#What Happened in the Cross-Chain Bridge Exploit
The recent cross-chain bridge exploit led to the draining of approximately $292 million in unbacked rsETH tokens from KelpDAO. The aftermath primarily impacted Aave, as the attacker leveraged the newly minted tokens to borrow $190 million in both WETH and stablecoins through Aave's V3 and V4 platforms. This incident has resulted in Aave facing bad debt estimated at around $195 million.
#How Did the Exploit Occur
The exploit unfolded on April 18 when roughly 116,500 uncollateralized rsETH tokens were minted via KelpDAO's LayerZero-enabled bridge. This amount equates to about 18% of the total rsETH supply. Subsequently, these tokens were deposited into Aave as collateral. Because Aave processes rsETH transactions at face value, the platform was tricked into approving loans that will likely never be recovered.
#What Are the Implications for Aave
Following the exploit, Aave decided to freeze its rsETH and WETH markets to mitigate further fallout. This decision came after Aave's total value locked (TVL) suffered a significant decline; from a high of approximately $26 billion, it lost between $6 billion and $10 billion as depositors rushed to withdraw their funds.
#How Did SparkLend Manage to Protect Itself
Amidst this chaos, SparkLend, the lending arm of MakerDAO, strategically reduced its rsETH exposure before the exploit. This foresight allowed SparkLend to dodge the majority of the exploit’s impact. In the aftermath, as users sought safer platforms, SparkLend saw nearly $1.7 billion in new deposits, effectively doubling its TVL within days.
#What Measures Were Taken Post-Exploit
In response to the bad debt situation, Aave's community and DAO have initiated a fundraising campaign aimed at securing $200 million to address the losses. So far, around $160 million has been successfully raised, with notable contributions coming from Mantle and the AAVE DAO.
#What Have We Learned About Cross-Chain Bridges
This incident highlights a critical risk in decentralized finance. Cross-chain bridges, which have historically represented a substantial attack vector in DeFi, show vulnerabilities that can lead to the creation of unbacked assets. Previous incidents like the Ronin bridge hack and the Wormhole exploit follow a similar pattern, emphasizing the need for increased security and oversight in decentralized systems.
Investors should remain vigilant about the risks associated with cross-chain technologies and maintain an understanding of how these systems operate.