The $290 Million Deficit: A Three-Way Game Between Aave, L0, and Kelp—Who Should Foot the Bill?

Odaily星球日报Опубликовано 2026-04-20Обновлено 2026-04-20

Введение

An incident involving the theft of 116,500 rsETH (worth approximately $290 million) from Kelp DAO’s cross-chain bridge contract has triggered a complex dispute over responsibility and compensation among Kelp DAO, LayerZero, and Aave. The attack occurred due to a compromised RPC provider used by LayerZero’s Decentralized Verifier Network (DVN). Since Kelp DAO’s bridge used a 1/1 DVN configuration—a single point of failure—the attacker successfully forged a cross-chain message, leading to the unauthorized release of rsETH tokens from the mainnet. These genuine tokens were then deposited into Aave and other lending platforms to borrow WETH, enabling the attacker to exit with the funds. Responsibility is attributed primarily to Kelp DAO for its risky 1/1 DVN setup. LayerZero bears secondary responsibility for permitting such a vulnerable configuration in its protocol layer. Aave also shares indirect blame for over-collateralizing rsETH and other Liquid Restaking Token (LRT) assets without adequate ongoing risk oversight. Kelp DAO lacks sufficient funds to cover the loss, shifting focus to the deeper-pocketed players: LayerZero, whose cross-chain ecosystem and reputation are at risk, and Aave, which faces massive bad loans and declining Total Value Locked (TVL). Aave has asserted that mainnet rsETH remains fully backed, implying it expects Kelp DAO to allow redemption of underlying ETH. This approach would preserve Aave’s mainnet positions but invalidate Layer2 rsETH, damaging...

Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

More than 30 hours have passed since the bridge contract of Kelp DAO's rsETH was compromised. Although the parties involved (LayerZero, Kelp DAO, Aave) have made statements (primarily "shifting blame" and emphasizing their own innocence), a final solution has yet to be provided.

Therefore, this article aims to discuss the current positions and attitudes of the involved parties, explore the reasons for the delay in finalizing a solution, and attempt to speculate on how the incident might ultimately be resolved.

Odaily Note: For background, please refer to "DeFi Hacked Again for $292 Million, Is Even Aave Unsafe Now?"

Who Should Be Responsible?

First, let's discuss the issue of responsibility.

According to the details disclosed by LayerZero, the direct cause of the incident is quite clear: the downstream RPC infrastructure relied upon by LayerZero's operated Decentralized Verifier Network (DVN) was compromised (see the analysis by SlowMist founder Yu Xian in the image below). Furthermore, because Kelp DAO's bridge contract used a 1/1 DVN configuration, the attacker only needed to complete one forged message verification to carry out the attack.

LayerZero believes that Kelp DAO, which adopted the 1/1 DVN configuration, is the most directly responsible party in this incident. This is indisputable—such an obvious "single point of failure" is utterly absurd.

However, as the underlying cross-chain protocol, LayerZero should also bear some responsibility. While LayerZero allows each upper-layer application to configure the number and threshold of DVNs itself, and the 1/1 DVN was Kelp DAO's own choice, as the designer of the underlying architecture, it should also avoid allowing such an obviously flawed configuration.

Finally, there are lending protocols like Aave (focusing on Aave here). Although they are also indirectly affected victims, objectively speaking, Aave's excessive lending permissions granted to rsETH and other LRT assets for expansion purposes are the direct reason it finds itself in its current passive position. Additionally, it is worth mentioning that Aave's former risk control team, BGD Labs (now separated from Aave), explicitly pointed out the DVN issue with Kelp DAO back in January last year. Kelp accepted the advice at the time but clearly did not make the changes... Aave's failure to continue supervising and taking corresponding measures is also a case of reaping what it sowed.

So the assignment of responsibility is clear: Kelp DAO bears primary responsibility, LayerZero secondary responsibility, and Aave also has some indirect responsibility.

The Awkward Reality

Reality is always more complex than theoretical expectations. The most critical issue is that the Kelp DAO team, which should bear the primary responsibility, does not have enough money to cover the shortfall... Directly imposing a loss write-down on all rsETH holders or betraying Layer2 token holders is essentially a dead end.

