Aave V3 is a non-custodial, overcollateralized lending protocol deployed across 17+ chains, scoring 52/100 (orange band) with a -10 penalty for unresolved incident remediation.
Security: Extensively audited by Trail of Bits, Certora (formal verification), PeckShield, OpenZeppelin, Sigma Prime, and others across V3.0–V3.7; active $5M Immunefi bug bounty; however, audit findings, fix status, and deployed-code bytecode matches are Not verifiable as of September 4, 2026 for most reports.
Incidents: Five documented events: (1) June 2022 Harmony bridge exploit (~$751k bad debt, unresolved); (2) March 2023 USDC depeg (~$260k–$360k, resolved without reimbursement); (3) August 2024 Paraswap adapter exploit (~$95k DAO funds, resolved); (4) March 2026 wstETH oracle misconfiguration (~$862k wrongful liquidations, reimbursed); (5) April 2026 Kelp rsETH/LayerZero bridge exploit (~$123.7M–$230.1M estimated bad debt, ~$193.2M attacker proceeds, remediation in progress, final loss and recovery Not verifiable as of September 5, 2026).
Governance & custody: Real DAO governance with 1-day (Level 1) and 7-day (Level 2) timelocks; 4-of-7 emergency guardian multisig can pause markets and cancel malicious payloads but cannot directly drain user funds; signer independence Not verifiable as of September 13, 2026; non-custodial (users hold aTokens, withdraw subject to liquidity/caps).
Top risks: Smart-contract complexity (upgradeable proxies, admin can replace implementations and freeze reserves); oracle dependency (Chainlink/CAPO, March 2026 misconfiguration precedent); bridge/collateral failure (April 2026 rsETH event demonstrates catastrophic tail risk from upstream dependencies); liquidation cascade and bad-debt absorption (Safety Module/Umbrella mechanisms exist but April 2026 event shows limits); cross-chain infrastructure (17+ chains, LayerZero/bridge risk, per-chain exposure Not verifiable as of September 5, 2026).
Strengths: Long public track record (March 2022 launch, evolved from 2017 ETHLend); deep audit coverage and formal verification; timelocked governance with emergency controls; broad multi-chain deployment; explicit published risk framework; SEC closed four-year investigation in December 2025 without enforcement action.
Unverified: Audit remediation and bytecode matches for most reports; current TVL/exposure by chain and asset; signer independence of 4-of-7 guardian; final rsETH bad debt, recovery, and user reimbursement status; treasury composition and mark-to-market value; 30-day yield trends; CoW Swap fee-routing controversy resolution.
Recommended exposure: Conservative position sizing (≤5% of portfolio) given orange score and unresolved $123M+ bad-debt incident; prioritize Ethereum mainnet over L2s/alt-L1s (deepest liquidity, most mature deployment); avoid or severely limit exposure to bridged collateral (wstETH, rsETH, WBTC) and isolated/E-mode positions; monitor health factor >1.5 and set stop-loss at liquidation threshold; verify emergency-guardian signer rotation and DAO treasury solvency before increasing allocation; treat April 2026 rsETH event as live systemic stress test—wait for confirmed resolution, final loss accounting, and governance framework updates.
Open questions: (1) What is the final realized bad debt, total recovery, and user reimbursement plan for the April 2026 rsETH/LayerZero incident? (2) Are all audit findings for V3.0–V3.7 remediated, and do deployed bytecodes match audited code? (3) What is the current TVL, utilization, and bad-debt balance by chain and collateral type? (4) Who are the 4-of-7 emergency guardian signers, and are they independent? (5) What is the DAO treasury composition, liquidity, and mark-to-market solvency post-rsETH event? (6) Has the CoW Swap fee-routing issue been resolved, and are all protocol revenues flowing to the DAO treasury? (7) What are the updated risk parameters and circuit breakers for bridged/LST/LRT collateral post-incident?
Score
Component
Weight
Raw
Points
Reason
Security
20%
100
20.0
45 audit(s); fresh audit bonus; active bug bounty bonus
Audits
20%
100
20.0
full audit within 365 days (latest 2026-03-31)
Incidents
20%
100
20.0
2 open incident(s), $124,459,727 at risk = 0.7% of TVL (threshold 10%)
Governance
20%
90
18.0
DAO governance; no single party can withdraw funds
TVL
20%
100
20.0
TVL $17,538,184,136 = 100% of reference ($17,538,184,136)
Identification (as of 4 September 2026). Name: Aave V3; website: aave.com; documentation: Aave developer/help documentation. Category: non-custodial, overcollateralised money-market/lending protocol. Launch: first V3 deployments in March 2022; Ethereum mainnet activation in January 2023.
Native/governance token: AAVE (V3 itself has no separate chain-native token). Chains in the supplied scope: Aptos, Arbitrum, Avalanche, BSC, Base, Celo, Ethereum, Gnosis, Linea, Mantle, MegaETH, Monad, OP Mainnet, Plasma, Polygon, Sonic and Xlayer. The current deployment status of every listed chain is Not verifiable as of 4 September 2026. Main contracts / verification. The canonical per-market contracts are the PoolAddressesProvider (market registry/proxy resolver), Pool, PoolConfigurator, AaveOracle, ACLManager and AaveProtocolDataProvider.
Examples from the official address book: Ethereum—Provider 0x2f39d218133AFaB8F2B819B1066c7E434Ad94E9e, Pool 0x87870Bca3F3fD6335C3F4ce8392D69350B4fA4E2; Base—Provider 0xe20fCBdBfFC4Dd138cE8b2E6FBb6CB49777ad64D, Pool 0xA238Dd80C259a72e81d7e4664a9801593F98d1c5. The address-book entries include corresponding Etherscan/Basescan references. However, the requested two-source cross-check including Dune and explorer verification for every chain are Not verifiable as of 4 September 2026 because Dune MCP was unavailable; no on-chain result is inferred. Fork lineage. Aave V3 is not a fork of an unrelated protocol; it is Aave’s internally developed successor to V2, with redesigned architecture and features including isolation mode, eMode, supply/borrow caps, portals and gas optimisations.
