On April 25, 2026, a coalition of five leading DeFi protocols — Aave Labs, KelpDAO, Layerzero, Etherfi, and Compound — submitted a Constitutional AIP (Arbitrum Improvement Proposal) to the Arbitrum governance forum, requesting the Arbitrum DAO to release 30,765.67 ETH that had been frozen by the Arbitrum Security Council following a bridge exploit in the KelpDAO rsETH system.
Origin of the Incident: rsETH Bridge Bug Creates Backing Shortfall
The exploit originated from a vulnerability in the KelpDAO rsETH bridge. According to a report by security firm Llamarisk, the KelpDAO rsETH Unichain-to-Ethereum bridge mistakenly released 116,500 rsETH on Ethereum on April 18 without corresponding source-side burns, breaking the fundamental bridge invariant that locked rsETH on Ethereum must back remote-chain minted supply. At the time of the report, only 40,373 rsETH remained in the adapter as confirmed backing for 152,577 rsETH in remote-chain claims, resulting in a shortfall of approximately 76,127 rsETH.
Impact on Aave Markets
The attacker supplied 89,567 rsETH to Aave across its Ethereum Core and Arbitrum markets, borrowing 82,650 WETH and 821 wstETH against those positions. The proposal authors explicitly noted that Aave's smart contracts were not compromised; the incident occurred entirely outside the protocol.
Freeze and Unfreeze Process
On April 21, the Arbitrum Security Council froze 30,765.667501709 ETH and moved them to address 0x0000000000000000000000000000000000000DA0, stating that a governance vote would be required before any further movement. The proposal requests that these funds be sent to a 2-of-3 Gnosis Safe — controlled by signers from Aave, KelpDAO, and Certora (address 0xf228130ce4fAB082C7D5522c90833cec83A9C15e) — to be used strictly for remediating losses from the exploit. Every unit of ETH returned is expected to narrow the backing gap and move rsETH closer to full collateralization.
Governance Timeline and Cost
The proposal estimates approximately 49 days from forum publication to execution: one week of forum discussion, one week temperature check, three-day voting delay, 14-day onchain vote, eight-day L2 waiting period, one-week L2-to-L1 message finalization window, and a final three-day L1 waiting period. No new treasury allocation is requested; the proposal only asks for the release of already-frozen funds, with zero direct budget cost to the Arbitrum DAO aside from standard governance execution overhead.
Aave Labs' Indemnification Commitment
To mitigate legal exposure, Aave Labs included a full indemnification clause, agreeing to indemnify the Arbitrum Foundation, Offchain Labs, the Arbitrum Security Council, and each of its members against any claims arising from the freeze, release, or related enforcement actions. If the coordinated recovery does not proceed as planned, the parties have committed to return to Arbitrum Governance for further direction.
The proposal authors emphasized that releasing the funds — whether resulting in full or partial recovery — is a better outcome for Arbitrum users than leaving the ETH frozen indefinitely. A Snapshot temperature check will precede the onchain vote, which, if approved, will be submitted via Tally as a Constitutional AIP targeting the Arbitrum Core governor.

