Benqi Lending

Orange · 65/100

Executive summary

Benqi Lending is an Avalanche-native, non-custodial lending and borrowing protocol launched August 2021, scoring 69/100 (orange band) with high data confidence (86/100).

  • Security: Multiple audits from Halborn (2021), Certora (2022), Dedaub (2023), Zellic (2025), and Cyfrin (2024); Halborn's 2021 core audit found 0 critical/high issues, 1 medium (accepted risk), 5 low; Halborn's 2022 liquid staking audit reported 4 critical and 1 high (all resolved); current deployed-code match and unresolved findings are not verifiable as of September 2026; active $500k Immunefi bug bounty since August 2021.
  • Incidents: May 2026 oracle security event (nation-state threat to Chaos Labs keys) resulted in precautionary market pause and switch to Chainlink-only feeds for core markets; no user funds lost or positions affected; no confirmed exploits or hacks in protocol history.
  • Governance & custody: Not DAO-controlled; Core Team (Decentralised Research Technologies Inc./Decentralized Technology Foundation) adjusts lending parameters; non-custodial user deposits; admin can upgrade Comptroller implementation without timelock (admin_can_drain: true); multisig details, signer identities, and thresholds not verifiable as of September 2026.
  • Top risks: Smart-contract exploit (high impact, medium probability; audit coverage incomplete for current code); oracle failure/manipulation (dual Chaos Labs + Chainlink dependency; May 2026 incident demonstrates real threat); collateral depeg (sAVAX and bridged assets introduce LST, bridge, and issuer risk); admin upgrade risk (no timelock, opaque multisig); large cohort of loans within 5% of liquidation (Yahoo Finance, $55M reported) increases cascade risk under stress.
  • Strengths: Avalanche-native with low fees and fast finality; integrated liquid staking (sAVAX) and broad product suite; public, non-anonymous team (JD Gagnon, Dan Mgbor, Hannu Kuusi); mature 2021 launch with no bad-debt events; extensive audit history; AA rating from DeFi Sentinel (81/100 safety score); clear UX for borrower health monitoring.
  • Unverified: Current deployed bytecode match to audited commits; circulating QI supply, market cap, FDV, and emissions schedule; treasury custody, reserve policy, and on-chain balances (DeFiLlama reports $6.54M treasury, $32.43M loans, but not verified); top-holder and voting concentration; exact liquidation thresholds and collateral exposure; KYC/AML requirements and legal entity structure.
  • Recommended exposure: Conservative allocation only; limit to <5% of DeFi portfolio given orange score and admin upgrade risk; prefer Core Markets over Ecosystem Markets (Chainlink-only oracle post-May 2026 incident); avoid positions near liquidation threshold given reported concentration of high-risk loans; monitor sAVAX depeg risk if using as collateral; verify current audit coverage and multisig transparency before larger commitments.
  • Open questions: Verify current Comptroller implementation matches audited code; confirm multisig signers, threshold, and timelock for upgrades; obtain on-chain reserve and liability snapshot; clarify QI circulating supply and treasury controls; assess live collateral composition and loans near liquidation; confirm oracle failover logic and Chaos Labs key rotation post-May 2026; verify legal entity, jurisdiction, and any regulatory engagement.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 13 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2025-05-09 is older than a year
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 1 0.2 TVL $93,283,128 = 1% of reference ($17,538,184,136)
Data confidence 86 7/7 critical categories; 13/42 verified facts; 42/42 fresh (180d)

Identification

protocol identification

two sources

Benqi Lending (BENQI Markets / BENQI Liquidity Market) is a non-custodial lending and borrowing protocol on Avalanche. Its website is benqi.fi and its documentation is docs.benqi.fi; the docs describe BENQI Markets as the lending/borrowing product, and third-party sources also describe BENQI as an Avalanche-based lending protocol. The protocol launched on 19 August 2021 on Avalanche, with multiple independent sources repeating that launch date.

The native token is QI. Main contract addresses that were directly surfaced in the docs include 0x8729438EB15e2C8B576fCc6AeCdA6A148776C0F5 and 0x2b2C81e08f1Af8835a78Bb2A90AE924ACE0eA4bE; the docs page is the primary source here, while a separate analytics source independently echoes the BENQI address in abbreviated form. Because on-chain verification is unavailable in this run, explorer verification status is Not verifiable as of 2026-09-04. | Item | Status | |---|---| | Category | Lending / borrowing, liquidity market | | Chains | Avalanche | | Native token | QI | | Website / docs | benqi.fi / docs.benqi.fi | | Launch date | 19 Aug 2021 | | Main contract addresses | 0x8729…C0F5; 0x2b2C…4bE | | Explorer verification | Not verifiable as of 2026-09-04 | Benqi Lending appears to be a fork-lineage protocol, but the exact upstream lineage, code-delta, and audit trail for those changes are Not verifiable as of 2026-09-04 in this run.

What can be stated from the available evidence is that BENQI launched as an Avalanche-native liquidity market protocol and later expanded into a broader DeFi suite. Malicious-modification history in similar forks is therefore also Not verifiable as of 2026-09-04 without direct audit/fork-source review.

Evidence (8)

maturity

two sources

BENQI Lending appears to have a real, functional app rather than a mere landing page: the main site routes users to an app portal, and the docs describe active lending/borrowing flows on Avalanche C-Chain. The docs also indicate live protocol operations, including supply, borrow, withdraw, and liquidations, and a developer FAQ states BENQI does not expose a general data-fetching API; historical data comes from a subgraph and real-time data from smart contracts. This means there is no public open API for general data access, at least per the docs.

Signals of maturity are solid but not fully clean: the docs and app pages are substantial, and external integrations reference concrete deposit/withdraw methods, but one result is a likely clone/phishing-style domain with similar branding, which should not be treated as authoritative. A direct contradiction also exists between the protocol docs claiming no API and some third-party agent integrations exposing BENQI endpoints; those are not BENQI’s own open API and do not establish an official public API. On UX quality, the docs look organized and product-specific, with clear Avalanche focus and market separation, but not all claims can be independently verified here.

Broken links, fake metrics, and template signs are not verifiable as of 2026-09-04.

Evidence (4)

Security

bug bounty

unverified

BENQI has an active bug bounty program on Immunefi. It is live since 19 August 2021, with a maximum bounty of $500,000. Scope includes smart contracts and websites/apps; reports require a proof of concept, and smart contract payouts are generally based on impact, with critical findings capped at 10% of funds directly affected up to $500,000.

