rsETH incident — 2026-04-18

I think a lot of the discussion here is implicitly assuming a worst-case where the loss equals ~100% of what was borrowed, which may be overstating things.

rsETH is not a zero-value asset. Even after the exploit, it still has underlying ETH backing (albeit impaired), and is currently trading at a discount rather than collapsing to zero. That suggests there is residual value that could be realized over time, particularly if redemption mechanisms are clarified.

3 Likes

We do not have a solvency crisis on Mainnet; we have a liquidity crisis caused by Kelp pausing their contracts. Slashing the Umbrella vault to cover a temporary liquidity freeze violates the purpose of the insurance fund. The DAO Treasury must bridge the liquidity gap (via borrowing or stablecoin conversion) until Kelp unpauses and the rsETH can be cleanly unwrapped. Do not permanently slash stakers for a temporary freeze.

2 Likes

Hi,

If this helps “keeping leveraged positions viable and preserving reserve stability across affected markets”, why mainnet hasn’t been adjusted?

Also, as mentionned by @ApuMallku this mostly make available liquidity even more difficult to get. Some people are arguing that, on the contrary, borrow should be increased to encourage debt repayment.

But still, why is the adjustment only on L2? As if the DAO would prefer users not to withdraw on L2…?

Genuinely interested in more insights on that matter.
Thanks!

Dear Community, dear Service Providers,

We are currently discussing ‘patience’ and ‘residual values’ while the protocol is de facto straining under a massive liquidity crisis. We must end this leadership vacuum now and face the reality of the situation:

The 100% Utilization Trap: ETH utilization on Aave has reached 100%. We are currently unable to process withdrawals. This is not a temporary glitch; it is a systemic standstill that undermines global trust in Aave.

Kelp is Solvent: Let’s stop pretending there is no money. Kelp holds 533,000 ETH. There is no lack of capital; there is only a lack of resolve from our leadership to demand this capital as liability collateral for our users.

Liquidations in a Vacuum: If ETH continues to drop at market open, we will face a liquidation wave that is blocked by the ‘freezing’ of our markets. This produces Bad Debt by the second—debt that the DAO and its token holders will ultimately have to cover.

My demand to Aave Labs and the remaining Service Providers:

We must move past internal budget disputes. The DAO needs leadership quality that lives up to its name. We require a Special Task Force to immediately hold Kelp DAO accountable under MiCA/DORA regulations. If Kelp pauses their contracts, Aave must act to secure those 533,000 ETH as protection for our affected users.

Who will take responsibility and initiate these necessary steps? If the current structure is unable to act, we as token holders must force an extraordinary governance vote to officially declare Kelp in default.

We do not need reassuring words. We need decisive action to secure the future of this protoco

6 Likes

The issue with this is that AAVE has no direct power over Kelp, “declaring them in default” has no bearing on the actual onchain reality, unless you’re proposing to just outright liquidate/confiscate all the rsETH deposited? If so, that’s a disastrous precedent unbecoming of a “DeFi” protocol and more becoming of a Communist Dictatorship, as you’re betraying the property rights of nearly a billion dollars worth of rsETH.

1 Like

@tsips1267, I appreciate the point, but there is a fundamental misunderstanding here. This is not about ‘reprogramming’ the blockchain. This is about legal liability and strategic leverage in 2026:

Legal Reality: Aave does not exist in a vacuum. Under MiCA/DORA, there are clear liability obligations. When Kelp DAO pauses contracts and causes market-driven losses, Aave DAO must officially hold them accountable to secure user claims. This is the essential first step for any insurance or compensation recovery.

Kelp is Evading Communication: I have spent tonight attempting to contact Kelp DAO across all channels (DMs, Email) to demand a statement on their liability and their 533,000 ETH reserves. The result: They have blocked communication and disabled DMs.

Leverage: If Kelp refuses to communicate, Aave must escalate. A ‘declaration of default’ is not a technical execution; it is a governance act that isolates Kelp within the DeFi ecosystem and makes them legally vulnerable.

Anyone who remains silent and blocks communication while user funds are at risk has de facto forfeited their trust. We need a task force to enforce these claims legally, rather than hiding behind the excuse of 'no power over the blockchain.

5 Likes

So you’re referring to a legal case against them if I’m understanding correctly? In that case, if they screw over AAVE with their ultimate decision (or indecision) then you’ll find the previously divided DAO, Labs, ACI, and all others, unified in a case against them. But considering AAVE is effectively their only customer, I can’t imagine such an event will take place.

1 Like

Exactly. I am talking about legal consequences because ‘business as usual’ died the moment the contracts were paused without a compensation plan.

