An incident report published by Llamarisk on the Aave governance forum says a bridge exploit targeting KelpDAO’s LayerZero V2-based rsETH pathway allowed an attacker to extract 116,500 rsETH from the Ethereum OFT adapter without any corresponding burn on the source chain. According to the report, the event left affected Aave V3 markets exposed to potential bad debt ranging from $123.7 million to $230.1 million, depending on how losses are ultimately allocated.
How the exploit unfolded
Llamarisk said the attack took place on April 18, 2026 at 17:35 UTC in Ethereum block 24,908,285. The report attributes the issue to the Unichain-to-Ethereum route being configured as a 1-of-1 DVN path, meaning a single verifier could certify an inbound packet without a matching outbound action. In practice, that opened the door for the attacker to craft a fraudulent packet that was verified, committed, and delivered on Ethereum.
Once processed, the forged message released rsETH from the OFT adapter. The adapter’s balance reportedly fell from 116,723 rsETH to just 223 rsETH in a single block. The attacker then distributed the extracted tokens across seven branch addresses. Of the 116,500 rsETH obtained, 89,567 rsETH was deposited as collateral into Aave V3 markets on Ethereum and Arbitrum.
Those collateral positions were then used to borrow approximately 82,650 WETH and 821 wstETH. Llamarisk said the attacker kept the positions narrowly above liquidation levels, with health factors held between 1.01 and 1.03. At the time of the report, all seven addresses remained active on Aave.
Aave contracts were not compromised
Aave service providers participating in the incident review stressed that Aave’s own smart contracts were not hacked. The protocol’s core mechanics, including supply, repayment, and liquidation logic, continued operating as designed throughout the episode. The risk came instead from the valuation and integrity of bridged collateral that entered the lending markets after the exploit.
In response, Aave’s Protocol Guardian began freezing all rsETH and wrsETH reserves across Aave V3 deployments at around 19:00 UTC on April 18. That action reduced their loan-to-value ratio to zero and disabled new supply and borrowing, while allowing existing positions to remain eligible for repayment and liquidation. The forum analysis cited 11 affected markets spanning Ethereum, Arbitrum, Avalanche, Base, Ink, Linea, Mantle, MegaETH, Plasma, and Zksync.
Llamarisk also noted that the Risk Steward later adjusted WETH interest-rate models on Arbitrum, Base, Mantle, and Linea on April 19, lowering borrowing costs at full utilization. A corresponding adjustment was applied to Aave Core on April 20. Protocol Guardian then froze WETH reserves on Core, Prime, Arbitrum, Base, Mantle, and Linea at about 02:00 UTC on April 20 in an effort to stop new borrowing and limit the spread of pressure into stablecoin liquidity.
Two bad-debt scenarios
The report modeled two loss-allocation scenarios, and the difference between them is critical for understanding Aave’s exposure. In the first scenario, 112,204 unbacked rsETH is socialized evenly across the total rsETH supply. Under that framework, rsETH would suffer a 15.12% depeg, producing an estimated $123.7 million in bad debt across affected Aave markets. Ethereum Core would absorb the largest absolute loss, at roughly $91.8 million, while Mantle would face a meaningful WETH reserve deficit.
The second scenario assumes losses are ring-fenced to rsETH on L2s, leaving Ethereum mainnet rsETH untouched while imposing a 73.54% haircut on remote-chain collateral. That approach would result in a steeper estimate of $230.1 million in bad debt, with the heaviest concentration falling on Mantle and Arbitrum. In short, the final damage to Aave depends heavily on whether KelpDAO chooses broad socialization or more localized loss distribution.
Llamarisk added that the adapter currently holds only 40,373 rsETH as confirmed backing for all remote-chain rsETH across L2 routes, versus total remote claims of 152,577 rsETH. That gap illustrates the scale of the shortfall. As of the report’s publication, Kelp had not publicly confirmed how any recovered funds would be allocated.
Liquidity strain and defense capacity
The incident also created severe liquidity stress. WETH reserves across Ethereum, Arbitrum, Base, Linea, and Mantle were reported at 100% utilization, with unused balances on each chain below $20. Under full utilization, liquidators receive aWETH rather than base WETH, a detail that can slow the pace of liquidation and impair market normalization.
Llamarisk identified Base and Arbitrum as the markets with the thinnest safety margins. Because the attacker’s positions were maintained near health factors of about 1.03, the first liquidations could be triggered by relatively small moves in WETH price: a decline of just 0.77% on Base and 1.77% on Arbitrum, according to the report.
Treasury position and recovery efforts
As of April 20, 2026, the Aave DAO treasury held $181 million in assets, including approximately $62 million in ETH-correlated assets, $54 million in AAVE, and $52 million in stablecoins. The report said the DAO generated $145 million in revenue in 2025 and $38 million so far in 2026. Llamarisk also stated that multiple initial recovery commitments had already been secured from ecosystem participants to address possible bad-debt outcomes.
In a further risk-management recommendation, Llamarisk said that under scenario one, Aave should immediately pause the Umbrella WETH staking module. At the time of the report, 18,922 out of 23,507 staked aWETH had already entered cooldown for unstaking. A pause would block deposits, withdrawals, transfers, and slashing, while reward distribution would continue.
The report said the remaining four rsETH-listed markets — Ethereum Lido, MegaETH, Plasma, and Zksync — held negligible balances and had no bad debt. Twelve other Aave V3 markets that do not list rsETH were not affected. Taken together, the incident highlights how bridge configuration choices, restaked asset design, and cross-chain collateral usage can combine into a system-wide credit event even when the lending protocol itself remains technically secure.

