Kelp DAO Bridge Hack Drains $292 Million in rsETH, Leaving Aave With Up to $190 Million Bad Debt

Kelp DAO Bridge Hack Drains $292 Million in rsETH, Leaving Aave With Up to $190 Million Bad Debt

N
News Editor 01
2026-07-23 17:15:15
A LayerZero bridge exploit at Kelp DAO led to the theft of 116,500 rsETH worth about $292 million. The aftermath pushed Aave V3 into an estimated $170 million to $190 million in bad debt and reignited debate over isolated lending models.
Kelp DAOAaversETHDeFicross-chain bridge security

Kelp DAO suffered a major exploit on its LayerZero cross-chain bridge, with 116,500 rsETH stolen in an attack valued at roughly $292 million at the time. According to the source material, the stolen amount accounted for about 18% of total rsETH circulating supply, making it the largest DeFi hack reported so far in 2026.

The attacker did not immediately dump the tokens. Instead, the stolen rsETH was deposited into Aave V3 on Ethereum mainnet and Arbitrum, where it was used as collateral to borrow large amounts of ETH. That move became the central problem. As the exploit hit confidence in rsETH, the collateral lost value and liquidity dried up, leaving Aave with an estimated $170 million to $190 million in bad debt.

Aave freezes rsETH markets as other protocols follow

Within hours of the incident, Aave froze all rsETH markets on V3 and V4. Other lending protocols that accepted rsETH as collateral moved in the same direction, with SparkLend and Fluid also freezing related markets.

At the time of publication, Aave had not issued a formal statement explaining how the bad debt would be handled. The report said reserve treasury assets were widely seen as a likely backstop, while some voices in the Aave community argued that LayerZero should contribute part of the financial support.

Michael Egorov says the incident exposes non-isolated lending risk

Curve Finance founder Michael Egorov commented on X after the attack, saying he hoped Aave could resolve the issue, but added that this was exactly the danger of non-isolated lending. In his view, that model scales well, yet carries higher risk, which puts risk management at the center of the design challenge. He also said fully isolated lending can still function like other markets.

The report said Egorov pointed to two alternatives. One is the fully isolated model used by Curve, where each market operates independently and risk does not spill across pools. The other is a hybrid model, which is more complex and aims to balance scale with safety.

Aave V4 structure returns to the center of DeFi debate

Egorov also spoke positively about Aave V4’s hub-and-spoke architecture, describing it as a possible step toward a semi-isolated and safer setup. Based on the source material, the design seeks to centralize liquidity management while separating risk by asset type, preserving capital efficiency but limiting contagion from a single high-risk asset.

The incident has pushed a familiar DeFi lending trade-off back into focus. Shared liquidity improves capital efficiency, but it can expose an entire system to single-point failures tied to external protocols. Full isolation offers stronger containment, but at the cost of scalability. The rsETH exploit has turned that architectural question into an urgent one again.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.