Aave Revises Risk Management After $230 Million rsETH Exploit
- The exploit involved KelpDAO’s restaked ether (rsETH) bridge, leading to a loss of $230 million.
- Aave’s review found the attack stemmed from a LayerZero bridge verification failure, not a flaw in its smart contracts.
- The incident allowed the attacker to mint and deposit 116,500 unbacked rsETH into Aave.
- Aave plans to overhaul its listing standards, incorporating assessments of bridge infrastructure and operational security.
- Since the exploit, Aave has made approximately 295 parameter changes across V3 markets to limit asset exposure.
Following the exploit, Aave aims to enhance its risk management practices by evaluating not just financial risks but also external infrastructure dependencies like bridges and oracles.
The protocol’s response includes new automated defenses and adjustments that have already led to significant parameter changes across its markets. (Source)