最终修复方案出炉,Aave坏账风波终于要结局了

Odaily星球日报Publicado a 2026-04-28Actualizado a 2026-04-28

原创 | Odaily 星球日报(@OdailyChina)

作者|Azuma(@azuma_eth)

折腾了一个多星期的 Aave 坏账风波已基本迎来尾声。

随着 DeFi United 已募集到了足够解决问题的资金(截至发文已募集 132704 ETH,价值约 3.02 亿美元),Aave 官方也在 4 月 28 日中午发布了关于修复 rsETH 抵押状况并恢复市场正常运行的技术实施方案。

  • Odaily注:前情提要可参阅《DeFi再次被盗2.92亿美元,这下连Aave都不安全了?》;《2.9亿窟窿下的三方博弈:Aave、L0、Kelp谁能买单?》;《Aave正因自己的愚蠢,拱手让出DeFi借贷的王座》。

背景回溯

关于 Kelp DAO 如何失窃 116500 rsETH 的细节已不用多提,重点在于被盗之后的赃款流向。

黑客得手之后,先是将这 116500 枚 rsETH 分散至多个地址。其中一部分被作为抵押存入以太坊主网上的 Aave V3 并借出 WETH,另一部分被桥接至 Arbitrum 并在该网络上的 Aave 抵押借出 WETH,其余少部分赃款则通过不同渠道转移。

目前,与黑客相关的 7 个地址在 Aave 和 Compound 上仍持有活跃的 rsETH 抵押头寸,约占最初被盗 116500 枚中的 107000 枚。

解决方案

为了实现修复目标,Aave 在拟设的实施方案中设置了两个目标。其一为恢复 rsETH 的抵押支撑;其二为清理 Aave、Compound 等借贷市场中的受影响头寸,以回收约 107000 枚 rsETH 的超额抵押资产,进而修复市场受损情况。

先来说说第一个目标 —— 恢复 rsETH 的抵押支撑。

目前的 rsETH 实质上是属于“资不抵债”状态,虽然底层质押中 ETH 仍然完好,但黑客已通过抵押借贷完成出逃,这部分缺口的存在就导致 rsETH 与 ETH 的兑换报价出现了“脱锚”。

因此 Aave 提到,为了恢复 rsETH 的抵押支撑,就需要将 rsETH 和 ETH 之间的兑换比例拉回到 1 :1.07。这将通过 DeFi United 推动实现,该组织现已获得足够的 ETH 承诺出资,以恢复系统的完整运作,但最终执行仍取决于治理批准、执行时间安排以及相关协议的签署。

若方案能够顺利推进,DeFi United 将通过向 rsETH 的桥接锁仓合约(RSETH_OFTAdapter 0x85d456b2...98ef3)存入 ETH 来完全恢复 rsETH 的抵押支持。具体流程如下:

  • 分批将 DeFi United 的 ETH 转换为 rsETH;
  • 将这些 rsETH 转入相关锁仓合约;
  • 使桥接系统能够安全恢复并全面运行。
  • LayerZero 和 Kelp DAO 方面会实施额外安全措施,以确保桥恢复后的安全性。

再来看第二个目标 —— 清理借贷市场中的受影响头寸。

rsETH 的抵押支撑恢复之后,理论上 Aave 的借贷市场便已不存在坏账(此时抵押价值已大于借出价值),但仍需将与黑客相关的几个异常抵押头寸清理(预计可回收 13000 ETH),以恢复市场的正常运行。

对此,Aave 表示将在以太坊与 Arbitrum 依次上发起治理提案,通过“受控的清算流程”来清理异常头寸。具体的解决流程为:

  • 暂时调整 rsETH 预言机价格,以触发高效清算;
  • 清算过程中会产生暂时性亏空(后续步骤将弥补该亏空);
  • 回收的 rsETH 抵押品将转移至 DeFi United 管理的多签地址。

Aave 强调,上述参数调整仅为临时措施,仅用于恢复执行,所有调整将在完成后恢复,不会对 Aave 协议造成长期影响。 在解决问题期间,以太坊主网、Arbitrum、Base、Mantle 和 Linea 上的 WETH 与 rsETH 存款均将保持冻结状态。

完成清算后的理想状况为:rsETH 价格预言机将恢复; 回收的 rsETH 将通过 Kelp DAO 标准赎回流程兑换为 ETH;这些 ETH 将用于填补 Aave 在以太坊和 Arbitrum 市场中的亏空。

