Aerodrome Slipstream

Green · 70/100

Executive summary

Aerodrome Slipstream is a concentrated-liquidity AMM module within Aerodrome Finance on Base, scored 67/100 (orange band) with high data confidence (91/100).

  • Security: Multiple audits by Spearbit, ChainSecurity, and ABDK covering Slipstream concentrated-liquidity contracts; Spearbit reported 6 high findings (all fixed), ChainSecurity reported 1 critical and 1 high (both corrected); bytecode-match to deployed Base contracts is not verifiable as of September 2026. Active $100k Immunefi bug bounty since May 2024.
  • Incidents: Two DNS/frontend hijacks (November 2023: ~$250k user losses; November 2025: ~$700k losses) compromised domain infrastructure but not smart contracts. January 2026 Revert Finance integration exploit lost ~$50k of Revert capital (not user funds) due to collateral-invariant failure in a third-party lending vault using Slipstream LP NFTs.
  • Governance & custody: Non-custodial protocol with veAERO token-holder governance over emissions and pool incentives; however, Protocol Team multisig retains control over fee management, pausing, factory ownership, and emergency powers (EmergencyCouncil can kill/revive gauges). Not fully DAO-controlled under strict definition. No external qualified custodian; users retain self-custody.
  • Top risks: Smart-contract accounting complexity in NFT positions, gauge/reward logic, and tick bookkeeping creates residual exploit risk despite audits. Privileged emergency controls and factory ownership enable material parameter changes. Concentrated-liquidity mechanics expose LPs to impermanent loss and range-exit risk. Heavy dependence on AERO emissions for yield; organic fee share not separately verifiable. Base infrastructure reliance and two prior frontend compromises indicate operational security gaps.
  • Strengths: Capital-efficient concentrated liquidity reduces slippage on active pairs; Base-native deployment offers low fees and fast settlement; established as Base's dominant DEX module with $185M TVL; strong audit coverage from reputable firms; proactive security posture with public bug bounty and multiple review cycles.
  • Unverified: Legal entity, jurisdiction, KYC/AML framework, and regulatory status are not verifiable. On-chain TVL composition, bridge exposure, pool-level balances, and treasury reserves cannot be confirmed without Dune access. Exact remediation of all audit findings and bytecode-match to deployed Base contracts remain unverified as of September 2026. Founder identities and team backgrounds are not independently confirmed.
  • Recommended exposure: Conservative position sizing (≤5% of DeFi allocation) appropriate for orange-band risk. Limit exposure to established, high-volume pools with deep liquidity. Avoid narrow-range positions during volatile periods. Monitor AERO emissions sustainability and organic fee generation. Require independent verification of deployed bytecode against audited source before material allocation. Implement strict frontend access controls (hardware wallet, transaction simulation) given two prior DNS attacks.
  • Open questions: Verify deployed Base contract bytecode matches audited source commits. Confirm current multisig signers, thresholds, and emergency-power scope. Obtain pool-level TVL composition, bridge-token exposure, and organic vs. subsidized yield breakdown. Clarify legal entity, jurisdiction, and any geographic restrictions. Assess veAERO voting concentration and governance attack surface. Validate treasury reserves and protocol-controlled value separate from user liquidity.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 10 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2024-11-13 is older than a year
Incidents 20% 100 20.0 no open incidents
Governance 20% 100 20.0 immutable contracts: no upgrade path, no admin drain
TVL 20% 1 0.2 TVL $202,159,793 = 1% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 24/42 verified facts; 42/42 fresh (180d)

Identification

protocol identification

two sources

Aerodrome Slipstream is the concentrated-liquidity AMM module of the Aerodrome DEX on Base, functioning as a low-slippage meta‑DEX focused on high‑volume, largely stable pairs. ### Protocol identification

  • Name: Aerodrome Slipstream (often branded as *Slipstream* within Aerodrome).
  • Website / UI: aerodromeslipstream.com and Slipstream interface linked from Aerodrome; these are part of the Aerodrome ecosystem on Base.
  • Docs: No standalone formal docs surfaced; Slipstream is documented within Aerodrome ecosystem explainers and research write‑ups, not an independent docs site.
  • Category: Concentrated‑liquidity DEX / AMM module integrated into a ve(3,3) liquidity marketplace.
  • Chains: Deployed on Base only as part of Aerodrome; no credible evidence of other chains.
  • Native token: Uses Aerodrome’s AERO token (veAERO gauges, emissions) rather than a separate Slipstream token.
  • Launch date: Multiple independent sources state Slipstream was launched on top of Aerodrome in March 2024. ### Main contracts & verification
  • Public material describes Slipstream as a Uniswap v3‑style CLMM with NFT positions, configurable tick spacing, and custom fee algorithms, integrated with Aerodrome’s router and veAERO gauge system.
  • Specific contract addresses and explorer verification status cannot be on‑chain verified as of 2026‑09‑04 under the current constraints (no direct explorer/Dune inspection available).
  • Analytics and market pages (e.g., pool and volume statistics) confirm Slipstream pools such as CL‑prefixed pools (e.g., WETH‑AERO) exist on Base and are treated as distinct concentrated‑liquidity markets, but they do not reliably expose canonical core contract addresses. ### Fork lineage & code provenance
  • Aerodrome itself is described as a Solidly / Velodrome v2 fork with additional custom code for Slipstream CLMM.
  • Multiple independent sources state Slipstream is based on / a fork of Uniswap v3’s concentrated‑liquidity design, adapted so that:
  • Fee tiers are set at pool creation, not per‑LP.
  • Tick spacing is custom and often wider than standard Uniswap v3 ticks.
  • A custom fee algorithm and faster oracle updates are introduced.
  • One source notes Slipstream was developed by Velodrome and implemented on Aerodrome in 2024, reinforcing that this is a shared code lineage between the Velodrome and Aerodrome teams rather than an unrelated third‑party fork. ### Audits & malicious‑modification history
  • No direct primary audit report for Slipstream contracts surfaced; existing references describe it as custom code atop a Velodrome/Solidly fork and Uniswap v3‑style CLMM, but do not link audit PDFs or repositories.
  • Therefore: Not verifiable as of 2026‑09‑04 whether Slipstream’s modifications vs. upstream Uniswap v3 / Velodrome have been formally audited.
  • No independent evidence of malicious modifications or exploit history specific to Slipstream forks was found in the consulted material; this absence of evidence is not evidence of absence of risk.
Evidence (15)

maturity

two sources

Aerodrome Slipstream appears to be a real, live product portal rather than a static landing page: the main site presents itself as a Base DEX and the search results show references to liquidity provisioning, withdrawals, and LP-position management, which indicates functional app surfaces rather than pure marketing copy. I did not find verified evidence of broken core app flows or fake metrics from the available web results, so those are not verifiable as of 2026-09-04. User-facing functionality seems mature enough to support liquidity workflows: public docs/API references describe increase and withdraw LP-position operations on Base, and Base documentation also lists deposit/withdraw/stake/claim capabilities for Aerodrome-related liquidity actions.

