Skip to Content

Aave Resumes rsETH Operations: $293M Kelp DAO Exploit Recovery Underway

Aave freezes rsETH markets after the Kelp bridge incident, while staged transfers later reopen bridging, withdrawals, mints, redemptions, and rewards.
2026-06-28 15:07:54 Updated 2026-08-21 10:00:45.026236 — min read 276 views
Aave Resumes rsETH Operations: $293M Kelp DAO Exploit Recovery Underway
“Aave rsETH recovery moved from emergency containment to staged restoration after the April 18 Kelp DAO bridge incident. Aave froze affected markets, LayerZero attributed the failure to a single-verifier setup and poisoned RPC infrastructure, and Kelp later reported that rsETH bridging, withdrawals, mints, redemptions, and rewards had returned to normal.

What You'll Learn

  • How the Kelp DAO rsETH bridge incident created exposure for Aave without a reported Aave contract failure
  • How Aave froze markets and how the two main bad-debt scenarios differ
  • What the Aave DAO funding proposal requested and why it was not the same as an executed payment
  • How staged rsETH restoration reopened bridging and user operations while leaving governance questions open

The Aave rsETH recovery story has two separate dates that should not be merged. On April 18, 2026, Kelp DAO's cross-chain rsETH configuration was exploited and Aave froze affected markets. By May 26, reporting hosted by TradingView said Kelp had completed a five-week recovery effort and that rsETH operations were running normally. The first event was a security and liquidity shock. The second was an operational restoration update.

LayerZero's first-party statement said the incident was isolated to Kelp DAO's rsETH configuration and involved a single-DVN setup with poisoned downstream RPC infrastructure. Aave's official governance thread said the incident did not stem from a vulnerability in the Aave protocol itself. Those statements do not remove the economic consequences for Aave users. They clarify where the failure began and why an external bridge configuration could affect a lending market.

The recovery also included a proposal rather than an immediate treasury transfer. Aave's April 24 ARFC asked the DAO to authorize a 25,000 ETH contribution within a wider DeFi United plan. The proposal described several recovery streams and stated that the plan still required governance steps. This article keeps that proposal separate from Kelp's later report that rsETH bridging, withdrawals, mints, redemptions, and rewards had resumed.

Aave rsETH Recovery at a Glance

The headline recovery is supported by the later Kelp update, but the path to that point involved containment, scenario modeling, governance coordination, and staged transfers. Aave did not simply turn a switch after a short interruption. It first froze rsETH and wrsETH markets, then dealt with liquidity pressure and uncertainty over how the backing shortfall would be allocated.

LayerZero described the exploit as approximately $290M. The protected title uses $293M, a figure also used in the recovery report. The article retains the title because it is protected, but the body identifies the source-specific difference rather than presenting the two amounts as one independently reconciled figure.

StageWhat happenedEvidence status
April 18, 2026Kelp DAO rsETH bridge configuration was exploited and Aave froze affected marketsAave and LayerZero first-party statements
April 24, 2026Aave published an ARFC requesting a 25,000 ETH treasury contribution within DeFi UnitedProposal for discussion and vote, not proof of payment
May 13, 2026A first 25,000 rsETH tranche was reported as transferred and bridging reopenedCointelegraph report hosted by TradingView
May 26, 2026Kelp said the final 20,373.7 rsETH tranche was sent and the operational recovery was closedCointelegraph report citing Kelp and Stani Kulechov

That sequence matters for readers who want to distinguish a functioning product from a resolved balance-sheet dispute. Kelp's operational statement addresses the bridge and user functions. It does not by itself establish that every Aave bad-debt scenario had been settled, that every governance question was closed, or that Aave's TVL had returned to the level before the exploit.

The site's Bitcoin ETF outflow analysis uses a similar separation between an observed market event and the later interpretation of its effect. For post 994, the observed sequence is more useful than a single recovery slogan.

How the LayerZero Bridge Failed

Kelp DAO's rsETH is a liquid restaking token designed to move across chains. LayerZero's incident statement explains that the application configuration used a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier. A DVN checks whether a cross-chain message is valid. With only one verifier required, there was no independent verifier to reject a forged message.