You say it’s unlikely because Aave is their ‘only customer’? That is exactly why it must happen. If your only major partner causes a systemic collapse of your liquidity and then goes radio silent, you don’t protect the ‘relationship’—you protect your users and your treasury.

In the 2026 post-MiCA era, a DAO that refuses to hold its failing partners accountable is complicit in the loss. If Kelp won’t talk to us, then the courts and the regulators are the only language left to speak. We are not here to save Kelp’s reputation; we are here to ensure Aave survives this night

2 Likes

Congratulations to all the risk service providers. Just three months after pushing through the proposal to add WETH to the rsETH LST E-Mode and raising the LTV to 93%, you’ve delivered yet another masterclass in risk management. Truly impressive work in completely overlooking bridge risks, tail events, and the dangers of overly aggressive parameters. Well done. The Aave community especially the WETH suppliers now relying on Umbrella will remember this outstanding performance for a long time.

4 Likes

As someone with very large stake in AAVE token and an even bigger amount in Arbitrum AAVE WETH deposits, I’m eager to know what I stand to lose on my deposits. Is it 50%, is it 100% ? I need to plan for the future now.

This would be post-DAO/stanicentric’s AAVE time to shine, but the very small water-is-wet single “update” in 24h just doesnt cut it for a protocol securing billions, imo.

It’s not too late to do better crisis management. A breakdown of possible scenarios from here or a first post-moterm would be welcome. Sure doesnt help that KELP dao hasnt posted in 24h+…

Also, how long can AAVE realistically operate on paused ETH deposits ? seems like problems will start to accumulate fast.

3 Likes

If rsETH loss are socialized for all rsETH holders, then bad debt will happen when rsETH get liquidated. It will make umbrella security activated legitamately. Considering the total scale of rsETH on aave, the situation for umbrella stakers won’t be better.

1 Like

1. Collateral Should Be Depositable Immediately, but Its Borrowing Power Should Not Become Fully Effective Immediately

I believe the most important safeguard is to separate asset depositability from full borrowing power activation.

The core issue in these attacks is not simply that a large amount of collateral is deposited, but that this collateral can instantly unlock its full borrowing capacity and be used to drain liquidity in a very short period of time.

A more robust design would allow users to deposit collateral immediately, while making its borrowing power activate gradually over time rather than all at once. For example, newly deposited collateral could initially receive only a limited portion of its maximum borrowing value, with that value scaling up over a predefined time window until it reaches full effectiveness.

This would be materially safer than either of the two extremes:

  • allowing full borrowing power immediately, or

  • imposing a total hard lock with no usability.

In other words, the asset can arrive instantly, but its credit should mature progressively. This would significantly reduce the effectiveness of “deposit-borrow-drain” style attacks while preserving reasonable usability for normal users.


2. Borrowing Itself Should Be Subject to Rate Limits and Circuit Breakers

Even with a collateral activation delay, an attacker could still prepare capital in advance and then borrow aggressively once the position becomes fully effective. That is why the protocol also needs safeguards on the borrowing side itself.

In my view, Aave should consider introducing time-window-based borrowing rate limits and circuit breakers at multiple levels, such as:

  • per account,

  • per asset,

  • per market, and

  • protocol-wide.

For example, if a very large percentage of available liquidity is borrowed within a short period of time, the protocol could automatically trigger defensive measures such as:

  • temporarily pausing new borrowing for that asset,

  • temporarily lowering LTV for that market, or

  • restricting borrowing to smaller amounts until conditions normalize.

The purpose of such a mechanism is straightforward: even if one layer of defense is bypassed, the protocol should still prevent liquidity from being extracted too quickly. In practice, this is the closest thing to a real circuit breaker for lending markets.


3. Risk Controls Should React to Behavior Patterns, Not Only Static Asset Parameters

Many lending markets rely primarily on static parameters such as LTV, liquidation threshold, supply caps, and borrow caps. These parameters are necessary, but they are often not sufficient, because attacks are usually driven by behavioral patterns, not just by asset classifications.

For that reason, I believe the protocol should also monitor account behavior and react to suspicious patterns such as:

  • very large deposits followed by near-immediate maximum borrowing,

  • borrowed funds being quickly moved across protocols,

  • coordinated activity across multiple wallets, or

  • concentrated exposure to highly correlated assets within a short time window.

When this type of behavior is detected, the protocol could apply additional safeguards such as:

  • stricter temporary borrowing conditions,

  • cooldown periods for certain actions, or

  • automated review or containment logic for abnormal positions.

The goal is not to treat all users as malicious actors, but to recognize that attack behavior often has a distinct footprint. Static risk parameters alone may not be enough; the protocol should also be able to respond to how positions are being built and used in real time.