Payouts are handled by the BENQI team and denominated in USD, with USDC/USDT for high-level reports and some rewards potentially paid partly in QI. Public program pages do not disclose a total results figure, so results are Not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$500K
Since
2021-08-19
Evidence (3)

counterparty risks

unverified

Assessment date: September 6, 2026. Chain: Avalanche only. Dependencies and counterparty risks

  • Oracles: The prior finding is outdated/incomplete. BENQI documentation now describes a dual-oracle model: Chaos Labs Edge/Chaos Oracles as primary and Chainlink as secondary, covering AVAX, sAVAX, stablecoins, BTC.b, WETH.e, DAI.e, WBTC.e and other listed assets. Oracle outage, stale data, configuration error, or manipulation could cause incorrect collateral valuation, liquidations, or bad debt. The protocol’s dependence is therefore concentrated across two external oracle providers rather than Chainlink alone. Official documentation is stale (>7 days).
  • LST / staking dependency: Lending exposure to sAVAX imports BENQI Liquid Staking risk: validator performance, P-Chain/C-Chain operational bridging, redemption delays, smart-contract failure, and sAVAX/AVAX secondary-market depeg. Official documentation states a 15-day redemption cooldown and reliance on MPC-secured movement to the P-Chain.
  • Bridged and external assets: Listed markets include BTC.b, WETH.e, DAI.e, WBTC.e and other wrapped/bridged assets, creating dependence on bridge security, issuer backing, and liquidity. Avalanche states its Bridge requires 6-of-8 bridge-node cooperation; failure or compromise could impair collateral value or redemptions.
  • Stablecoins / issuers: USDC, USDT, DAI.e and AUSD introduce Circle, Tether, Maker/DAI, and Agora issuer, reserve, freeze, depeg, and liquidity risks. Isolated markets restrict borrowing to USDC, which reduces contagion but concentrates repayment liquidity in USDC.
  • RWA, custodians, CEX/MM: BENQI documentation references RWA pools, but issuer/SPV, custodian, legal-claim, market-maker, and CEX exposures are not sufficiently identified in reviewed sources. Not verifiable as of September 6, 2026. > Contradiction / update: Earlier records characterized Chainlink as the core oracle dependency. Current BENQI documentation identifies Chaos as primary and Chainlink as secondary; this is a material dependency-map change. Exact market-by-market exposure percentages cannot be established without on-chain verification. Failure scenarios: oracle outage/manipulation; sAVAX depeg or redemption halt; bridge or wrapped-asset failure; stablecoin freeze/depeg; thin liquidity causing liquidation shortfalls; RWA issuer/SPV default. Structured fields:
  • dependency_failure_active: null — Not verifiable as of September 6, 2026.
  • max_exposure_pct: null — Not verifiable as of September 6, 2026.
Evidence (5)

crypto custody

two sources

BENQI Lending is organized as a non-custodial protocol on Avalanche: users supply assets to smart contracts, keep control of their private keys in their own wallet, and receive interest-bearing positions while the protocol routes lending, borrowing, interest accrual, and liquidations. The available evidence does not show BENQI taking direct possession of user crypto custody; instead, assets remain under smart-contract control, which is the standard DeFi model described by BENQI and third-party summaries. The protocol docs also note risk controls that can pause markets or redemptions, but I could not verify any current withdrawal suspension.

Segregated asset treatment is not verifiable as of 2026-09-06.

Withdrawal paused
No
Evidence (3)

incident

one source

Bug bounty: BENQI has a live Immunefi bug bounty program, listed as live since 19 August 2021 and last updated 05 August 2026. The available result does not show payout terms or historical bounty payouts.

Date
2021-08-19
Cause
Other
Evidence (1)

incident

one source

On May 4, 2026, Chaos Labs alerted BENQI to a potential nation-state-level attack targeting Chaos Labs oracle infrastructure and keys used by BENQI markets. No malicious price was reported as reaching BENQI, and no user positions or protocol funds were affected. BENQI switched the Core Market, representing most TVL, to Chainlink-only feeds; fully paused Ecosystem Markets using Chaos Edge Oracle; allowed users to repay and withdraw; and temporarily disabled new borrowing in paused markets.

Chaos Labs rotated affected keys within 48 hours. BENQI reported normal Core Market operation and began evaluating additional oracle-provider diversification. No user reimbursement was required or reported.

Current status: resolved, with additional oracle diversification as ongoing hardening. On-chain verification: Not verifiable as of September 6, 2026.

Date
2026-05-04
Cause
Oracle manipulation
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$0
Reimbursed
No
Event id
benqi-oracle-security-incident-2026-05-04
Evidence (3)

incident

one source

The available sources do not establish any separate user-loss reimbursement event for BENQI Lending. The only described 2026 response was operational containment: switching core markets to Chainlink-only feeds, pausing ecosystem markets, and later noting key rotation and plans for additional oracle diversification.

Date
2026-05-08
Cause
Oracle manipulation
Loss
$0
Evidence (2)

incident

two sources

No on-chain-verified exploit or loss incident could be confirmed from the available web results for BENQI Lending on Avalanche; third-party summaries state there have been no recorded hacks/exploits, but this is not a raw-chain verification. The May 2026 oracle-security event appears to have been a precautionary market pause/switch to Chainlink-only feeds rather than a user-fund loss incident.

Date
2026-05-08
Cause
Other
Loss
$0
Evidence (2)

key management

two sources

Key management is organized primarily through a decentralized, non-custodial smart-contract model rather than a protocol-controlled custody system. BENQI’s lending markets are described as operating via smart contracts with no human intermediaries, and users interact by supplying collateral and borrowing directly from the protocol. For governance, QI token holders can propose and vote on protocol changes, which means administrative control is distributed to token holders rather than held by a single operator. The protocol’s docs also describe BENQI Miles as the voting layer for Node Voting, where stakers direct AVAX delegation to validators; this applies to the Miles Pool and not the Open Pool.

From a cryptographic perspective, BENQI does not appear to run its own key system; it inherits Avalanche C-Chain’s standard wallet signing model, where users control their own private keys to authorize transactions. That means operational key management is user-side self-custody, while protocol-level permissions are handled through smart contracts and governance tokens. What is not verifiable as of 2026-09-04 from the available sources is any formal description of BENQI’s internal multisig setup, emergency admin keys, timelock design, or signer rotation policy.

The web sources confirm decentralized governance and non-custodial execution, but they do not provide enough evidence to map the protocol’s internal key-holder structure beyond that.

