends on how Kelp handles the shortfall. If losses are socialized across all rsETH holders, the token would depeg by an estimated 15%, resulting in about $124 million in bad debt for Aave. If losses are isolated to Layer 2 networks such as Arbitrum and Mantle, the impact would be far larger, with bad debt hitting roughly $230 million.

The exploit stemmed from weaknesses in Kelp's cross-chain message verification using LayerZero. By manipulating this process, the attacker made certain assets appear fully backed when they were not. LayerZero itself was not hacked directly, but its messaging layer exposed flawed assumptions in how Kelp validated data. Users pulled back sharply: around $6 billion in total value locked was withdrawn from Aave after the incident. Aave's DAO treasury holds about $181 million in assets, and discussions are ongoing with ecosystem participants to address losses. Kelp has yet to detail how it will allocate the shortfall, leaving Aave's final exposure uncertain.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.