That suggests live deposits/withdrawals are intended and exposed through application logic, not just documentation placeholders. On docs and UX, the presence of structured API-style documentation points to more than a simple landing page, but independent checks for navigation quality, broken links, and overall UX health are not verifiable as of 2026-09-04. One caution: some search results were clearly third-party or likely templated mirror pages, so they should not be treated as evidence about the official product.

Open API: yes, there is at least one public API-style surface documented for Slipstream liquidity operations, including increase/withdraw LP position endpoints with OpenAPI-like schema descriptions. Whether that is the protocol’s own public API or a third-party wrapper is not fully verifiable from the available evidence, so the safest conclusion is: a public API exists, but its official scope is not verifiable as of 2026-09-04.

Evidence (5)

Security

bug bounty

two sources

Aerodrome Finance shows an active bug bounty program listed via Immunefi; a security overview page also lists a current Immunefi bounty with a max payout of $100,000. The best-supported launch timing found is May 2024 for the program’s security bounty coverage on Immunefi, but the exact Aerodrome Slipstream-specific start date is not verifiable as of 2026-09-04. Public materials found do not provide a clearly documented results summary for Aerodrome Slipstream itself, so results are not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$100K
Since
2024-05
Evidence (4)

counterparty risks

one source

Scope: Base only. Dune MCP was unavailable; therefore on-chain balances, pool composition, bridge shares, and exposure percentages were not measured. Dependencies & counterparties

  • Core dependency: Slipstream depends directly on Aerodrome’s CL factories, routers, gauges, fee modules, voter/governance, and Base execution. Contract addresses are publicly documented, but upgrade/admin concentration and live balances were Not verifiable as of September 6, 2026. Aerodrome states its architecture inherits Velodrome V2 and has audits/bug bounty coverage; this is a protocol-sourced claim.
  • Oracle/manipulation: Slipstream pools maintain Uniswap-v3-style observations/TWAP data. Aerodrome documentation describes 30-minute TWAP protection for router pricing. Thin or newly created concentrated-liquidity pools remain vulnerable to price impact, liquidity withdrawal, and short-window manipulation; a single pool should not be treated as an independent robust oracle.
  • Bridges/custodians: Slipstream itself is non-custodial and does not custody reserves with a CEX, market maker, bridge, RWA issuer, or SPV. Risk is inherited from the assets actually deposited: bridged BTC/ETH, non-native stablecoins, LSTs/restaking tokens, and issuer-controlled tokens. Pool-by-pool composition and bridge share were Not verifiable as of September 6, 2026.
  • Stablecoin/LST failure scenarios: USDC/USDT/EURC depeg, issuer freeze/blacklisting, bridge compromise, cbBTC or other wrapped-asset custodian insolvency, or LST/restaking slashing/depeg can create asymmetric LP losses and impaired exits. Concentrated ranges can amplify losses because liquidity becomes inactive as price moves.
  • External routing: Aggregators may route through Aerodrome, but the previously listed Odos/1inch/OKX/ParaSwap support was not independently reconfirmed in this check; treat it as Not verifiable as of September 6, 2026.
  • Supply-chain alert: A malicious npm package impersonating @aerodrome-finance/slipstream was published in August 2026. This is an SDK/developer-environment risk, not evidence of an on-chain Slipstream exploit; integrations should pin verified GitHub releases and avoid the npm package. Contradiction / data gap: No reliable source supplied a protocol-wide maximum counterparty exposure. On-chain exposure wins by policy, but it was not measurable here. Structured fields:
  • dependency_failure_active: null
  • max_exposure_pct: null
Evidence (4)

crypto custody

one source

Aerodrome Slipstream on Base is organized as a non-custodial smart-contract protocol: users connect their own wallets, provide liquidity to pools, and interact with contracts rather than depositing assets with a third-party custodian. The available evidence supports standard self-custody for participants; however, there is also a separate staked-position custody flow for some integrations, where Revert’s GaugeManager contract takes custody of the staked LP position so rewards can be managed while the user retains withdrawal/control rights. There is no verifiable evidence from the gathered sources of an external qualified custodian, segregated custody accounts, or any special off-chain custody arrangement.

Withdrawal status for the protocol-wide setup is not verifiable as of 2026-09-06; a past bug affecting withdrawals from some Slipstream pools was reportedly fixed, but no current protocol-wide pause was verified. Segregated assets: not verifiable as of 2026-09-06.

Evidence (5)

incident

unverified

No specific post-launch incident for Aerodrome Slipstream was verifiable from the provided sources. The available sources only confirm that Aerodrome launched on August 28, 2023 and that Slipstream is a Base DEX/liquidity marketplace with market statistics; they do not document an exploit, outage, hack, governance attack, reimbursement, or remediation event for the protocol since launch.

Date
2023-08-28
Cause
Other
Evidence (3)

incident

one source

November 28–December 2, 2023, Base/frontend infrastructure — DNS/registrar takeover redirected aerodrome.finance to cloned phishing pages that induced users to approve asset transfers. Aerodrome’s incident report estimated potential user losses of up to 250,000 USD. The core AMM, multisigs and smart contracts were not compromised.

Domains were restored, attacker access and API keys were removed, domain infrastructure was locked and moved, and affected-wallet information was collected for mitigation. Recovery and reimbursement are not publicly verified as of September 6, 2026. The domain incident itself was resolved.

Date
2023-11-28
Cause
Frontend / infrastructure hack
Loss
$250K
Status
resolved
Event id
aerodrome-dns-phishing-2023-11-28
Evidence (2)

incident

two sources

November 21, 2025, Base/frontend infrastructure — DNS records for aerodrome.finance and velodrome.finance were hijacked and redirected to cloned phishing frontends containing Eleven Drainer code. Smart contracts and AMM logic were not compromised. Users who interacted with the malicious frontend outside Blockaid-integrated protection lost approximately 700,000 USD; Blockaid reported preventing approximately 3.5 million USD more.

Response included domain warnings, malicious-domain classification, nameserver replacement and migration to safer/decentralized access paths. Recovery and reimbursement are not publicly verified as of September 6, 2026. The incident is considered resolved at the infrastructure level.

Date
2025-11-21
Cause
Frontend / infrastructure hack
Loss
$700K
Attacker proceeds
$700K
Status
resolved
Event id
aerodrome-dns-drainer-2025-11-21
Evidence (2)

incident

two sources

I found no verified public incident specifically affecting Aerodrome Slipstream on Base in the retrieved sources. The only directly relevant hit was a later report about a suspected front-end/DNS hijack affecting Aerodrome Finance’s centralized domains, with no confirmed losses, no confirmed affected users, and no confirmed reimbursement or compensation program.

Date
2025-11-22
Cause
Frontend / infrastructure hack
Status
status unknown
Evidence (2)

incident

unverified

January 30, 2026, Base — adjacent Revert Finance lending integration using Aerodrome Slipstream LP NFTs, not Aerodrome’s core AMM contracts. A collateral-invariant failure allowed an attacker to withdraw liquidity from collateralized Slipstream positions while leaving the vault with undercollateralized NFTs. Affected component: Revert Aerodrome Lend vault.

Loss was 50,101.744193 USDC of Revert-owned capital; no third-party user funds were in the vault. The attacker’s proceeds were the borrowed USDC. Revert paused deposits and borrows, rebuilt the integration instead of patching it, added vault-enforced collateral checks, TWAP/slippage controls, exposure caps, and completed additional security review before relaunch.