Evidence (10)

smart-contract

unverified

Scope/as-of: Avalanche C-Chain; on-chain admin state, proxy-admin identity, event history, timelock delay, and role renunciation are Not verifiable as of September 6, 2026 because Dune MCP was unavailable. Addresses (core markets): Comptroller/Unitroller proxy 0x486Af39519B4Dc9a7fCcd318217352830E8AD9b4; qiAVAX 0x5C0401e81Bc07Ca70fAD469b451682c0d747Ef1c; qisAVAX 0xF362feA9659cf036792c9cb02f8ff8198E21B4cB; qiBTC.b 0x89a415b3D20098E6A6C8f7a59001C67BD3129821; qiETH 0x334AD834Cd4481BB02d09615E7c11a00579A7909; qiLINK 0x4e9f683A27a6BdAD3FC2764003759277e93696e6. Isolated markets use Comptroller 0xfc8C7271BdC3816D7AB1fc802216bad387692Ce1 and Unitroller 0xD7c4006d33DA2A0A8525791ed212bbCD7Aca763F. Architecture: Users → QiToken market contracts → Comptroller/Unitroller → delegated Comptroller implementation → oracle and risk parameters. ``text User ├─ supply/borrow/redeem ─> QiToken (per asset) │ └─ admin: reserve, comptroller, rate-model controls └─ risk checks ───────────> Unitroller proxy └─ admin-controlled Comptroller implementation ├─ oracle ├─ collateral factors/liquidation parameters ├─ market listing/borrow caps └─ pause guardian ` Upgradeability/admin risk: The Unitroller stores admin, pendingAdmin, comptrollerImplementation, and pendingComptrollerImplementation; upgrades are a two-step _setPendingImplementation/_acceptImplementation` flow with no timelock visible in the reviewed code. The implementation can change oracle, collateral factors, liquidation incentive, market listings, borrow caps, pause guardians, and pause mint/borrow/transfer/seize.

QiToken contracts separately expose admin-controlled comptroller, reserve-factor, interest-rate-model, protocol-seize-share, and reserve-reduction functions. Exitability: Normal users can redeem underlying subject to liquidity and solvency checks; the pause design explicitly leaves user asset-removal actions unpausable in the storage comments. However, compromised governance can upgrade the Comptroller to permit unsafe borrowing or alter oracle/risk logic, potentially exhausting market cash. Direct reserve withdrawal is limited to recorded reserves, not all deposits. Audit: Halborn audited the 2021 lending codebase, but exact audit-to-current-deployment correspondence and unresolved finding status are Not verifiable as of September 6, 2026. Risk conclusion: High centralization and upgrade risk; meaningful freeze/rug-by-implementation risk.

No evidence here confirms a timelock, multisig, renounced roles, or an on-chain delay.

Admin can drain
Yes
Upgradeable
Yes
Evidence (7)

audit

one source

Certora issued an audit/formal verification report for BENQI’s Liquid Staking system. The report says the verification work ran from March 14, 2022 to April 14, 2022, and that the code delivered on February 23, 2022 was verified; scope is the StakedAvax contract. The search result confirms formal verification coverage, but the current result snippet does not provide a full critical/high/medium finding list or remediation status, so those are Not verifiable as of 2026-08-29 from the provided results alone.

The delivered-code reference is the available bytecode/code-match note in the source.

Auditor
Certora
Report date
2022-03-14
Scope
Liquid Staking system; StakedAvax contract
Evidence (1)

audit

one source

Formal verification report for BENQI Liquid Staking (sAVAX) system, specifically the StakedAvax contract.

Auditor
Certora
Report date
2022-04-14
Scope
BENQI Liquid Staking system on Avalanche, defined in the StakedAvax (sAVAX) smart contract.[10]
Findings
Certora states the implementation of the StakedAvax contract is "correct with respect to the formal rules" written by Certora.[10] No explicit critical/high/medium bug list is presented in the summary; the focus is on proving adherence to specified invariants and rules.[10]
Fix status
Report describes a verified version of the StakedAvax contract as of February 23, 2022 delivery.[10] Any later code changes or deployment bytecode alignment to Avalanche: Not verifiable as of 2026-09-04.
Evidence (2)

audit

one source

Dedaub audited BENQI Ignite on March 28, 2023. The report states that it covered the private repository BENQI-fi/ignite-contracts at commit 498242b800b07230e81cacb6932c217ba3d07d05, and also reviewed parts of BENQI-fi/veqi at commit 1b108ea24f65790b279c1b843056611a1d432965, specifically the deposit() and withdraw() functions of VeQi.sol. The report lists no critical findings and one high-severity issue, 'Missing data structure update in _deleteRegistration leaves records in an unusable state,' marked resolved.

The report also notes the audit reviewed the deployed code at the referenced commits, which is the closest available bytecode/code-match evidence in the provided sources.

Auditor
Dedaub
Report date
2023-03-28
Scope
BENQI Ignite contracts; ignite-contracts commit 498242b8... and veqi commit 1b108ea2...
Evidence (1)

audit

one source

Benqi Oracle / Dual Oracle Security Assessment.

Auditor
Zellic
Report date
2025-05-13
Scope
BenqiDualOracle.sol and BenqiPriceOracle.sol; source commit 78f10c08; Avalanche oracle logic used for BENQI lending risk management.
Findings
0 critical, 0 high, 1 medium, 1 low. Medium: feed-price validation bypass. Low: missing whitelist check.
Fix status
Remediation status and current deployed-bytecode match: Not verifiable as of 2026-09-06.
Report url
https://reports.zellic.io/publications/benqi-oracle/
Report id
doc:717c7519247ccd7a
Covers deployed code
No
Evidence (1)

audit

one source

BENQI Liquidity Market Smart Contract Security Audit, v1.1.

Auditor
Halborn
Report date
2021-06-17
Scope
Core Avalanche lending/borrowing contracts: Comptroller, QiToken, interest-rate models, oracle, governance, Timelock, Reservoir and interfaces; commit b94f5b…
Findings
0 critical, 0 high, 1 medium, 5 low, 2 informational. Medium: missing payment-amount check. Low: address validation, block.timestamp, outdated/floating pragma, inline assembly. Informational: whitepaper division error and missing input validation.
Fix status
5 solved; 1 not applicable; 2 accepted risks. Medium accepted risk. Current deployed-bytecode match: Not verifiable as of 2026-09-06.
Report url
https://github.com/HalbornSecurity/PublicReports/blob/master/Solidity%20Smart%20Contract%20Audits/Benqi_Smart_Contract_Security_Audit_Halborn_v1_1.pdf
Report id
doc:933965445ebe86bf
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

BENQI Liquid Staking Smart Contract Security Audit.

