The $290 Million Deficit: A Three-Way Game Between Aave, L0, and Kelp—Who Should Foot the Bill?

Odaily星球日报Опубликовано 2026-04-20Обновлено 2026-04-20

Введение

An incident involving the theft of 116,500 rsETH (worth approximately $290 million) from Kelp DAO’s cross-chain bridge contract has triggered a complex dispute over responsibility and compensation among Kelp DAO, LayerZero, and Aave. The attack occurred due to a compromised RPC provider used by LayerZero’s Decentralized Verifier Network (DVN). Since Kelp DAO’s bridge used a 1/1 DVN configuration—a single point of failure—the attacker successfully forged a cross-chain message, leading to the unauthorized release of rsETH tokens from the mainnet. These genuine tokens were then deposited into Aave and other lending platforms to borrow WETH, enabling the attacker to exit with the funds. Responsibility is attributed primarily to Kelp DAO for its risky 1/1 DVN setup. LayerZero bears secondary responsibility for permitting such a vulnerable configuration in its protocol layer. Aave also shares indirect blame for over-collateralizing rsETH and other Liquid Restaking Token (LRT) assets without adequate ongoing risk oversight. Kelp DAO lacks sufficient funds to cover the loss, shifting focus to the deeper-pocketed players: LayerZero, whose cross-chain ecosystem and reputation are at risk, and Aave, which faces massive bad loans and declining Total Value Locked (TVL). Aave has asserted that mainnet rsETH remains fully backed, implying it expects Kelp DAO to allow redemption of underlying ETH. This approach would preserve Aave’s mainnet positions but invalidate Layer2 rsETH, damaging...

Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

More than 30 hours have passed since the bridge contract of Kelp DAO's rsETH was compromised. Although the parties involved (LayerZero, Kelp DAO, Aave) have made statements (primarily "shifting blame" and emphasizing their own innocence), a final solution has yet to be provided.

Therefore, this article aims to discuss the current positions and attitudes of the involved parties, explore the reasons for the delay in finalizing a solution, and attempt to speculate on how the incident might ultimately be resolved.

Odaily Note: For background, please refer to "DeFi Hacked Again for $292 Million, Is Even Aave Unsafe Now?"

Who Should Be Responsible?

First, let's discuss the issue of responsibility.

According to the details disclosed by LayerZero, the direct cause of the incident is quite clear: the downstream RPC infrastructure relied upon by LayerZero's operated Decentralized Verifier Network (DVN) was compromised (see the analysis by SlowMist founder Yu Xian in the image below). Furthermore, because Kelp DAO's bridge contract used a 1/1 DVN configuration, the attacker only needed to complete one forged message verification to carry out the attack.

LayerZero believes that Kelp DAO, which adopted the 1/1 DVN configuration, is the most directly responsible party in this incident. This is indisputable—such an obvious "single point of failure" is utterly absurd.

However, as the underlying cross-chain protocol, LayerZero should also bear some responsibility. While LayerZero allows each upper-layer application to configure the number and threshold of DVNs itself, and the 1/1 DVN was Kelp DAO's own choice, as the designer of the underlying architecture, it should also avoid allowing such an obviously flawed configuration.

Finally, there are lending protocols like Aave (focusing on Aave here). Although they are also indirectly affected victims, objectively speaking, Aave's excessive lending permissions granted to rsETH and other LRT assets for expansion purposes are the direct reason it finds itself in its current passive position. Additionally, it is worth mentioning that Aave's former risk control team, BGD Labs (now separated from Aave), explicitly pointed out the DVN issue with Kelp DAO back in January last year. Kelp accepted the advice at the time but clearly did not make the changes... Aave's failure to continue supervising and taking corresponding measures is also a case of reaping what it sowed.

So the assignment of responsibility is clear: Kelp DAO bears primary responsibility, LayerZero secondary responsibility, and Aave also has some indirect responsibility.

The Awkward Reality

Reality is always more complex than theoretical expectations. The most critical issue is that the Kelp DAO team, which should bear the primary responsibility, does not have enough money to cover the shortfall... Directly imposing a loss write-down on all rsETH holders or betraying Layer2 token holders is essentially a dead end.

So who has the money? The first is LayerZero, which is facing a reputation crisis due to this incident, has been temporarily disabled by multiple institutions and protocols such as Bitgo, Tron, Ethena, Curve, and ether.fi, and risks losing a significant share of the cross-chain market. The second is Aave, which is facing huge potential bad debts and watching over ten billion dollars in TVL flow out.

Thus, the "ulterior motives" of each party are clear. The primarily responsible party, Kelp DAO, is basically paralyzed and unable to lead the subsequent compensation efforts; what to do needs to be discussed with the two bigger players. Meanwhile, LayerZero and Aave, the secondary and indirectly responsible parties with the ability to pay, have both stated that their protocols did not have vulnerabilities, clearly indicating they are not planning to easily take on such a huge responsibility... So the situation seems somewhat deadlocked for now.