至于 Compound,也将采取类似的清理方式,在 DeFi United 提供流动性支持的情况下,预计可额外回收约 16776 ETH。

待两大目标都有效完成后,Aave 解除所有相关市场中的 rsETH 与 ETH 暂停和冻结状态,随后会恢复 ETH 及其他资产的贷款价值比(LTV)等参数配置。

待解问题

Aave 补充提到,尽管上述方案有望在不出现社会化损失的情况下实现修复目标,但仍存在以下几点不确定性。

一是尽管已获得足够 ETH 承诺,但资金部署仍依赖最终协议与治理批准; 二是受影响头寸的清理依赖治理提案顺利通过与执行; 三是攻击者若刻意干扰,可能导致亏空未完全形成,需要额外清算步骤; 四是LayerZero 与 Kelp 已部署额外安全措施,但在生产环境验证前仍存在残余风险;

但无论如何,已搅扰 DeFi 市场许久的“Kelp DAO 被盗,Aave 坏账”事件看起来终于是要有个尾声了,后续需要看的就是方案能否在实际环境下如预期般推进。

正如 The Rollup 创始人 Andy 的评论:“接下来几天对 DeFi 来说至关重要,任务艰巨,且必须既快速又稳妥地完成。这既是一次技术挑战,更是一场社会协同的考验。能实时见证这一切的发展,确实有种不真实的感觉。”

希望好运站在 DeFi 这一侧。

Criptos en tendencia

Lecturas Relacionadas

Beyond the Stadium: The Profitable Games Surrounding the World Cup

"Beyond the Pitch: The Profit Game Around the World Cup" The FIFA World Cup transcends being a sporting spectacle, evolving into a massive global arena for speculation and profit-seeking. The 2026 tournament has amplified this dynamic, creating a multi-layered ecosystem of financial opportunism alongside the football. **Prediction markets** have surged into the mainstream. Platforms like Polymarket and Kalshi saw trading volumes for World Cup contracts soar, attracting new users with their financial trading model and high-profile, chain-based wealth stories that overshadow traditional sports betting in terms of growth and narrative. However, **traditional sportsbooks** remain the dominant force, leveraging established user habits, legal markets, and comprehensive product offerings to handle the vast majority of speculative wagers, with projections suggesting record-breaking betting volumes. Capital markets also react. **"Concept stocks"** in countries like South Korea and Japan experience volatile price swings based on team performance and anticipated fan spending on items like chicken, beer, and viewing parties, effectively becoming a stock market reflecting fan sentiment. The **ticket resale market** has become a sophisticated arena for arbitrage. Prices fluctuate wildly based on team draws and star power, with sellers sometimes listing tickets they don't yet own in a practice akin to short-selling, while FIFA's own "Right to Buy" tokens add another layer of speculative trading. **Collectibles and merchandise** offer another avenue. Panini sticker albums, with their inherent scarcity and nostalgic value, can become high-value collectibles. Limited-edition or locally themed jerseys command significant premiums on secondary markets, and even counterfeit vendors profit from fans' desire for affordable match-day identity. The **cryptocurrency** space has seen a frenzy of speculative, unauthorized World Cup-themed meme coins on chains like Solana. These tokens, often exploiting team names and player imagery, experience extreme pump-and-dump cycles, creating stories of massive gains for a few early entrants and steep losses for many others. Finally, an entire industry thrives on **providing information and tools** to other speculators. Developers create platforms like SeatSidekick to track ticket inventory and prices, while paid Telegram groups and subscriptions sell betting tips and predictions, monetizing the widespread desire for an informational edge. In essence, the World Cup has become a compressed, global laboratory for speculation. While the games determine champions on the field, a parallel, complex network of financial transactions—spanning prediction contracts, bets, stocks, tickets, collectibles, crypto, and information services—settles its own scores in the global market.

marsbitHace 37 min(s)

Beyond the Stadium: The Profitable Games Surrounding the World Cup

marsbitHace 37 min(s)