Auditor
Halborn
Report date
2022-02-14
Scope
BENQI Liquid Staking contracts; engagement November 13, 2021–February 14, 2022.
Findings
4 critical, 1 high, 2 medium, 1 informational, based on the published BENQI/third-party audit summary.
Fix status
Critical, high and medium findings reported resolved; informational finding acknowledged. Exact issue-level remediation and current deployed-bytecode match: Not verifiable as of 2026-09-06.
Report url
https://162914606-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MViz_ikDZy4OemUj_VI%2Fuploads%2Fsjpc2u859ZnLjsedBuel%2FBenqi_LiquidStaking_Smart_Contract_Security_Audit_Report_Halborn_Final.pdf
Report id
doc:b4de128ae8e044c9
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Liquid Staking Formal Verification Report.

Auditor
Certora
Report date
2022-04-06
Scope
StakedAvax contract; code delivered February 23, 2022; formal rules for BENQI liquid staking.
Findings
No conventional critical/high/medium finding table. Certora states the implementation was correct with respect to the specified formal rules.
Fix status
Verified delivered code; later deployment alignment: Not verifiable as of 2026-09-06.
Report url
https://www.certora.com/reports/benqi-report
Report id
doc:cf9a3bb84c986f1c
Covers deployed code
No
Evidence (1)

audit

one source

BENQI Ignite Audit Report, version 2.0.

Auditor
Cyfrin
Report date
2024-12-11
Scope
Ignite staking, validator registration, reward/payment logic, oracle integration and related Avalanche contracts; public Cyfrin repository/report.
Findings
0 critical, 1 high, 5 medium, 5 low, 14 informational.
Fix status
The report is published as v2.0. Issue-level production remediation and current deployed-bytecode match: Not verifiable as of 2026-09-06.
Report url
https://github.com/Cyfrin/2025-01-benqi
Report id
doc:d10bdc87cd01f31b
Covers deployed code
No
Evidence (1)

audit

one source

Aave V3 sAVAX Verification and Listing Stewards Audit.

Auditor
Certora
Report date
2022-06-28
Scope
sAVAX/StakedAvax, sAVAXOracleAdapter and AaveV3SAVAXListingSteward on Avalanche; steward commit 1d00da87; deployed-token verification completed June 28, 2022.
Findings
One issue: wAVAX was not configured in the same eMode category; no critical/high/medium severity classification was stated.
Fix status
Issue fixed before deployment. Current deployed-code match: Not verifiable as of 2026-09-06.
Report url
https://162914606-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MViz_ikDZy4OemUj_VI%2Fuploads%2FMZ8kV2ZaRIroyeV5Oyt8%2Fstweard-savax.pdf
Report id
doc:f133cfd3378d4164
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

BENQI Isolated Markets / Avalanche Ecosystem Markets Audit.

Auditor
Not verifiable as of 2026-09-06
Report date
2024
Scope
Benqi isolated-markets repository, reviewed commit bd47157401a5918adb1c0e3d93c23f69ed6d1261.
Findings
0 critical, 0 high, 4 medium, 5 low, 2 informational. Four medium and one low resolved; four low and two informational unresolved in the report summary.
Fix status
Partial remediation documented. Auditor identity and current deployed-bytecode match: Not verifiable as of 2026-09-06.
Report url
https://2452785816-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MViz_ikDZy4OemUj_VI%2Fuploads%2FFX0XuZ24gLs8LUbWzUvS%2FBENQI%20Isolated%20Markets%20Audit.pdf
Report id
doc:f5761644f3ad9c15
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

two sources

Smart Contract Security Audit for BENQI Liquidity Market (core lending/borrowing on Avalanche). Engagement 3–23 May 2021.

Auditor
Halborn
Report date
2021-05-23
Scope
Avalanche C‑Chain BENQI Liquidity Market smart contracts (non‑custodial lending/borrowing). Core protocol contracts used for the lending market on Avalanche.[2][6]
Findings
Halborn reports "few security risks"; specific issues are summarized in the PDF but not publicly classified by severity counts in the snippet available.[2] Overall risk rated low after remediation, with recommendations for further testing.[2]
Fix status
Docs state BENQI "addressed all critical and high-severity findings before mainnet deployment" for audited smart contracts; this is an unverified marketing claim.[9][1] Bytecode-match to currently deployed Avalanche lending contracts: Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

According to Halborn’s official audit repository, Benqi Lending (Benqi Protocol) on Avalanche underwent at least one smart‑contract security audit by Halborn in 2021. The report describes review of core lending/borrowing contracts and protocol architecture; typical Halborn scope includes contract logic, access control, economic attacks, and integration with Avalanche-specific tooling. However, the exact list of contracts, coverage of current deployed bytecode, and detailed issue breakdown for Benqi Lending are not publicly accessible in full from Halborn’s site as of the latest search; only a summary/entry confirming the audit engagement is visible.

Auditor
Halborn
Report date
2021-08-24
Scope
Smart-contract security audit of Benqi Protocol/Lending on Avalanche (core lending and borrowing contracts; detailed contract list and bytecode-match status not publicly disclosed).
Findings
Not verifiable as of 2026-09-03 (full issue list and severities for the Halborn Benqi Lending audit are not publicly available; only audit existence is confirmed).
Fix status
Not verifiable as of 2026-09-03 (no public, issue-level remediation table or explicit statement tying fixes to currently deployed bytecode could be located).
Evidence (1)

audit

one source

Security assessment of Benqi Oracle used in Chaos Labs dual‑oracle setup (relevant to lending market risk management). Assessment 8–9 May 2025.

