A cross-chain bridge exploit at KelpDAO let an attacker mint unbacked rsETH tokens and use them as collateral on Aave, leaving the lending protocol with roughly $195 million in bad debt. SparkLend, which had already trimmed its rsETH exposure, is now absorbing billions of dollars in deposits from users fleeing to safer ground.
Aave is facing approximately $195 million in bad debt after a cross-chain bridge exploit at KelpDAO minted unbacked rsETH tokens that an attacker then weaponized as collateral. The hack drained roughly $292 million worth of unbacked rsETH tokens from KelpDAO. The attacker then used those tokens to borrow $190 million in WETH and stablecoins across Aave V3 and V4.
SparkLend, the lending arm under MakerDAO, had already reduced its rsETH exposure before the incident. As a result, it caught the wave of capital fleeing Aave rather than the damage.
How the exploit unfolded
On April 18, an attacker minted roughly 116,500 rsETH tokens without backing through KelpDAO's LayerZero-powered bridge. That figure represented about 18% of rsETH's entire supply. The attacker then deposited those tokens into Aave as collateral, and because Aave's markets recognized rsETH at face value, the protocol processed the borrows like any other transaction.
Estimates for the resulting bad debt range from $124 million to $230 million depending on recovery assumptions. Still, $195 million has emerged as the most widely referenced figure. Aave immediately froze its rsETH and WETH markets to prevent further damage.
Therefore, the protocol's total value locked (TVL) took a severe hit. Aave fell from peaks near $26 billion, with declines reported between $6 billion and more than $10 billion as depositors pulled funds.
Spark absorbs the fallout
SparkLend's decision to limit rsETH exposure before the exploit meant the bridge hack barely grazed it. Users fleeing Aave and other affected platforms deposited roughly $1.7 billion into SparkLend in the days following the exploit, doubling its total value locked.
Meanwhile, Fluid halted operations entirely as a precaution, and several other platforms initiated their own market freezes.
Cleaning up the damage
Aave's community and DAO have moved to address the bad debt through a coordinated fundraising effort targeting $200 million. So far, roughly $160 million has been raised, with contributions from Mantle and the AAVE DAO itself.
Cross-chain bridges have been the single largest attack vector in DeFi for years. The Ronin bridge hack, the Wormhole exploit, and now the KelpDAO incident follow a similar pattern: a bridge vulnerability creates unbacked assets that propagate through the system before anyone can react.
Source: Crypto Briefing
Trading involves risk.