Stolen: $290 million, Three Parties Refuse to Acknowledge Responsibility - Who Should Bear the Loss in the KelpDAO Incident?

Original Title: "The Tripartite Game Under a $290 Million Hole: Aave, L0, Kelp - Who Will Foot the Bill?"
Original Author: Azuma, Odaily Planet Daily
It has been over 30 hours since the rsETH bridging contract of Kelp DAO was exploited. Although the parties involved (LayerZero, Kelp DAO, Aave) have made statements (mostly blaming others and emphasizing their own innocence), they have not yet provided a final solution.
Therefore, this article aims to discuss the current positions and attitudes of the involved parties, explore the reasons for the delayed solution, and speculate on how the incident may eventually be resolved.
Editor's Note: For context, please refer to "Even with No Code Issue, How Did the 2026 Major Hackers' Ringleader, the 'DVN Configuration Vulnerability,' Happen?".
Who Should Take Responsibility?
First, let's discuss the issue of accountability.
According to details disclosed by LayerZero, the direct cause of the incident is quite clear. The decentralized validator network (DVN) operated by LayerZero relied on downstream RPC infrastructure that was compromised (see the analysis by Wu Xin, the founder of SlowMist, in the figure below). As Kelp DAO's bridging contract adopted a 1/1 DVN, the attacker only needed to complete a forged message verification to execute the attack.

LayerZero believes that Kelp DAO, which used a 1/1 DVN configuration, bears the most direct responsibility for this incident. There is no question about it; such an obvious "single point of failure" is truly outrageous.
However, as the underlying cross-chain protocol, LayerZero should also bear some responsibility. LayerZero allows each upper-layer application to configure the number and threshold of DVNs independently. Although the 1/1 DVN was Kelp DAO's own choice, as the designer of the underlying architecture, LayerZero should also avoid such obviously flawed settings.
Lastly, there are the lending protocols like Aave (with a focus on Aave). Although they are also indirectly affected, objectively speaking, Aave, for expansion purposes, granted excessive borrowing power to assets like rsETH, resulting in the current dilemma. Additionally, it is worth mentioning that Aave's former risk team, BGD Labs (now separated from Aave), explicitly pointed out the issue with Kelp DAO's DVN in January of last year. While Kelp accepted the suggestion at the time, it evidently did not make the necessary changes... Aave's failure to continue monitoring and take corresponding actions has led to their own downfall.

So the liability is very clear, with Kelp DAO being primarily responsible, LayerZero secondarily responsible, and Aave also bearing some indirect responsibility.
The Awkward Reality
Reality is always more complex than theoretical expectations. The most critical issue is that the Kelp DAO team, which should bear the primary responsibility, cannot come up with so much money to cover the deficit... Whether directly deducting the loss from all rsETH or betraying Layer 2 token holders, it is essentially a dead end.
So who has the money? The first is LayerZero, which has suffered a reputation crisis due to this incident and has been temporarily disabled by many institutions and protocols such as Bitgo, Tron, Ethena, Curve, and ether.fi, watching the potential loss of a large amount of cross-chain shares; the second is Aave, facing a huge potential bad debt and watching billions of dollars in TVL drain away.
Therefore, the "ghost pregnancy" of all parties is now very clear. The primary responsible party, Kelp DAO, is basically paralyzed and unable to lead the subsequent compensation. They need to discuss with the two big brothers on how to proceed; at the same time, the secondary responsible party and the indirectly responsible parties, LayerZero and Aave, which have the compensation strength, have both stated that their protocols have no vulnerabilities and are clearly unwilling to easily take on such a huge blame... So it seems that the situation is a bit deadlocked now.
However, I do not think this situation will last long because both protocols have a need to resolve the issue quickly—LayerZero cannot give up its OFT cross-chain ecosystem map, and Aave cannot ignore the continuous outflow of funds.
The Key to Multi-party Game
This morning, Aave issued an updated statement on this incident, with the most important piece of information emphasizing that "rsETH on the Ethereum mainnet is well supported."
How should this statement be understood? We need to start with the design of rsETH.
rsETH is essentially a liquidity-backed re-staking certificate token issued by Kelp DAO, with each rsETH having 1 ETH in the underlying staking and restaking system support. The path is "ETH - Lido - EigenLayer - Kelp DAO - rsETH".
The rsETH on the mainnet is the original proof-of-stake token issued by Kelp DAO on Ethereum. To expand within the Layer 2 ecosystem, Kelp DAO will use LayerZero's cross-chain bridging contract (the entity involved in this incident) to map the mainnet rsETH to various Layer 2 solutions. For each rsETH minted on Layer 2, an equivalent amount of mainnet rsETH will be held in Kelp DAO's custodial contract, only to be released when rsETH is bridged back from Layer 2 to the mainnet.
Now, let's revisit the incident itself. As mentioned earlier, the theft occurred because the hacker manipulated DVN to forge a cross-chain message, causing the bridging contract to "mistakenly release" 116,500 rsETH—note that this did not involve minting new tokens out of thin air but rather withdrawing the original proof-of-stake tokens from the mainnet that should not have been released.