Auditor
Zellic (for Chaos Labs)
Report date
2025-05-09
Scope
Benqi Oracle smart contracts and associated code reviewed for security vulnerabilities, design issues, and weaknesses, used within Chaos Labs risk management for Benqi lending markets on Avalanche.[13][1]
Findings
Zellic reports: Critical 0, High 0, Medium 1, Low 1, Informational 0 for the Benqi Oracle code.[13] The identified medium‑severity issue and low‑severity issue are described in the full report (not fully quoted here due to length).[13]
Fix status
Zellic’s publication does not, in the accessible summary, explicitly state whether all findings were fixed in production; Chaos Labs/BENQI claim ongoing risk monitoring, but remediation status of the specific Oracle findings is Not verifiable as of 2026-09-04.[13][1] Bytecode/implementation match to current deployed oracle: Not verifiable as of 2026-09-04.
Evidence (2)

Team & Reputation

founders

two sources

Benqi Lending on Avalanche is founded and run by a fully public, non-anonymous team with prior DeFi and software experience, organized primarily through Rome Blockchain Labs Inc., rather than as a pure anonymous web protocol. Founders & key team

  • Core founders: Multiple sources identify JD Gagnon, Dan Mgbor, and Hannu Kuusi as co-founders of BENQI and Rome Blockchain Labs Inc.
  • Other early contributors/key leads include Dexter Lee (DeFi lead/co-founder in some descriptions), Jason Tuang, Hansen Niu, Alexander Szul, and others, all named with professional backgrounds in engineering, finance, and strategy.
  • A Token Terminal interview presents JD Gagnon as Co‑Founder & CEO, indicating a clear leadership structure. Prior projects & track record
  • Founders previously co‑founded Rome Blockchain Labs Inc., a DeFi‑focused software development/incubation firm that built BENQI.
  • Backgrounds include tech consulting, engineering, finance (ex‑Big4 accountant), family office investing, and blockchain engineering.
  • As of the latest available information, there are no public records of major protocol hacks or rug pulls involving BENQI’s core team, though this is Not verifiable as of 2026‑09‑04 from raw on-chain data. Public vs. anon; credibility signals
  • Multiple profiles (IQ.wiki, interviews, LinkedIn) list real names, bios, and work history, which is inconsistent with an anonymous team.
  • BENQI has conducted public AMAs, media interviews, and appears in institutional-facing platforms like Token Terminal and Preqin, which profile the company and founders.
  • Preqin states BENQI was established in Costa Mesa, California, by founders Mgbor, Kuusi, and Gagnon, suggesting a U.S.-linked corporate setup. Jurisdiction, office, business reality
  • Preqin’s listing of Costa Mesa, California indicates a real-world company registration or presence, but detailed corporate filings and exact office address are Not verifiable as of 2026‑09‑04.
  • Team members are distributed globally (Canada, USA, Finland, UK, Malaysia, Australia) and operate largely as a remote-first organization, typical for DeFi.
  • Overall, BENQI appears to be a real operating business with public founders and institutional investors, not a pure anonymous web front, but the precise legal structure, onshore/offshore status, and regulatory posture remain Not verifiable as of 2026‑09‑04.
Evidence (15)

general reputation

two sources

Benqi Lending on Avalanche currently has a strong, conservative reputation in DeFi, with multiple independent audits, no reported bad-debt or insolvency events, and no public allegations of fraud or rug pull as of 2026-09-04. Team, investors, positioning

  • Public, non-anonymous team is highlighted by third‑party risk reviews, which treat this as a positive for accountability.
  • Benqi is described as Avalanche’s main or “core” lending market since 2021, integrated with its own liquid staking token sAVAX.
  • Institutional access is mentioned (e.g., Anchorage Digital), but that is an *unverified marketing claim* unless independently confirmed. Audits and security reputation
  • Multiple sources note extensive audit coverage: Halborn as primary auditor for the liquidity market (May 2021) and liquid staking (2021–22), plus additional firms such as Certora, Quantstamp, Dedaub, Cyfrin, Zellic, Chaos Labs.
  • Benqi’s own docs list several audits and risk assessments across lending, liquid staking, oracles, and web app pentesting.
  • Independent reviewers emphasize that audit reports are public and that Benqi has “one of the most comprehensive public audit records in Avalanche DeFi.” Risk ratings and sentiment
  • DeFi Sentinel assigns Benqi an AA (very low risk) rating with an 81/100 safety score, noting 7 audits and only medium/low‑severity alerts.
  • Other review sites give positive but more moderate ratings (e.g., 7.3/10, conservative parameters, no bad‑debt event).
  • Exponential.fi and DefiLlama describe Benqi as a non‑custodial, permissionless lending market with conservative, Compound‑style architecture. Criticisms and unresolved concerns
  • RIADeFi rejects Benqi’s sAVAX and its lending market mainly due to systemic loop‑collateral concentration (large fractions of sAVAX leveraged as collateral on Benqi and Aave at high LTVs), flagging systemic liquidation and cascade risk rather than direct protocol misconduct.
  • Risk analyses stress that audits do not eliminate smart contract or liquidation risk, and that Benqi’s design still carries standard DeFi lending risks. Incidents, fraud, regulatory/sanctions
  • No credible reports found of rug pull, theft of user funds, insolvency, or sanctions actions against the protocol or team as of 2026-09-04.
  • No major legal or regulatory enforcement actions are reported in the reviewed sources as of the same date. On‑chain verification of incident history and ownership concentration: Not verifiable as of 2026-09-04.
Evidence (10)

Economy

TVL: $93.3M

model

one source

Assessment (Avalanche only; as of September 6, 2026). BENQI Lending is a non-custodial, over-collateralized pooled lending market. Suppliers deposit supported assets and receive variable interest generated by borrower demand; rates adjust with utilization. Deposits may also serve as collateral for borrowing. Assets/yield and risk. Yield is primarily organic borrower interest, not a strategy-generated or market-making return.

For a passive lender it is broadly market-neutral relative to directional trading, but the lender retains asset-price, liquidity, oracle, smart-contract, and borrower-liquidation risks. Lending is distinct from BENQI Liquid Staking; supplying sAVAX would add liquid-staking/AVAX exposure. Current subsidy or QI-incentive contribution is Not verifiable as of September 6, 2026.

Therefore organic_yield_pct is null. Leverage/looping. Users can recursively supply and borrow, subject to collateral factors and available liquidity, but protocol-wide looping usage and leverage are Not verifiable as of September 6, 2026; leverage_ratio is null. Isolated Avalanche ecosystem markets restrict borrowing to USDC, while Core Markets support broader assets. Withdrawals, lockups, gates. No protocol-imposed maturity is identified for ordinary lending deposits. Withdrawals are subject to pool liquidity and collateral requirements; collateral cannot be withdrawn if it would make the account unsafe.

Liquidations sell collateral to repay debt, with a close factor limiting repayment per transaction. Exact current market-by-market limits and liquidation incentives are Not verifiable as of September 6, 2026. Fees/revenue. DeFiLlama defines fees as borrower interest and revenue as the protocol’s retained share. It reports approximately $132,240 fees and $24,169 revenue over 30 days, with $92.97m TVL and $36.04m active loans; Avalanche represents 100% of tracked TVL.

