LlamaRisk
LlamaRisk is a risk service provider that joined Aave as its second risk manager in 2024 and has carried Aave's risk-management functions since Chaos Labs left in April 2026. It publishes its asset-onboarding framework openly and co-authored Aave's report on the April 2026 rsETH exploit.
Suits: Aave depositors, and readers who want the reasoning behind a collateral listing before it goes live
How this score was reached
Every firm starts at 10.0. The lines below are the only things that move it: each event on the ledger after credits for the response, and the two firm-level checks. A limited or well-handled record, or a short or undocumented method.
| Start | 10.0 |
| 18 Apr 2026 — Kelp rsETH bridge exploit leaves bad debt on Aave | −1.0 |
| Public risk methodology | 0.0 |
| At least one year of documented mandates | 0.0 |
| Score | 9.0 |
|---|
The facts, with sources
A value with no source does not count toward the score. Where a fact could not be found it reads “not published” and is scored by the published rule for missing data.
| Criterion | Value | Source | Checked |
|---|---|---|---|
| Public risk methodology | PublishedPublic Aave V3 framework: asset fundamentals, then market, technological and counterparty risk, then the parameters proposed. | github.com ↗ | 21 Sept 2026 |
| First documented mandate or vault | 20 Mar 2024Proposed onboarding as an Aave risk service provider | governance.aave.com ↗ | 21 Sept 2026 |
| Mandate — Aave | Risk service provider; parameter changes through the Risk StewardSince 2024; sole incumbent provider after April 2026 | governance.aave.com ↗ | 21 Sept 2026 |
| Incidents on the ledger | 1Each listed below with its sources | — | 21 Sept 2026 |
On the record
- Co-authored a detailed incident report on the rsETH exploit two days after it, with per-market bad-debt scenarios.
- Its asset-onboarding framework is public, covering market, technological and counterparty risk before parameters are proposed.
- Depositors on the affected Aave markets did not absorb the loss: the attacker positions were liquidated and the DeFi United coalition funded the remaining gap.
Against it
- rsETH and wrsETH were accepted as collateral at up to 95% loan-to-value on eleven Aave deployments while bridged copies depended on a LayerZero route secured by a single verifier; the attacker borrowed about $193M against it.
- Under the incident report's uniform-loss scenario, bad debt on Aave's Ethereum WETH reserve alone would have been about $91.8M.
LlamaRisk on the ledger
- −1.0
Kelp rsETH bridge exploit leaves bad debt on Aave
Role: Aave risk service provider holding the parameter controls through the Risk Steward
- Loss or bad debt
- $91.8M−3.0Bad debt modelled for Aave's Ethereum Core WETH reserve alone under the incident report's uniform-loss scenario; Mantle, Arbitrum and Base add about $26.8M more. The attacker borrowed about $193M against 89,567 rsETH on Aave. Every scenario is far above the $10M threshold.
- Response
- ✓ Post-mortem in 2 days +1.0✓ Depositors paid +1.0— No ignored public warning documented
rsETH and wrsETH were frozen across all Aave V3 deployments within about 90 minutes, WETH rate curves were flattened and WETH frozen on affected markets; a co-authored incident report with bad-debt scenarios followed two days later.
The attacker positions were liquidated on 6 May 2026, recovering 106,993 rsETH across Aave and Compound, and the DeFi United coalition — to which the Aave DAO contributed — committed ETH to cover the remaining bad debt in all affected Aave markets.
Primary sourcersETH Incident Report (20 April 2026) — co-authored by Aave service providers ↗Payout record ↗
◆ Not on this ledger, and why
The rsETH event is recorded against LlamaRisk because it held Aave's parameter controls on 18 April 2026, after Chaos Labs' offboarding plan of 8 April rotated the Risk Steward keys. The rsETH collateral settings in force that day had been set while both firms served Aave.