The issue lies here: these tokens were already circulating on Layer 2 through mapping, while the mainnet tokens were supposed to be in a locked state. However, after the hack, the hacker deposited them into protocols like Aave, borrowed more liquid WETH, and then absconded—emphasizing again that the deposited rsETH was genuine, which is why Aave supported the token for lending and borrowing activities.
Now, revisiting Aave's statement is quite intriguing. The phrase "the rsETH on the Ethereum mainnet is fully backed" is essentially saying: "These tokens are all real; Kelp DAO, you should help us redeem the underlying ETH with these tokens (contract paused, redemption currently not possible)…as for the Layer 2 mapped rsETH that lost the support of the mainnet rsETH, I can't do anything about that!"
This seems to be Aave's stance. While emphasizing the value of mainnet rsETH implies disregarding the value of Layer 2 mapped rsETH, and due to Aave's own rsETH debt position in Layer 2 lending products (currently around $359 million in real-time), this could lead to some defaults. However, choosing the lesser of two evils, Aave likely evaluated the potential impacts of both options and believed that preserving the mainnet core product aligns best with its interests.
But this is only Aave's position. The resolution of the incident ultimately depends on reaching an agreement with LayerZero and Kelp DAO.
While the latter has not yet made any further statements, I personally believe that LayerZero is unlikely to accept this proposal, as abandoning the Layer 2 pegged token would directly threaten LayerZero's cross-chain reputation.
Potential Solution
The problem will eventually need to be resolved. In recent days, various industry leaders on social media have been providing suggestions to Aave, LayerZero, and Kelp DAO.
DefiLlama founder 0xngmi has deduced three possible paths, but has also noted that all three paths have significant flaws. The first path involves all rsETH holders collectively bearing a 18.5% haircut (proportion of lost tokens to total supply), with Kelp DAO taking responsibility, and Aave facing approximately $216 million in bad debt on the mainnet; the second path disregards the value of all Layer 2 pegged rsETH, allowing Aave's mainnet product to remain intact, but the Layer 2 version is likely to collapse, leading to a loss of Kelp DAO's reputation; the third path involves fully reimbursing pre-hack rsETH holders based on a snapshot, while subsequent buyers or transferees would bear the losses themselves, but due to significant post-hack fund movement, this operation is deemed almost impossible.
OneKey founder Yishi stated: "The best outcome now would be to negotiate with the hacker, offer a 10–15% bounty, reclaim the majority of the funds, and everyone will be happy. If negotiations fail, the LayerZero Ecosystem Fund should step in, as it has the most funds and long-term interests, which would allow the OFT ecosystem to be preserved. Kelp DAO is the poorest, either offering a token + future income compensation, or simply selling the entire project to LayerZero or Bitmine. Aave's Umbrella and stkAAVE provide the final layer of protection, but WETH depositors must not bear the brunt of the haircut; otherwise, Morpho, Spark, Fluid, and Euler will all need to be repriced, the LRT track will be stigmatized, and the entire DeFi industry will regress three years."
In any case, all parties are certainly going to continue discussions for a while, given the involvement of billions in actual funds—no one wants to be the biggest loser in this situation.
As for how long it will take to provide a solution, as mentioned earlier, both giants are not willing to delay too much. LayerZero has now been forced into a pause by major collaborating institutions and protocols; if delayed, these partners will certainly switch cross-chain pathways. The situation for Aave is also not optimistic, as the utilization rates of multiple pools have reached 100%, with depositors in a "liquidity mining death spiral." If ETH were to suddenly plummet, Aave is likely to experience further insolvency due to an inability to effectively liquidate (which is currently the case), ultimately leading to a snowball effect of increasing bad debt—should it truly reach this point, the industry's foundation may be severely shaken, a scenario that no one would want to witness.
Original Article Link
Recommended
Eight-Year Investment U-Turn: Why Did Ethereum Suddenly Abandon Poseidon?
Aug 16, 10:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?
Aug 15, 14:00
Tencent Still Has a Dream
Aug 15, 11:27
To Catch North Korean Hackers, They Set Up a Fake Project
Aug 15, 10:00
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA
Aug 14, 19:32
11,742 Shipping Addresses Exposed Alongside Trezor Orders
Aug 14, 19:01