Transcription
Welcome back, guys. Today, we are jumping straight in to talk about all of the controversy around Aave, KelpDAO, LayerZero, and everything that has been [clears throat] happening. Without further ado, let's dissect it all.
Okay, so first and foremost, it has been a rough few weeks in the world of DeFi. It's kind of hard to sugarcoat it because we had the Drift Protocol hack on Solana a few weeks ago, I think, to the effect of something in the region of $200 million. We then had a Polkadot bridge hack as well. And now we're after having this latest hack from the Lazarus Group on the KelpDAO and LayerZero bridge. And then the knock-on effect is that Aave have been roped into this whole situation because the hackers effectively used the rETH as collateral on Aave to borrow a whole bunch of ETH so they could essentially extract that capital out and then profit from it.
And so, what has ultimately happened here is that essentially you had a failure with um the KelpDAO setup and the LayerZero bridge where the hacker was essentially able to mint and create a whole bunch of rETH, a wrapped staked version of Ethereum, and then they were able to take that and bring it over onto the Aave lending and borrowing protocol where rETH is a very valid um asset that can be used as collateral and effectively then borrowed against. And so, technically speaking here, the Aave smart contract on the Aave protocol is just working as intended because you had the hackers, i.e. the people linked to the Lazarus Group, taking those funds in the form of the wrapped staked ETH which they were able to take from uh exploiting LayerZero and everything over on KelpDAO, and then they brought it over and they essentially just took advantage of the Aave smart contract on the protocol to be able to leverage that as collateral, and now effectively bring it over and then borrow against it.
And so, that is the crux of the matter here. Technically, there's no um hack happening on Aave per se. The vulnerability and the exploit actually took place across LayerZero and KelpDAO. And so, there's a lot of finger-pointing going on. There's a little bit of a blame game at play here. And obviously, these protocols and their respective founders and the people behind them have to be somewhat careful in how they communicate what actually happened and figuring out who is ultimately to blame here. But essentially, what what has happened is very unfortunate. And now Aave, because they're the largest uh protocol in the entire DeFi space, are kind of being looked at to come up with some kind of solution.
Now, there has been a few different incidents that have happened here over the past few days as everything has transpired. It's looking like the KelpDAO hacker has now been able to swap um nearly all of the 75,000 ETH holdings, worth about 175 million, into Bitcoin over a day and a half period here in the past 24 to 48 hours. And those cross-chain swaps were primarily routed through ThorChain. Now, what happened was the extent of the hack initially was about 30,000 Ethereum, and they were able to um well, Arbitrum were able to actually jump in here and freeze a certain amount of that 30,000 Ethereum, sorry, that they were able to identify as having come from those nefarious actors from the Lazarus Group. And essentially, there's a big argument then happening, you know, the knock-on effect of this is why should Arbitrum actually be able to freeze funds from a given user's wallet.
My understanding is that this is because of something in the code from Arbitrum as a Layer-2 solution on the Ethereum network. Again, Arbitrum and other Layer-2s like Base, like Optimism, technically do have the ability to be able to freeze these types of funds. Obviously, before they went and did this freeze, they identified with law enforcement that the funds, or this 30,000 Ethereum, was actually coming from the hacker wallet. And so, that raises a whole side argument, you know, should these Layer-2s be able to actually go and freeze funds. My understanding is that because they are a Layer-2 and they're the ones that have to reconcile back onto Ethereum mainnet, they have this technical function built in where they're able to do certain things like this. This would not be possible and is not possible on the actual Layer-1 like Ethereum or other Layer-1s like Bitcoin, Solana, or Sui, for example. So, that's a whole side debate that has kind of spun up in light of everything that's happening here. I think it's great that Arbitrum have been able to identify those 30,000 Ethereum as coming from the hackers and they were able to freeze it, you know, contributing to the actual solution here. But there is still some speculation as to what is the final solution going to be.
