DeFi attack wipes $292M as Aave sees $10B exit

A major DeFi attack has wiped $292 million and triggered about $10 billion in withdrawals from Aave. The exploit centered on a LayerZero–KelpDAO vulnerability that let an attacker mint 116,500 unbacked rsETH tokens. About 90,000 rsETH were posted on Aave as collateral, enabling borrowing of roughly $190 million in ETH and other assets. As DeFi users rushed to withdraw, market stress spread quickly. Total value locked (TVL) across DeFi fell from nearly $15B to $10B, and Aave reported an rsETH collateral “hole” of over 112,000 tokens. In response, major protocols launched “DeFi United” to stabilize the system and restore confidence in rsETH. Lido Labs proposed 2,500 stETH (about $5.7M) for the recovery fund. EtherFi proposed an additional rescue package of 5,000 ETH, and Aave founder Stani Kulechov pledged 5,000 ETH. On fund recovery, part of the stolen assets was tracked to Arbitrum, where an Arbitrum security council froze 30,766 ETH (~$71M). Other funds were routed via Thorchain to BTC, complicating direct retrieval. Current priorities focus on recapitalizing rsETH rather than immediately chasing all stolen funds. For traders, this DeFi attack raises near-term liquidity and risk-management concerns around lending markets and cross-chain infrastructure, while the multi-protocol rescue may reduce tail risk if execution holds.
Bearish
这是一起明确的“DeFi attack”且已引发资本外流:Aave 相关资金撤出规模约 100 亿美元,TVL 也从接近 150 亿美元降到约 100 亿美元。此类事件通常会在短期压制风险偏好,带来借贷市场降杠杆、清算担忧和跨链风险溢价上升。尽管行业启动 “DeFi United” 救援、并在 Arbitrum 冻结部分 ETH,但救援核心在于修复 rsETH 抵押缺口与防止坏账扩散,落地存在执行与时间窗口风险。 与过去桥接/跨链漏洞导致的事件相似(如曾出现的跨链消息故障与衍生品脱锚),市场往往在最初数日出现剧烈波动和流动性收缩,随后才看救援方案能否恢复抵押可信度。长期来看,多协议联合救援可能推动保险、风险管理与桥接审计更快完善;但在短期,攻击细节与资金流向不确定性仍可能令交易者保持谨慎,故整体偏 bearish。