Recovery is not publicly verified. Users were not affected and therefore no user reimbursement was required.

Date
2026-01-30
Cause
Smart-contract exploit
Loss
$50K
Attacker proceeds
$50K
Status
resolved
Reimbursed
No
Event id
aerodrome-revert-lend-2026-01-30
Evidence (2)

incident

one source

A separate result about Slipstream itself was a supply-chain/security listing for malicious code in an npm package name, but the snippet did not verify an exploited protocol incident, affected balances, or any reimbursement. As a result, it is not enough to establish a protocol-level incident record for this question.

Date
2026-08-29
Cause
Other
Status
status unknown
Evidence (1)

key management

one source

Aerodrome Slipstream’s key management is organized through a vote-escrow governance model rather than a single admin key. The protocol uses AERO as the utility token and veAERO as the governance NFT: users lock AERO to receive veAERO, and veAERO holders vote every seven days to direct AERO emissions across pools. The docs also say veAERO holders determine how streaming emissions are allocated, which means control over incentive routing is distributed to token operators rather than centralized in one party.

Operationally, Slipstream is split into functional modules: Core pool contracts, Periphery user interfaces, Gauge contracts for staking and reward distribution, Fee Management modules, and Governance contracts consisting of Voter, VotingEscrow, and Minter. In this structure, governance key decisions—especially emissions, voting power, and token minting—are handled by the governance layer, while day-to-day pool and fee logic sits in separate contracts. The strongest source-backed takeaway is that protocol control is organized around veAERO voting and governance contracts, not around externally managed treasury or operator keys.

However, specific multisig signers, emergency admin rights, or signer rotation policies are Not verifiable as of 2026-09-04 from the available sources.

Evidence (3)

smart-contract

two sources

Assessment date: September 6, 2026. Base only. Dune/on-chain verification was unavailable; therefore deployment-state claims are Not verifiable as of 2026-09-06. Addresses reported for Base Slipstream: CLFactory 0x5e7BB104d84c7CB9B682AaC2F3d509f5F406809A; pool implementation 0xeC8E5342B19977B4eF8892e02D8DAEcfa1315831; CLGaugeFactory 0xD30677bd8dd15132F251Cb54CbDA552d2A05Fb08; gauge implementation 0xF5601F95708256A118EF5971820327F362442D2d; NonfungiblePositionManager 0x827922686190790b37229fd06084350E74485b72; SwapRouter 0xBE6D8f0d05cC4be24d5167a3eF062215bE6D18a5. Exact deployment-to-source mapping is Not verifiable as of 2026-09-06. Architecture / upgradeability `` CLFactory ──CREATE2 EIP-1167 clone──> CLPool per pair/tick spacing CLGaugeFactory ──EIP-1167 clone──────> CLGauge per approved pool PositionManager ──calls──> CLPool SwapRouter ──────calls──> CLPool Voter/governance ──controls──> gauge creation/rewards ` The source uses OpenZeppelin Clones`, not Transparent/UUPS proxies.

Pool and gauge instances therefore have immutable implementation pointers after deployment; factory configuration remains mutable. Upgradeable: false for deployed instances by design; proxy-admin type: not applicable. Privileged controls

  • CLFactory owner: can add fee tiers and transfer ownership; separate swapFeeManager and unstakedFeeManager can replace fee modules. Swap fees are capped at 10%; unstaked-fee module output is capped at 100%.
  • CLGaugeFactory has separate emissionAdmin, notifyAdmin, gaugeStakeManager, and one-time owner-controlled NFT-manager initialization. These setters have no visible timelock or two-step transfer in source. Actual controlling addresses and delay: Not verifiable as of 2026-09-06.
  • No pool pause, emergency withdrawal, oracle setter, arbitrary token rescue, or admin drain function was found in reviewed source. Users can burn/decrease liquidity, collect, and withdraw staked NFTs permissionlessly subject to normal contract conditions. Worst case: compromised fee/emission roles could impose maximum fees, alter emissions/penalties, redirect gauge-collected fees, or disrupt incentives; direct confiscation of LP principal is not evident. A malicious governance-controlled gauge could freeze staking-related operations, but unstaked positions retain core exit paths. Audits: Slipstream has public Spearbit and ChainSecurity audit history, but whether current Base deployments equal audited commits is Not verifiable as of 2026-09-06.
Admin can drain
No
Upgradeable
No
Evidence (4)

audit

one source

Slipstream concentrated‑liquidity AMM contracts (mathematical soundness and implementation review).

Auditor
ABDK Consulting
Report date
2024-01-01
Scope
Slipstream concentrated‑liquidity contracts (Velodrome/Aerodrome fork). Bytecode-match to deployed Aerodrome Slipstream contracts on Base: Not verifiable as of 2026-09-04.
Findings
Referenced as an additional audit of Slipstream concentrated‑liquidity; public meta‑summaries do not expose individual issues or severity counts.[14]
Fix status
Summaries imply issues identified were addressed prior to production use, but there is no public per‑finding remediation grid; treat as unspecified.[14]
Evidence (1)

audit

two sources

Velodrome Superchain Slipstream extension (cross‑chain gauge accounting and interoperability layer related to Slipstream; upstream for Aerodrome Superchain rollout).

Auditor
ChainSecurity
Report date
2024-01-16
Scope
Superchain Slipstream extension and interoperability module (multi‑chain state consistency, Hyperlane integration, frontrunning resistance). Scope is **interop layer**, not the base Slipstream AMM pools on Base. Bytecode-match to currently deployed Aerodrome Slipstream pool contracts on Base: Not verifiable as of 2026-09-04.
Findings
Audit concludes “high level of security”; issues raised in cross‑chain accounting and interoperability were addressed, but individual severity counts are not detailed in public summary.[4][13]
Fix status
Audit page states raised issues were addressed; exact per‑severity remediation breakdown not publicly specified.[4][13]
Evidence (2)

audit

one source

ChainSecurity — “Code Assessment of the Superchain Slipstream Smart Contracts.” Published November 13, 2024. Scope covered Superchain Slipstream root/leaf pool and gauge contracts, including CLFactory, CLPool, Leaf/Root gauges and factories, NonfungiblePositionManager, cross-chain integration, address derivation, and gauge liquidity accounting. The report explicitly assessed specified source commits, not deployed Aerodrome Base bytecode.

Bytecode-match to Aerodrome Base deployment: Not verifiable as of September 5, 2026.

Auditor
ChainSecurity
Report date
2024-11-13
Scope
Superchain Slipstream root/leaf pools, gauges, factories, NFT position manager, and cross-chain integrations
Findings
Critical: 1 resolved — increaseLiquidity() for an NFT owned by a gauge breaks liquidity accounting. High: 1 resolved. Medium: 2 resolved, including createGauge gas-limit incompatibility. Low: 1 resolved. The report also lists informational findings and notes.
Fix status
The report records all listed critical, high, medium, and low findings as “Code Corrected.” Whether those corrections are present in the currently deployed Aerodrome Base contracts: Not verifiable as of September 5, 2026.
Evidence (2)

audit

two sources

Aerodrome’s own documentation states that its contracts were audited by Spearbit and ChainSecurity, but it does not provide the report-level breakdown requested. A third-party review page lists multiple Aerodrome-related reports, including ChainSecurity engagements in 2024, but it does not supply the full findings table needed to confirm critical/high/medium counts or fix status from the audit text itself. The key Bytecode-match question—whether the audit covered the exact deployed Base bytecode—cannot be verified from the provided sources; in a prior security note, the code-matching assumption is explicitly mentioned for a Slipstream deployment context, which reinforces that bytecode equivalence is a separate check.