LayerZero said the attacker targeted downstream RPC infrastructure used by its DVN. The statement described the event as RPC poisoning rather than a compromise of LayerZero protocol code, DVN key management, or a smart-contract bug. Galaxy Research described the attack as a forged packet that released 116,500 rsETH from the Ethereum mainnet escrow. The exact technical chain is therefore specific. A cross-chain verification choice allowed a false release to pass, and the released tokens were then used in lending markets.

The distinction between an application configuration and a base protocol failure is important. LayerZero said the incident was isolated to Kelp DAO's rsETH configuration and that its review found zero contagion to other cross-chain assets or applications. That is a statement about the scope of the LayerZero review. It does not mean the event had a small financial effect. A single asset can create a large cross-protocol shock when it is accepted as collateral.

LayerZero also said that affected RPC nodes were deprecated and replaced and that its DVN was live. It described multi-DVN diversity and redundancy as industry best practice. The remediation point is not that every bridge has the same design. It is that the security setting of each application is part of the asset's risk profile.

How Aave Contained the Incident

Aave's official governance thread said its Guardian began freezing rsETH and wrsETH markets at 18:52 UTC on April 18. The freeze applied across deployments where the assets were listed. Aave said the measure prevented new deposits and new borrows against rsETH as collateral while existing positions were unaffected by the freeze itself.

Aave also said that all pools remained safe and operational and that the incident did not stem from a vulnerability in the Aave protocol. Its statement is narrower than a claim that the protocol had no exposure. Aave's lending markets had accepted rsETH as collateral, so a failure in rsETH backing could still create bad debt or withdrawal pressure in markets that were functioning according to their configured rules.

The response extended to Aave V4. The Protocol Security Council disabled new supply and borrow activity against rsETH through configuration updates. Aave later reported a precautionary WETH freeze across Core, Prime, Arbitrum, Base, Mantle, and Linea. These actions show a staged response. The Guardian first isolated the named asset, then the protocol protected adjacent liquidity while service providers assessed the position book.

Why rsETH Created Aave Exposure

The attacker did not need to drain Aave's own contracts to create a lending problem. Galaxy Research reported that the stolen rsETH was deposited as collateral on Aave, Compound, and Euler and used to borrow an estimated $236M in WETH and wstETH. Metrika separately reported that 89,567 rsETH was deposited as collateral on Aave across Ethereum and Arbitrum to borrow approximately $190M in WETH.

Those numbers are not treated as a contradiction that can be solved by averaging. Galaxy's figure covers estimated borrowing across three protocols and two assets. Metrika's figure focuses on WETH borrowed on Aave. The difference reflects source scope and measurement. The article uses both only with clear attribution.

The collateral chain is the core lesson. Aave's contracts can process a deposit and loan according to their rules, but the value of the collateral depends on the external asset's backing. When the bridge released rsETH without a matching locked balance, the market held a claim whose cross-chain backing had been damaged. Aave then had to manage a lending position whose collateral value could not be treated as fully intact.

The Tether Gold and bullion-backed lending report covers a different collateral model. The relevant comparison is not the asset type. It is the need to trace a lending asset back to its backing, custody, pricing, and redemption assumptions before judging a credit position.

Two Bad-Debt Scenarios

Galaxy Research and Metrika both described two broad ways to allocate the loss. Under uniform socialization, the shortfall is spread across rsETH holders. Under an L2-only approach, the loss is concentrated on rsETH represented on layer 2 networks while mainnet rsETH remains treated as backed by Kelp's underlying ETH deposits.

Galaxy's summary of LlamaRisk modeling estimated about $123.7M of Aave bad debt under uniform socialization and about $230.1M if losses were isolated to L2 rsETH. These are modeled scenarios, not final realized losses. The selected path would depend on Kelp's backing position, governance decisions, available recovery funds, and the treatment of affected deployments.

