Aave’s effort to recover from the rsETH exploit has moved into a new stage. On May 6, the attacker’s eight positions on Aave V3 across Ethereum and Arbitrum were fully liquidated, and the recovered collateral was sent to the Recovery Guardian, a multisig controlled by DeFi United. The technical part advanced quickly. Full restoration has not happened yet, because about 30,765 ETH, valued in the report at roughly $71 million, is still frozen by a U.S. court restraining notice.
How the exploit created more than $190 million in bad debt
According to the report, the attack began on April 18, 2026, when the exploiter abused Kelp DAO’s LayerZero bridge and fraudulently minted 116,500 rsETH without real backing. About 89,500 tokens were then deposited into Aave V3 as collateral, allowing the attacker to borrow wrapped ETH against them. That action alone left Aave with more than $190 million in bad debt. The market impact was immediate inside the protocol as well: Aave’s TVL fell by $12 billion in one week.
To make liquidation possible, the Aave rsETH recovery team, working under the DeFi United coalition, pushed through a DAO vote to temporarily change the price oracle. That created a deficit in the attacker’s positions and opened the way for forced liquidations. After the liquidations were executed, the report highlighted three outcomes: regular users were not affected, Aave’s Umbrella insurance fund was not activated, and TVL, after dropping to $14.2 billion, has climbed back above $15 billion.
The legal freeze is now the main obstacle
The largest remaining hurdle sits outside the protocol. Arbitrum DAO voted to return 30,765 ETH to the recovery process, with more than 90% of voters in favor. Then, on May 1, a U.S. law firm acting for plaintiffs holding judgments against North Korea filed a restraining notice, arguing that the ETH might be connected to the Lazarus Group. The notice froze the funds before they could be distributed to users.
LLC then filed an emergency motion seeking to vacate the notice. A hearing was held on May 6, and the judge accepted a proposal that would allow an onchain Arbitrum DAO vote to transfer the frozen ETH to LLC, while the restraining order would continue to follow the funds after transfer. The report also made one point clear: no court has concluded that North Korea or the Lazarus Group carried out the exploit. The legal process is still ongoing.
Recovery is about 90% complete, but no final timeline is set
Thaddeus Pinakiewicz, vice president of research at Galaxy Digital, said the recovery is now only about 10% short of the ETH needed to fully restore rsETH backing. Until the frozen assets are legally released, the parties involved said they will borrow separate funds to cover the gap.
The next operational steps have already been outlined. Liquidated rsETH on Arbitrum will be burned to reduce the attacker’s inflated supply. Kelp DAO will retire the related LayerZero message so new tokens cannot be minted on Ethereum. Seized rsETH on Ethereum will move to the bridge lockbox to help restore backing. Once that lockbox is fully backed, withdrawals will reopen and bridge activity will resume. Temporary protocol settings introduced to enable liquidation will then be reversed, and the WETH loan-to-value ratio on Aave V3 Ethereum Core, which had been set to zero as a precaution, will return to normal.
Based on the published update, the recovery is roughly 90% complete. What remains depends on the legal outcome tied to the $71 million and on the final ETH commitments from DeFi United. No exact schedule has been confirmed. Two unresolved issues remain in view: the court dispute could last for weeks, and the blame dispute between LayerZero and Kelp DAO is still open, with Kelp DAO saying LayerZero approved the vulnerable bridge setup and LayerZero CEO Bryan Pellegrino publicly rejecting that claim.