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

This article explains the three primary methods for Codex to interact with a computer, each with distinct use cases, permission boundaries, and trust levels. **1. Computer Use:** This offers the broadest access, allowing Codex to visually control and interact with the graphical user interface of authorized macOS/Windows apps, system settings, and even iOS simulators. It's ideal for tasks lacking APIs or structured tools, such as operating legacy software or multi-app workflows. However, it's the slowest method and has the widest permission scope, requiring careful supervision for sensitive actions. **2. Chrome Extension:** This grants Codex access to the user's logged-in Chrome browser state, including cookies, profiles, and open tabs. It's best for tasks requiring user identity across websites like Gmail, LinkedIn, Salesforce, or internal dashboards. Its key advantage is multi-tab control for complex workflows. While more powerful for browser-based tasks than Computer Use, it carries higher sensitivity as actions are performed under the user's identity. **3. In-App Browser:** This is a browser isolated within the Codex thread, separate from the user's personal browsing data. It excels in web development and debugging scenarios—previewing local servers, testing responsive layouts, or annotating designs directly on the page. Its isolation is a strength for development but a limitation for tasks requiring login sessions. The core principle is to choose the narrowest, safest, and most structured interface for the task. Use plugins or MCPs first, resort to visual control (Computer Use) only for GUI-dependent tasks, employ the Chrome extension for identity-reliant browser work, and prefer the In-App Browser for isolated development. **Appshots** are clarified as a fourth, complementary tool for *inputting* context—capturing a screenshot of a window to point Codex to something—rather than a method for Codex to *act*. Together, this layered approach highlights a key to AI agent productization: not granting unlimited permissions, but constraining them within clear boundaries for specific tasks while preserving user oversight.

marsbitHace 2 hora(s)

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

marsbitHace 2 hora(s)

The "Iron Rule" of Chip Equipment Is Being Broken

For years, the semiconductor equipment industry followed an unwritten "iron rule": suppliers offered steep discounts for new tool introductions (Design-in) and faced consistent price pressure during repeat orders, especially during market downturns. This long-standing buyer's market dynamic is now being upended. Recently, SK Hynix's primary equipment suppliers have reportedly requested a 3-4% price *increase*, a nearly unprecedented move. This shift is driven by a severe supply-demand imbalance fueled by the AI compute boom. Securing equipment has become an urgent arms race as chipmakers' expansion speed dictates their ability to fulfill massive AI chip orders. Key areas feeling the strain include: **TCB (Thermal Compression Bonding) Equipment:** Demand is exploding, driven by the simultaneous needs of HBM4 memory stacking, AI chip Chip-on-Substrate (C2S), and logic Chiplet Chip-on-Wafer (C2W) packaging. Players like Hanmi Semiconductor, Hanwha Semitech, and ASMPT are receiving major orders. While hybrid bonding is seen as the future, TCB remains the pragmatic choice for HBM4 mass production, with its lifecycle extended by relaxed specifications and ongoing technological upgrades. **Test Equipment Bottlenecks:** Ironically, AI-driven shortages are now crippling test equipment manufacturing. Critical components like FPGAs, Driver ICs, and CPUs face severe shortages and extended lead times (up to 52 weeks for FPGAs), as AI data center and server vendors prioritize supply. This creates a paradoxical cycle: AI chip shortages drive fab expansion, which requires more test equipment, whose production is delayed because its key parts are diverted to make AI chips. The industry is entering a broad, AI-powered upcycle. SEMI forecasts global semiconductor equipment sales to hit a record $156 billion by 2027, fueled by investment in advanced logic/foundry, HBM-driven DRAM, and advanced packaging (like CoWoS). Major players like TSMC, SK Hynix, and Micron are aggressively ramping capital expenditure. In conclusion, leading equipment vendors are no longer just selling tools; they are selling the critical capability to deliver AI-era capacity. Pricing power is shifting decisively to those with indispensable technology in key process nodes like advanced logic, HBM, and advanced packaging, rewriting the industry's traditional power structure.

marsbitHace 2 hora(s)

The "Iron Rule" of Chip Equipment Is Being Broken

marsbitHace 2 hora(s)

Trading

Spot
Futuros

Artículos destacados

Cómo comprar AAVE

¡Bienvenido a HTX.com! Hemos hecho que comprar Aave Protocol (AAVE) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Aave Protocol (AAVE) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Aave Protocol (AAVE)Después de comprar tu Aave Protocol (AAVE), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Aave Protocol (AAVE)Tradear fácilmente con Aave Protocol (AAVE) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

332 Vistas totalesPublicado en 2024.12.11Actualizado en 2026.06.02

Cómo comprar AAVE

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de AAVE (AAVE).

活动图片