However, I do not believe this situation will last long because both major protocols have a need to resolve the issue quickly—LayerZero cannot abandon its OFT cross-chain ecosystem ambitions, and Aave cannot ignore the continued outflow of existing funds.

The Key to the各方博弈 (Parties' Game Theory)

This morning, Aave issued an updated statement on the incident. The most important piece of information in the statement was—Aave emphasized that "rsETH on the Ethereum mainnet is fully backed".

How should this be understood? We need to start with the design of rsETH.

rsETH is essentially a liquidity restaking voucher token issued by Kelp DAO. Each rsETH token is backed by 1 ETH within the staking and restaking system, following the path "ETH - Lido - EigenLayer - Kelp DAO - rsETH".

The rsETH on the mainnet refers to the original voucher tokens issued by Kelp DAO on Ethereum. Later, to expand within the Layer2 ecosystem, Kelp DAO would use LayerZero's bridge contract (the thing that caused trouble in this incident) to map the mainnet rsETH to various Layer2s. For every 1 rsETH issued on a Layer2, the corresponding rsETH on the mainnet is deposited into Kelp DAO's custodian contract, to be released only when the Layer2 rsETH is bridged back to the mainnet.

Now, back to the incident itself. As mentioned earlier, the reason for the theft was that the hacker tricked the DVN into forging a cross-chain message, causing the bridge contract to "mistakenly release" 116,500 rsETH—note, this did not involve printing new coins out of thin air, but rather obtaining the original voucher tokens from the mainnet that should not have been released.

The problem lies precisely here. These tokens were already circulating on Layer2 through mapping, while the tokens on the mainnet were in a locked state. However, after the hacker obtained them, they deposited them into lending protocols like Aave and borrowed more liquid WETH, thus completing their escape—again, it must be emphasized that the rsETH deposited by the hacker was real, which is why Aave supported the抵押借贷 (collateralized lending) behavior for this token.

Now, looking back at Aave's statement is very interesting. The phrase "rsETH on the Ethereum mainnet is fully backed" is essentially saying: "These coins are real! Kelp DAO, you should support us in using these coins to redeem the underlying ETH (contracts are paused, redemption is currently not possible)... As for the mapped version of rsETH on Layer2 that lost the backing of the mainnet rsETH, we can't deal with that!"

This is likely Aave's inclination. Although emphasizing the value of mainnet rsETH means disregarding the value of the mapped rsETH on Layer2, and since Aave itself also has some rsETH debt positions on its Layer2 lending products (current real-time scale is $359 million), this would also create some bad debt. But weighing the two evils, Aave most likely assessed the potential impact of both options and determined that protecting its core mainnet product best serves its maximum interests.

But this is just the stance of Aave alone. How the incident is resolved ultimately depends on whether an agreement can be reached with LayerZero and Kelp DAO.

Although the latter have not yet issued further statements, I personally believe LayerZero will have difficulty accepting this solution, because abandoning the mapped tokens on Layer2 would directly threaten LayerZero's cross-chain reputation.

Potential Solutions

The problem must ultimately be solved. Various big names on social media have been offering suggestions to Aave, LayerZero, and Kelp DAO these past two days.

DefiLlama founder 0xngmi speculated on three possible paths but also stated that all three have obvious flaws. The first path is for all rsETH holders to jointly bear an 18.5% value write-down (proportion of lost tokens/issued tokens), with Kelp DAO taking the blame itself, and Aave also bearing roughly $216 million in bad debt on the mainnet. The second path is to disregard the value of all mapped rsETH on Layer2, thus preserving Aave's mainnet product, but likely causing the Layer2 ecosystem to collapse and Kelp DAO's reputation to hit zero. The third path is to fully compensate holders of rsETH before the hacker attack based on a snapshot, with subsequent buyers or transferees bearing the losses themselves. However, since funds have moved significantly after the attack, this is practically impossible to execute.

OneKey founder Yishi stated: "The best outcome now is to negotiate with the hacker, offer a 10–15% bounty, get most of the funds back, and everyone is happy. If negotiations fail, the LayerZero生态基金 (ecosystem fund) should contribute the most—it's the richest, has the most long-term interest, and paying up could save the OFT ecosystem. Kelp DAO is the poorest; either use tokens + future revenue to compensate, or simply sell the entire project to LayerZero or Bitmine. Aave's Umbrella and stkAAVE cover the last layer, but WETH depositors absolutely must not suffer a value write-down. Otherwise, Morpho, Spark, Fluid, Euler would all undergo repricing simultaneously, the entire LRT sector would be blacklisted, and the entire DeFi industry would be set back three years."

In any case, the parties will certainly continue to argue for a while longer, as involving hundreds of millions in real money means no one wants to be the biggest sucker.

