🧔♂️ A friendly human may check it before it goes live. More news here
Crypto lending protocol Aave reviews listings after exploit
Aave, a decentralized lending protocol, said in a postmortem this week that it will review every asset listed on V3 and rewrite its listing standards after April’s rsETH exploit let an attacker post unbacked collateral and borrow funds.
rsETH is KelpDAO’s liquid restaking token for ether. KelpDAO lets users reuse staked ether in decentralized finance. rsETH is used as collateral because it is designed to track ether while accruing staking and restaking rewards.
Aave said the losses stemmed from LayerZero message verification, not its smart contracts.
According to the protocol, KelpDAO’s bridge used a 1-of-1 verifier configuration, and a forged cross-chain message released 116,500 unbacked rsETH on Ethereum without a real burn on the source chain.
Under Aave V3, new collateral is approved by governance with parameters such as caps and isolation modes. External analyses said the attacker later used about 89,567 rsETH on Aave to borrow about US$190 million to US$236 million. That created potential bad debt that could fall on wrapped ether depositors if recoveries or backstops do not cover the losses.
KelpDAO paused contracts within 46 minutes. LayerZero said it will stop attesting applications that use 1-of-1 decentralized verifier network setups, and Aave said its risk managers have made about 295 parameter changes across V3 since the exploit.
🔗 Source: CoinDesk
Recent Aave developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