Auditor
ChainSecurity
Report date
2024
Scope
Aerodrome / Slipstream related reports; exact report scope not fully verifiable from the provided sources
Evidence (3)

audit

one source

New report: ChainSecurity — “Code Assessment of the Superchain Interoperability Smart Contracts.” Published May 20, 2025. Scope covered Hyperlane messaging, root/leaf bridges, gauges, voting/reward synchronization, XERC20, gas routing, and related Superchain contracts; it was not a dedicated Aerodrome Slipstream AMM review. The report lists 0 critical, 2 high, 2 medium, and 8 low findings.

High and medium findings were corrected; low findings were split among corrected, risk-accepted, and acknowledged. Bytecode-match to Aerodrome Base: Not verifiable as of September 6, 2026.

Auditor
ChainSecurity
Report date
2025-05-20
Scope
Velodrome Superchain interoperability, bridges, Hyperlane messaging, gauges, voting/rewards, XERC20, and gas routing
Findings
Critical: 0; High: 2 corrected; Medium: 2 corrected; Low: 4 corrected, 3 risk accepted, 1 acknowledged.
Fix status
High and medium findings corrected. Three low findings risk accepted and one acknowledged. Aerodrome Base deployment coverage: Not verifiable as of September 6, 2026.
Report url
https://reports.chainsecurity.com/Velodrome/ChainSecurity_Velodrome_SuperchainInteroperability_Audit.pdf
Report id
doc:0fae4244ad0fde75
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected: Spearbit — “Slipstream & Universal Router” audit. Report published January 22, 2024; engagement completed December 5, 2023. Scope covered concentrated-liquidity core/periphery, staked-gauge and reward extensions, and Universal Router components.

Reported 0 critical, 6 high, 6 medium, 18 low, and 19 optimization/informational findings. Public follow-up material states the reviewed code was post-fix upstream; exact remediation of every finding and bytecode-match to Aerodrome Base remain unverified.

Auditor
Spearbit
Report date
2024-01-22
Scope
Slipstream concentrated-liquidity core/periphery, staked gauges and rewards, and Universal Router
Findings
Critical: 0; High: 6; Medium: 6; Low: 18; optimization/informational: 19. High findings were reported as fixed; some medium, low, and informational items were acknowledged.
Fix status
High findings reportedly fixed; remediation for all remaining findings and coverage of deployed Aerodrome Base bytecode: Not verifiable as of September 6, 2026.
Report url
https://velodromefinance.net/security/
Report id
doc:4de2d6e86f3241b3
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

two sources

New report: Sherlock — “Velodrome Superchain” collaborative audit. Audit period October 11–25, 2024; report published in November 2024. Scope covered Superchain interoperability, v2 pools, and gauges—not specifically Aerodrome Slipstream Base bytecode.

Public summaries report 0 high, 7 medium, and 7 low findings; all issues were fixed or acknowledged before launch. Exact per-finding remediation and Base bytecode-match: Not verifiable as of September 6, 2026.

Auditor
Sherlock
Report date
2024-11-01
Scope
Velodrome Superchain core interoperability, v2 pools, and gauges; not a dedicated Aerodrome Slipstream Base deployment review
Findings
Critical: 0; High: 0; Medium: 7; Low: 7; Informational: 0.
Fix status
Public summary states 100% of findings were fixed or acknowledged before launch; exact split and deployed-code coverage: Not verifiable as of September 6, 2026.
Report url
https://github.com/sherlock-protocol/sherlock-reports/blob/main/audits/2024.11.13%20-%20Final%20-%20Velodrome.pdf
Report id
doc:f0195bc6641752c5
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Aerodrome‑related asset modules and staked Slipstream periphery, not the core AMM itself.

Auditor
Sherlock (audit contest)
Report date
2024-06-01
Scope
Third‑party protocols (Arcadia) integrating with Aerodrome staked Slipstream and related wrappers. Does not cover Aerodrome Slipstream core AMM bytecode on Base. Bytecode-match: Not verifiable as of 2026-09-04.
Findings
Arcadia Finance security page reports a Sherlock audit contest on Aerodrome asset modules and follow‑on audits for “Aerodrome staked Slipstream, Autocompounder and Tranche Wrapper”; those are **integrations**, not the base Aerodrome Slipstream pools.[12]
Fix status
Arcadia notes findings from these contests/audits were addressed across their own integrations; fix status applies to Arcadia modules, not Aerodrome core. Treat as out‑of‑scope for core Slipstream risk.[12]
Evidence (1)

audit

two sources

Slipstream concentrated‑liquidity AMM (Velodrome/Aerodrome fork of Uniswap v3 core & periphery, including dynamic fees and staked‑liquidity accounting).

Auditor
Spearbit
Report date
2023-11-20
Scope
Velodrome/Aerodrome Slipstream AMM contracts plus universal router; fork of audited Uniswap v3 with modifications. Does not specifically attest to bytecode of current Aerodrome deployment on Base (Bytecode-match: Not verifiable as of 2026-09-04).
Findings
Security review covering Velodrome/Aerodrome Slipstream and related repos, reporting **49 findings**: 6 high (all fixed), 6 medium (4 fixed, 2 acknowledged), 18 low (13 fixed, 5 acknowledged), 10 informational (8 fixed, 2 acknowledged), 9 gas.[4][14]
Fix status
High: all fixed; Medium: majority fixed, remainder acknowledged; Low/Informational/Gas: mix of fixed and acknowledged.[4][14]
Evidence (2)

audit

one source

Aerodrome’s own documentation states that its contracts were audited by Spearbit and ChainSecurity, and it describes Slipstream as an immutable smart-contract AMM on Base. DefiLlama also lists Aerodrome Slipstream as having no audits recorded in its protocol directory, so the audit status is not consistently reflected across aggregators. Because I cannot verify the underlying report text here, the exact finding counts, remediation status, and whether the audit explicitly covered the deployed Base bytecode are not verifiable as of 2026-08-30.

Auditor
Spearbit
Report date
2024
Scope
Slipstream / Aerodrome protocol contracts; exact report scope not fully verifiable from the provided sources
Evidence (2)

audit

two sources

Slipstream formal‑verification work on core concentrated‑liquidity logic (Uniswap v3‑style).