Average supply APY is 2.35%. These are aggregator figures, not on-chain verification. Trend/APY/Dune comparison. DeFiLlama shows 6.7% 30-day TVL growth and historical revenue/interest series, but a complete APY volatility and sustainability analysis is Not verifiable as of September 6, 2026. Dune MCP is unavailable; Dune-vs-DeFiLlama TVL, product split, and trend reconciliation are therefore Not verifiable as of September 6, 2026.

DeFiLlama’s TVL methodology counts collateral, not borrowed funds, so TVL should not be compared directly with supplied assets or active loans.

Evidence (5)

reserves

one source

As of September 6, 2026, Dune/raw on-chain verification is unavailable in this run. Therefore: Not verifiable as of 2026-09-06 for Avalanche treasury/reserve addresses, token balances, custody control, wallet ownership, or a reproducible on-chain reserve snapshot. No Dune query ID or execution ID is available. Aggregator cross-check (not on-chain verified): DeFiLlama currently reports BENQI treasury of $6.54m, all protocol TVL on Avalanche.

Composition: $154,977 majors, $2.50m stablecoins, $2.54m own tokens, and $1.35m others. This changed from the previously recorded approximately $8.12m figure; the discrepancy is a finding, and the newer displayed DeFiLlama value should not be treated as proof of reserves. Own-token and “others” holdings may not be immediately liquid. Liabilities: DeFiLlama reports $32.43m active loans, but borrower loans are protocol assets, not the protocol’s depositor liabilities.

A total depositor-claim/liability figure was not found. Not verifiable as of 2026-09-06. Reserve policy/control: BENQI documentation describes a lending-market reserve factor: a percentage of borrower interest retained for protocol reserves and financial sustainability. This is a parameterized accrual mechanism, not evidence of a segregated treasury, minimum reserve ratio, or enforced liquidity policy. The documentation also states that protocol parameters were adjusted by the core team, with decentralization planned over time. Custody and attestations: No independent reserve attestation or proof-of-reserves report was identified.

BENQI’s public contract documentation identifies lending contracts, including the Core Markets Comptroller at 0x486Af39519B4Dc9a7fCcd318217352830E8AD9b4, but this is a protocol controller—not a verified treasury address. Assessment: Reserve transparency is insufficient for institutional verification; treat the DeFiLlama amount as an analytics estimate only.

Evidence (3)

tokenomics

unverified

BENQI Lending on Avalanche has a native token, QI (BENQI), with contract address 0x8729438EB15E2C8B576fCc6AeCdA6A148776C0F5 on Avalanche/Snowtrace. The protocol docs state QI total supply is 7,200,000,000 tokens. Public trackers in the search results show supply figures that vary by source and date: some list circulating supply near 7.20B while others show materially lower values, so circulating supply, market cap, and FDV are not verifiable as of 2026-09-04 from the gathered evidence alone.

QI’s stated utility is governance over the treasury/protocol, and vote-escrowed QI (veQI) is used for governance-style participation and AVAX delegation incentives; this was described in the protocol materials and secondary coverage. The allocation model repeatedly reported across sources is: 45% liquidity mining/community incentives, 25% investors/token sale, 15% treasury, 10% team/core contributors, 5% exchange liquidity. One source also breaks token sale into seed/private/public tranches, but that breakdown is not independently confirmed here.

On revenue share, buybacks, burns, staking rewards, I could verify only that veQI is linked to staking/governance incentives; revenue-share, buyback, and burn mechanics are not verifiable as of 2026-09-04 from the gathered evidence. The search results indicate emissions were primarily distributed via liquidity mining, but the exact live emissions schedule is not verifiable as of 2026-09-04 from the evidence collected. Similarly, the detailed unlock schedule and whether all announced unlocks actually occurred on-chain are not verifiable as of 2026-09-04 without on-chain analysis.

For holder concentration, insider wallets, mint/blacklist/fee-switch functions, and control, the gathered sources do not provide auditable on-chain proof, so these are not verifiable as of 2026-09-04. DEX liquidity depth and main listings are also not verifiable as of 2026-09-04 from the collected evidence, though the protocol materials mention liquidity mining incentives and exchange liquidity allocation.

Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 would be a severe *market-wide stress event* for Benqi Lending on Avalanche, but the protocol-specific impact cannot be quantified from the available sources. The only directly relevant evidence here is that Benqi has had a large pool of high-risk loans—defined as loans within 5% of liquidation price—which increases the chance of liquidation cascades if collateral prices fall sharply. For Benqi users with BTC collateral, a drop below $10,000 would likely push many positions toward or into liquidation, depending on each borrower’s starting LTV and the protocol’s liquidation thresholds; however, exact liquidation outcomes for Benqi’s live Avalanche markets are Not verifiable as of 2026-09-04 because no on-chain query results were provided.

If the borrowed assets are stablecoins or other assets against BTC, the main risk is a forced collateral sale, which can amplify downside through a liquidation feedback loop. A broader stress scenario is that cascading liquidations could depress collateral prices further, especially if market depth is thin, which is the standard mechanism described for crypto lending platforms under sharp drawdowns. Benqi is specifically described as an Avalanche-based lending and borrowing protocol, so this stress would be concentrated on the Avalanche deployment rather than across unrelated chains.

What cannot be confirmed from the provided sources: Benqi’s current BTC-collateral exposure, the share of loans near liquidation, the protocol’s live liquidation parameters, and any chain-specific TVL split. Those are Not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral would be stressful, but the exact loss rate, liquidations, and any bad debt are not verifiable as of 2026-09-04 from the available sources. The strongest protocol-specific evidence is that BENQI’s risk documentation explicitly warns that supplied or borrowed assets can lose peg, and that collateral factors determine how much a position can withstand before liquidation. What can be said with confidence is the mechanism: if the largest collateral token on Benqi Lending falls 20% in market value, borrowers using that asset as collateral would see their health factor drop, triggering liquidations for positions close to threshold; if liquidations cannot clear the debt fast enough or the asset is illiquid, cascading pressure can deepen the depeg.

Independent risk analysis on Benqi specifically highlights sAVAX as a reflexive depeg risk asset, where liquidation sales of seized collateral can amplify the discount during AVAX stress. Media coverage also indicates Benqi has had a large cohort of loans close to liquidation, with IntoTheBlock data showing $55 million of loans within 5% of liquidation price at one point, which implies meaningful sensitivity to even modest collateral shocks. However, a protocol-wide quantitative answer for this exact scenario requires the current collateral mix, collateral factors, liquidation thresholds, borrow balances, and asset liquidity on Avalanche; those are not verifiable from the provided sources.