As for how much more time is needed to provide a solution, as mentioned earlier, the two giants dare not delay too long. LayerZero is currently forced into a pause by various partner institutions and protocols; delaying longer will likely lead these partners to switch cross-chain solutions. Aave's situation is also not optimistic; the utilization rates of multiple pools have reached 100%, leaving depositors 'trapped'... If ETH were to suddenly plummet sharply, Aave would likely be unable to effectively liquidate (which is indeed the case now) and could incur more bad debt, ultimately causing the problem to snowball—if it reaches this point, the foundation of the industry could be shaken, a situation obviously no one would like to see.

Связанные с этим вопросы

QWhat was the direct cause of the security incident involving Kelp DAO's rsETH bridge contract?

AThe direct cause was the compromise of the downstream RPC infrastructure relied upon by LayerZero's Decentralized Verifier Network (DVN). The attacker exploited this to forge a cross-chain message validation, which was possible because Kelp DAO's bridge contract used a 1/1 DVN configuration, creating a single point of failure.

QAccording to the article, how is the responsibility for the incident allocated among Aave, LayerZero, and Kelp DAO?

AKelp DAO bears the primary responsibility for using a flawed 1/1 DVN configuration. LayerZero bears secondary responsibility as the underlying protocol designer that allowed such a risky configuration. Aave also has indirect responsibility for granting excessive borrowing permissions to rsETH and failing to follow up on previously identified risks.

QWhat is the key reason why resolving the situation is particularly complex and slow?

AThe primary responsible party, Kelp DAO, lacks the financial resources to cover the massive $290 million shortfall. Meanwhile, the parties with the funds to potentially help—LayerZero and Aave—have both publicly claimed their protocols were not at fault and are reluctant to accept the financial burden, leading to a stalemate in negotiations.

QWhat does Aave's statement that 'rsETH on the Ethereum mainnet is fully backed' imply about their proposed solution?

AIt implies that Aave's preferred solution is to treat the mainnet rsETH (the original tokens) as the only valid assets, using the underlying staked ETH to cover losses on its mainnet platform. This would mean writing off the value of the Layer2 mapped versions of rsETH, which would severely impact LayerZero's cross-chain ecosystem and Kelp DAO's reputation.

QWhat are two potential negative outcomes if a resolution is not reached quickly, as mentioned in the article?

A1. LayerZero risks losing significant cross-chain market share as partners like Bitgo and Tron have already disabled its services. 2. Aave faces the risk of its bad debt snowballing if ETH prices drop sharply, as high utilization rates in its pools prevent effective liquidations, potentially causing wider instability in the DeFi sector.

Похожее

GitHub, Transfixed by AI

On the night of February 9th, GitHub suffered a major outage caused by a simple configuration change—reducing a cache refresh interval from 12 to 2 hours—that triggered a cascade of failures. This was not an isolated event, but part of a broader pattern. In early 2026, GitHub experienced at least 8 major incidents, failing to meet its promised 99.9% availability. These outages stemmed from structural issues: explosive growth in load, tight service coupling, and insufficient protection against abnormal traffic. This unprecedented load is driven by AI Agents. In 2025, GitHub handled ~1 billion commits. By 2026, weekly commits reached 275 million, projecting to ~14 billion for the year—a 14x increase. AI tools like Claude Code now contribute 4.5% of all public repository commits, with weekly submissions surging 25x in just three months. AI-generated pull requests jumped from 4 million to 17 million per month in half a year. Unlike human developers, AI Agents work continuously, generating commits at a scale that overwhelms infrastructure designed for human rhythms. The surge also shattered GitHub's business model. Copilot's flat-rate pricing, based on assisting human developers, became unsustainable as Agentic AI sessions consumed resources worth hundreds of dollars for a few dollars in fees. In response, GitHub imposed usage limits and, by June 1st, shifted to a pay-per-use "AI Credits" system. Facing this new reality, GitHub realized a 10x scaling plan was insufficient. It announced a need to *redesign* its architecture for 30x current scale—decoupling services, adding fault isolation, and improving change management to prevent cascading failures. Other platforms like Stripe and AWS are facing similar challenges with AI Agents. Fundamentally, GitHub is transitioning from a human collaboration platform to an "exhaust pipe" for automated AI workflows. Its detailed post-mortem reports aim to maintain trust during this turbulent rebuild. The February outage was not just a technical glitch, but a signal of the software industry's entry into a new, AI-driven era.