The core code and successive upgrades were audited/formally verified by OpenZeppelin, Trail of Bits, PeckShield, Sigma Prime, ABDK and Certora. Changes in third-party Aave forks and any malicious-modification history: Not verifiable as of 4 September 2026.
Aave V3 looks like a real, mature product rather than a landing page. The main app is live, shows active market surfaces, and the documentation exposes both TypeScript and GraphQL developer interfaces, including a documented GraphQL endpoint for querying market data, user positions, and transactions. The UX is also more than promotional: the app pages explicitly reference specific markets such as Main Ethereum and Base, and the docs include concrete deposit and withdrawal flows for vaults, which is consistent with a functioning product surface rather than template content.
The presence of an official GitHub organization and SDK documentation further supports product maturity. An open API does exist: Aave’s documentation states that the protocol exposes a GraphQL API at api.v3.aave.com/graphql, and the docs describe AaveKit TypeScript as a low-level client for interacting with Aave Protocol v3. That is a clear signal of developer-facing API availability.
No reliable evidence in the gathered sources shows broken links, fake metrics, or template-site signs. However, those specific issues are not fully verifiable as of 2026-09-04 from the available evidence, so they should be treated as Not verifiable as of 2026-09-04.
Aave V3 has an active bug bounty program. The main Core Aave V3 bounty is hosted on Immunefi and was live since Oct 18, 2023, with payouts denominated in USD and paid in AAVE and stablecoins on Ethereum. The publicly stated payout structure is: Critical up to $1,000,000 on the 2023 governance proposal, later updated on Aave’s security page to up to $5,000,000; High $10,000 to $75,000; Medium $10,000; Low $1,000.
Aave’s security page also lists a separate Aave V3 Aptos bounty on Cantina, while the core V3 bounty remains active on Immunefi. Disclosed results are not clearly enumerated in the retrieved sources, so results are Not verifiable as of 2026-09-04.
Assessment as of September 5, 2026. Dune MCP was unavailable; all on-chain exposure, TVL, and percentage calculations are therefore Not verifiable as of September 5, 2026. Primary dependencies and scenarios
Oracles: Aave V3 relies primarily on Chainlink, with CAPO/custom feeds for some LST/LRT assets. Oracle, adapter, stale-price, or governance-configuration failure can cause wrongful liquidations or under-liquidation. V3 mitigations include supply/borrow caps, isolation/siloed mode, L2 oracle sentinels, and emergency guardians, but these are configuration-dependent.
Bridges/cross-chain assets: Bridged collateral inherits bridge, verifier/DVN, mint/burn-invariant, sequencer, and issuer risk. The April 18, 2026 Kelp rsETH/LayerZero exploit released unbacked rsETH, producing estimated Aave bad-debt scenarios of approximately $62.4M–$162.5M after recoveries. This is a confirmed dependency failure, not an Aave smart-contract exploit.
LST/LRT/restaking: wstETH, rsETH and similar assets add staking, withdrawal-queue, slashing, exchange-rate, rehypothecation and bridge dependencies. The rsETH event demonstrates that upstream collateral failure can transmit into WETH and other reserves through shared liquidity.
Stablecoins: USDC, USDT, GHO, USDe and other stablecoins introduce issuer, reserve, banking/custodian, depeg and liquidity risks. Concentrated utilization can amplify withdrawal runs and liquidation cascades; August 2026 risk analysis reported USDT utilization recovering to 92.5% on Ethereum Core.
Custodians, CEX/MMs, RWA issuers/SPVs: No reliable current quantitative exposure split was established. Not verifiable as of September 5, 2026.Contradiction / unresolved item: Prior findings cite a ~$27.8M CAPO-related liquidation event and a wstETH oracle incident, but those figures were not independently reverified through available primary evidence in this check: Not verifiable as of September 5, 2026.Failure path: upstream bridge/issuer/oracle failure → collateral depeg or counterfeit collateral → borrowing against inflated collateral → liquidator shortfall/market illiquidity → bad debt socialization through reserves, Umbrella, treasury, or liquidity providers. "dependency_failure_active": null "max_exposure_pct": null
Aave V3 is organized as a non-custodial, smart-contract-based protocol: users deposit into Aave markets from self-custodial wallets, receive aTokens that represent the supplied position, and can withdraw the underlying asset subject to liquidity and risk constraints; the protocol documentation also says withdrawals burn the equivalent aTokens and send the underlying to the user or another chosen receiver. The EmergencyAdmin role can pause specific reserves for risk management, but Aave’s FAQ says this does not let anyone freeze or directly manage individual user funds, so the custody model remains with the user and the protocol contracts rather than a centralized custodian. Segregated assets are not verifiable as of 2026-09-05.
Withdrawal is not generally paused; it is only conditionally restricted by reserve-level pauses or insufficient liquidity, not as a protocol-wide custody feature.
Horizon Bridge exploit depegged Harmony-wrapped assets (1USDC/1USDT), while Aave’s oracle initially retained $1 pricing. Opportunistic users supplied depegged collateral and borrowed ONE/LINK, draining the V3 Harmony pool. Latest Aave estimate: ~$751,000 bad debt; an earlier analysis estimated ~$1.24M.
Aave froze the market, adjusted risk controls, and pursued joint Harmony recovery proposals. No executed reimbursement or confirmed recovery was found; market remains stranded.
USDC depeg during the SVB crisis caused insolvencies in Aave V3 stablecoin E-Mode, concentrated in three large Avalanche positions. Reported bad debt was ~$260,000 on Avalanche; later Aave material cited approximately $360,000 as the majority of V3 bad debt from this event. Aave set stablecoin LTVs to zero/froze affected reserves, reviewed E-Mode, later offboarded DAI from V3 E-Mode, and deployed tooling to clear legacy bad debt.
An attacker exploited Aave’s Paraswap-powered periphery adapters through arbitrary call/data handling. Approximately $95,284.44 of accumulated dust held by adapter contracts was drained across Aave networks. The funds belonged to the DAO, not users; core Aave contracts were unaffected.
Aave disabled repay-with-collateral and debt-switch features, shipped patched implementations reviewed by Certora, upgraded the Paraswap SDK, and executed an AIP to rescue remaining balances. No user reimbursement was required.