ScenarioReported Aave estimateEconomic treatment
Uniform socializationAbout $123.7M bad debtAll rsETH holders absorb a common haircut in the model
L2-only isolationAbout $230.1M bad debtThe shortfall is concentrated on affected layer 2 rsETH
Backing position112,204 rsETH unbacked and 40,373 rsETH in the adapter, per GalaxySource-reported incident figures used in the scenario analysis
L2 claims152,577 rsETH outstanding, per Galaxy and the Aave ARFCClaim size used in recovery calculations

The difference between the scenarios is not a simple accounting preference. It changes who absorbs the impairment and how much support is needed from Aave's DAO, Kelp, external partners, or affected suppliers. The Aave ARFC explicitly said its central-case numbers were not guaranteed. That language should remain attached to any discussion of recovery coverage.

It is also premature to treat a scenario estimate as a loss booked by Aave. A modeled number can change when collateral is recovered, positions are liquidated, bridge backing is restored, or governance chooses a different allocation method. A cautious article should report the range and explain the decision rather than choose the more dramatic figure.

Aave's DeFi United Funding Proposal

On April 24, Aave governance published an ARFC titled `rsETH Incident Funding Update`. The document proposed Aave DAO participation in a broader DeFi United recovery effort. It was submitted for discussion and vote. Its next steps included community feedback, a possible Snapshot stage, and an AIP stage if the Snapshot outcome supported escalation.

The ARFC described an original shortfall of approximately 163,183 ETH from the extraction of 152,577 rsETH at a reference ratio of 1.0696 rsETH per ETH. It said Kelp recovered and froze 40,373 rsETH, equivalent to approximately 43,168 ETH at that reference ratio. It also listed 30,766 ETH frozen by the Arbitrum Security Council, up to 12,323 WETH from Aave liquidation, and 1,845 WETH from Compound liquidation as recovered or recoverable streams.

The proposal calculated approximately 87,955 ETH of recovered or recoverable funds, or roughly 54% of the original shortfall. It described an approximate 75,081 ETH residual gap. These figures belong to the proposal's recovery model. They are not evidence that all amounts were liquid, distributed, or accepted by affected users.

Recovery stream in the ARFCReported amountStatus in the proposal
Kelp freeze40,373 rsETH, about 43,168 ETHImmediately deployable backing stream described by the ARFC
Arbitrum Security Council30,766 ETHFrozen and subject to the recovery process
Aave liquidationUp to 12,323 WETHRecoverable from the attacker position
Compound liquidation1,845 WETHRecoverable from the attacker position
Total modeled streamsAbout 87,955 ETH, roughly 54%Recovered or recoverable in the ARFC model

The ARFC said ecosystem partners had committed 14,570 ETH and that Mantle had committed a credit facility of up to 30,000 ETH. It requested authorization for 25,000 ETH from the Aave DAO treasury as the DAO's contribution. The proposal also described an upfront placement of 120,015 ETH into the LayerZero lockbox, with 44,787 ETH of that amount tied to recoveries that were not yet liquid at the time of the proposal.

These terms should not be read as an executed treasury transfer. The proposal said Snapshot and AIP steps remained. It also said later contributions could be applied to repayment facilities and that refined figures, asset composition, payment schedule, and counterparty terms would be disclosed later. The correct description is a proposed funding stack with governance conditions.

Staged Restoration of rsETH Operations

The recovery report published May 26 gives the clearest operational update. It said Kelp reported that a first tranche of 25,000 rsETH was transferred on May 13, allowing rsETH bridging between Ethereum mainnet and layer 2 networks to reopen. Kelp reopened rsETH withdrawals the following day.

The same report said Kelp later sent a final tranche of 20,373.7 rsETH to the LayerZero smart contract responsible for locking, minting, burning, and releasing rsETH during cross-chain transfers. Kelp described that transfer as closing the operational part of the recovery plan. The report said several protocols had contributed funds under the DeFi United initiative.

The report also said Kelp stated that rsETH mints, redemptions, and rewards operations were running normally. That is an operational statement attributed to Kelp. It does not independently verify every holder balance, prove that the Aave funding proposal was executed, or remove the need for governance follow-up.

