0x200054262000…20005423

ConfirmedDeFi594 vB38 sat/vB3 min decode

Santiment Maps Compound's Liquidation of KelpDAO Hacker's Collateral

Santiment's deep dive documents how Compound's liquidation engine absorbed collateral from the KelpDAO exploit, framing the outcome as governance-orchestrated recovery rather than routine default.

Deep Dive: How DeFi Governance Liquidated the KelpDAO Hacker’s Collateral on Compound - Sanbase
WitnessDeep Dive: How DeFi Governance Liquidated the KelpDAO Hacker’s Collateral on Compound - SanbaseAI-generated

Outputs

  1. Santiment published an analysis titled "How DeFi Governance Liquidated the KelpDAO Hacker's Collateral on Compound."

  2. Kelp DAO operates as a liquid restaking protocol built on EigenLayer.

  3. Exploit proceeds entered Compound markets as loan collateral before being absorbed by the liquidation engine.

  4. Permissionless liquidation bots — not a specific post-incident COMP governance vote — triggered the position's liquidation.

  5. Compound's next governance cycle is expected to bring V3 collateral-market proposals that will shape future liquidation speed under stress.

The on-chain analytics platform Santiment has published a deep dive titled "How DeFi Governance Liquidated the KelpDAO Hacker's Collateral on Compound," framing the liquidation of exploit-linked deposits as a textbook case of governance-orchestrated recovery.

The analysis treats Compound, one of Ethereum's largest decentralized lending markets, as both venue and enforcement mechanism for funds connected to the KelpDAO exploit. Kelp DAO is a liquid restaking protocol built on EigenLayer, the Ethereum middleware that routes staked ETH into actively validated services.

The two protocols intersected when the Kelp DAO attacker routed exploit proceeds into Compound markets as collateral for borrowing, giving Santiment's researchers a clean chain of custody to reconstruct. The chain terminated at the liquidation engine, where the position was absorbed by third-party liquidation participants.

What did Santiment actually analyze?

The deep dive walks readers through the on-chain mechanics by which liquidators and Compound governance participants interacted with the attacker's position. Coverage focuses on the timestamps of liquidation events, the borrowing parameters set by the attacker, the liquidation penalty schedule in effect at the time, and the downstream flow of seized collateral into fresh wallets.

The piece also details the role of liquidation bots, automated actors who repay underwater debt in exchange for discounted collateral, as the proximate trigger for the liquidation. Santiment frames the bots as the operational layer beneath a higher-order governance decision.

How does Compound's liquidation engine work?

Compound's liquidation logic operates without permission. Any external participant can scan for underwater positions, repay a portion of the borrower's debt, and receive a discounted chunk of the corresponding collateral. The mechanism, originally designed to socialize default risk across lenders, now doubles as a tool for chain-level enforcement — a trajectory the report cites explicitly.

What precedent does the liquidation set for restaking exploits?

The KelpDAO incident joins an emerging cluster of exploits targeting liquid restaking primitives on EigenLayer and downstream LRTs. Attackers prize the deep pool of staked capital; protocol teams absorb the integration surface that third-party markets expose. Santiment argues that liquidation-enabled recovery mechanisms have become part of the design trade-off restaking teams factor into incident response.

Liquid restaking tokens, including Kelp's rsETH and peers from protocols such as Renzo and EtherFi, have grown into a multi-billion-dollar LRT category on Ethereum. The systemic implication is that a successful restaking exploit can transmit directly into lending collateral at scale, multiplying the recovery stakes for affected protocols.

Why does the "governance" label matter here?

Framing the outcome as "DeFi Governance" — rather than as a routine protocol default — points to the role of COMP token holders, who vote on oracle integrations, collateral listings and reserve factors. In the KelpDAO case, the report indicates, the liquidation depended less on a specific post-incident governance vote and more on the existing market plumbing that COMP holders had previously put in place. Santiment frames this split between preset rules and post-hoc coordination as the central lesson of the case.

What to watch next

Two follow-on items are likely. First, additional Santiment research from the same product line may extend the methodology to other restaking-related incidents that have crossed lending markets. Second, Compound faces an active operational queue: V3 parameterization, oracle venue adjustments and reserve-factor calibration across new collateral types. The next Compound governance cycle is expected to bring fresh proposals on isolated collateral markets under the V3 design, with risk parameters directly governing how quickly future exploit-deposited collateral can be cleared in stress conditions.

via Google News - DeFi Protocol Governance (Source)

More from Elena Vasquez

Elena Vasquez

Show full bio

Staff writer covering marketplaces and e-commerce at Mempool Brief.

440 articles