A Kelp rsETH upgrade over-minted rsETH to a privileged treasury address because of a numeric-scaling bug. Aave froze rsETH across V3 Core, Prime, Arbitrum and Base, but circuit-breaker/oracle protections prevented impact to Aave positions. Kelp burned the excess and fixed the contract; Aave unfroze the asset on May 8, 2025.
On April 18, 2026, a forged LayerZero message released approximately 116,500 unbacked rsETH from Kelp’s Ethereum adapter. The attacker supplied approximately 89,567 rsETH to Aave V3 Ethereum and Arbitrum and borrowed about $193.2M of WETH/wstETH. Aave froze rsETH/wrsETH across deployments, set LTV to zero, froze exposed WETH reserves, adjusted interest-rate parameters, liquidated the eight identified attacker positions, and transferred recovered collateral to the Recovery Guardian.
Arbitrum also froze approximately 30,766 ETH associated with the attacker. Aave and ecosystem partners launched DeFi United to restore backing and address the deficit. Estimated Aave bad debt scenarios were approximately $123.7M to $230.1M initially, later reduced under one recovery scenario to about $62.4M.
Final realised loss, total recovery, and completed user reimbursement remain Not verifiable as of 2026-09-05. Affected markets were partly unpaused, but recovery and collateral-risk remediation continued; current status: remediation_in_progress.
Primary authority: Aave DAO. Governance is Ethereum-anchored: AAVE voting controls proposals, while chain-specific payloads are delivered to execution networks. Passed payloads are queued behind timelocks; the documented Governance V3 design allows permissionless execution after the delay, so an operator key is not required to execute an approved action.
Role-based protocol access. Each EVM deployment uses PoolAddressesProvider and ACLManager. The ACL separates DEFAULT_ADMIN, POOL_ADMIN, EMERGENCY_ADMIN, RISK_ADMIN, ASSET_LISTING_ADMIN, BRIDGE, and FLASH_BORROWER roles. Pool configuration is further restricted to the PoolConfigurator, limiting the blast radius of any individual authority.
Governance execution keys. Executors hold the permissions needed to apply governance payloads; their owner is the PayloadsController. PayloadsController and cross-chain controllers have separate owner/guardian permissions, with guardians able to cancel queued proposals or payloads. This creates a layered model: DAO approval → timelock → executor, with emergency cancellation as a separate control path.
Emergency key. Aave documents a Protocol Emergency Guardian holding EMERGENCY_ADMIN; its multisig configuration is 5-of-9. This is intended for rapid defensive actions, not routine governance. The exact current signer custody, key-generation procedures, hardware-wallet policy, and rotation process are Not verifiable as of September 4, 2026.
Cross-chain key surface. Governance messages rely on Aave’s delivery infrastructure and approved bridge adapters. Therefore, bridge adapters, trusted remotes, cross-chain controllers, executors, and guardians are additional key/permission domains that must be reviewed per chain. Risk conclusion: The design is compartmentalized and governance-led rather than dependent on one protocol-owner key. The main residual risks are executor/guardian compromise, cross-chain messaging or bridge-control compromise, and privileged risk stewards. Exact live permissions and signer sets for every listed chain are Not verifiable as of September 4, 2026 because Dune/on-chain verification was unavailable.
Assessment (as of September 5, 2026): Medium–High admin/upgrade risk; low classic rug risk, but meaningful freeze, oracle, and implementation risk.Addresses / verification. Canonical Ethereum V3 anchors remain PoolAddressesProvider 0x2f39d218133AFaB8F2B819B1066c7E434Ad94E9e, Pool 0x87870Bca3F3fD6335C3F4ce8392D69350B4fA4E2, and PoolConfigurator 0x64b761D848206f447Fe2dd461b0c635Ec39EbB27, as listed in Aave’s maintained address book. Per-chain live implementation, proxy-admin type, role membership, and explorer verification for all 17 supplied chains: Not verifiable as of September 5, 2026. Architecture / authority.PoolAddressesProvider is an owner-controlled registry. Its owner can replace the Pool and PoolConfigurator implementations through proxy updates, replace arbitrary registered addresses, and set the price oracle.
This is an upgradeable, registry-mediated proxy architecture—not renounced ownership. ACLManager assigns DEFAULT_ADMIN_ROLE from PoolAddressesProvider.getACLAdmin() and administers pool, emergency, risk, asset-listing, bridge, and flash-borrower roles. ``text Governance / Executor(s) │ ▼ PoolAddressesProvider (owner) ├─ Pool proxy ─────────► Pool implementation ├─ PoolConfigurator proxy ► Configurator implementation ├─ ACLManager ─────────► role-gated admins └─ Price Oracle / other registered addresses `` Admin powers. Pool admins can change reserve parameters, token implementations, activation, premiums, and interest-rate data; emergency or pool admins can pause the pool. These controls can freeze new activity and impair withdrawals/liquidations; oracle replacement can corrupt valuations. Users generally exit permissionlessly while reserves remain active and unpaused, but guaranteed exit under hostile administration: Not verifiable as of September 5, 2026. Timelock / proxy-admin events. Dune MCP is unavailable; proxy-admin type, decoded admin events, exact on-chain timelock delay, renounced roles, and current role holders: Not verifiable as of September 5, 2026.
Governance documentation describes queued payload execution after a timelock, but does not establish the live per-chain delay. Worst case if privileged keys are compromised: malicious implementation/oracle/configuration changes, market-wide pause/freeze, insolvency through corrupted pricing or risk parameters, and potentially fund extraction through a hostile upgraded implementation. Aave V3 has extensive listed audits, including V3, V3.1–V3.7 and Aptos reviews; audit coverage does not eliminate live admin or deployment risk.
Protocol identity The Aave ecosystem (including Aave V3) originates from ETHLend, a peer‑to‑peer lending project founded in 2017 and later relaunched as Aave in 2020 with a pooled-liquidity model. Founders & key individuals
Stani Kulechov – universally cited as the *founder* and continuing CEO / main public face of Aave.
Background: Finnish, trained lawyer (Master of Laws, University of Helsinki), early Ethereum/DeFi builder.
