Key Highlights:
  • Aave liquidates attacker-linked rsETH positions
  • Part of broader DeFi United recovery effort
  • Governance temporarily altered oracle pricing to complete liquidation
  • Community-driven response becomes major DeFi stress test

A Coordinated Recovery Effort

Aave has completed the liquidation of the remaining rsETH positions tied to the Kelp DAO exploit, marking a major step in the recovery process following one of the largest DeFi attacks of the year.

The seized collateral will now move into the DeFi United Recovery Guardian, a multisig structure created to coordinate reimbursements and stabilize affected protocols.

How the Exploit Spread Across DeFi

The original Kelp DAO exploit involved the fraudulent minting of unbacked rsETH tokens through a compromised cross-chain bridge.

The attacker then used those assets as collateral on lending protocols like Aave to borrow real ETH and other assets, effectively creating bad debt throughout the ecosystem.

A Rare Governance Intervention

To complete the liquidation, Aave governance temporarily manipulated the rsETH oracle price.

Normally, decentralized protocols avoid manual intervention because it undermines the neutrality of automated systems. However, governance participants argued the move was necessary to isolate and unwind the attacker’s positions safely.

DeFi’s “Crisis Response” Moment

The response to the Kelp exploit has become one of the largest coordinated rescue efforts in DeFi history.

Protocols, DAOs, security councils, and individual contributors collectively pledged hundreds of millions of dollars to contain damage and protect users. The event may ultimately shape future standards for cross-protocol crisis management and security coordination.