Ethereum infrastructure firm Consensys and its founder Joseph Lubin have joined the DeFi United recovery effort, pledging up to 30,000 ETH to plug the collateral hole left by the Kelp DAO bridge exploit. The April 18 attack stole roughly $293 million in rsETH, making it the largest DeFi hack of 2026.
How the attacker exploited rsETH without selling
Instead of dumping stolen rsETH on the open market, the attacker deposited the 116,500 rsETH as collateral on Aave, Compound v3, and Euler, borrowing approximately $236 million in ETH and WETH. This forced protocols to halt markets and freeze user collateral until a path to recovery could be negotiated.
To close the deficit, the DeFi United coalition has secured 14,570 ETH in pledges from protocols like EtherFi, Lido, and Ethena. Mantle extended a credit line of up to 30,000 ETH. Aave DAO is separately considering a proposal to contribute 25,000 ETH from its treasury, structured as an “anchored” contribution that will not be reduced even if more donations arrive.
Consensys and Lubin provide both capital and strategy
In an Aave governance update, the Consensys commitment was called “critical to the recovery plan.” Contributors noted that “without this support, the current recovery process would be difficult to advance.” Consensys also coordinates stakeholder communication, leveraging its role as the builder behind MetaMask and Linea.
Strategic advisory is provided by Sharplink, the digital asset treasury firm chaired by Lubin, which has helped design multi-tranche funding structures for earlier Ethereum ecosystem recoveries. The DeFi United framework combines protocol donations, credit lines, and treasury contributions into a unified approach to handling systemic collateral failures.

