@StaniKulechov@aave don't deserve the position. Endless review is neither wise nor responsible. TVL is bleeding out. Go look at how @0xfluid handled. https://t.co/dklEeeWL7c
@StaniKulechov@aave don't deserve the position. Endless review is neither wise nor responsible. TVL is bleeding out. Go look at how @0xfluid handled. https://t.co/dklEeeWL7c
We are aware of the incident affecting Resolv earlier today.
Fluid automated ceilings prevented excessive borrowing of the funds, and USR markets have been paused. These safeguards worked as intended to contain the situation.
In case of any remaining bad debt on Fluid, all user losses will be fully covered.
User funds and protocol safety remain our top priority. We’re conducting a full review and will share a detailed post-mortem once the investigation is complete.
Claude explains the $71M @arbitrum clawback:
What this transaction is
Tx: 0x5618...0f6b on Arbitrum, block 454686044, April 21, 2026 03:35 UTC
From: 0x5d39...7Ccc — labeled on Arbiscan as “Kelp DAO Exploiter 1”
To: 0x0000000000000000000000000000000000000DA0 — a special system/recovery sink (not the normal 0x...dEaD burn address)
Value: 30,765.667 ETH (~$71M) — effectively the entire Arbitrum-side balance of the attacker’s hub wallet
Tx type: ArbitrumUnsignedTxType (EIP-2718 type 0x65 / 101)
The “type 101” is the key. That is not a user-signed transaction — a normal EOA physically cannot produce one. ArbitrumUnsignedTxType is an ArbOS system transaction that only the chain itself (via the sequencer / ArbOS upgrade path controlled by the Arbitrum Security Council) can inject. It bypasses the attacker’s private key entirely.
The remediation (this tx): Arbitrum’s Security Council used its emergency powers to inject an ArbitrumUnsignedTxType that forcibly moved the attacker’s full 30,765 ETH from the hub address into a protocol-controlled recovery sink (0x...0DA0).
Why it’s “extraordinary”
Arbitrum did not perform a reorg or historical rewrite — the chain’s ordering is intact. Instead, the Security Council used a privileged state-override transaction type that is part of ArbOS but has essentially never been used before. It is functionally a state-level clawback: the attacker’s private key still signs txs, but that address’s ETH was moved by the chain itself.
This is the mechanism Arbitrum’s progressive-decentralization docs reserve for “catastrophic” emergencies (12-of-N Security Council action), and this is one of the clearest public demonstrations of it being invoked. Note that it only recovered the Arbitrum leg of the theft — the ~75,700 ETH on Ethereum is outside Arbitrum’s control and remains with the attacker, which is why Aave is still facing up to ~$230M of potential bad debt on the Ethereum side.
Sources:
Arbiscan tx: https://t.co/gP9TxztB86
Arbitrum Docs — ArbOS / Sequencer forced inclusion: https://t.co/tLra60c8rC
Arbitrum Foundation — progressive decentralization & Security Council: https://t.co/nNGfC4l37M
@jerallaire How come the Arc block explorer shows that dprk.arc minted this North Korean propaganda NFT to your public address jerallaire.arc?
Transaction hash:
https://t.co/Ej802MlM5H