marsbit9 мин. назад

GitHub, Transfixed by AI

marsbit9 мин. назад

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

Facing massive paper losses exceeding $90 billion each amidst a sharp market downturn, "Digital Asset Treasury" (DAT) giants Strategy and Bitmine find themselves in a precarious position, but with different underlying risks. Strategy, heavily invested in Bitcoin (BTC), faces significant financial strain. Its strategy relies heavily on debt, including convertible notes and preferred stock (STRC) requiring substantial dividend payments. With its cash reserves dwindling and BTC offering no staking yield for cash flow, Strategy's high leverage makes it vulnerable. A continued price decline could force asset sales to meet obligations, potentially creating a negative feedback loop. Its market value has already fallen sharply. In contrast, Bitmine, an Ethereum (ETH) holder, appears on firmer financial ground. It primarily funds its purchases through equity offerings (like ATM programs), avoiding debt pressure. It also generates income by staking a large portion of its ETH holdings. While not immune to market drops and shareholder dilution concerns, Bitmine maintains more flexibility, recently announcing a new preferred share offering to raise further capital. The core divergence lies in their financing: Bitmine uses equity (investor money), while Strategy uses debt (borrowed money). Consequently, Bitmine currently faces less immediate liquidity pressure than Strategy, which must navigate the dual challenge of servicing debt/dividends and a declining core asset (BTC) price.

marsbit16 мин. назад

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

marsbit16 мин. назад

Where the AI Bubble Really Is: Which Layer of Players Are Naked

AI Bubble: Where It Really Is and Who's Swimming Naked This analysis dissects the AI industry not as a single entity but as a five-layer pyramid, arguing that bubbles are concentrated in specific tiers, not uniformly distributed. **Key Distinction from the 2000 Dot-com Bubble:** Unlike 2000, where companies had stock prices before revenue, today's leading AI players have massive, contract-backed revenue driving their valuations. Core infrastructure demand is real, with every GPU running at full capacity for paying customers. **The Five-Layer Pyramid & Bubble Assessment:** * **L0 (Fab/Manufacturing) & Top L4 (Leading AI Apps): NO BUBBLE.** Companies like TSMC, NVIDIA, major cloud providers (Microsoft, Google, Meta, Amazon), and top AI labs have real revenues and orders. Supply is tightly constrained by TSMC's disciplined capacity control and physical limits like power/land for data centers, preventing a supply glut. * **L1 (Memory): BATTLEGROUND.** Sky-high HBM margins could signal a new structural cycle or a classic "boom before bust." The oligopoly of three major players may enforce supply discipline, making this a high-stakes bet. * **L2 (Interconnect/Optical Modules): BUBBLE TERRITORY.** Companies like Lumentum and AAOI have seen stock surges (4-10x) far outpacing revenue growth. This hardware segment has lower physical barriers to expansion than fabs, allowing speculation. It mirrors the 2000 bubble's epicenter—optics. * **L3 (Infrastructure/"GPU Landlords"): VULNERABLE.** GPU leasing companies profit from the current compute shortage but own no long-term moat. Their business model relies on a temporary bottleneck that will ease as big tech expands and new tech (e.g., potential space-based data centers) emerges. * **L4 Long Tail (VC-backed Startups): STRONG BUBBLE SIGNALS.** VC funding concentration in AI is twice that of the 1999 peak. Many startups with little revenue use the valuation logic of successful giants to justify their own, creating high risk of a "valuation crunch" when funding dries up. **Critical Risks to Monitor:** 1. **GPU Depreciation & Accounting:** Companies extending the assumed useful life of GPUs artificially boost profits. The true economic life depends on future generational leaps from NVIDIA. 2. **"GPU Credit" & Off-Balance-Sheet Leverage:** Emerging structures where shell companies borrow to buy GPUs and lease them out (with chipmakers sometimes investing) move debt off major balance sheets. This echoes the "vendor financing" of 2000 and the securitization risks of 2008, though currently small-scale. 3. **TSMC Abandoning Caution:** If the primary supply bottleneck (TSMC's conservative capacity planning) breaks, runaway supply could trigger a bust. 4. **Algorithmic Efficiency Breakthrough:** A major leap in software efficiency could drastically reduce the need for raw compute hardware, undermining the investment thesis. **Conclusion:** The AI boom is expensive and has frothy areas, but its core is underpinned by real demand and physical supply constraints. The bubble risk is layered: most present in optical components, GPU leasing, and the long-tail startup ecosystem, while the foundational chip manufacturing and leading application layers remain relatively solid—for now.

marsbit29 мин. назад

Where the AI Bubble Really Is: Which Layer of Players Are Naked

marsbit29 мин. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить AAVE

Добро пожаловать на HTX.com! Мы сделали приобретение Aave Protocol (AAVE) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Aave Protocol (AAVE).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Aave Protocol (AAVE)После приобретения вами Aave Protocol (AAVE) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Aave Protocol (AAVE)С легкостью торгуйте Aave Protocol (AAVE) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

954 просмотров всегоОпубликовано 2024.04.12Обновлено 2026.06.02

Как купить AAVE

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на AAVE (AAVE) представлены ниже.

活动图片