So who has the money? The first is LayerZero, which is facing a reputation crisis due to this incident, has been temporarily disabled by multiple institutions and protocols such as Bitgo, Tron, Ethena, Curve, and ether.fi, and risks losing a significant share of the cross-chain market. The second is Aave, which is facing huge potential bad debts and watching over ten billion dollars in TVL flow out.

Thus, the "ulterior motives" of each party are clear. The primarily responsible party, Kelp DAO, is basically paralyzed and unable to lead the subsequent compensation efforts; what to do needs to be discussed with the two bigger players. Meanwhile, LayerZero and Aave, the secondary and indirectly responsible parties with the ability to pay, have both stated that their protocols did not have vulnerabilities, clearly indicating they are not planning to easily take on such a huge responsibility... So the situation seems somewhat deadlocked for now.

However, I do not believe this situation will last long because both major protocols have a need to resolve the issue quickly—LayerZero cannot abandon its OFT cross-chain ecosystem ambitions, and Aave cannot ignore the continued outflow of existing funds.

The Key to the各方博弈 (Parties' Game Theory)

This morning, Aave issued an updated statement on the incident. The most important piece of information in the statement was—Aave emphasized that "rsETH on the Ethereum mainnet is fully backed".

How should this be understood? We need to start with the design of rsETH.

rsETH is essentially a liquidity restaking voucher token issued by Kelp DAO. Each rsETH token is backed by 1 ETH within the staking and restaking system, following the path "ETH - Lido - EigenLayer - Kelp DAO - rsETH".

The rsETH on the mainnet refers to the original voucher tokens issued by Kelp DAO on Ethereum. Later, to expand within the Layer2 ecosystem, Kelp DAO would use LayerZero's bridge contract (the thing that caused trouble in this incident) to map the mainnet rsETH to various Layer2s. For every 1 rsETH issued on a Layer2, the corresponding rsETH on the mainnet is deposited into Kelp DAO's custodian contract, to be released only when the Layer2 rsETH is bridged back to the mainnet.

Now, back to the incident itself. As mentioned earlier, the reason for the theft was that the hacker tricked the DVN into forging a cross-chain message, causing the bridge contract to "mistakenly release" 116,500 rsETH—note, this did not involve printing new coins out of thin air, but rather obtaining the original voucher tokens from the mainnet that should not have been released.

The problem lies precisely here. These tokens were already circulating on Layer2 through mapping, while the tokens on the mainnet were in a locked state. However, after the hacker obtained them, they deposited them into lending protocols like Aave and borrowed more liquid WETH, thus completing their escape—again, it must be emphasized that the rsETH deposited by the hacker was real, which is why Aave supported the抵押借贷 (collateralized lending) behavior for this token.

Now, looking back at Aave's statement is very interesting. The phrase "rsETH on the Ethereum mainnet is fully backed" is essentially saying: "These coins are real! Kelp DAO, you should support us in using these coins to redeem the underlying ETH (contracts are paused, redemption is currently not possible)... As for the mapped version of rsETH on Layer2 that lost the backing of the mainnet rsETH, we can't deal with that!"

This is likely Aave's inclination. Although emphasizing the value of mainnet rsETH means disregarding the value of the mapped rsETH on Layer2, and since Aave itself also has some rsETH debt positions on its Layer2 lending products (current real-time scale is $359 million), this would also create some bad debt. But weighing the two evils, Aave most likely assessed the potential impact of both options and determined that protecting its core mainnet product best serves its maximum interests.

But this is just the stance of Aave alone. How the incident is resolved ultimately depends on whether an agreement can be reached with LayerZero and Kelp DAO.

Although the latter have not yet issued further statements, I personally believe LayerZero will have difficulty accepting this solution, because abandoning the mapped tokens on Layer2 would directly threaten LayerZero's cross-chain reputation.

Potential Solutions

The problem must ultimately be solved. Various big names on social media have been offering suggestions to Aave, LayerZero, and Kelp DAO these past two days.

