Skip to content
archive

Aave overhauls listing standards after $230M rsETH exploit exposed bridge risks

Crypto · · 1 min read · coindesk.com ↗

Aave overhauls listing standards after $230M rsETH exploit exposed bridge risks

Source: CoinDesk
Published: Jun 1, 2026
Ingested: 2026-06-02T10:12:01Z

The most expensive DeFi attack of 2026 began with KelpDAO's restaked ether (rsETH) bridge, not a bug in Aave's code. The $230 million exploit traced to a LayerZero bridge verification failure where a single verifier approved a forged cross-chain message releasing 116,500 unbacked rsETH.

Changes:

  • Sweeping review of all V3 assets and listing standards
  • New risk framework covering bridges, oracles, custodians, operational security
  • Automated defenses to strip collateral borrowing power on threshold breach
  • ~295 parameter changes executed (168 supply-cap reductions, 66 borrow-cap reductions)
  • Standardized Technical Asset Listing Framework for V3, V4, and Horizon

Context: Aave, KelpDAO, Mantle, Lido, EtherFi stabilized via "DeFi United." Aave holds ~$25B TVL.