On April 18, 2026, a meticulously planned attack on the KelpDAO cross-chain bridge quickly escalated into one of the most severe bad debt crises in decentralized finance (DeFi) history. Exploiting a configuration flaw in the Layerzero V2 bridge, attackers forged and minted a large amount of unbacked rsETH tokens, which were then deposited as collateral into Aave V3 markets, leaving Aave with up to $230.1 million in bad debt exposure. In response, the DeFi United coalition, a cross-protocol relief fund, raised $160 million within a week—marking one of the largest coordinated rescue efforts ever in DeFi.
Attack Details: A Single Vulnerability Triggers a Cascade
The exploit began at 17:35 UTC on Ethereum block 24,908,285. Attackers targeted KelpDAO's Layerzero V2 bridge route from Unichain to Ethereum for rsETH, which was configured as a 1-of-1 DVN (Decentralized Verifier Network) without additional validators. They submitted a forged incoming packet that minted 116,500 unbacked rsETH, worth approximately $292 million at the time, without a corresponding lock or burn on the source chain.
The attacker acted swiftly. About 89,567 rsETH (worth around $221 million) were deposited as collateral across Aave V3 markets on Ethereum and Arbitrum. The attacker then borrowed roughly 82,650 WETH (about $191 million) plus smaller amounts of wstETH. The positions were left with health factors between 1.01 and 1.03, making full repayment highly unlikely. Aave's smart contracts were not exploited; the bad debt originated solely from the unbacked external collateral.
Aave's Emergency Response and Bad Debt Magnitude
Aave's Protocol Guardian reacted within hours. By approximately 19:00 UTC on April 18, all rsETH and wrsETH reserves across V3 deployments were frozen, loan-to-value (LTV) ratios were set to zero, and interest rate models were adjusted to address liquidity pressure.
On April 20, Aave Labs and risk manager Llamarisk published a formal incident report modeling two bad debt scenarios. In the first scenario, with a smooth haircut across all rsETH holders, Aave faced about $123.7 million in bad debt. In the second, with losses isolated to L2 rsETH holders, the bad debt reached approximately $230.1 million, with Mantle and Arbitrum bearing the largest exposure. Other estimates placed Aave's total exposure between $196 million and $200 million.
Market impact was severe. Aave's total value locked (TVL) fell between $6 billion and $9 billion in the days following the event. The price of AAVE dropped 10% to 22% in the immediate aftermath. Broader DeFi TVL losses reportedly exceeded $13 billion.
The Birth of DeFi United and the $160M Rescue
To contain the contagion, Aave service providers launched DeFi United, a cross-protocol bailout liquidity fund directing contributions to defiunited.eth (Ethereum address 0x0fCa5194baA59a362a835031d9C4A25970effE68). The fund targeted the rsETH shortfall, originally modeled at 68,900 to over 100,000 ETH, depending on recoveries and final bad debt numbers.
By Saturday, April 25, Arkham Intelligence confirmed that DeFi United had raised $160 million. Key contributors included:
- Mantle: Proposed up to 30,000 ETH structured as a three-year credit facility at Lido staking yield plus 1%.
- Aave DAO: Proposed 25,000 ETH from its treasury, with governance voting still ongoing.
- Stani Kulechov (Aave founder and CEO): Committed 5,000 ETH from personal funds.
- Ether.fi: Committed 5,000 ETH.
- Lido DAO: Offered up to 2,500 stETH.
- Golem Foundation: 1,000 ETH.
- Aave VP Emilio Frangella: 500 ETH.
- Community donations: Over 272 ETH reported onchain.
- Ethena, Layerzero, Ink Foundation, Frax, Tydro, and others also provided support.
Mantle and Aave DAO together contributed 55,000 ETH, accounting for about $127 million of the total. The Arbitrum Security Council also froze a portion of the attacker's funds, reducing the net gap the fund needed to cover. Additionally, a subsequent malicious packet for 40,000 rsETH was reversed and recovered by Kelp before it could be processed.
Industry Reflections: Cross-Chain Security Warnings
Charles Hoskinson, founder of Cardano, commented on the incident, pointing out that the KelpDAO exploit exposed the fatal flaws of cross-chain bridge designs lacking sufficient verification, and highlighted Cardano and Midnight as safer alternatives. DeFi United participants described the effort as one of the largest coordinated recovery operations in DeFi history. Governance votes for outstanding contributions remain active, and the fund continues to accept donations as the protocol works toward restoring full rsETH coverage and eliminating remaining bad debt.
This incident serves as a stark reminder of cross-chain security risks: when relying on single verifiers or lightweight configurations, system vulnerabilities are amplified. DeFi's resilience and collaborative spirit were tested, but fundamental security improvements remain a long-term industry imperative.