DefiLlama founder 0xngmi speculated on three possible paths but also stated that all three have obvious flaws. The first path is for all rsETH holders to jointly bear an 18.5% value write-down (proportion of lost tokens/issued tokens), with Kelp DAO taking the blame itself, and Aave also bearing roughly $216 million in bad debt on the mainnet. The second path is to disregard the value of all mapped rsETH on Layer2, thus preserving Aave's mainnet product, but likely causing the Layer2 ecosystem to collapse and Kelp DAO's reputation to hit zero. The third path is to fully compensate holders of rsETH before the hacker attack based on a snapshot, with subsequent buyers or transferees bearing the losses themselves. However, since funds have moved significantly after the attack, this is practically impossible to execute.

OneKey founder Yishi stated: "The best outcome now is to negotiate with the hacker, offer a 10–15% bounty, get most of the funds back, and everyone is happy. If negotiations fail, the LayerZero生态基金 (ecosystem fund) should contribute the most—it's the richest, has the most long-term interest, and paying up could save the OFT ecosystem. Kelp DAO is the poorest; either use tokens + future revenue to compensate, or simply sell the entire project to LayerZero or Bitmine. Aave's Umbrella and stkAAVE cover the last layer, but WETH depositors absolutely must not suffer a value write-down. Otherwise, Morpho, Spark, Fluid, Euler would all undergo repricing simultaneously, the entire LRT sector would be blacklisted, and the entire DeFi industry would be set back three years."

In any case, the parties will certainly continue to argue for a while longer, as involving hundreds of millions in real money means no one wants to be the biggest sucker.

As for how much more time is needed to provide a solution, as mentioned earlier, the two giants dare not delay too long. LayerZero is currently forced into a pause by various partner institutions and protocols; delaying longer will likely lead these partners to switch cross-chain solutions. Aave's situation is also not optimistic; the utilization rates of multiple pools have reached 100%, leaving depositors 'trapped'... If ETH were to suddenly plummet sharply, Aave would likely be unable to effectively liquidate (which is indeed the case now) and could incur more bad debt, ultimately causing the problem to snowball—if it reaches this point, the foundation of the industry could be shaken, a situation obviously no one would like to see.

Связанные с этим вопросы

QWhat was the direct cause of the security incident involving Kelp DAO's rsETH bridge contract?

AThe direct cause was the compromise of the downstream RPC infrastructure relied upon by LayerZero's Decentralized Verifier Network (DVN). The attacker exploited this to forge a cross-chain message validation, which was possible because Kelp DAO's bridge contract used a 1/1 DVN configuration, creating a single point of failure.

QAccording to the article, how is the responsibility for the incident allocated among Aave, LayerZero, and Kelp DAO?

AKelp DAO bears the primary responsibility for using a flawed 1/1 DVN configuration. LayerZero bears secondary responsibility as the underlying protocol designer that allowed such a risky configuration. Aave also has indirect responsibility for granting excessive borrowing permissions to rsETH and failing to follow up on previously identified risks.

QWhat is the key reason why resolving the situation is particularly complex and slow?

AThe primary responsible party, Kelp DAO, lacks the financial resources to cover the massive $290 million shortfall. Meanwhile, the parties with the funds to potentially help—LayerZero and Aave—have both publicly claimed their protocols were not at fault and are reluctant to accept the financial burden, leading to a stalemate in negotiations.

QWhat does Aave's statement that 'rsETH on the Ethereum mainnet is fully backed' imply about their proposed solution?

AIt implies that Aave's preferred solution is to treat the mainnet rsETH (the original tokens) as the only valid assets, using the underlying staked ETH to cover losses on its mainnet platform. This would mean writing off the value of the Layer2 mapped versions of rsETH, which would severely impact LayerZero's cross-chain ecosystem and Kelp DAO's reputation.

QWhat are two potential negative outcomes if a resolution is not reached quickly, as mentioned in the article?

A1. LayerZero risks losing significant cross-chain market share as partners like Bitgo and Tron have already disabled its services. 2. Aave faces the risk of its bad debt snowballing if ETH prices drop sharply, as high utilization rates in its pools prevent effective liquidations, potentially causing wider instability in the DeFi sector.