Track record: led ETHLend ICO (~$16–17m, ~1bn LEND tokens sold); oversaw rebrand and migration from LEND to AAVE token and evolution to the current protocol.
Broader team: multiple sources describe “ETHLend/Aave team of developers” in London and Switzerland, but do not consistently name other founders; Stani is the only clearly documented founder-level individual. Public vs. anonymous; credibility
Stani is fully public, active in media, conferences, and governance; profiles by exchanges, educational sites and Aave governance posts all confirm his identity and long-running leadership.
No evidence that Aave V3 is led by anonymous founders; branding and governance are explicitly tied to Aave Labs and Stani.
Long operating history since 2017, major TVL and multiple versions suggest significant ecosystem credibility, though this is not a guarantee of safety. Corporate structure, offices, onshore/offshore
Aave Limited appears in UK company and LEI registries with addresses at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ and another London address (74 Wigmore St).
Indicates a UK-incorporated, onshore legal entity.
Additional commentary notes operations/office presence in Switzerland alongside London.
These records support that Aave operates as a real business with registered offices, not just a web front. Prior outcomes / incidents (high-level)
ETHLend’s original P2P model struggled with liquidity and was rebuilt into Aave’s pool-based model during the 2018–2019 bear market – a pivot rather than a failure/hack.
Major protocol hacks of Aave’s core lending pools are not mentioned in the surveyed sources; risk events in Aave ecosystem have typically related to specific assets/markets, but hard on-chain verification is Not verifiable as of 2026-09-04. Reality check for institutional lens
Legal wrapper: documented UK entity with real addresses; additional Swiss presence.
Business substance: multi‑year product evolution, governance forum, and regulated-style identifiers (LEI) indicate operational substance beyond a pure web interface.
Some details (full cap table, all jurisdictions, comprehensive incident history) remain Not verifiable as of 2026-09-04 and require direct legal / technical due diligence.
Aave V3 has a strong but recently stressed reputation: long-standing blue‑chip DeFi status with extensive audits and no evidence of fraud or regulatory sanctions, but serious 2026 risk events and governance frictions have materially elevated perceived operational and economic risk. Founders / team / investors Aave was founded by Stani Kulechov and has operated as one of the largest DeFi lending protocols for years, generally viewed as institution‑grade infrastructure. No credible sources allege founder‑related fraud or rug‑pull behavior. Security track record & incidents
V3 is heavily audited: Trail of Bits, PeckShield, Certora (formal verification), Oxorio and others have audited various V3 versions and upgrades.
There is an active bug bounty on Immunefi with up to $1m for critical smart‑contract bugs, signaling mature security processes.
Nonetheless, 2026 brought material incidents:
March 2026 oracle/CAPO misconfigurations caused about $27m wrongful wstETH liquidations across 34 accounts; another CAPO error led to an ~$862k event later refunded.
April 2026 KelpDAO / LayerZero bridge exploit: attackers drained ~116,500 rsETH, used it as unbacked collateral on Aave V3, generating roughly $195–200m in bad debt and triggering a $6.6–8.45bn TVL drop and liquidity stress in stablecoin pools. These were not direct bugs in Aave’s core contracts but exposed dependence on external bridges/oracles.
Aave’s Safety Module (“Umbrella”) may be slashed to cover this deficit, meaning real loss risks for stakers. Governance / organizational reputation
Long‑term use of external risk stewards (e.g., Gauntlet, Chaos Labs) reflects professionalized risk management, but Gauntlet publicly terminated its engagement in 2024 amid criticism and governance tensions.
In 2026, core contributors BGD Labs and Aave Chan Initiative announced exits over centralization and governance disputes, flagged by independent auditors as elevating execution risk. Regulatory / legal / sanctions
A multi‑year SEC investigation (2021–2025) was formally closed without enforcement action or sanctions, which independent coverage frames as a positive regulatory outcome.
No credible records of criminal prosecutions, AML‑specific sanctions, or protocol‑level bans have been reported; watchdog databases note the probe but no prosecutions. Market sentiment & criticisms
Historically perceived as blue‑chip, low‑technical‑risk DeFi; recent independent risk assessments now rate overall risk MEDIUM, citing 2026 oracle failures, bridge‑linked bad debt, and governance instability despite robust code audits.
Key unresolved concerns for institutional risk:
Reliance on external bridges/oracles and complex cross‑chain interactions (systemic risk highlighted by KelpDAO/LayerZero incident).
Potential future Safety Module slashing to repair bad debt, impacting staked AAVE holders.
Governance fragmentation and key‑person/committee risk after departures of major risk and dev stewards. No evidence to date of intentional fraud or rug‑pull, but recent events show non‑negligible economic and operational risk despite strong technical and regulatory reputation. Not verifiable as of 2026-09-04: precise current bad‑debt balances per chain, exact slashing parameters enacted, chain‑by‑chain TVL distribution, and up‑to‑block on‑chain health metrics.
Strategy / exposure. Aave V3 is non-custodial, overcollateralized lending. Suppliers receive aTokens and earn variable interest; borrowers post collateral and borrow supported assets. Supplier exposure is broadly market-neutral to directional asset price moves, but borrowers may be directional.
Yield is primarily organic borrower interest; rewards, where configured, are subsidies and should be excluded from organic yield. The protocol is not inherently leveraged, looped, restaked, or externally invested, although users can create leverage/loops by recursively supplying and borrowing. organic_yield_pct: not quantifiable from available evidence; leverage_ratio: not verifiable as of September 5, 2026. Assets, collateral and controls. Supported assets vary by isolated market/chain. Collateral is overcollateralized and governed by LTV/liquidation-threshold parameters.
V3 uses supply caps, borrow caps, isolation mode, e-mode, debt ceilings and reserve-specific risk parameters. Withdrawals are generally permissionless and available subject to pool liquidity, caps and accrued debt; there is no protocol lock-up or redemption queue identified. Flash loans are atomic and repaid within the transaction. Fees and revenue. Supply APY is funded by borrower interest.
