🚨 UPDATE: The rsETH exploit exposed a different risk than I predicted
What I warned (April 14): Aave's $8.6B looping amplifies market crashes
What happened (April 18): A security breach froze the protocol
But the root cause is the same: concentrated collateral dependency
➢ The attack (April 18, 17:38-17:43 UTC)
Attacker executed 4 rapid transactions:
1️⃣ Supply 1 rsETH → Borrow 0.98 WETH (test)
2️⃣ Supply 5,000 rsETH → Borrow 4,924 WETH
3️⃣ Supply 20,000 rsETH → Borrow 19,745 WETH
4️⃣ Supply 27,999 rsETH → Borrow 27,771 WETH
Total: 53,000 rsETH → 52,440 WETH borrowed (~$120M)
Result: WETH drained → stablecoin markets locked → $5.08B frozen
Attacker:
(Labeled by
@zachxbt as "Kelp DAO Exploiter 3" | Funded by Tornado Cash)
➢ Why Spark survived
Jan 20, 2026 (88 days before):
Spark froze rsETH citing "concentrated usage"
But the real difference: Strategic choices
Spark:
• Looping exposure: $519M (controlled)
• rsETH: Froze in January
• ETH max rate: High (deters loopers)
• Current WETH liquidity: $66.5M available
Aave:
• Looping exposure: $8.6B (aggressive)
• rsETH: Kept live until exploit
• ETH max rate: 10% (attracts loopers)
• Current USDT/USDC liquidity: $0 available (5.05B 100% utilization)
Spark chose safety over growth.
➢ The real danger ahead
@MonetSupply's warning:
"At 100% utilization, liquidations can't execute. A 15-20% ETH drop could cause significant bad debt on Aave (on top of the rsETH exploit)."
Translation:
• Trigger was different (security breach vs market crash)
• But the systemic risk is identical: over-concentrated collateral + no liquidity buffer
• The real test comes if ETH drops
Original analysis:
Live data: |