Похожее

AI PC Battle: Bet on the Toll Booth, Not the Camp

**Title:** The AI PC Battle: Don't Bet on Sides, Bet on the Tollbooth **Summary:** The AI PC competition is moving beyond simple "x86 vs. Arm" narratives. The core investment thesis should focus on identifying which players can sustain margins, cash flow, and pricing power throughout the upgrade cycle, rather than backing a particular architecture. The opportunity is analyzed in three layers: 1. **The Advanced Foundry Tollbooth:** TSMC is positioned to collect "tolls" regardless of which chip designer wins, due to its dominant ~70% share in advanced semiconductor manufacturing, which is essential for high-end AI PC chips. 2. **Compute & Platform Spillover:** AMD represents an offensive in the x86 CPU+GPU space, while NVIDIA leverages its GPU and CUDA software stack dominance. Both benefit from the demand for increased local AI compute. 3. **Architecture Diffusion & Turnaround Plays:** ARM and Intel offer potential for significant upside (elasticity), but investments here require stricter discipline due to higher execution risks and competitive challenges. The industry is transitioning from concept to shipment validation. While short-term forecasts for AI PC adoption have been revised down slightly due to tariffs and procurement delays, the long-term trend towards AI becoming a standard PC feature remains intact. The key driver for upgrade cycles will be whether compelling enterprise applications (e.g., privacy-sensitive computing, low-latency inference) emerge beyond consumer-focused features like meeting summarization. Investment strategy should prioritize companies with platform-level advantages and recurring revenue streams. TSMC offers high certainty as the foundational tollbooth. AMD presents a strong offensive play within the established ecosystem. ARM and Intel are higher-risk, higher-potential-reward turnaround bets. The report cautions against chasing short-term hype and emphasizes a disciplined, long-term approach focused on buying ecosystem strength and cash-flow certainty after market enthusiasm subsides. **Key Risks:** Underwhelming AI PC applications slowing upgrade cycles; slow improvement in Windows on Arm compatibility; macro/tariff impacts on PC demand; potential advanced node supply-demand mismatches affecting TSMC; high overall AI sector valuations making stocks vulnerable to a risk-off shift in markets.

marsbit5 мин. назад

AI PC Battle: Bet on the Toll Booth, Not the Camp

marsbit5 мин. назад

Ten-Thousand-Word Analysis: From $10 to $290, MRVL Wins the Entire AI Era by 'Not Making GPUs'

Marvell Technology's stock price surged from under $10 in 2016 to a record $290 in June 2026, fueled not by making GPUs, but by dominating AI infrastructure connectivity. This analysis argues the market misvalues MRVL as merely a smaller Broadcom in custom AI chips, overlooking its true, unique position. Marvell's core strength lies in enabling high-speed data flow for AI clusters through three interconnected businesses. First, it holds a commanding ~70% market share in high-speed optical DSPs (essential for data center light modules), a deep-moat business with accelerating growth. Second, its custom AI chip design business serves hyperscalers like AWS, Microsoft, and Google, with a significant revenue pipeline despite lower margins. Third, stable cash flows come from Ethernet switch chips and enterprise storage controllers. Together, they form a full-stack "AI data movement" platform. CEO Matt Murphy's transformative leadership since 2016, involving strategic divestments, key acquisitions (like Inphi for optical DSPs), and securing long-term agreements with major cloud providers, repositioned the company. A pivotal $2 billion strategic investment from NVIDIA in 2026 underscored Marvell's critical role in the AI ecosystem, particularly through collaborations like NVLink Fusion. While Marvell faces risks—including client concentration (losing the Amazon Trainium3 design), lower-margin business mix, competitive threats, insider selling, and complex supply chains—its fundamentals remain strong. The optical interconnect moat is widening with the acquisition of Celestial AI (photonics fabric), and financial metrics show accelerating revenue growth and operating leverage. With a PEG ratio suggesting undervaluation relative to its growth, the thesis is that the market undervalues Marvell's monopolistic position in AI "plumbing" while overemphasizing its competitive custom chip segment. The story transcends investing, symbolizing how in any complex system—from the internet to AI—the value of "connection" ultimately surpasses that of individual "nodes."

marsbit35 мин. назад

Ten-Thousand-Word Analysis: From $10 to $290, MRVL Wins the Entire AI Era by 'Not Making GPUs'

marsbit35 мин. назад

AI Relay Stations Spark Heated Debate on Zhihu: Behind Cheap Tokens, What Are Users Really Worried About?

