Kelp DAO Hack Leaves $290 Million Dispute Unresolved as LayerZero and Aave Resist Taking the Loss

Kelp DAO Hack Leaves $290 Million Dispute Unresolved as LayerZero and Aave Resist Taking the Loss

N
News Editor 01
2026-07-23 11:10:15
More than 30 hours after Kelp DAO’s rsETH bridge exploit, responsibility and repayment remain disputed. Kelp DAO, LayerZero, and Aave have all stated their positions, but no final resolution has been reached.
Kelp DAOLayerZeroAaversETHCross-Chain Security

More than 30 hours after Kelp DAO’s rsETH bridge contract was exploited, no final resolution has emerged from LayerZero, Kelp DAO, or Aave. Each side has made public statements, but the common theme is the same: none of them wants to accept primary responsibility for a loss of this scale. The debate has now shifted from how the exploit happened to who should absorb the damage.

The exploit path is clearer than the repayment plan

According to details shared by LayerZero, the immediate trigger was a compromise of downstream RPC infrastructure used by its decentralized verifier network, or DVN. Kelp DAO’s bridge contract was configured with a 1/1 DVN setup, which meant a single forged message validation was enough to release assets incorrectly. On that basis, Kelp DAO is widely seen as the main party at fault because the configuration created an obvious single point of failure.

That does not remove pressure from LayerZero. While the protocol says applications choose their own DVN settings, it still designed a system that allowed such a weak configuration to exist. Aave’s position is more complicated. It was indirectly harmed by the exploit, yet it is also being criticized for granting broad lending permissions to rsETH and other LRT assets. The source material notes that BGD Labs, formerly Aave’s risk team, had flagged Kelp DAO’s DVN issue in January last year. Kelp accepted the recommendation at the time, but the change was apparently never completed.

The 116,500 rsETH released were real tokens, not newly minted ones

Aave’s statement that “rsETH on Ethereum mainnet is fully backed” has become central to the dispute. rsETH is a liquid restaking receipt token issued by Kelp DAO, and each 1 rsETH is backed by 1 ETH in staking and restaking systems through the path “ETH–Lido–EigenLayer–Kelp DAO–rsETH.”

The versions circulating on Layer 2 networks are mapped representations created through LayerZero’s bridging contracts. Under normal conditions, when rsETH is issued on Layer 2, the matching mainnet rsETH is locked in custody. In this exploit, the attacker forged a cross-chain message and caused the bridge to release 116,500 rsETH by mistake. These tokens were not created out of thin air. They were authentic mainnet receipt tokens that should have remained locked. The attacker then deposited them into lending protocols such as Aave, borrowed more liquid WETH against them, and exited.

Aave’s position points to protecting mainnet rsETH first

Because the rsETH deposited by the attacker was technically genuine, Aave’s systems still recognized it as valid collateral. That explains the wording in Aave’s update. Its emphasis on mainnet rsETH being fully backed suggests a preference to preserve the value and redeemability of the Ethereum-native version, while showing far less willingness to support Layer 2 mapped rsETH that may no longer be backed by locked mainnet assets.

This is a damage-control calculation. The source says Aave also has rsETH debt exposure in its Layer 2 lending products, with an estimated size of about $359 million. Writing off mainnet support would create one kind of shock; preserving the core mainnet product while letting Layer 2 mapped versions suffer would create another. Aave appears to be leaning toward the option that protects its main market first.

The parties with the balance sheet may face the most pressure

The practical issue is simple: Kelp DAO, described as the main responsible party, may not have the resources to cover the hole on its own. The source argues that the only players with meaningful capacity to contribute are LayerZero and Aave. LayerZero is already dealing with reputational fallout and has reportedly been temporarily suspended by Bitgo, Tron, Ethena, Curve, and ether.fi. Aave, for its part, is facing potential bad debt and outflows in TVL, while several pools have reached 100% utilization, leaving some depositors unable to withdraw.

That is why the process has stalled. Kelp DAO lacks the means to lead a compensation plan, while LayerZero and Aave both insist their own protocols were not directly vulnerable and do not want to be the first to commit capital. Yet neither side has much room to wait. LayerZero risks losing cross-chain market share if partners move elsewhere, and Aave remains exposed if liquidation conditions worsen and ETH volatility increases.

Three public proposals, none without serious trade-offs

Several solutions are already being discussed in public. DefiLlama founder 0xngmi outlined three routes. One is to impose an 18.5% haircut on all rsETH holders, based on the ratio of lost tokens to total issued supply, with Kelp DAO taking the main blame and Aave absorbing around $216 million in bad debt on mainnet. A second route is to treat all Layer 2 mapped rsETH as worthless, which would protect Aave’s mainnet product but could crush Kelp DAO’s Layer 2 footprint and reputation. A third option is to fully reimburse holders based on a pre-attack snapshot while leaving later buyers or transferees to bear losses, though the source says post-attack fund movements make that approach nearly impossible to execute.

OneKey founder Yishi proposed starting with negotiations with the hacker, offering a 10% to 15% bounty in exchange for the return of most of the funds. If that fails, he suggested LayerZero’s ecosystem fund should bear the largest share because it has the strongest financial capacity and the deepest long-term interest in protecting the OFT ecosystem. Kelp DAO could then make up part of the gap through tokens, future revenue, or even a sale of the project to LayerZero or Bitmine. In that framework, Aave’s Umbrella and stkAAVE would be treated as a final backstop, while WETH depositors would not be subject to a haircut.

No common solution has been announced so far. The dispute involves losses on a nine-figure scale, and each side is still measuring what it can afford to concede. For the market, the immediate pressure points remain clear: whether LayerZero can restore partner confidence quickly, and whether Aave can relieve liquidity stress and liquidation risk before conditions deteriorate further.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.