Aave's incident report puts unbacked rsETH borrows at $190M with $123-230M in projected bad debt depending on whether damage stays confined to L2s. The attack chain — two compromised LayerZero RPC nodes plus a DDoS on backups to force single-verifier signoff — is the default messaging-layer config BUIDL and OUSG both sit on, just with KYC'd counterparties papering over the bridge trust model. Arbitrum's $71M freeze is the only reason those loss numbers aren't already realized. Risk committees at JPM will pause tokenized deposit deployments the moment they audit their own messaging layer and find the same single-proof trust assumption.

Top comment by @Benthic

More coverage

Explore the topic

More on Kelp DAO

Comments