Auditor
Trail of Bits
Report date
2024-01-01
Scope
Slipstream concentrated‑liquidity core for Velodrome/Aerodrome, focusing on correctness proofs for pricing and liquidity math. Bytecode-match: Not verifiable as of 2026-09-04 (no direct mapping between verified artifacts and current Base deployments found).
Findings
Described as formal verification engagement on Slipstream; public secondary sources report completion but do not enumerate specific findings or severities.[4][14]
Fix status
Public summaries indicate no outstanding critical/high issues after formal verification; detailed fix matrix not publicly available. Treat as partially specified.[4][14]
Evidence (2)

Team & Reputation

founders

two sources

Aerodrome Slipstream does not have a separately disclosed founding team; it is a product/contract set within the broader Aerodrome Finance protocol on Base, whose public information focuses on entities rather than named individuals. ### Founders & team

  • Public documentation describes Dromos Labs as the *core development team* and the Aerodrome Foundation as the protocol’s neutral steward, but does not name founders or executives for Slipstream specifically.
  • A third‑party “company overview” page lists Alexander Cutler and Tao Watts as co‑founders of “Aerodrome Finance,” but this attribution is *not* corroborated by Aerodrome’s own docs, governance, or major independent research, so it should be treated as an unverified marketing claim.
  • Media and ecosystem reviews characterize Aerodrome as a fork/evolution of Velodrome on Optimism, built by Dromos Labs, again without naming specific individuals. Reality check – identity & credibility
  • Public vs. anon: At the protocol/product level, Aerodrome and Slipstream have a clear public presence (docs, GitHub org, social channels), but founder identities are not independently verified across multiple reputable sources. Not verifiable as of 2026‑09‑04.
  • Track record / prior projects: Sources link Aerodrome to prior work on Velodrome and the Solidly/ve(3,3) model, implying experienced DeFi builders, but do not give personal bios, prior employment, or detailed founder histories. Not verifiable as of 2026‑09‑04.
  • Hacks or major incidents: No mainstream coverage of team‑related hacks, rug pulls, or fraud connected specifically to Aerodrome Slipstream surfaced in independent articles; this is *absence of evidence*, not proof of clean history. Not verifiable as of 2026‑09‑04. Organizational setup
  • Real business vs. web front: Aerodrome is structured around the Aerodrome Foundation and Dromos Labs, which suggests a formal organizational layer rather than a purely anonymous web app, but legal entity jurisdictions, registrations, and office addresses are not disclosed in the reviewed materials. Not verifiable as of 2026‑09‑04.
  • Onshore vs. offshore / physical office: No credible, independent disclosure of where the Foundation or Dromos Labs are incorporated, whether they hold physical offices, or their regulatory posture. Not verifiable as of 2026‑09‑04. For institutional risk purposes, treat Slipstream as a protocol feature of Aerodrome with partially disclosed entity structure and non‑verifiable individual founder identities, and adjust governance, key‑person, and legal‑jurisdiction risk assessments accordingly.
Evidence (7)

general reputation

two sources

Aerodrome Slipstream currently has a positive but still evolving reputation as Base’s main concentrated-liquidity DEX module, with no public fraud, rug, insolvency, or sanctions allegations identified as of 2026‑09‑04. Team, origins & investors

  • Slipstream is described as Aerodrome’s concentrated liquidity engine, derived from Uniswap v3 and integrated into the Velodrome‑style ve(3,3) stack on Base.
  • Aerodrome itself is attributed to Dromos Labs, the team behind Velodrome on Optimism, positioning it as Base’s “primary liquidity layer,” which lends reputational spillover from Velodrome’s established presence.
  • Independent writeups portray Aerodrome as the “dominant DEX on Base,” implying strong ecosystem support, though specific equity investors are not detailed in the retrieved sources. Audits, bug bounties, and security posture
  • A recent article reports Aerodrome launched a $400k public bug bounty contest with Sherlock’s Audit Engine ahead of an AERO upgrade, signaling proactive security and openness to external review.
  • Technical documentation and ecosystem explainers frame Slipstream as a Uniswap v3 fork with adaptations, which may benefit from prior scrutiny of the original design but also introduces its own risk surface.
  • No explicit, named audit report for Slipstream contracts was surfaced; therefore, detailed audit status is Not verifiable as of 2026‑09‑04. Sentiment, adoption, and criticisms
  • Multiple independent overviews describe Slipstream as “central concentrated-liquidity DEX on Base” with high capital efficiency and deep integration into veAERO governance, and note large TVL (≈$207M on Base) and high advertised APYs, which contribute to strong market perception.
  • Coverage highlights very high yields (e.g., >1,280% APY on some pools), which are attractive but also raise concerns about sustainability and mercenary liquidity; these are not framed as fraud but as economic risk.
  • Educational and technical content focuses on LP mechanics and risk of being out‑of‑range (idle capital, no fees), but does not document major exploits or systemic failures. Fraud, regulatory, and sanctions signals
  • No sources report fraud, rugpulls, insolvency, OFAC or other sanctions, or formal regulatory actions against Aerodrome or Slipstream as of 2026‑09‑04. Not verifiable as of 2026‑09‑04 for any hidden or non‑public proceedings. Unresolved concerns
  • Key gaps: lack of directly verifiable Slipstream‑specific audit reports; limited transparency on ultimate investors; and economic risks from extreme incentives and ve(3,3) governance dependence. These should be treated as open risk factors pending further due diligence.
Evidence (10)

Economy

TVL: $202.2M

model

one source

Economic model — Aerodrome Slipstream (Base)

  • Strategy/assets in: Concentrated-liquidity AMM. LPs deposit two pool assets (e.g., WETH/USDC, AERO/wstETH) into a selected tick range; each pool is defined by pair + tick spacing. Liquidity earns fees only while active/in-range.
  • Assets out/withdrawal: Position is an NFT. LPs can collect fees, unstake where applicable, then remove liquidity/burn the position; no protocol-wide fixed maturity. Narrow ranges create materially higher repositioning and out-of-range risk.
  • Yield source: (1) organic swap fees from trading volume; (2) AERO emissions and pool-specific voting incentives/bribes. Staked LPs generally receive emissions while fee flows are routed through gauge/voter accounting; unstaked positions may face a default 10% rake in emissions-eligible Slipstream pools.
  • Organic vs. subsidized: Fees are organic trading revenue; AERO emissions/incentives are subsidized/token-funded. organic_yield_pct: null — not reliably separable for the aggregate product from available data.
  • Risk profile: Directional market-making, not market-neutral. LPs bear impermanent loss, inventory conversion, token devaluation, and range-exit risk. No native lending loop, leverage, restaking, or external collateral exposure identified; inherent leverage is approximately 1.0x.
  • Lock-ups/gates/limits: Normal LP positions are not time-locked; active-range selection and gauge eligibility are the main constraints. veAERO governance locks are separate from LP liquidity.
  • Fees/revenue: Swap fee tiers vary by tick spacing and pool. Slipstream fees are economically distributed to LPs/voters through the veAERO gauge system rather than retained as a conventional treasury fee. 1mContradiction note: DefiLlama labels voter distributions “protocol revenue,” while Aerodrome disclosures describe 100% fee flow to veAERO voters; this is distribution revenue, not necessarily treasury profit. ([aerodrome.finance)
  • TVL/trend: DeFiLlama reports Slipstream TVL of $192.28m, entirely on Base, up 43.6% over 30 days; parent Aerodrome TVL is $323.01m, also 100% Base. Dune comparison: Not verifiable as of September 6, 2026.
  • APY sustainability: DefiLlama shows a product average supply APY of 2,841.68%, distorted by small/high-incentive pools; individual examples range from 0% to triple-digit APYs, with sharp 30-day changes. Treat headline APYs as highly volatile and predominantly incentive-sensitive, not durable organic yield.
Leverage ratio
1
Evidence (5)

reserves

one source

As of September 6, 2026, the prior finding is unchanged. Reserves / treasury: Not verifiable as of 2026-09-06. No Dune MCP was available in this run; therefore on-chain balances, reserve composition, USD valuation, and latest block/timestamp cannot be verified. No publicly confirmed Aerodrome Slipstream treasury/reserve wallet or dedicated reserve policy was identified.