Protocol economics include the reserve factor, flash-loan fees, liquidation fees/penalties, Paraswap swap fees and Ethereum Chainlink SVR recapture; DefiLlama classifies these as protocol fees/revenue. V3 reserve income requires mintToTreasury() rather than accruing automatically. Liquidation protocol fees are configured per collateral and can be changed by governance. TVL / APY snapshot. DefiLlama reports approximately $17.32B TVL, $12.319B active loans, +23.8% 30-day TVL growth, and Ethereum at 84.3% of TVL; it reports approximately $31.97M fees and $4.38M revenue over 30 days.
Its average supply APY is about 1.44%, while reference-rate pages show Aave V3 supply APY 3.25% and borrow APY 4.34%; rates are utilization- and asset-dependent. Individual pools show materially different APYs and generally stable 30-day classifications. Contradiction / data gap. The submitted chain list is not fully confirmed by the current official deployment page; sources differ on supported networks, including Aptos and newer deployments. Exact TVL by every submitted chain, product-level TVL, Dune-vs-DefiLlama trend, and protocol-wide APY volatility/sustainability are Not verifiable as of September 5, 2026 because Dune MCP is unavailable and no reproducible raw on-chain query was executed.
Scope. Aave V3 Pool balances are user supplied assets, not DAO treasury assets. Reserve-factor and liquidation-fee revenue is routed to chain-specific Collector contracts; the reserve factor is risk-calibrated by asset risk, with the referenced framework describing a 10%–35% range. Size and composition. The latest located DAO disclosure (February 28, 2026) reports >$100M in non-AAVE assets, distributed across fee-generating networks and periodically consolidated on Ethereum. It separately reports >$50M in stablecoins and approximately $39.9M in ETH-correlated assets; these figures may overlap and are DAO/service-provider disclosures, not independent attestations.
Exact current composition, chain split, and mark-to-market value: Not verifiable as of September 6, 2026. Addresses and custody. The June 2026 treasury SAFE design lists budget/asset-holding SAFEs including AFC 0x22740deBa78d5a0c24C58C740e3715ec29de1bFa, APE 0xAA43203167317DeeF8288095C44b84a686918d2E, ALC 0xA1c93D2687f7014Aaf588c764E3Ce80aF016229b, AHAB 0xAA2461f0f0A3dE5fEAF3273eAe16DEF861cf594e, Aave Rewards, CEX Earn, and Aave v4 Security. The proposal describes 2-of-3 organisation-controlled nested SAFEs, capped just-in-time operational funding, and separation of proposal from signing authority. These are governance-documented custody addresses; whether every proposed configuration was executed on-chain is Not verifiable as of September 6, 2026. Control and policy. Governance retains ownership and can revoke Finance Steward permissions.
Finance Stewards are designed to execute pre-approved treasury operations through Collector-admin contracts; swaps are whitelist-, budget-, oracle-, and slippage-constrained, while Pool Exposure Steward transfers are limited to approved Aave pools and minimum reserve floors. The address book is the canonical registry for Aave ecosystem contracts. On-chain balances / liabilities. Dune was unavailable in this run: balances, chain-by-chain percentages, token quantities, and liabilities are Not verifiable as of September 6, 2026. No independent reserve attestation was identified: Not verifiable as of September 6, 2026. Contradiction / limitation. Reported DAO totals cannot be reconciled to raw on-chain balances in this run; the disclosure is therefore treated as an unverified governance/analytics claim, not proof of reserves.
Native token: Aave (AAVE), Ethereum ERC-20 contract 0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9. Other listed chains use bridged/representation tokens; a complete chain-by-chain address inventory is Not verifiable as of September 4, 2026. The official Aave Address Book is the authoritative registry.
Supply/valuation: Fixed maximum and total supply: 16,000,000 AAVE. CoinGecko reports 15,427,181 circulating, $2.014B market cap, and $2.089B FDV; these are aggregator figures, not raw on-chain verification.
Initial allocation/emissions: 13M AAVE were designated for LEND migration and 3M for the Ecosystem Reserve. There is no documented perpetual inflation schedule; remaining reserve distributions are governance-controlled. Detailed team/investor allocations were not identified in the reviewed primary sources. Unlock schedule and whether announced unlocks occurred on-chain: Not verifiable as of September 4, 2026.
Utility/governance: AAVE provides governance/proposition and voting power, with cross-chain governance execution. It historically also served as Safety Module collateral. Current Umbrella primarily stakes aTokens/GHO, while legacy stkAAVE remains available and can earn safety incentives subject to slashing risk.
Value accrual: No automatic holder revenue share or protocol-level burn is established in the reviewed sources. A 2025 Aavenomics proposal authorized revenue-funded buybacks and distribution to the Ecosystem Reserve, with a proposed $1M/week initial pace; buybacks were publicly reported paused from April 19, 2026, with no transactions since that date. On-chain execution, burns, and current reward rates: Not verifiable as of September 4, 2026.
Allocations, holders, insiders, liquidity/listings: Top-holder concentration, insider-wallet identification, DEX depth, and chain-specific liquidity: Not verifiable as of September 4, 2026. CoinGecko lists Binance, KuCoin, and Bybit among major venues; this is not a liquidity-depth measurement.
Admin risks: The token repository describes governance ownership/control of deployment proxies, but current mint, blacklist, fee-switch, proxy-admin, and controller state require on-chain verification: Not verifiable as of September 4, 2026.
If BTC falls below $10,000, Aave V3’s design (over‑collateralization, conservative BTC LTVs and active liquidations) makes the protocol likely to remain solvent, but you should expect heavy BTC‑backed position liquidations, short‑term liquidity stress in key pools, and elevated oracle/liquidation risk across chains. 1. Current BTC-related exposure (high level) Web data (not on-chain verified) indicates Aave V3 supports WBTC, cbBTC and BTCB as collateral on Ethereum and BNB Chain, plus BTC-like assets on Sonic and others. Indicative parameters for BTC collateral show max LTV ~70–74% and liquidation thresholds ~75–79%, depending on chain and asset.
TVL is dominantly on Ethereum (~80–85% of Aave V3 TVL), with smaller but non‑trivial exposures on Arbitrum, Base, BNB, Avalanche, Polygon and others. 2. Mechanics of the BTC < $10k shock If BTC falls sharply, BTC-collateral positions see their health factor drop; once below 1, liquidations are triggered per reserve‑specific thresholds. BTC is modeled as more volatile than ETH and stablecoins; risk frameworks (Chaos Labs, Gauntlet) explicitly size BTC haircuts for large price moves.