In other words, the recovery had a functional phase and a financial-resolution phase. The functional phase concerns bridge operation, withdrawals, mints, redemptions, and rewards. The financial-resolution phase concerns bad debt, treasury commitments, partner facilities, recovery proceeds, and the final allocation of losses. The first can improve before the second is fully settled.

The site's Bitcoin ETF outflow report shows why dates and measurement windows matter in financial news. A recovery update dated May 26 should not be presented as a live June balance-sheet statement without a new source.

What Resumed and What Remained Open

Based on the recovery report, rsETH bridging reopened after the first tranche, Kelp reopened withdrawals the following day, and Kelp said mints, redemptions, and rewards were normal after the later stage of the plan. Those are the functions supported by the retrieved report.

Several questions remained open in the sources. The Aave ARFC said the recovery depended on actions by Kelp, LayerZero, the Arbitrum Security Council, liquidation markets, and other parties. It said some recovery streams were not yet liquid and that the numbers were not guaranteed. The article therefore does not say that all affected users were made whole or that every Aave market had returned to its pre-incident state.

The recovery report also said Aave's TVL fell from $26.4B to below $14B after the exploit and had not recovered to its earlier level in the period described. That is a historical source-reported observation. It does not establish a current TVL figure or a permanent change in Aave's competitive position.

The Sensex and Nifty banking report is a useful contrast. A market index can be checked against a dated price series. A DeFi recovery requires separate checks for asset backing, market parameters, withdrawals, governance decisions, and debt resolution.

Security Lessons from the DVN Configuration

LayerZero's statement places the single-DVN setting at the center of the incident. An application that requires one verifier has a narrow approval path. A multi-DVN design adds independent checks, so one compromised verifier or downstream infrastructure path should not be sufficient to release a cross-chain message.

This does not make multi-DVN systems automatically safe. The configuration still needs diverse operators, reliable monitoring, clear pause authority, and limits on how much value can move through an adapter. The incident shows why asset risk cannot stop at the token contract. It must include the bridge, verifier set, RPC dependencies, escrow balance, minting logic, and the protocols that accept the token as collateral.

Aave's governance thread also shows that emergency controls can operate at multiple layers. The Guardian froze markets, the Protocol Security Council changed V4 configuration, and the WETH precautionary freeze covered several deployments. The speed of those controls is valuable during an exploit, but their use also raises questions about governance authority, criteria for a freeze, and the point at which a market can reopen.

The related Big Tech demand and customer-reality analysis follows the same due-diligence principle in a different sector. A headline metric is not enough. The underlying dependency chain and the control surface determine the actual risk.

Implications for DeFi Lending and Risk Review

The rsETH event challenges a common separation between protocol risk and asset risk. Aave can have functioning contracts and still face losses because a collateral asset depends on infrastructure outside Aave's own code. For lending markets, the relevant unit of analysis is therefore the complete collateral stack.

That stack includes how the asset is issued, how it is backed, how it moves between chains, how messages are verified, how much value can be minted or released in one event, and how quickly a market can freeze deposits or borrowing. It also includes the liquidation path when a token becomes impaired. A lender that checks only the token contract can miss the bridge and custody assumptions that control the collateral's real value.

Shared liquidity pools create a second review question. If one impaired asset is used to borrow a widely supplied asset, withdrawals can become constrained even for users who never held the impaired token. Galaxy and Metrika describe that type of spillover in their April reports. The exact outflow figures differ by source, but the mechanism is consistent. Collateral impairment can affect utilization, withdrawal access, and confidence across a larger pool.

Future listings should therefore record supply caps, collateral parameters, chain-specific exposure, verifier redundancy, emergency controls, and recovery responsibilities. None of these controls guarantees that a future event will be prevented. They make the risk assumptions visible and reduce the chance that a bridge decision remains hidden inside a lending-market parameter.

The Bitcoin risk report discusses a separate market. Its relevant lesson here is that a scenario warning must be labeled as a scenario. The same discipline applies to Aave bad-debt models and recovery estimates.