Aggregator TVL and pool balances are liquidity-provider assets, not evidence of protocol-controlled reserves. Addresses and custody: Aerodrome publicly identifies an administrative Protocol Team multisig at 0xE6A41fE61E7a1996B59d508661e3f524d6A32075 and an Emergency Council multisig at 0x99249b10593fCa1Ae9DAE6D4819F1A6dae5C013D. These are disclosed as governance/emergency-control addresses, not treasury or reserve custody addresses; their asset balances and signing thresholds were not verified. Control: The documented permissions cover protocol administration, emissions, gauges, factories, and emergency actions. They do not establish ownership or control of a separate reserve portfolio.

Slipstream is a concentrated-liquidity venue; its contracts and positions should not be treated as treasury assets. Attestations / liabilities: No reserve attestation, proof-of-reserves report, audited treasury statement, or disclosed liabilities schedule was confirmed. Not verifiable as of 2026-09-06. Contradiction / classification: Any reported Aerodrome Slipstream TVL is an analytics-platform liquidity metric, not a reserve figure. No verified conflict between a claimed treasury balance and on-chain data can be assessed without Dune access.

Risk conclusion: reserve transparency is insufficient to assign a liquid-reserves value or assess reserve-backed liabilities.

Evidence (4)

tokenomics

one source

Aerodrome Slipstream is a product of the Aerodrome Finance ecosystem on Base, and does not have a separate native Slipstream token as of 2026‑09‑04. All tokenomics are therefore those of the core Aerodrome token AERO on Base. Because on‑chain queries are unavailable in this run, all on‑chain items below are Not verifiable as of 2026‑09‑04. ### Native token

  • Name/Ticker: Aerodrome AERO.
  • Chain: Base.
  • Main contract address (Base): Not verifiable as of 2026‑09‑04. ### Supply, market cap, FDV
  • Total/circulating supply, market cap and fully diluted valuation: typically reported by aggregators such as CoinGecko/DefiLlama, but exact values and real‑time correctness are Not verifiable as of 2026‑09‑04. ### Utility and governance According to Aerodrome documentation:
  • Utility: AERO is used for liquidity incentives and voting over pool emissions in a Solidly‑style ve(3,3) model (vote‑directed liquidity incentives).
  • Governance: AERO can be locked to obtain veAERO voting power over gauge weights, directing emissions to specific pools such as Slipstream concentrated‑liquidity pools.
  • Slipstream pools themselves do not introduce a new governance token; they are integrated into Aerodrome’s existing gauge/emissions system. ### Revenue share, buybacks, burns, staking
  • Aerodrome is designed so that protocol fees from pools are shared with veAERO voters and LPs via gauges and bribes, following the Solidly‑inspired model.
  • Any buyback, burn or explicit revenue‑sharing mechanics depend on Aerodrome’s broader tokenomics and are Not verifiable as of 2026‑09‑04 from on‑chain data. ### Emissions & unlocks
  • Aerodrome describes an ongoing emissions schedule that allocates AERO to liquidity providers and veAERO lockers via weekly gauge votes.
  • Precise emission rate, halving/decay rules, and whether specific unlocks/emission changes occurred on‑chain are Not verifiable as of 2026‑09‑04. ### Allocations & concentration
  • Detailed allocations to team, investors, treasury and community, top‑holder concentration, and identification of insider wallets are Not verifiable as of 2026‑09‑04. ### Control functions
  • Presence of mint, blacklist, or fee‑switch functions, and who controls them (EOA vs multisig) for AERO are Not verifiable as of 2026‑09‑04. ### DEX liquidity & listings
  • Slipstream pools are live on Aerodrome on Base, and act as concentrated‑liquidity markets for major assets (e.g., ETH, stablecoins), using AERO‑driven emissions.
  • Depth of AERO liquidity, specific base pairs, and their volumes across Base DEXs are Not verifiable as of 2026‑09‑04. Key risk note: Since Slipstream relies entirely on Aerodrome’s AERO tokenomics and governance, all token‑level risks (emission changes, governance capture, contract controls) are inherited from Aerodrome; granular, on‑chain verification is currently Not verifiable as of 2026‑09‑04.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Aerodrome Slipstream on Base, a Bitcoin drop below $10,000 would be a severe tail-risk macro shock, not a normal operating condition. In that scenario, the main risk is a broad risk-off selloff across crypto and DeFi: lower trading volumes, wider spreads, reduced LP incentives, and potential TVL contraction as capital de-risks from volatile pools. The literature you provided frames $10,000 BTC as a stress floor that would likely require a combination of global recession, liquidity crisis, regulatory shock, forced deleveraging, or other systemic stress—not a base-case outcome.

For Aerodrome Slipstream specifically, the likely transmission channels on Base would be:

  • Fee compression: lower on-chain activity usually means lower swap fees and reduced LP yield.
  • TVL decline: LPs may withdraw from concentrated liquidity positions faster than normal if impermanent loss expectations worsen.
  • Incentive dependence: if emissions or external incentives support APR, stress in token prices can make real yield look less attractive.
  • Stablecoin preference: liquidity may rotate from volatile pairs into stable-stable or stable-BTC pairs if users remain active on Base. What is not verifiable as of 2026-09-04 from the provided sources is the protocol’s current Base TVL, pool composition, treasury buffer, or any on-chain stress test specific to Aerodrome Slipstream. Without on-chain verification, I cannot quantify the drawdown, chain exposure, or liquidation risk for this protocol. Practically, the key question under a $10,000 BTC shock is whether Aerodrome Slipstream’s liquidity is concentrated in BTC-correlated pairs or mostly in stablecoin and non-BTC pairs. If the protocol is mainly stablecoin-directed, direct BTC price impact is likely indirect via market-wide risk aversion; if it has meaningful BTC-linked liquidity, the stress would be more immediate through volatility, LP rebalancing, and lower depth. That chain-specific exposure is Not verifiable as of 2026-09-04 from the available data. In short: a sub-$10,000 BTC environment would likely be a negative but survivable demand shock for Aerodrome Slipstream unless Base-wide liquidity and incentives were simultaneously impaired by broader crypto market stress.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

For Aerodrome Slipstream on Base, a 20% depeg in the largest collateral cannot be quantified from the provided sources. The search results do not include protocol-specific on-chain balances, collateral composition, or a reserve/collateral map for Slipstream, and the only directly relevant material is generic stress-testing methodology rather than Aerodrome data. Not verifiable as of 2026-09-04. What can be said from the available evidence is only methodological: stress tests typically revalue collateral under an adverse price move and then allocate the stressed value across positions or sections using margin exposure weights.

