TGViewer
Curious facts from Michael@Curve Curious facts from Michael@Curve @michael_curve · 1.22K subscribers
Post #107 1.73K
Observing the hack which happened yesterday to rsETH, which caused a serious contagion at Aave. Wow, it's a lot to unfold.

First of all, looks like there is no exposure of Curve or Yield Basis to either rsETH or Aave problems. But this all of the issue started with LayerZero which is relied upon by crypto with quarter of a trillion in value. How? Let's have a look.

Kelp's rsETH uses a LayerZero bridge. The bridge allows to transfer rsETH to/from other chains. Minting of rsETH can only happen on Ethereum, and all the rsETH on non-Ethereum chain are backed by mainnet-rsETH kept in the bridge.

On LayerZero one can choose so-called DVNs. DVNs are nodes which essentially bring a message from another chain. 2-of-3 DVN configuration would mean that two DVNs should agree on the fact that "give 100'000 rsETH to Eve" is exactly what was requested on another chain. And here's the problem: rsETH has a 1-of-1 DVN configuration: just one DVN (although it's the main LayerZero DVN) is used and fully trusted. So it approved a message which allowed to give the hacker all the rsETH in the bridge, although it was never sent on the source chain (Unichain in this case).

As you probably heard, 1-of-1 configuration for multisigs is kinda unsafe. Same with DVNs. But this was THE official LayerZero DVN - how could it approve a wrong message? Was it hacked? Was it fooled? We don't know. But things can happen when you trust one single party - whoever that would be.

So ok, the hacker fooled the official LayerZero DVN to give him a lot of rsETH. What's next? The most profitable for the hacker appeared to supply rsETH on Aave and borrow all possible ETH there. And Aave was left with rsETH which cannot be really sold and maxborrowed ETH, so no one can withdraw ETH. Potentially 300m-sized bad debt. Maybe not - technically those are still backed, but bank run on Aave is happening.

So which conclusions could we make from this?

* Non-isolated lending like on Aave is very risky (although it's the most capital efficient!). Aave v4 with hub-and-spoke model is probably less risky. Morpho also. And lending on Curve, as well as Silo, is probably the most isolated -> safest in that regard.

* Lending protocols are riskier than DEXes to supply funds. USDC/USDT pool on Curve has only exposure to the two assets in the pool, Aave has exposure to all asset added there.

* Asset onboarding on lending protocols should be looked at more carefully. 1-of-1 DVN configuration on rsETH is really a miss: this should have been upgraded to at least 2-of-2 before onboarding.

* Cross-chain is hard and potentially risky. Only use cross-chain infrastructure when absolutely necessary, and do it REALLY carefully.

In any case, I think DeFi will learn from this incident and become stronger than before. Crypto is a harsh environment which no bank would have survived - yet we are working with that. Permissionless infrastructure requires extraordinary efforts to be safe - and we are doing those efforts!
  • ❤ 34
  • 🔥 16
  • 👍 5
  • 👌 2
More from @michael_curve
  1. Jul 20, 2026In his recent interview, Andre Cronje weighted heavily (https://x.com/therollupco/status/2…
  2. Jun 25, 2026So looks like Uniswap finds out tech which was used by Curve since its start in 2020 (usin…
  3. Jun 9, 2026Seeing a lot of fears about Claude Mythos allegedly being released today or tomorrow and "…
  4. May 26, 2026Here we go again. Custodial stablecoins EURR and USDR were hacked by company-s multisig wa…
  5. May 11, 2026Seeing many people getting their telegram hacked. The malware uses telegram of someone fro…
  6. Apr 26, 2026I've made a proposal on how to recover bad debts in lending protocols, starting with Curve…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →