Kelp DAO suffered a major exploit on its LayerZero cross-chain bridge, with 116,500 rsETH stolen in an attack valued at roughly $292 million at the time. According to the source material, the stolen amount accounted for about 18% of total rsETH circulating supply, making it the largest DeFi hack reported so far in 2026.
The attacker did not immediately dump the tokens. Instead, the stolen rsETH was deposited into Aave V3 on Ethereum mainnet and Arbitrum, where it was used as collateral to borrow large amounts of ETH. That move became the central problem. As the exploit hit confidence in rsETH, the collateral lost value and liquidity dried up, leaving Aave with an estimated $170 million to $190 million in bad debt.
Aave freezes rsETH markets as other protocols follow
Within hours of the incident, Aave froze all rsETH markets on V3 and V4. Other lending protocols that accepted rsETH as collateral moved in the same direction, with SparkLend and Fluid also freezing related markets.
At the time of publication, Aave had not issued a formal statement explaining how the bad debt would be handled. The report said reserve treasury assets were widely seen as a likely backstop, while some voices in the Aave community argued that LayerZero should contribute part of the financial support.
Michael Egorov says the incident exposes non-isolated lending risk
Curve Finance founder Michael Egorov commented on X after the attack, saying he hoped Aave could resolve the issue, but added that this was exactly the danger of non-isolated lending. In his view, that model scales well, yet carries higher risk, which puts risk management at the center of the design challenge. He also said fully isolated lending can still function like other markets.
The report said Egorov pointed to two alternatives. One is the fully isolated model used by Curve, where each market operates independently and risk does not spill across pools. The other is a hybrid model, which is more complex and aims to balance scale with safety.
Aave V4 structure returns to the center of DeFi debate
Egorov also spoke positively about Aave V4’s hub-and-spoke architecture, describing it as a possible step toward a semi-isolated and safer setup. Based on the source material, the design seeks to centralize liquidity management while separating risk by asset type, preserving capital efficiency but limiting contagion from a single high-risk asset.
The incident has pushed a familiar DeFi lending trade-off back into focus. Shared liquidity improves capital efficiency, but it can expose an entire system to single-point failures tied to external protocols. Full isolation offers stronger containment, but at the cost of scalability. The rsETH exploit has turned that architectural question into an urgent one again.