A discussion on Zhihu about "AI relay stations" shifted the niche developer topic of "cheap tokens" into broader user awareness. Users moved beyond simply questioning the legitimacy of these services to focus on practical concerns: Where do cheap tokens truly come from? Is the model being accessed the real one? Can relay stations see prompts, code, and API keys? For occasional users, are the risks worth it? The core debate centered less on price and more on trust. A primary worry is model authenticity—the risk of "model swapping," where users paying for a premium model might be routed to a cheaper one, creating an information asymmetry. Others argued that cost comparisons matter; while cheaper than official pay-as-you-go APIs, relay stations may not be the lowest-cost option versus subscriptions, domestic models, or free tiers, making user needs assessment crucial. Speculation about token sources ranged from legitimate bulk discounts to gray-area methods like account sharing or exploiting regional pricing. This opacity makes risk assessment difficult for users. Data security emerged as a critical concern, especially for enterprise use. When processing sensitive information like code, contracts, or client data, the inability to verify a relay station's data handling, retention, or access policies poses significant compliance and confidentiality risks. The evolving consensus suggests relay stations can be used cautiously for low-sensitivity, disposable tasks (e.g., summarizing public info, simple translation). However, they should not be the default for sensitive, professional, or production workflows involving proprietary data, Agents, or automated systems. Recommendations include avoiding large prepayments, not relying on a single service, using test prompts to monitor quality, anonymizing data where possible, and keeping official channels as backups. Ultimately, the discussion framed tokens not just as a billing unit but as a measure of real cost encompassing price, model integrity, data security, and service stability. The popularity of relay stations highlights user demand for affordable access, but the debate underscores a key trade-off: the savings from cheap tokens may come at the price of trust, transparency, and control over one's data and AI experience.

marsbit1 ч. назад

AI Relay Stations Spark Heated Debate on Zhihu: Behind Cheap Tokens, What Are Users Really Worried About?

marsbit1 ч. назад

In-Depth Research Report on TradFi: The Convergence Wave of Crypto and Traditional Finance

In 2026, the crypto industry is undergoing a profound infrastructure-level transformation—TradFi assets are migrating on-chain at an unprecedented pace. According to CoinGecko's Q1 2026 report, the total value locked (TVL) of tokenized real-world assets (RWA) has surpassed $31 billion, a nearly 4x increase from $7.8 billion at the beginning of 2025, with the sector’s aggregate market capitalization reaching $19.3 billion. Among these, the market cap of tokenized stocks surged from $2 million to $486 million, with Q1 spot trading volume reaching $15.1 billion—a single quarter already surpassing the entire second half of 2025. RWA perpetual contract Q1 trading volume reached a staggering $524.8 billion, far exceeding the $313 billion for all of 2025. Meanwhile, BlackRock's BUIDL fund has reached $2.3 billion in scale and has filed for two new tokenized funds, signaling that the world's largest asset manager's tokenization strategy is evolving from pilot to product suite expansion. HTX, as a core participant in the crypto exchange sector, officially launched TradFi perpetual futures products including NVDA, AAPL, MSFT, META, and SPY in 2026, enabling crypto users to gain 24/7 trading access to core U.S. equities. Boston Consulting Group predicts that global tokenized asset scale could reach $16 trillion by 2030, while McKinsey offers a conservative estimate of approximately $2 trillion. The on-chain migration of TradFi assets is no longer a "future narrative" but a structural transformation unfolding in real time, as crypto exchanges evolve from single crypto asset trading platforms toward "multi-asset-class trading infrastructure."

HTX Learn1 ч. назад

In-Depth Research Report on TradFi: The Convergence Wave of Crypto and Traditional Finance

HTX Learn1 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить AAVE

Добро пожаловать на HTX.com! Мы сделали приобретение Aave Protocol (AAVE) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Aave Protocol (AAVE).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Aave Protocol (AAVE)После приобретения вами Aave Protocol (AAVE) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Aave Protocol (AAVE)С легкостью торгуйте Aave Protocol (AAVE) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

954 просмотров всегоОпубликовано 2024.04.12Обновлено 2026.06.02

Как купить AAVE

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на AAVE (AAVE) представлены ниже.

活动图片