Timeline and Checks After the Recovery

The timeline below separates confirmed operational updates from governance and financial questions that required later evidence.

DateConfirmed eventWhat to check next
April 18, 2026rsETH exploit, Aave market freezes, and WETH precautionary controlsBridge configuration, collateral exposure, and market utilization
April 19, 2026LayerZero incident statement on the 1-of-1 DVN and RPC poisoningVerifier diversity, RPC remediation, and other application configurations
April 24, 2026Aave ARFC proposed a 25,000 ETH treasury contribution within DeFi UnitedSnapshot, AIP, executed contribution, and recovery accounting
May 13 and May 14, 2026First 25,000 rsETH tranche, bridging reopening, and withdrawal reopeningBacking reconciliation and user access by deployment
May 26, 2026Kelp reported final 20,373.7 rsETH tranche and normal operationsFinal debt allocation, governance outcome, and Aave market recovery

Readers should also separate data sources by role. Aave governance is the right source for freezes and proposals. LayerZero is the right first-party source for its DVN and RPC account. Kelp's own statement, as reported by Cointelegraph, is the source for the operational recovery claim. Galaxy and Metrika provide analysis and scenario estimates, not final settlement records.

This source map prevents a common error in incident coverage. An analyst may combine a protocol's proposed treasury ask, a research firm's bad-debt estimate, and a later token restoration update into a single sentence that sounds like a completed recovery. The underlying events may have different dates and different evidentiary status.

Conclusion: Operations Restored, Resolution Still Measured

The Aave rsETH recovery moved through several stages. Kelp DAO's bridge configuration was exploited on April 18. LayerZero attributed the event to poisoned downstream RPC infrastructure interacting with a 1-of-1 DVN configuration. Aave froze affected markets and said its own protocol was not the source of the vulnerability. Research firms then modeled different bad-debt outcomes and identified possible recovery streams.

Aave's April 24 ARFC proposed a 25,000 ETH treasury contribution within a wider DeFi United plan, but it remained subject to governance steps in the retrieved source. The May recovery report later said a 25,000 rsETH first tranche reopened bridging, withdrawals reopened the next day, and a final 20,373.7 rsETH tranche closed the operational recovery phase. Kelp said mints, redemptions, and rewards were running normally.

The evidence supports a careful conclusion. rsETH operations were reported as restored after staged transfers, while the broader questions around bad debt, recovery accounting, governance authority, and cross-chain risk remained separate matters. The incident is therefore not only a story about a token returning to service. It is a case study in how bridge security, collateral acceptance, shared liquidity, and emergency governance interact inside DeFi lending.

Frequently Asked Questions

LayerZero said Kelp DAO was exploited for approximately $290M after an attacker abused a 1-of-1 DVN configuration and poisoned downstream RPC infrastructure.
Aave's official governance thread said the incident was scoped to the rsETH asset and did not stem from a vulnerability in Aave's protocol contracts.
Aave's Guardian froze rsETH and wrsETH markets starting at 18:52 UTC and later applied precautionary WETH controls across several deployments.
Galaxy reported LlamaRisk scenarios of about $123.7M under uniform socialization and about $230.1M if losses were isolated to layer 2 rsETH. These were estimates, not final losses.
The April 24 ARFC requested authorization for a 25,000 ETH Aave DAO treasury contribution within a wider DeFi United recovery plan. It remained subject to governance steps in the source.
The recovery report said a first tranche of 25,000 rsETH was transferred on May 13, bridging reopened, and Kelp reopened rsETH withdrawals the following day.
The May 26 recovery report said Kelp stated that rsETH mints, redemptions, and rewards operations were running normally after the staged recovery effort.
SK Jabedul Haque
Written by

SK Jabedul Haque

Founder & Chief Editor

Building India's most trusted finance education platform — simplifying news, schemes and market trends so anyone can understand and invest confidently.

Read full bio

Never miss an update

Get our clearest explainers on schemes, markets and money — read what matters, without the noise.

Explore more articles
In this article