Skip to content
All library documents

KelpDAO Exploit: Bridge Verification Failure and DeFi Lending Contagion

Article Galaxy Research

Summary

The report examines the theft of rsETH through KelpDAO’s LayerZero bridge and the resulting stress across lending markets. It explains how a single-verifier setup relied on RPC data that attackers manipulated, prompting the bridge to release tokens without a valid withdrawal. The stolen rsETH was then used as collateral to borrow liquid assets, shifting the damage from the bridge into lending pools and related protocols.

The analysis follows market freezes, depleted withdrawal liquidity, bad-debt estimates, and Arbitrum’s recovery of some ETH. It describes two possible ways Aave losses could be allocated and considers how collateral limits, shared liquidity, oracle choices, and bridge security affect contagion. The report also discusses the trade-offs between isolated lending markets and shared pools. Its figures and resolution scenarios were provisional when written; the report notes that protocol disclosures and governance decisions could materially change the estimates. It is an incident analysis, not a trading strategy or a settled account of final losses.

Key ideas

  • A bridge’s security depends on its message verification design and the reliability of the infrastructure supplying verification data.
  • The attacker used stolen rsETH as collateral to borrow assets, spreading losses into lending markets.
  • High collateral limits and shared liquidity can amplify the effects of a bridge exploit.
  • Market freezes can contain new exposure while also restricting withdrawals when lending pools are fully utilized.
  • Loss estimates and recovery paths remained uncertain pending further disclosures and governance decisions.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.