The Aave founder himself, Stani uh Kulechov, has been commenting on this over the course of the past few days. And again, you've also seen in the past few hours here Lido coming in with a proposal to contribute to um Aave's coordinated wrapped staked ETH relief efforts by capping contributions of up to 2,500 um stETH to contribute to the solution as well. Basically, the problem resides in the fact that, you know, all of this rETH, there is backups for it essentially on mainnet, but then the problem lies in where are the actual um wrapped versions and restaked versions on the likes of Arbitrum, Base, Optimism, and other networks. Where are the funds going to come from for backing up those actual Layer-2 solutions? And so, the main impact here is on Ethereum mainnet. There was freezes put in place by Aave, but we have seen a lot of funds coming out of Aave over the past few days. And essentially, the full and final solution has not yet been um worked out.
So, if you're looking to keep on top of things, I would suggest coming over here and checking out everything that Stani is putting out. Follow Aave on X. They are giving better and more timely updates now compared to a few days ago related to the solutions coming out here for the rETH incident. Again, they're telling you that rETH reserves have been paused now across Ethereum, Arbitrum, Base, Mantle, and Linea. This was done with the objective of recovering additional funds as the recovery plans progress. And that's what it is, guys. It is a work in progress as they continue to try and recover as much of those funds as possible for users on those protocols.
Now, I am a user of Aave. Um I have cbBTC and other assets that are outside of that Ethereum asset itself are available for withdrawal and you can get things in and out of Aave, no problem. Again, it is unfortunate that Aave have been kind of at the center of this because technically, their smart contract is just working as it should be and the hackers took advantage of KelpDAO and everything on LayerZero to extract wrapped staked ETH and then bring it over to Aave to borrow against. So, that is the crux of the issue here. Personally, I do think we will have a solution being rolled out here. It might be progressive over the next few days or even the next couple of weeks. I still have a lot of faith in Aave as the largest lending and borrowing protocol in all of decentralized finance. I'm not personally concerned having my own funds in there because I know how well-established they are. I know where their intention is. And technically, again, I have to emphasize this, this was not an exploit on Aave or anything to do with their smart contract. It is going back to KelpDAO and LayerZero more specifically.
And so, that's where I was referring to the finger-pointing. There is things being worked out there behind the scenes, I'm sure, and they have to be careful with how they're communicating this. But I think the final point to make here in this video is the fact uh that the bigger picture here could be actually pointing back to artificial intelligence and the power that we're seeing all of these hackers being able to leverage with AI as it continues to advance. And so, artificial intelligence is fantastic and we can um make lots of phenomenal progress in terms of being traders, being liquidity providers, automated solutions, building tools, building applications that are that we're able to leverage in our daily lives as a liquidity providers and investors. But the other side of it is the power of that artificial intelligence can be used for nefarious purposes. And I think you're seeing that as a general trend here with uh these hacks and these incidents over the past few weeks in the world of DeFi. And so, just as much as you are able to leverage those tools and those powers of artificial intelligence for good, there's always going to be people who are leveraging it to hack and exploit different vulnerabilities in the world of Web3 and DeFi.
And so, what I try to remember at times like this is I want to control the variables that I can control. I cannot control if there's hackers trying to take advantage of certain smart contracts or protocols that have vulnerabilities. What I can control is my own assets, my own portfolio, and I personally never like to have one single source of failure. If you're using something like Aave, or if you're using protocols like LayerZero or KelpDAO, you don't want to be having all of your assets or all of your lend borrows or all of your portfolio in one single place with one single source of failure. Having an element of diversification, whether it comes to using bridges, whether it comes to using lending and borrowing protocols, whether it comes to using both hardware and software wallets, and even when it comes to using centralized exchanges, cannot be overemphasized enough. Having that diversification in your own portfolio, in the protocols that you use, in the lending and borrowing that you're executing, is so, so important. You can control that. You cannot control what other hackers or nefarious actors are doing. So, take back control, control the variables that you can control, enhance and upgrade your own security best practices. We've got tons of content for that if you want to check it out in the UIG community, but use this as a learning point. Use this as a way to level up and upgrade your own security best practices. Control what you can control and improve your own security from there.
So, hopefully that gives you an update, guys. Check out the stani, check out the AAVE X account, and there's also some good governance um conversations happening over here. They're giving updates on the ARS ETH incident report on governance.aave.com. You can check out that for all the latest updates to follow what's happening because it is a work in progress to finalize the solution here, and I think it's going to take another few days um for all of that to actually um get enforced here over the next little while.