Therefore the stressed outcome for Benqi Lending under a 20% depeg of the largest collateral is Not verifiable as of 2026-09-04.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

In Benqi Lending on Avalanche, insolvency of the largest borrower is handled entirely via the protocol’s liquidation and bad‑debt mechanisms; losses are first socialized across suppliers in the affected market, then potentially across the protocol via backstop mechanisms, if any exist. Not verifiable as of [2026-09-04] for precise on-chain magnitudes. ### 1. Stress setup: top counterparty insolvent Assumptions (conceptual, not on-chain verified):

  • Top borrower holds a large debt position in one asset (e.g., AVAX) and uses volatile collateral (e.g., AVAX or other supported tokens).
  • A sharp price move or protocol‑specific event renders their position under‑collateralized and they stop repaying. ### 2. Expected loss path 1. Health factor breach
  • Price oracle reports collateral value drop; borrower health factor <1 ⇒ position becomes liquidatable.
  • Smart contracts: the Benqi Lending core uses an interest‑bearing token model (qiTokens) and borrows against supplied collateral, similar to Compound/Aave‑style design. 2. Liquidation attempts
  • Liquidators repay part of the insolvent borrower’s debt and seize collateral at a discount (liquidation bonus).
  • If collateral value is sufficient, the debt is fully covered ⇒ no loss to suppliers. 3. Bad debt creation
  • If price gaps or oracle failure make collateral insufficient, a shortfall remains in the market:
  • The protocol records bad debt in that asset’s pool.
  • The pool’s total assets < total liabilities ⇒ qiToken exchange rate drops vs. the theoretical “no‑loss” path. ### 3. Who absorbs the loss?
  • Suppliers in the affected market
  • Loss is implicitly socialized: qiToken holders receive less backing per token; their redeemable value is reduced.
  • Protocol / backstop mechanisms
  • If Benqi has insurance funds, risk funds, or QI‑denominated backstops (e.g., via governance or treasury), these could be used to buy bad debt or recapitalize the pool; this would shift part of the loss to QI token holders.
  • Exact backstop size and rules: Not verifiable as of [2026-09-04]. ### 4. Compensation
  • Standard DeFi lending design: no automatic compensation to suppliers beyond what backstop/insurance funds explicitly cover.
  • Any ex‑post compensation (e.g., governance‑approved treasury distributions) would be discretionary and governance‑driven, not contractual. ### 5. Impact path through smart contracts
  • Oracles: price update ⇒ health factor breach.
  • Core lending pool: marks position as liquidatable; liquidations executed via pool’s liquidation functions.
  • qiToken accounting: exchange rate reflects realized losses; all qiToken holders in that market bear them pro‑rata.
  • Governance/treasury contracts (if used): may execute recapitalization or debt buy‑backs, transferring part of losses to QI holders. General description of Benqi Lending architecture and liquidations (similar to Compound‑style pools). Avalanche ecosystem documentation referencing Benqi Lending as a pooled, over‑collateralized money market.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For Benqi Lending on Avalanche, I found no verifiable evidence in the provided sources that the DAO or owners committed fraud. The available materials describe BENQI as a decentralized lending protocol and note general smart-contract and operational risks, but they do not document a fraud event, governance theft, treasury drain, or owner misconduct. What can be said with confidence is limited to risk posture: BENQI’s own risk page says users face known and unknown smart-contract risks that could lead to assets being locked or lost, and its bug-bounty listing shows the protocol has an active security program.

DeFiLlama identifies BENQI Lending as a non-custodial liquidity market on Avalanche, which is consistent with a protocol design that reduces custodial abuse risk but does not itself prove anything about fraud history. I also did not find any credible report in the supplied results alleging a governance attack, malicious proposal, or owner-controlled drain specific to BENQI Lending. The governance-fraud articles in the results are about a different protocol case (BONK DAO) and are not evidence against BENQI. Assessment: Not verifiable as of 2026-09-04.

Based on the available evidence, there is no confirmed fraud finding for this stress scenario, and the prudent institutional conclusion is that the scenario remains unsubstantiated from the provided sources.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For Benqi Lending on Avalanche, the primary yield source is lending interest, supplemented by QI rewards according to BENQI’s own site and docs. Under a stress scenario with the primary yield source negative over 30 days, the protocol would face a direct compression of depositor returns: interest income would not offset principal outflows, and any reward emissions would become the only remaining offset if they were still active. A concrete 30-day negative-yield stress outcome is not verifiable as of 2026-09-04 from the provided sources, because the available materials do not disclose Benqi’s on-chain cash-flow composition, reward rate, or treasury backstop in a way that can be independently checked here.

What can be said from the evidence is limited to this: BENQI describes itself as a non-custodial lending market on Avalanche, and DeFiLlama shows the Avalanche deployment with 30-day fees data, which indicates ongoing protocol activity but does not establish that user yield remains positive under stress. Therefore, the correct risk finding is that a negative 30-day primary-yield shock would likely make Benqi’s depositor proposition reliant on non-interest incentives, but the magnitude and persistence of the shortfall are not verifiable from the supplied sources.

Evidence (3)

Governance & Legal

governance

unverified

Assessment as of September 13, 2026: BENQI Lending is not demonstrably DAO-controlled. BENQI documentation states the founding team bootstraps the protocol, while the Core Team currently adjusts lending parameters including collateral factors, reserve factors, close factors, liquidation incentives, and interest-rate models. BENQI Miles governance is presently evidenced primarily by validator/node voting; broader lending governance is described as progressive/future decentralization rather than an implemented autonomous process. Control map: Development is maintained through the Benqi-fi organization’s public smart-contract repository; the frontend/site is provided by Decentralised Research Technologies Inc. under the April 4, 2026 Terms of Service.

The Terms also reference the Decentralized Technology Foundation as the company’s sole shareholder and acknowledge multisig/operational frameworks for upgrades, parameter changes, and emergency response. Exact control addresses, signers, thresholds, independence, and powers are not disclosed in the reviewed sources. Proposal process: No verifiable formal proposal, quorum, voting-period, execution, or veto process controlling BENQI Lending upgrades/parameters was found. Node Voting is a narrower, implemented governance function for validator delegation.

Top-holder concentration and voting concentration via Dune are Not verifiable as of September 13, 2026 because Dune MCP/on-chain verification is unavailable. Contradiction / governance finding: BENQI marketing/documentation describes future voting over lending parameters and protocol improvements, but its current parameter documentation says the Core Team adjusts those parameters. The latter indicates DAO governance is presently symbolic or incomplete for Lending. Company details: Entity: Decentralised Research Technologies Inc.; related shareholder: Decentralized Technology Foundation. Jurisdiction, registration number, and directors: Not verifiable as of September 13, 2026 from the reviewed Terms or other independent sources.

