Aave faces $195M in bad debt after KelpDAO bridge exploit as Spark absorbs billions in fleeing capital

1 hour ago 17

A cross-chain bridge exploit drained roughly $292M worth of unbacked rsETH tokens from KelpDAO, and the fallout landed squarely on Aave’s balance sheet. The attacker used those freshly minted tokens as collateral to borrow $190M in WETH and stablecoins across Aave V3 and V4, leaving the protocol staring at approximately $195M in bad debt.

SparkLend, the lending arm under MakerDAO, had already reduced its rsETH exposure before the incident. The protocol absorbed between $1.4B and $1.7B in new deposits from users scrambling for safer ground, effectively doubling its total value locked within days.

How the exploit unfolded

On April 18, roughly 116,500 rsETH tokens were minted without backing through KelpDAO’s LayerZero-powered bridge. That figure represented about 18% of rsETH’s entire supply.

The attacker then deposited those tokens into Aave as collateral. Because Aave’s markets recognized rsETH at face value, the protocol processed the borrows like any other transaction. The result was $190M in borrowed assets that will almost certainly never be repaid.

Estimates for the resulting bad debt range from $124M to $230M depending on recovery assumptions, but $195M has emerged as the most widely referenced figure. Aave immediately froze its rsETH and WETH markets to prevent further damage.

The protocol’s TVL took a severe hit in the aftermath. From peaks near $26B, Aave saw declines reported between $6B and more than $10B as depositors pulled funds.

SparkLend’s strategic positioning pays off

SparkLend’s decision to limit rsETH exposure before the exploit meant the bridge hack barely grazed it. Users fleeing Aave and other affected platforms deposited roughly $1.7B into SparkLend in the days following the exploit, doubling its TVL.

SparkLend wasn’t the only protocol to react quickly. Fluid halted operations entirely as a precaution, and multiple other platforms initiated their own market freezes.

Cleaning up the damage

Aave’s community and DAO have moved to address the bad debt through a coordinated fundraising effort targeting $200M. So far, roughly $160M has been raised, with significant contributions from Mantle and the AAVE DAO itself.

Cross-chain bridges have been the single largest attack vector in DeFi for years. The Ronin bridge hack, the Wormhole exploit, and now the KelpDAO incident all follow a similar pattern: bridge vulnerability creates unbacked assets that propagate through the system before anyone can react.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article