A cross-chain bridge exploit at KelpDAO left Aave with roughly $195 million in bad debt while SparkLend doubled its deposits absorbing fleeing capital.
A cross-chain bridge exploit at KelpDAO left Aave with roughly $195 million in bad debt while SparkLend doubled its deposits absorbing fleeing capital.

Aave faces $195 million in bad debt after a $292 million KelpDAO bridge exploit, while SparkLend absorbed $1.7 billion in fleeing deposits.
Galaxy Research's Lucas Tcheyan, Vice President of Research, said the attacker "tricked the bridge into releasing tokens that should not have been released," depositing stolen rsETH as collateral on Aave, Compound, and Euler before borrowing an estimated $236 million in WETH and wstETH.
Aave's total value locked fell from $26.4 billion to $17.9 billion within two days, a roughly $8.45 billion outflow that cost the protocol its position as the largest DeFi lending platform. WETH utilization hit 100 percent as depositors raced for exits, and approximately $5.4 billion in ETH and WETH left the protocol by Sunday morning. DeFi's aggregate TVL dropped about $13 billion to $86.3 billion.
The exploit has triggered a broader reassessment of cross-chain bridge security and collateral risk frameworks across DeFi. Aave's community launched a fundraising effort targeting $200 million, with roughly $160 million raised from Mantle and the AAVE DAO, while SparkLend's earlier decision to cap rsETH exposure let it capture the capital flight.
KelpDAO uses a LayerZero omnichain fungible token (OFT) adapter to make rsETH available across roughly 20 Ethereum layer-2s. The adapter runs a lock-and-mint model where rsETH bridged out of Ethereum is locked in a mainnet escrow. KelpDAO ran a 1-of-1 configuration with LayerZero Labs as the sole verifier.
At 17:35 UTC on April 18, the attacker delivered a forged LayerZero packet claiming to originate from Unichain, releasing 116,500 rsETH to the attacker's address on Ethereum L1 in a single transaction. LayerZero's post-mortem identified the mechanism as an RPC poisoning attack rather than key theft or a protocol bug. The DVN signing keys were never compromised; instead, attackers corrupted two downstream RPC nodes the DVN relied on and launched a DDoS attack on uncompromised RPCs to force failover to the poisoned ones.
LayerZero attributes the operation with preliminary confidence to North Korea's Lazarus Group, specifically its TraderTraitor subunit. The same group is linked to the Drift exploit on April 1 ($285 million), totaling roughly $575 million drained by one state-sponsored unit in 18 days through two structurally different attack vectors.
Aave's decision in January to allow rsETH as collateral for wETH in its E-Mode, raising the maximum loan-to-value to 93 percent from 72 percent, worsened the damage. For comparison, SparkLend caps rsETH-backed borrowing at 72 percent LTV and Fluid at roughly 75 percent.
LlamaRisk, Aave's risk manager, modeled two resolution scenarios. Under uniform socialization across all rsETH, bad debt totals approximately $123.7 million. If losses are isolated to L2 rsETH, bad debt reaches $230.1 million. The most widely referenced figure is $195 million.
The onchain position book shows 27 rsETH-collateralized positions on Aave Ethereum Core with outstanding WETH debt totaling approximately $1.16 billion. Of those, 17 positions with $818 million in debt operate with health factors below 1.05, within 5 percent of their liquidation threshold.
SparkLend, the lending arm under MakerDAO (now Sky), had already reduced its rsETH exposure before the incident. The protocol absorbed between $1.4 billion and $1.7 billion in new deposits from users fleeing Aave and other affected platforms, effectively doubling its total value locked within days.
The exploit also triggered a broader security reassessment. LayerZero stated it will no longer sign or attest messages from any application running a 1-of-1 DVN configuration. Multiple protocols paused their LayerZero OFT bridges, and the Arbitrum Security Council took emergency action to freeze 30,766 ETH held by the attacker on Arbitrum.
The direction of travel for DeFi now hinges on whether protocols tighten collateral frameworks, adopt multi-DVN configurations, and reduce privileged upgrade authority — or whether the MultisigFi response of treating centralization as a feature for rapid crisis intervention prevails.
This article is for informational purposes only and does not constitute investment advice.