Five DeFi Protocols Ask Arbitrum DAO to Release 30,765 ETH Frozen After rsETH Bridge Exploit

Five DeFi Protocols Ask Arbitrum DAO to Release 30,765 ETH Frozen After rsETH Bridge Exploit

N
News Editor 01
2026-07-08 18:42:19
Aave Labs, KelpDAO, Layerzero, Etherfi, and Compound have asked Arbitrum DAO to release 30,765.67 ETH frozen after the rsETH bridge exploit to help close the collateral shortfall.
ArbitrumDeFiKelpDAOAaversETH

A coalition of Aave Labs, KelpDAO, Layerzero, Etherfi, and Compound has submitted a Constitutional AIP to the Arbitrum governance forum, asking the Arbitrum DAO to release 30,765.67 ETH that was frozen by the network’s Security Council following the KelpDAO rsETH exploit. If approved, the recovered ETH would be sent to a designated 2-of-3 Gnosis Safe controlled by signers associated with Aave, KelpDAO, and Certora, with the stated goal of remediating losses tied to the incident.

Proposal centers on already-frozen funds, not new treasury spending

The proposal does not seek a fresh treasury allocation from Arbitrum. Instead, it requests the release of assets that were already frozen on April 21 and moved by the Arbitrum Security Council to a designated address, with the understanding that any further movement would require governance approval. According to the proposal authors, the direct budgetary cost to the Arbitrum DAO should be zero apart from ordinary governance execution overhead.

The coalition argues that putting the ETH into the remediation process is preferable to leaving it immobilized, regardless of whether the eventual recovery outcome is full or partial. The funds are intended to help narrow the gap in rsETH backing created by the exploit and support affected users and positions linked to the shortfall.

How the rsETH bridge failure created a large backing gap

The root cause, according to an incident report cited in the proposal, was a vulnerability in the KelpDAO rsETH bridge from Unichain to Ethereum. The flaw reportedly allowed 116,500 rsETH to be released on Ethereum without a corresponding burn on the source side. That broke the bridge’s core accounting assumption: the amount of rsETH locked or accounted for on Ethereum should match the supply minted or represented on remote chains.

At the time of the report, only 40,373 rsETH remained in the adapter as confirmed backing for 152,577 rsETH in remote-chain claims. That left an estimated backing shortfall of around 76,127 rsETH. The coalition’s position is that every unit of ETH recovered and redirected into remediation reduces that deficit and moves rsETH closer to full collateral support.

Aave says its contracts were not compromised

One of the most important points in the proposal is the distinction between the source of the exploit and the protocols affected by its fallout. The authors explicitly state that Aave’s smart contracts were not hacked. Instead, the incident originated outside Aave, but still had direct consequences for Aave users because of how the attacker used rsETH inside the lending system.

During the exploit, the attacker supplied 89,567 rsETH across Aave’s Ethereum Core and Arbitrum markets, then borrowed 82,650 WETH and 821 wstETH against those positions. That sequence amplified the impact of the bridge failure by bringing under-backed collateral into money markets. As a result, users and markets connected to Aave V3 on Arbitrum were directly exposed to the downstream effects of the rsETH deficit, even though Aave itself was not the original point of failure.

Why Arbitrum governance is now central to the recovery path

Because the Arbitrum Security Council froze 30,765.667501709008927568 ETH, the Arbitrum DAO now has a decisive role in determining whether that capital can be used in the broader remediation effort. The proposal requests that the frozen ETH be transferred to a recovery address through a governance-approved process. The chosen wallet structure, a 2-of-3 Gnosis Safe, is meant to provide controlled access while ensuring that the funds are used only for exploit-related remediation.

The proposal further states that if the coordinated recovery effort does not proceed as expected, the participating parties will return to Arbitrum governance for additional direction. This framing is designed to reassure tokenholders that the release is not open-ended and that governance oversight remains in place after the initial transfer.

Governance timeline could stretch to roughly 49 days

The expected process is lengthy. The proposal estimates about 49 days from forum publication to execution. That timeline includes approximately one week of forum discussion, one week for a temperature check, a three-day voting delay, a 14-day onchain vote, an eight-day Layer 2 waiting period, a one-week L2-to-L1 message finalization window, and a final three-day waiting period on Layer 1.

A Snapshot temperature check may be used before the measure moves onchain. If the proposal advances, the onchain vote would be submitted through Tally and routed to the Arbitrum Core Governor as a Constitutional AIP. In practical terms, that means the release process is subject to one of Arbitrum’s more formal governance tracks, reflecting both the size of the frozen funds and the sensitivity of the exploit’s aftermath.

Indemnification is intended to reduce legal and operational friction

To support execution, Aave Labs included a full indemnification commitment in the proposal. According to the filing, the firm agreed to indemnify the Arbitrum Foundation, Offchain Labs, the Arbitrum Security Council, and individual council members against claims arising from the freeze, the release of the funds, or related enforcement actions. This is a notable part of the proposal because governance participants and infrastructure operators often face legal and reputational concerns when intervening in exploit situations.

By including indemnification, the authors appear to be addressing one of the key non-technical obstacles in post-exploit recovery: the hesitation of governance actors to approve exceptional transfers without clear legal protection.

Broader implications for DeFi bridge security

The incident has also renewed scrutiny on bridge architecture and cross-chain accounting controls. The rsETH shortfall underscores how vulnerabilities in bridge design can cascade into lending markets, liquid staking products, and governance systems across multiple chains. Even when a lending protocol’s own contracts remain intact, external collateral failures can still produce major losses or solvency concerns for users.

That is why this Arbitrum proposal matters beyond the immediate release of 30,765.67 ETH. It highlights how DeFi recovery increasingly depends not just on smart contract code, but on coordinated action among protocol teams, governance bodies, risk analysts, and security councils. In this case, the coalition is asking Arbitrum tokenholders to determine whether frozen assets should remain locked or be actively deployed to reduce the damage from a bridge failure that spilled into the wider DeFi ecosystem.

For now, the key question is whether Arbitrum governance agrees that releasing the frozen ETH offers a better outcome for users than leaving the funds untouched. If approved, the transfer would not fully eliminate the estimated 76,127 rsETH backing gap, but it would represent a meaningful contribution toward closing it and restoring confidence in the remediation path.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.