Dao governance
No
Evidence (4)

legal & regulatory

one source

BENQI’s Terms of Service state that the services are not offered to restricted persons and are unavailable in certain jurisdictions, including Belarus, Crimea/Sevastopol, Cuba, Iran, North Korea, Syria, Venezuela, Zimbabwe, and others; they also say users may use the services only where permitted by applicable law. The privacy policy states that BENQI processes personal information and allows EEA/UK/Switzerland/Brazil users to lodge complaints with a supervisory authority, indicating a standard data-protection compliance posture. I found no confirmed evidence in the gathered sources of KYC onboarding being mandatory for BENQI Lending users; the available material instead suggests the protocol is presented as a DeFi lending market accessible without intermediaries, and any claim of formal KYC/AML onboarding is not verifiable as of 2026-09-04.

The protocol is described in third-party coverage as an Avalanche-based DeFi lending protocol, but I found no regulator action, court case, or sanctions designation against BENQI or a clearly identified operating entity in the gathered sources; active enforcement is therefore not established on the current evidence.

Active enforcement
No
Sanctioned
No
Entity
BENQI / BENQI Finance (legal entity not clearly identified in gathered sources)
Jurisdiction
Not verifiable as of 2026-09-04
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'BENQI', 'BENQI Finance', 'Benqi Lending'. OFAC SDN screening of 'BENQI', 'BENQI Finance', 'Benqi Lending': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • BENQI
  • BENQI Finance
  • Benqi Lending
Sanctioned
No
Evidence (4)

Stability

stability

one source

Benqi Lending does not appear to issue its own stablecoin; its markets are for lending/borrowing assets like USDC, DAI, USDT and other tokens, while BENQI itself is described as a lending and liquid-staking protocol on Avalanche. A protocol-specific stablecoin depeg history is not verifiable as of 2026-09-06, but the stablecoins used in BENQI markets include USDC and USDT. For the stablecoins used by the protocol, a clear, documented depeg event exists for USDC in March 2023 after the Silicon Valley Bank closure, and BENQI reportedly froze stablecoins on its platform in response; however, the available sources do not provide a BENQI-specific count of depeg occurrences, last depeg date for all supported stablecoins, or a protocol-level maximum depeg percentage.

Therefore, the exact number of depegs and the worst depeg magnitude for BENQI’s used stablecoins are not verifiable as of 2026-09-06. ## Structured fields

  • own_stablecoin: false
  • stable: null
  • depeg_count: null
  • max_depeg_pct: null
  • last_depeg_date: null
  • stablecoin_ids: ["USDC", "USDT", "DAI"]
Own stablecoin
No
Stablecoin ids
  • USDC
  • USDT
  • DAI
Evidence (3)

Risks & Strengths

risks

two sources

BENQI Lending’s principal risks are smart-contract failure, oracle malfunction, liquidation-driven bad debt, liquidity stress, and governance/administrative control. Risk controls exist—including audits, isolated markets, dual oracles, borrow caps, and emergency controls—but several controls are protocol- or administrator-dependent, and current deployment state and exposure concentrations are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract exploitA logic, upgrade, accounting, or integration defect could enable unauthorized withdrawals, insolvency, or permanently locked deposits. Audits reduce but do not eliminate this tail risk.HighMediumMultiple audits are listed, production code is public, and the protocol maintains emergency pause controls in lending storage.High-impact loss remains possible; audit coverage and current deployed-code equivalence are Not verifiable as of September 5, 2026.
Oracle failure or manipulationIncorrect collateral prices can trigger premature liquidations or allow undercollateralized borrowing, particularly for volatile, long-tail, or thinly traded assets.HighMediumDual-oracle design uses Edge/Chaos as primary and Chainlink as secondary; a 2025 Zellic review found no critical or high findings.Medium to High; oracle administration and feed behavior remain trust and availability dependencies.
Liquidation cascade and bad debtFast AVAX or collateral-price declines, depegs, or insufficient liquidator liquidity can leave collateral short of debt and socialize losses to suppliers.HighHighCollateral factors, close factors, liquidation incentives, reserve factors, and isolated markets are used to limit contagion.High during abrupt market stress; live parameters and reserve adequacy are Not verifiable as of September 5, 2026.
Liquidity and withdrawal stressHigh utilization or concentrated borrowing can make withdrawals difficult and sharply increase variable borrow rates; a liquidity mismatch can impair suppliers.HighMediumInterest-rate curves, borrow caps, reserve factors, and separate ecosystem markets are intended to preserve liquidity.Medium to High; current market-level utilization, concentration, and available liquidity are Not verifiable as of September 5, 2026.
Governance and administrator controlPrivileged actors may change risk parameters, oracle administration, market listings, or emergency settings; compromise or poor decisions could harm users.HighMediumContract storage documents pauseGuardian and borrowCapGuardian controls. Contradiction: BENQI’s newer marketing page says no administrative pause functions, while the lending repository documents pause controls.High until current deployed roles, multisig signers, timelocks, and permissions are independently verified; Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

BENQI Lending’s top strengths are its Avalanche-native design, broad product suite, liquid staking integration, user-friendly risk controls, and security/maturity profile. It is built specifically for Avalanche C-Chain, which the Avalanche Builder Hub says gives it low fees and fast finality, and BENQI itself markets the protocol as the Avalanche DeFi hub for lending, borrowing, liquid staking, and validator bootstrapping. 1. Avalanche-native performance: BENQI benefits from Avalanche’s low fees and fast transaction finality, which supports efficient lending, borrowing, and liquidations.

2. Integrated product suite: Beyond lending, BENQI combines liquid staking, swaps, governance, and validator-related products, which increases capital utility and makes it more than a single-purpose money market. 3. Liquid staking advantage: Its sAVAX liquid staking product lets users stake AVAX while keeping liquidity available for DeFi use, improving composability and capital efficiency. 4. Clear borrower safety UX: Exponential notes a visible borrowing limit dashboard and health factor indicator, which helps users monitor liquidation risk more easily.

5. Mature, audited protocol: Exponential reports a Halborn audit, no documented protocol hacks since launch, and a mature 2021 launch; it also notes broad controls against oracle manipulation and no death spiral concerns. A practical institutional takeaway is that BENQI’s strongest edge is not just lending market depth, but its role as a broader Avalanche liquidity hub with native staking and borrowing utilities.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 22 one source, 5 unverified.
  • Oldest fact verification date: 2026-08-29.