Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Aave Overhauls Asset Listing Standards After $230 Million rsETH Exploit Exposed Bridge Risks
00

Aave Overhauls Asset Listing Standards After $230 Million rsETH Exploit Exposed Bridge Risks

Jun 1, 2026

Aave published a postmortem tracing the April 2026 rsETH exploit that caused $230 million in losses to a LayerZero bridge verification failure, where a single verifier approved a fake message allowing 116,500 unbacked rsETH tokens to be minted. Aave is overhauling asset-listing standards to evaluate bridge infrastructure, oracle dependencies, and custodial arrangements, and has executed 295 parameter changes across V3 markets. The protocol is reviewing every asset listed on Aave V3.

rsETH exploit mechanics

  • ▪The unbacked rsETH tokens were deposited into Aave and used to take out loans that Aave could not recover once the rsETH was revealed as worthless
  • ▪Aave's own code worked exactly as designed during the April 2026 rsETH exploit
  • ▪The token rsETH represents a user's claim on restaked ether in the KelpDAO system
  • ▪The April 2026 rsETH exploit caused $230 million in losses
  • ▪The April 2026 rsETH exploit resulted in the minting of 116,500 unbacked rsETH tokens on the receiving blockchain
  • ▪KelpDAO is a restaking service that lets users take their ether already locked into Ethereum to earn staking rewards and reuse it as collateral to earn additional yield from other protocols
  • ▪The April 2026 rsETH exploit is the most expensive DeFi attack of 2026

LayerZero bridge failure

  • ▪In the April 2026 attack, a single LayerZero verifier approved a fake cross-chain message that allowed the attacker to mint 116,500 rsETH with no actual ether backing it
  • ▪LayerZero acknowledged in May 2026 that it made a mistake by allowing its own verification system to secure high-value assets in a one-of-one configuration
  • ▪KelpDAO uses LayerZero, a cross-chain bridge infrastructure, to move rsETH between blockchains
  • ▪Aave's postmortem traced the April 2026 rsETH attack to a LayerZero bridge verification failure rather than a flaw in Aave's smart contracts

Aave asset listing overhaul

  • ▪Aave's risk managers have executed approximately 295 parameter changes across V3 markets since the April 2026 exploit
  • ▪Aave is launching a review of every asset listed on Aave V3 following the April 2026 rsETH exploit
  • ▪Aave is rewriting its asset listing standards after the April 2026 rsETH exploit exposed a new class of DeFi risk
  • ▪Aave executed 168 supply-cap reductions across V3 markets following the April 2026 exploit

Expanded risk assessment framework

  • ▪Aave's postmortem argues that traditional reviews focused on volatility, liquidity and smart contract audits failed to capture the risks created by bridges, verification networks and other infrastructure that sits outside application code
  • ▪Aave's new collateral assessments will weigh bridges, oracle dependencies, custodians and operational security alongside the financial and smart-contract risks Aave has traditionally screened for
  • ▪Aave will evaluate bridge infrastructure, oracle dependencies, third-party contracts, custodial arrangements, operational security practices, and secondary-market liquidity before approving or expanding collateral listings

Automated defense mechanisms

  • ▪Aave's postmortem proposes a system that would automatically reduce an asset's loan-to-value ratio to zero once predefined risk thresholds are breached, removing its borrowing power before losses can spread through the broader market
  • ▪Aave is building new automated defenses designed to react faster when collateral assets show signs of distress

Perspective of LayerZero

  • ▪LayerZero acknowledged in May 2026 that it made a mistake by allowing its own verification system to secure high-value assets in a one-of-one configuration

1 source

Coindesk
Aave overhauls listing standards after $230 Million rsETH exploit exposed bridge risks
View source article

Story comments

Loading comments…

Related entities

Bridge exploitrsETH

Related Projects

AaveLayerZero

Topics

Crypto hacksBlockchain interoperabilityDeFi lendingDeFi securityDeFi