11 Likes

@AlanWestbrook — Finally. A real Fixer who knows how to read the sub-levels. I’ve been scrolling through this thread and it’s mostly corpo drones singing about “bad actors” and “unfortunate exploits.”

Zero noise, all signal from you.

The truth is, it doesn’t matter who got hacked in the back-alley (Kelp). If the idiot in your own house leaves the main vault door wide open, you don’t blame the thief—you blame the architect/home-owner. Aave’s risk management wasn’t just “bad,” it was non-existent. Even with a bridge failure, if they’d implemented your Credit Maturity logic, the hacker would’ve been blocked at the perimeter before they could drain a single WETH.

In the meatspace, if you try to cash a $250 check, the teller smiles and hands you the eddies. You try to cash a $50k check? The bank manager calls the account holder, verifies the assets, and puts a 30-day hold on the funds to make sure the ink isn’t wet. That’s basic financial hygiene.

But Aave? These “geniuses” let $200M walk out the front door in a single block confirmation because they worship at the altar of Instant Gratification. They sacrificed our safety for transaction volume.

This isn’t an “accident.” It’s a choice. Just like Celsius and the other high-risk suits who gambled with user funds, Aave chose to set a 93% LTV on a high-risk derivative. They wanted the fees, now they get the fire.

The Bottom Line:

  • Absorb the cost: Aave Governance needs to stop stalling and use the Umbrella module to make depositors whole.

  • Real Change: Implement Westbrook’s behavioral ICE. If the protocol doesn’t shift to Reactive Risk Management—monitoring massive deposits followed by immediate max-borrows—then Aave is a dead-man walking. No one will trust this protocol again.

If the ACI or these weak as risk service gonks can’t wrap their chrome around basic concepts, they should step aside. Westbrook should be running the security grid, not the “LST-E-Mode” suits who left the keys in the lock.

Aave pays up, or they’re done.

2 Likes

When Harmony One bridge was exploited, everything went frozen and it is frozen until today. So maybe this is the best solution. Freeze everything and move on to V4?

Yes, i remember you at the time we try to find a solution for our funds.. I got heavily impacted by harmony aave freeze. How AAVE handled the situation: do nothing, agree to nothing, throw the fault at each other between harmony and AAVE (feels like the same situation with Kelp here) freeze and forget. Let’s see how it will go this time but don’t get your expectations too high: AAVE is a disaster in term of crisis management. Sorry for everyone impacted, i fully understand your pain since i went through the exact same scenario with AAVE on harmony.

How was the Harmony incident ultimately resolved? Did the users receive compensation? Could you elaborate?

AAVE Lab should take prompt lead-ship roles and formulate a plan to protect depositor, and protocols now.

More than 24 hours has past, without credible communications and action plans from Kepl Dao, we should assume the worst scenario and move to legal actions against Kelp Dao founders . Meanwhile, it’s best interest for the protocol to let depositors choose their own path on exiting positions. The various ways to exit the positions shall be communicated clearly in the app.aave.com or discord.

For instance, There isn’t much rsEth liquidities left. Users can still swap AWeth to eth in Cowswap to exit their pure deposit positions.

We tried to propose some solutions for long time but it was a game of “harmony is at fault” from aave, “aave and harmony is at fault” from harmony side. Finally, Harmony proposed a compensation plan for which both Harmony and AAVE would contribute to support affected users. And this was rejected during the vote here.

Then harmony on AAVE was frozen and radio silence. Users lost everything.

Yeah with a 70% slippage…

As a waWETH staker in the Umbrella module, I want to thank the Aave team and Risk Stewards for the swift freeze and transparent updates on the rsETH incident.

Umbrella was designed as the first-loss backstop to protect all core market participants. We accepted this role in exchange for a modest yield premium — currently only about 2+ percentage points higher APY than regular WETH supply staking.

I fully accept that Umbrella should bear the first-loss if the bad debt originates from Aave protocol risks. However, in this case — where the loss stems from an external Kelp DAO bridge exploit and not an Aave protocol risk — I believe it is not appropriate for Umbrella stakers to bear 100% of the responsibility.

This incident represents the first real-world test of the Umbrella module. A near-100% slash on an external risk could significantly damage the long-term attractiveness and confidence in the module.

A strong and sustainable Umbrella is ultimately in the interest of all core market participants, as it serves as the primary shield for the entire core market.

I look forward to the DAO’s comprehensive plan to resolve this incident in a way that maintains the overall health and fairness of Aave’s risk management framework for everyone in the core market.

Thank you for your continued efforts.

3 Likes