Key systemic channels:
Mass liquidations of BTC-backed borrows (mainly stablecoin and ETH borrows), increasing on‑chain sell pressure on BTC proxies and pushing up stablecoin supply APYs.
Liquidity concentration on Ethereum: with most TVL on Ethereum, liquidation cascades will be most intense there; L2s and BNB Chain face smaller but more brittle liquidity.
Oracle risk: BTC feed failures, lags or outliers during extreme moves can cause under‑ or over‑liquidation and bad debt, particularly on newer chains. 3. Risk assessment for an institutional lender/LP Primary risks in this scenario are liquidation execution risk, oracle integrity, and stablecoin pool liquidity, not protocol insolvency. BTC collateral is already treated conservatively, but a sub‑$10k BTC could still create pockets of bad debt if liquidations cannot clear fast enough or if thin-chain markets (smaller L2s, Sonic, Xlayer) lack depth. As of 2026‑09‑04, precise on‑chain BTC exposure per chain and reserve is Not verifiable as of 2026-09-04; risk views above rely on public governance, analytics and secondary research, not raw ledger data. Institutional recommendation (scenario-specific)
Prefer Ethereum and major L2 markets for BTC‑adjacent lending/LP exposure; treat smaller chains as higher stress‑beta.
Monitor governance and risk parameter updates (caps, LTV, liquidation bonuses) closely for BTC assets.
Size positions assuming temporary spikes in liquidation discounts and stablecoin APYs, and potential short‑term withdrawals by other LPs during the BTC<10k shock.
Assume the largest collateral asset on each Aave V3 deployment drops 20% vs USD while everything else (including debt assets) holds parity. All references to on-chain positions are Not verifiable as of 2026-09-05. ### 1. Core mechanics of a 20% collateral depeg On Aave V3, user health factor (HF) is roughly: \[HF = (Σ\,collateral\_value·LTV\_i) / (Σ\,debt\_value)\] A 20% price drop in the dominant collateral:
Reduces collateral value and HF proportionally for all users concentrated in that asset.
Pushes the most levered accounts below liquidation threshold (LT), triggering liquidations. Because Aave uses chainlink-style oracles with safety modules like price caps, staleness checks, and circuit breakers, the risk is primarily economic (bad debt, cascade liquidations), not oracle-manipulation in this scenario. ### 2. Chain-by-chain exposure focus (qualitative) Given chains differ in asset mix, the “largest collateral” risk varies: | Chain | Typical largest collateral (qualitatively) | Risk note under −20% | | --- | --- | --- | | Ethereum | WETH, USDC, wstETH mix | If stETH/wstETH is largest: a 20% depeg vs ETH or USD stresses LSD positions; leverage loops unwind; but deep liquidity limits long bad-debt tails. | | Arbitrum / OP / Base | Often WETH / USDC / stable LSD wrappers | Similar pattern; smaller pools, so oracle or liquidity frictions can more easily cause partial auctions, but systemic bad debt still unlikely absent further shocks. | | Avalanche / Polygon / BSC / Gnosis | More local blue chips (AVAX, MATIC, BNB, etc.) | A 20% drop is common in volatile L1s; Aave parameters (LTV/LT) are tuned for this; risk is concentrated where users rehypothecate volatile collateral into stablecoin debt. | | Smaller / newer chains (Linea, Mantle, etc.) | Often USDC / WETH derivatives / local tokens | Main vulnerability is shallower DEX and CEX liquidity, making liquidations more likely to slip and create bad debt. ### 3. Where does systemic risk emerge? Key risk drivers:
High LTV on the largest collateral (especially LSDs) → thin HF buffers.
Leverage loops (e.g., deposit LSD, borrow stable, buy more LSD) → amplify losses when LSD depegs.
Liquidity depth in spot markets → determines whether auctioned collateral can clear without steep additional slippage.
Cross-chain contagion via common assets (e.g., USDC, WETH, major LSDs) and shared market maker balance sheets. In a 20% depeg limited to a single largest collateral asset per chain, Aave V3’s risk parameters, isolation mode, supply caps, and E-Mode constraints are specifically designed to confine losses at user level and protect the protocol from structural insolvency, though local and short-lived bad debt on thinner chains remains a realistic outcome.
stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;
two sources
In Aave V3, a “top counterparty insolvent” stress event manifests as large undercollateralized positions that cannot be fully cleared by liquidators, creating bad debt that is ultimately absorbed by liquidity providers and, in extremis, the Aave Safety Module and ecosystem reserve. Below is the generic path; it is broadly similar across all Aave V3 chains (Ethereum, Arbitrum, Polygon, etc.), with parameter differences per asset and chain. 1. Stress onset – health factor collapse
A top borrower (or correlated cluster) suffers a sharp collateral price drop or borrowed-asset spike; its health factor (HF) falls below 1, making the position liquidatable.
As HF approaches insolvency (HF < 0.95), V3 allows up to 100% close factor, meaning the entire debt can be liquidated in one go. 2. Liquidation attempt – who absorbs first losses
External liquidators repay the debt asset into the pool and receive the borrower’s collateral plus a liquidation bonus (discount).
Mechanically: variable debt tokens are burned, collateral aTokens are transferred/burned, and the debt asset moves from the liquidator to the reserve; a protocol share of the bonus can go to the treasury.
If market/liquidity conditions are normal, liquidators fully clear the position, and liquidity providers (LPs) face only temporary utilization spikes and earn interest plus liquidation-derived fees. 3. Path to bad debt – when liquidators cannot clear
If collateral becomes illiquid or gaps down so hard that even full liquidation (close factor 100%) does not cover outstanding debt, the position becomes insolvent and residual bad debt remains in the pool.
This bad debt is economically borne by LPs in that specific reserve, whose claim to the pool’s assets is diluted by the shortfall. 4. System-level absorption – Safety Module and governance
Aave’s framework explicitly treats solvency risk as covered by the Safety Module, with incentives funded from the ecosystem reserve.