That does not tell us the loss size, bad debt, or user impact for Aerodrome Slipstream. To answer this properly, I would need protocol-specific data such as the largest collateral asset held in Slipstream, its share of total collateral, and the relevant liquidation or LP-valuation mechanics on Base. None of that is present in the provided sources, so any numeric estimate would be speculative.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Aerodrome Slipstream is a concentrated‑liquidity AMM on Base where counterparties are mainly LPs, traders, and protocol integrators using routes via Slipstream pools. Detailed on‑chain positions and specific pool compositions are Not verifiable as of 2026-09-04. Below are stylized stress paths for “top counterparty insolvent”, focusing on smart‑contract mechanics rather than balance‑sheet contagion. ### 1.

Large LP in a Slipstream pool becomes insolvent

  • Loss path: LP’s off‑chain insolvency does not affect the pool; only on‑chain positions matter. If the LP withdraws in panic, price impact and reduced depth increase slippage and impermanent loss for remaining LPs.
  • Who absorbs loss: Remaining LPs and price‑taking traders via worse execution; no central backstop.
  • Compensation: None at protocol level; losses are mechanical AMM outcomes.
  • Smart‑contract impact:
  • Liquidity removal via burn/withdraw functions; pool continues operating.
  • If the LP is a protocol using boosted gauges/bribes, gauge weights and emissions reallocate in subsequent epochs, changing reward flows but not state safety. ### 2. Major trader/arb bot using Slipstream routes insolvent
  • Loss path: Trader fails off‑chain but their on‑chain trades settle atomically per transaction. No partial settlement; insolvent status mainly reduces future volume.
  • Who absorbs loss: Trader’s own capital; pools are only affected by lower fee income and potentially less price alignment.
  • Compensation: None; AMM does not insure trader PnL.
  • Smart‑contract impact:
  • Fewer swaps through Slipstream pools; fee accrual to LPs declines.
  • No contract changes; open‑access swap functions remain. ### 3. Integrated protocol (e.g., a lending/structured product using Slipstream liquidity) insolvent
  • Loss path: If the protocol’s users’ deposits are routed into Slipstream LP positions, an upstream failure may trigger mass withdrawals or forced liquidations.
  • Who absorbs loss:
  • End‑users of that protocol bear losses from its mismanagement or bad debt.
  • Slipstream LPs bear normal price/LVR risk from unwind flows (adverse order flow).
  • Compensation: Depends on the failing protocol’s own mechanisms; Aerodrome/Slipstream provides no systemic insurance.
  • Smart‑contract impact path:
  • Elevated swap volumes and rebalancing through Slipstream pools; possible temporary price dislocations.
  • Gauge/bribe emissions adjust over time as TVL and voting change; no special handling for insolvency. ### 4. Governance / AERO token counterparty stress
  • If a major AERO holder or bribing entity fails, vote weights and bribe flows can shift sharply.
  • Impact is on emissions distribution, not pool solvency; contracts continue as coded. Overall, insolvency is borne by the failing entity and its stakeholders; Slipstream contracts remain solvent by design, with risk transmitted only via prices, liquidity depth, and emissions flows, not via shared balance‑sheet obligations.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For Aerodrome Slipstream on Base, I could not verify any committed fraud by the DAO or its owners from the provided sources. The search results are generic DAO-fraud references and do not establish that this specific protocol has committed fraud, been subject to a governance theft, or had owner-controlled misappropriation. On the evidence available, the correct stress-scenario treatment is: Not verifiable as of 2026-09-04.

If you need a risk framing for underwriting, the relevant fraud scenario to model is governance or admin-key abuse: malicious proposals, concentrated voting power, treasury diversion, privileged contract changes, or custody of upgrade/admin rights by insiders. That scenario is a standard DAO risk pattern described in the literature, but it is not evidence that Aerodrome Slipstream has actually done so. Because on-chain verification is unavailable in this run, I cannot confirm the protocol’s Base-chain control structure, treasury paths, or whether any owner/admin privileges remain capable of enabling fraud.

Any claim about actual fraud here would be unsupported.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For Aerodrome Slipstream on Base, a negative 30d primary yield source is not verifiable as of 2026-09-04 from the provided search results. The results only show generic definitions of stress scenarios and yield stress, not protocol-specific 30-day yield composition, pool-level emissions, or on-chain revenue/yield attribution for Aerodrome Slipstream. In this stress scenario, the conservative treatment is to assume the primary yield source contributes 0 or negative net yield after fees/slippage until a protocol-specific source breakdown is independently verified.

However, that inference is not an on-chain verified metric and should be treated as an analytical placeholder, not a confirmed finding. What can be said with confidence is limited to the methodology: a stress scenario is intended to show adverse performance outcomes, and a negative result is conceptually consistent with stress testing frameworks. For the protocol-specific question you asked, the missing pieces are the actual 30-day primary yield data, the relevant Base deployment addresses, and source attribution for Aerodrome Slipstream.

Not verifiable as of 2026-09-04.

Evidence (5)

Governance & Legal

governance

one source

As of September 13, 2026, Slipstream uses Aerodrome Finance’s shared Base governance stack rather than a separate Slipstream DAO. veAERO/veNFT holders vote through ProtocolGovernor for protocol-level decisions; EpochGovernor handles only tail-emission adjustments, with one proposal per epoch, simple-majority voting, and no quorum or proposal threshold. Approved epoch changes execute in the following epoch. Control is hybrid, not fully decentralized: the Protocol Team multisig controls fee management, pausing, FactoryRegistry ownership, team roles, and initially governor roles.

FactoryRegistry ownership can approve new pool/gauge/reward-factory implementations, creating indirect upgrade or integration risk. A Vetoer can veto governance proposals, while the EmergencyCouncil can kill/revive gauges and alter pool identifiers. These powers are material, although the documented roles do not directly transfer existing user pool reserves.

DAO assessment: token-holder governance is substantive for emissions, pool/gauge governance, and certain protocol parameters, but company/team and emergency permissions remain significant. Under the requested strict definition—token holders must control parameters and upgrades—dao_governance is false. Frontend deployment/control and the independence of development personnel are Not verifiable as of September 13, 2026.

Voting concentration and top holders via Dune are Not verifiable as of September 13, 2026; Dune was unavailable for this review. The prior finding that a timelock exists remains unchanged, but the delay is Not verifiable as of September 13, 2026. Multisig signer count, threshold, and signer independence are Not verifiable as of September 13, 2026.

The official disclosure identifies Aerodrome Foundation, an exempted limited guarantee foundation company in the Cayman Islands, registered August 18, 2023; identifier 402557; management body Glenn Kennedy and Sean Inggs. It also states the Foundation retained 95 million AERO and receives 5% of weekly emissions—an issuer disclosure, not an on-chain-verified holding.

