Bridges rely on a set of independent verifiers who confirm each message is real before the receiving chain releases the equivalent tokens.

In April’s attack, just one of those verifiers approved a fake message, which let the attacker mint 116,500 rsETH on the receiving chain with no actual ether backing it.

Those tokens were then deposited into Aave, a lending protocol where users borrow against collateral they post, and used to take out loans Aave could not recover once the rsETH was revealed as worthless. Aave’s own code worked exactly as designed. The collateral it accepted turned out to be fake because the bridge that delivered it had been compromised.

While LayerZero acknowledged earlier this month that it “made a mistake” by allowing its own verification system to secure high-value assets in a one-of-one configuration, Aave’s postmortem goes further by using the incident to justify a broader overhaul of DeFi risk management.

The protocol argues that traditional reviews focused on volatility, liquidity and smart contract audits failed to capture the risks created by bridges, verification networks and other infrastructure that sits outside application code.

Beyond smart contract audits and financial risk analysis, Aave said it will now evaluate bridge infrastructure, oracle dependencies, third-party contracts, custodial arrangements, operational security practices, and secondary-market liquidity before approving or expanding collateral listings.

The protocol is also building new automated defenses designed to react faster when collateral assets show signs of distress. Among the proposals outlined in the postmortem is a system that would automatically reduce an asset’s loan-to-value ratio to zero once predefined risk thresholds are breached, removing its borrowing power before losses can spread through the broader market.

Since the exploit, Aave says its risk managers have already executed roughly 295 parameter changes across V3 markets, including 168 supply-cap reductions and 66 borrow-cap reductions aimed at limiting exposure to individual assets.

As DeFi protocols become more interconnected, Aave’s postmortem suggests the industry may need to scrutinize not only the assets it lists, but also the infrastructure those assets depend on

More For You

Bull and bear market (Midjourney/modified by CoinDesk)

U.S. spot bitcoin ETFs lost $2.97 billion across 10 trading days through Friday, the longest outflow streak on record. Oil’s bounce on the stalled Iran deal added pressure even as global equities hit new highs on the Nvidia and SoftBank AI trade.

What to know:

  • Global equities hit fresh records on the back of the AI trade, even as rising oil prices and Middle East tensions weighed on broader risk sentiment.
  • Bitcoin and major cryptocurrencies declined over the past week amid a record 10-session, $2.97 billion outflow streak from U.S. spot bitcoin ETFs and sustained…

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Stories