In severe systemic events (e.g., top counterparty or asset failure), governance can trigger Safety Module mechanisms (e.g., slashing staked AAVE) to recapitalize affected reserves; this shifts part of the loss from LPs to SM stakers and the protocol treasury. 5. Impact propagation across contracts and chains
The impact is per-reserve and per-chain: bad debt arises in a given market (e.g., Aave V3 Ethereum WETH reserve) via its Pool, aToken, and debt-token contracts; other chains and reserves are insulated unless correlated positions are simultaneously stressed.
Governance risk actions (tightening LTVs, offboarding assets, deprecating low-revenue chains) can follow to limit future insolvency exposure, but they do not retroactively remove existing bad debt. Not verifiable as of 2026-09-04: exact current TVL distribution and % exposure per chain for Aave V3, given the lack of direct on-chain tooling in this context.
stress scenario - committed fraud by the DAO or owners
two sources
There is no public evidence of criminal or regulatory findings of fraud by the Aave DAO or Aave Labs/founders as of the latest available data, but there are serious governance and misappropriation allegations from within the community that matter for stress testing. ### 1. External regulators / courts
The U.S. SEC concluded a four‑year investigation into Aave in December 2025 without recommending enforcement action. That strongly reduces the probability of past securities‑law fraud findings, though the SEC explicitly noted this does *not* grant immunity and could revisit if facts change.
Current major legal dispute: Aave LLC is in U.S. federal court over $71m of ETH recovered from the April 2026 Kelp DAO exploit on Arbitrum. Plaintiffs (North Korea terror‑victim judgment holders) are trying to seize the funds; their lawyers re‑characterize the exploit as “fraud” rather than “theft” to argue legal title. These filings allege fraud by the *attacker/exploit transaction*, not by Aave DAO or Aave Labs.
No search results indicate sanctions, criminal fraud charges, or regulatory fraud findings against the Aave DAO or its owners as of the most recent articles. ### 2. Internal governance / misappropriation risk For stress scenarios, a key signal is the CoW Swap fee controversy:
Multiple reports note that after a front‑end change from ParaSwap to CoW Swap, swap fees (≈$200k/week, potentially >$10m/year) were redirected from the Aave DAO treasury to wallets controlled by Aave Labs, apparently without explicit DAO approval.
One detailed account frames this as “misappropriation of funds” and “implicit privatization”, where DAO‑funded infrastructure and brand routed value to a Labs‑controlled address rather than the DAO vault.
Community reaction: governance delegates and DAO members publicly challenged this, describing it as a governance crisis and conflict of interest rather than labeling it criminal fraud. ### 3. Stress‑scenario framing for an institutional risk book Assuming a worst‑case “committed fraud by DAO/owners” scenario, current information mainly supports:
High governance‑capture risk: ability of Aave Labs/front‑end operators to redirect significant protocol‑adjacent revenue without prior DAO vote.
Legal‑process risk: Aave LLC’s involvement in large, contested court proceedings around exploit‑recovery flows, which could expose the protocol to adverse precedents or asset seizures even if Aave is not found to have committed fraud itself. No on‑chain verification is possible in this run; any quantitative impact from alleged misappropriation is Not verifiable as of 2026‑09‑04.
Aave V3 is deployed across multiple chains, including Ethereum, Arbitrum, Avalanche, BNB Chain, Base, Celo, Gnosis, Linea, Mantle, Polygon, Sonic, and others; the protocol’s deployment list also includes several of the chains you named, such as Arbitrum, Avalanche, Base, BNB Chain, Celo, Ethereum, Gnosis, Linea, Mantle, and Polygon. However, for the stress scenario you asked about — primary yield source negative 30d — I cannot verify the 30-day yield signal from the available sources here. Not verifiable as of 2026-09-04.
A few points matter for risk interpretation:
The only yield data surfaced in the search results was a live APY snapshot on yield aggregators, not a 30-day time series, and it did not establish a negative 30-day primary yield source.
Some third-party analytics pages show large TVL and chain breakdowns, but these are aggregator interpretations rather than raw on-chain verification.
Because on-chain validation is unavailable in this run, I cannot confirm whether the protocol’s dominant yield source is negative over 30 days or quantify chain-by-chain exposure. Not verifiable as of 2026-09-04. For an institutional stress memo, the prudent conclusion is: the negative-30d primary-yield condition is unverified, so it should be treated as a potential scenario rather than a confirmed protocol state.
Assessment as of September 13, 2026. Aave V3 has real DAO governance, but operates as a hybrid service-provider model. Aave Labs leads core development, ecosystem growth, documentation, and the canonical frontend; its Terms state that it does not own, operate, or control the underlying Aave Protocol, which runs through governance-controlled contracts. Proposal process: forum ARFC and risk/technical review → Snapshot (where applicable) → on-chain AIP vote → cross-chain delivery/queueing → executor timelock → permissionless execution. Governance v2 describes Level 1 proposals with a 1-day timelock and Level 2 proposals with a 7-day timelock; Level 2 controls governance, token, executor, and timelock changes. Control and emergency powers: PayloadControllers and Executors hold protocol permissions.
The emergency guardian can pause markets, freeze reserves, and cancel unexecuted malicious payloads without waiting for a normal vote. This is an emergency bypass, but not documented authority to arbitrarily drain user positions. Executors may hold execution funds and have limited rescue authority for funds sent by mistake. Multisigs: the Protocol Emergency Guardian is configured as 4-of-7 across deployments.
Public addresses are listed, but signer identities are intentionally not attributed; signer independence is therefore Not verifiable as of September 13, 2026. Treasury budget/asset SAFEs are described as 2-of-3 nested SAFEs, not one universal treasury multisig. Voting concentration/top holders:Not verifiable as of September 13, 2026 (Dune unavailable in this run; no on-chain substitute used). Quantitative concentration should not be inferred from forum commentary. Company-control legal fields: DAO governance is not company-controlled; entity jurisdiction, registration number, and directors are therefore not applicable to the control conclusion.
For Aave Labs specifically: Not verifiable as of September 13, 2026 from the reviewed sources.