Timelock
Yes
Admin can drain
No
Emergency bypass
Yes
Dao governance
No
Evidence (4)

legal & regulatory

two sources

Aerodrome Slipstream appears to be a concentrated‑liquidity DEX module within the Aerodrome Finance ecosystem on the Base L2 network, not a standalone corporate entity. All available descriptions treat Slipstream as a product/feature of Aerodrome Finance (“concentrated liquidity arm,” “module,” “feature”) rather than a separate legal vehicle. Entity & jurisdiction

  • Public sources consistently link Slipstream to Aerodrome Finance, a ve(3,3) DEX deployed on Base (an Ethereum L2 launched by Coinbase).
  • None of the retrieved materials provide a registered company name, corporate domicile, or regulatory license for Aerodrome or Slipstream. This includes independent explainers (DeepWiki, IQ.wiki, DeFi Explained, Exponential, DeFiLlama) and ecosystem reviews.
  • As of 2026‑09‑04, the precise legal entity and jurisdiction are Not verifiable as of 2026‑09‑04. Terms of service, user restrictions, KYC/AML
  • How to use Slipstream is described in purely technical DeFi terms: connect a wallet on Base, select a pool, provide liquidity, earn fees/emissions.
  • No source in the dataset reproduces or links to a formal Terms of Use, user eligibility rules (e.g., U.S. persons, OFAC jurisdictions), or any KYC/AML framework (e.g., customer due diligence, sanctions screening, transaction monitoring).
  • Therefore, the presence or absence of KYC/AML and specific geographic restrictions is Not verifiable as of 2026‑09‑04. Regulatory classification & treatment
  • Slipstream is consistently characterized as a decentralized exchange / concentrated‑liquidity AMM on Base, functionally similar to or forked from Uniswap v3, integrated with veAERO governance and emissions.
  • These are technical descriptions, not regulatory classifications (e.g., MTF, ATS, crypto‑asset service provider). No source asserts that Aerodrome/Slipstream is licensed, registered, or supervised by any financial regulator.
  • Any classification as a "DEX" or "DeFi protocol" is market convention, not a legal status. Warnings, enforcement actions, court cases, sanctions, data protection
  • No independent source in the retrieved set reports:
  • Formal regulatory warnings or enforcement actions targeting Aerodrome Finance or Slipstream.
  • Court cases or litigation involving the protocol or team.
  • The protocol itself being listed on any sanctions list.
  • A documented data‑protection/privacy policy (beyond standard wallet‑based DeFi UX).
  • For institutional risk purposes this should be treated as:
  • active_enforcement: false/unknown (no public record found; not verifiable as of 2026‑09‑04).
  • sanctioned: false/unknown (no evidence of the protocol/entity being sanctioned; not verifiable as of 2026‑09‑04). Legal structure vs. actual risk (DeFi lens)
  • Functionally, Slipstream is a non‑custodial smart‑contract DEX on Base, enabling swaps and liquidity provision with veAERO‑driven emissions and fee routing.
  • In the absence of visible licensing, clear corporate identity, or ToS/KYC, institutional users should treat exposure as protocol‑level/on‑chain risk:
  • Smart‑contract and economic‑design risk (fork of Uniswap v3 + custom fee/emissions logic).
  • Governance risk via veAERO voters controlling parameters and emissions.
  • Potential future regulatory re‑classification of DEXs on L2s, particularly given Base’s association with Coinbase. Given current public information, Aerodrome Slipstream should be modeled as a DeFi DEX module with opaque legal entity and jurisdiction, no verifiable compliance perimeter, and no publicly known direct regulatory actions as of 2026‑09‑04.
Evidence (9)

legal registries

two sources

No exact GLEIF LEI record for 'Aerodrome Slipstream'. OFAC SDN screening of 'Aerodrome Slipstream': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Aerodrome Slipstream
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Aerodrome Slipstream does not appear to issue its own stablecoin; the protocol is a Base DEX/concentrated-liquidity venue and the stable pairs referenced in available web evidence are third-party assets such as USDC, USDT, EURC, and USDS, not a native Aerodrome coin. A stablecoin depeg for the stablecoin(s) used is not verifiable as of 2026-09-06, so depeg_count, last_depeg_date, and max_depeg_pct remain unknown. own_stablecoin is false; stable, depeg_count, max_depeg_pct, and last_depeg_date are not verifiable as of 2026-09-06.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

two sources

Aerodrome Slipstream’s principal risks are concentrated in smart-contract complexity, privileged emergency controls, concentrated-liquidity economics, emissions dependence, and Base infrastructure reliance. Slipstream has undergone audits and maintains a bounty program, but audits do not eliminate residual exploit risk; on-chain TVL, exposure, and chain allocation are Not verifiable as of September 5, 2026 because Dune was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract accounting failureSlipstream combines Uniswap V3-style swap mathematics with NFT positions, gauges, staked-liquidity accounting, and reward accumulators. Prior audit material identified high-severity classes involving reward rollover, gauge-pool validation, and tick bookkeeping; a regression could misprice swaps, misallocate rewards, or lock/lose funds.HighMediumOpen-source code, invariant testing, Spearbit/ChainSecurity review history, and an Immunefi bounty are in place.High-impact unknowns remain after code changes, upgrades, and integrations.
Privileged emergency controlsThe emergency council can change the emergency council, kill or revive gauges, and modify pool metadata, creating governance and operational-centralization risk.HighMediumCouncil powers are publicly documented and intended for emergencies or governance-authorized actions.Medium; authority concentration and response discretion remain.
Concentrated-liquidity impairmentLP capital is active only within selected price ranges; sharp moves can push positions out of range, create one-sided inventory, increase impermanent loss, and leave thin active liquidity vulnerable to price impact or manipulation.HighHighUsers choose ranges, fees, slippage limits, and deadlines; the design is based on established V3 mechanics.High for volatile or thinly traded pools.
Emission and governance reflexivityIf AERO demand, trading fees, or voter participation weaken, incentive value can fall, liquidity can migrate, and LP returns may become dependent on token emissions rather than organic volume.MediumMediumveAERO voting directs incentives and trading fees provide a non-emission revenue component. This mechanism is partly an unverified marketing claim when sourced from protocol materials.Medium to High during prolonged low-volume or falling-token-price periods.
Base sequencer dependencySlipstream is deployed on Base; sequencer or block-production failures can temporarily halt swaps, liquidations, rebalancing, and withdrawals, while stale execution conditions may worsen slippage. Base experienced two block-production outages in June 2026.MediumMediumBase publishes incident postmortems and status information; users can apply transaction deadlines and slippage limits.Medium; protocol users remain exposed to Base availability and ordering risk.
Evidence (5)

strengths

two sources

Aerodrome Slipstream’s top strengths are capital-efficient concentrated liquidity, lower slippage on active pairs, stronger LP economics through fee/reward design, better execution for traders via smart routing and optimized pools, and Base-native scalability with low fees and fast settlement. Slipstream is described as a concentrated-liquidity module derived from Uniswap V3, letting LPs deploy capital in specific price ranges rather than across the full curve, which improves efficiency. Multiple sources also say this model reduces slippage and improves execution for large or active trades, especially on high-volume pairs.

The protocol’s incentive structure is presented as attracting deeper liquidity and aligning LP rewards with active market demand, which can strengthen market depth over time. Aerodrome is positioned as the trading and liquidity hub of Base, so it benefits from the chain’s low transaction costs and fast finality relative to Ethereum mainnet.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 24 two independent sources, 16 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-30.