The rsETH attack, which began on Saturday night, April 18th, escalated from a single bridge hack into one of the biggest liquidity crises in DeFi history within a week. 116,500 rsETH, worth approximately $292 million, were minted via a fake message on KelpDAO's LayerZero-based rsETH bridge. The attacker then directly deposited these "unbacked" tokens into Aave, effectively borrowing real assets. Here's a summary of the week's events:



How did the attack work?

Using LayerZero's single validator (1-of-1) configuration, the KelpDAO bridge validated the attacker's fake lzReceive message. This allowed rsETH to be minted without locking any ETH in the wallet.

These rsETH were deposited into Aave V3 as collateral within minutes. The protocol, by its nature, accepted the request, and the attacker withdrew approximately $190 million worth of WETH, wstETH, and stablecoins. Aave later stated that "the system worked according to its design, the problem was that the collateral was fraudulent."

The same tokens were also used in the Aave markets on Arbitrum and Base. The total deficit, according to initial estimates, ranges between $123 million and $230 million.

Bank run on Aave

As soon as the news spread, users panicked. The total supply on Aave, which was $45.8 billion on Saturday evening, dropped to $30.8 billion by Wednesday morning. The outflow of approximately $15 billion was the fastest withdrawal in the protocol's history.

The most critical moment was when the USDT and USDC pools reached 100% usage. Approximately $5 billion worth of stablecoins became unusable because borrowers failed to repay. While users protested with complaints of "my money is locked" on X, the AAVE token lost 17.7% of its value in three days.

Aave management froze the rsETH markets on Ethereum, Arbitrum, and Optimism. New collateral deposits and borrowing were halted.

Freezing and Tracking

On Monday, the Arbitrum Security Council froze 30,766 ETH, approximately $71 million, in the attacker's wallet and moved it to an unattended vault. This sparked a decentralization debate, but at least some of the money was recovered.

The remaining funds are being rapidly laundered. On-chain detectives have determined that the attacker converted 34,500 ETH, approximately $175 million, into Bitcoin via THORChain. Smaller amounts were routed through the Umbra privacy protocol. LayerZero attributed the attack to the "TraderTraitor" cell of the North Korea-linked Lazarus group.

DeFi United: The Sector's Counter-Move

Something unusual happened midweek. Aave, Spark, Morpho, Curve, and Mantle formed a recovery pool called "DeFi United." The goal is to rebuild the collateral for rsETH.

Initially, 43,500 ETH, approximately $101 million, was deposited into the common pool.
Mantle opened a 30,000 ETH credit line to Aave and stated, "we will contribute from the treasury if needed."
To date, over $204 million in assets have been repaid, and liquidity has begun to normalize.

The KelpDAO team has paused all rsETH contracts and is rewriting the bridge with LayerZero. LayerZero announced that it has canceled all single validator configurations and stopped message signing.

So what is the situation with rsETH now?

The token still doesn't back ETH one-to-one. It's trading at a 6-8% discount in the market. Aave hasn't yet decided whether to socialize the loss. Three options are on the table:

Aave treasury coverage
Passing losses on rsETH holders
Gradual buyback with the DeFi United pool

The most pressing issue for users is locked stablecoins. Aave says USDT/USDC withdrawals will be opened as borrowers' repayments accelerate.

What's the lesson?

The $292 million attack showed how a single line of configuration error can wipe out $14 billion of DeFi TVL. "Infrastructure" projects like LayerZero are now responsible not just for code, but also for operational security.

The latest data shared under the #rsETHAttackUpdate hashtag shows that the worst of the crisis is over, but the wound is not healed. Arbitrum's freeze saved $71 million, DeFi United raised $100 million, but there's still a $120 million deficit.

For the sector, this is the biggest "test of trust" since the 2022 Terra crash. If Aave absorbs the damage, DeFi's "code is law" narrative will give way to a "community insurance" narrative. If it doesn't, a lengthy legal process will begin between rsETH holders and Aave depositors.

The attack, which began a week ago, is now a problem not just for KelpDAO, but for the entire restaking ecosystem.
AAVE-0,45%
ETH0,09%
ZRO-2,98%
ARB-0,4%
User_any
#rsETHAttackUpdate
The recent rsETH-focused attack in the cryptocurrency ecosystem is not only a technical security vulnerability but also a critical test of how DeFi infrastructure reacts under stress.

Initial findings indicate that the attack created a chain reaction through liquidity manipulation and price oracle mechanisms. This event clearly demonstrates how vulnerable complex financial structures, such as restaking derivatives, can become when market depth is limited. ✨

The most striking aspect of this process is that the systemic risk was not limited to the targeted protocol. The interconnectedness of liquidity pools and collateral mechanisms created a ripple effect, putting pressure on different platforms. This situation once again proves how limited the concept of "isolated risk" is in practice within the DeFi ecosystem.

So, what does this attack change? First and foremost, a reassessment of the risk models for restaking and derivative staking products becomes inevitable. The reliability of price feed (oracle) systems, the sustainability of collateral ratios, and resilience to sudden liquidity outflows now require tighter oversight. ✨

Another critical question is the issue of trust:
How do such events shape investor behavior?
In the short term, capital may tend to shift to assets perceived as safer. However, in the long term, if these stress tests are managed correctly, they contribute to building the ecosystem on a more solid foundation.

What is clear at this point is:
As DeFi continues to grow, as complexity increases, risk grows not linearly, but exponentially. Therefore, security is no longer a feature, but a necessity at the heart of the system. ✨

In conclusion, the rsETH event offers much more than a short-term shock to the markets:
This is a turning point that tests the maturity level of decentralized finance and will shape its future building blocks.
repost-content-media
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
Add a comment
Add a comment
User_any
· 19h ago
LFG 🔥
Reply0
User_any
· 19h ago
Thanks my friend for beatifull post and your support 🙏
Reply0
FenerliBaba
· 20h ago
2026 GOGOGO 👊
Reply0
ybaser
· 20h ago
Just charge forward 👊
Reply0
  • Pin