In a significant breach at the KelpDAO rsETH bridge, 116,500 rsETH, worth approximately $29.2 million (around 41.17 billion KRW), was stolen, causing a ripple effect in the decentralized finance (DeFi) lending market. The conservative collateral limits set by Spark were evaluated as a factor that slowed the spread of issues from external assets to the lending market.
LayerZero reported that the KelpDAO rsETH bridge was attacked on April 18. The incident occurred on KelpDAO's cross-chain path that connects different blockchains using LayerZero.
The attack took place at 2:35 AM KST on April 19. A forged packet passed verification on the 1-of-1 Distributed Verification Network (DVN) path heading from Unichain to Ethereum (ETH), releasing rsETH that was locked in the Ethereum side adapter.
DVN is a verification system that checks whether messages traveling between different blockchains are legitimate. In a 1-of-1 structure, since a single verification path determines the validity of the message, if the underlying infrastructure of that path is compromised, it becomes difficult to filter out forged messages.
LayerZero identified the single DVN setup and the contamination of the underlying remote procedure call (RPC) infrastructure as the cause of the incident. They explained that the operational structure for message delivery and verification acted as the attack surface rather than an error in the smart contract itself. LayerZero stated that the issue was limited to KelpDAO's rsETH setup and did not propagate to other assets or applications.
The incident, which began at an external bridge, spread to AAVE, where rsETH was being used as collateral. A total of 89,567 rsETH supplied to AAVE through seven attacker addresses was recorded, and AAVE froze the market for rsETH and wrapped rsETH (wrsETH) before additionally locking WETH.
AAVE's smart contract itself was not compromised. However, as some of the stolen rsETH flowed into collateral, the loan positions based on that asset were exposed to default risk. Earlier reports indicated that AAVE was exposed to $195 million (approximately 275 billion KRW) in bad debts due to the impact of this attack.
rsETH is typically a liquidity re-staking token designed to allow Ethereum staking assets to be reused. When such assets are adopted as loan collateral, capital utilization increases, but shocks arising from bridges or price-linked structures can simultaneously affect collateral value and loan soundness.
SparkLend had been considering measures to limit the collateral risk of rsETH for over a year before the incident. A risk assessment document posted on the Sky forum on March 9, 2025, proposed a loan-to-value (LTV) ratio of 72% and a liquidation threshold of 73% for rsETH. LTV is the ratio of the value of collateral to the amount of assets that can be borrowed.
The same document suggested a borrowing limit of 0 for rsETH and a supply limit of 2,000 rsETH. It also recommended limiting the maximum supply to 20,000 rsETH and using an oracle that reflects the exchange rate between rsETH and ETH. The supply limit restricts the amount of rsETH flowing in as collateral, while the LTV lowers the scale of borrowing based on that collateral. A borrowing limit of 0 prevents the borrowing of rsETH itself.
At that time, approximately $837 million (around 1.18 trillion KRW) worth of rsETH was supplied to AAVE as of March 7, 2025. The top five suppliers accounted for about 89% of the total amount, indicating that the movements of a few large accounts could significantly impact market soundness.
Galaxy Research analyzed that SparkLend, Fluid, and Upshift froze the rsETH market within hours after the incident. Unlike AAVE, which applied a higher LTV structure to rsETH-based loans, SparkLend limited it to 72%, allowing for some absorption of the shock.
This measure did not prevent the bridge loss itself. However, by setting the borrowing and supply limits low in advance and blocking the market after the incident, it narrowed the pathways through which defaults could spread throughout the lending market. The case of Spark demonstrates that when accepting collateral assets, it is essential to reflect not only liquidity but also the risks of bridges and oracles.
The dispute over responsibility for the incident continues. KelpDAO claimed that there were issues with LayerZero's basic settings and infrastructure, while LayerZero countered that KelpDAO chose the 1-of-1 DVN configuration, as reported by CoinDesk. As the attribution of cause is disputed, the key issue is who chose and managed the single verification structure.
This incident revealed that the failure of verification at individual bridges could spread to the lending market through collateral assets. The structure confirming that collateral management devices such as LTV, borrowing limits, and supply limits determine the extent of losses in DeFi was confirmed.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