As of September 4, 2026.Entity / jurisdiction. Aave V3 is open-source, self-custodial smart-contract software governed through Aave DAO; the protocol itself is not a legal person. The principal contractual interface entity identified is Aave Interfaces Ltd., a Cayman Islands company; “Aave Labs”/Aave Labs Ltd. is the developer and service-provider group. The interface Terms apply Cayman law, designate Cayman arbitration/courts, waive class actions, and cap liability generally at US$1,000.
ToS, restrictions and KYC/AML. The Terms concern Aave.com and the hosted interface—not the underlying protocol—and state that Aave Labs does not control or operate deployed Aave markets or custody user assets. The interface may suspend or deny access where use creates legal/liability risk or appears unlawful. The privacy policy says wallet addresses may be collected to block wallets linked to legally prohibited conduct and that blockchain-transaction monitoring providers may be used.
However, the permissionless protocol has no universal account-opening KYC process identified in the reviewed materials; interface-level controls should not be treated as protocol-wide AML/KYC. Classification. No binding regulator or court determination classifying AAVE or Aave V3 lending positions was identified. A U.S.
SEC-filed AAVE investment-product disclosure states counsel generally cannot provide a legal opinion on AAVE’s securities status and warns that a future securities determination could materially impair trading. This is regulatory uncertainty, not a finding. Warnings, enforcement, litigation and sanctions. The SEC’s public litigation-release index reviewed does not list Aave or Aave Labs as a respondent.
A May 8, 2026 New York federal order in *Kim v. DPRK* permitted assets to be transferred to an Aave-controlled wallet and required Aave LLC to honor a restraining notice; it was not an enforcement finding against Aave. No regulator warning, judgment, or sanctions designation against the protocol/entity was identified. Not verifiable as of September 4, 2026 whether any non-public investigation or unindexed proceeding exists.
Legal structure vs. actual risk. Cayman contractual separation and DAO decentralization reduce obvious centralized counterparty exposure, but do not eliminate regulatory, jurisdictional, operator/developer, interface, sanctions-screening, or litigation risk. On-chain positions remain exposed to applicable law in each user’s jurisdiction and to smart-contract/governance failure. Structured fields: active_enforcement: false; sanctioned: false; entity: Aave Interfaces Ltd / Aave Labs group; jurisdiction: Cayman Islands.
Active enforcement
No
Sanctioned
No
Entity
Aave Interfaces Ltd / Aave Labs group; Aave V3 itself has no legal personality
Aave V3 issues its own native stablecoin, GHO. A depeg event for GHO is documented in Aave governance: on 2023-10-26 it fell from $0.962 to $0.946, which is a maximum observed depeg of about 5.4% below $1.00 during that event. The web results gathered here do not verify a complete depeg count across all Aave V3 markets or the last depeg date beyond this event, so those fields remain not verifiable as of 2026-09-05.
There is also no on-chain verification in this run, so protocol-wide depeg frequency for the stablecoin used in Aave V3 cannot be confirmed here.
Aave V3’s principal risks arise from the interaction of smart-contract complexity, oracle dependency, liquidation liquidity, cross-chain infrastructure, and DAO-controlled administration. Its risk controls—caps, isolation mode, liquidation mechanisms, audits, timelocks, guardians, and cross-chain validation—reduce but do not eliminate tail-loss scenarios. Chain-level exposure, TVL concentration, and current bad-debt status are Not verifiable as of September 5, 2026 because Dune MCP/on-chain verification is unavailable.
Risk
Impact
Severity
Probability
Mitigation in place
Residual risk
Smart-contract exploit
A vulnerability in pool, tokenization, liquidation, upgrade, or ancillary contracts could enable unauthorized asset loss or insolvency. Audits reduce discovery risk but cannot prove absence of exploitable defects. Aave’s core repository was archived in October 2025, increasing the importance of deployment/version governance.
High
Medium
Multiple audits, open-source code, formal verification/testing references, governance-controlled deployments, emergency controls, and a bug-reporting process.
High-impact zero-day, implementation divergence, or dependency failure remains possible; loss could be permanent.
Oracle and valuation failure
Stale, manipulated, unavailable, or incorrectly configured prices can misvalue collateral and debt, causing under-collateralized borrowing or unfair liquidations. Risk is higher for thin-liquidity, long-tail, or issuer-derived assets.
High
Medium
Chainlink feeds where available, emergency oracle modes, asset-specific risk reviews, supply/borrow caps, isolation mode, and governance parameter controls.
Rapid collateral declines, stablecoin depegs, thin market liquidity, congestion, or liquidation slippage can leave debt exceeding recoverable collateral and transmit losses to suppliers.
High
Medium
Overcollateralization, health factors, liquidation incentives, close-factor rules, caps, isolation mode, risk monitoring, and Umbrella/first-loss coverage for designated markets.
Medium-High; insurance capacity and liquidation performance may be insufficient during correlated, discontinuous stress.
Cross-chain messaging failure
A compromise, outage, replay, misconfiguration, or delayed message across bridges or delivery infrastructure could execute incorrect governance payloads or leave markets with inconsistent parameters.
High
Medium
Aave Governance V3, timelocks, emergency guardian powers, message validation, multiple bridge/provider designs in some routes, and per-chain governance execution.
High; every additional chain, bridge, oracle path, and deployment increases the aggregate attack and coordination surface.
Governance and privileged-role risk
Concentrated voting power, compromised delegates, rushed proposals, or misuse of risk stewards/guardians could alter listings, caps, rates, pauses, or implementation permissions before users can exit.
Aave V3’s top strengths are: (1) a long and public security-review record, including multiple independent audits and formal verification, with no confirmed critical or high-severity issue reported in the cited security page; (2) strong governance and control design, with upgradeability constrained by timelocks, emergency guardians, and risk stewards rather than fully open-ended admin power; (3) cross-chain architecture, including Portal/Cross-Chain functionality that is restricted to governance-approved bridge permissions; (4) broad deployment footprint across many networks, which improves reach and liquidity access for users across ecosystems; and (5) an explicit, published risk framework that requires audits, re-attestation for material upgrades, and independent verifiers for bridged exposure. ## Key caveat These are strengths of the protocol design and security posture; on-chain usage, TVL, and chain-by-chain exposure are not verifiable in this run, so they are not assessed here.