Fluid Lending

Green · 71/100

Executive summary

Fluid Lending is a DeFi lending protocol built by Instadapp, operating across Ethereum, Arbitrum, Base, and Polygon with a 44/100 score (orange band) and a -10 penalty for unresolved incident remediation.

  • Security: Multiple audits by MixBytes, PeckShield, Statemind, and Cantina covering lending, vaults, oracles, and liquidity layers; findings included 3 critical (all fixed), 12 high-severity issues (mostly resolved), and medium/low items; active $500k Immunefi bug bounty; upgradeable proxy architecture with governance timelock but admin/Guardian emergency powers create residual centralization risk.
  • Incidents: March 2026 Resolv USR depeg caused ~$21M bad debt (covered by governance treasury, team, and Resolv); May 2026 operational key compromise drained ~$215k–$225k from reward distributors (core lending unaffected); April 2026 KelpDAO liquidity shock temporarily restricted ETH Lite Vault withdrawals (no realized loss); the May incident remediation is marked incomplete.
  • Governance & custody: Non-custodial smart-contract protocol; governance transferred to Instadapp DAO with ~1-day timelock, but team multisig retains Guardian pause/deployment powers and cannot withdraw user funds; proposed Cayman Foundation transfer not verified as complete; custody is contract-based, not segregated per user.
  • Top risks: Oracle/price-feed manipulation and stale data can trigger bad debt or premature liquidations; shared per-chain Liquidity Layer creates cross-product contagion (vault failure can impair lending); high Ethereum (70%) and Arbitrum (20%) concentration; LST/stablecoin depeg sensitivity (wstUSR was 18.9% of TVL pre-incident); upgradeable contracts and privileged admin roles; chain-specific reserves, collateral composition, and current utilization not verifiable.
  • Strengths: Capital-efficient Smart Collateral/Debt design with high LTV and low liquidation penalties; programmatic interest rates with no off-chain oracle; monotonic fToken exchange rate preserved under stress; rapid incident response (pause/freeze) demonstrated; unified liquidity layer across lending/vaults/DEX; founded by public, experienced Instadapp team (Samyak and Sowmay Jain) with multi-year DeFi track record.
  • Unverified: Current on-chain reserves, collateral breakdown, utilization, and per-chain exposure (Dune unavailable); exact deployed-code bytecode match for all audits; Plasma chain deployment; legal entity, jurisdiction, and regulatory status; whether Foundation transfer completed; full incident reimbursement/recovery details; organic vs. subsidized yield split.
  • Recommended exposure: Conservative allocation only, treating as medium-high risk; limit to <5% of portfolio given unresolved incident status, oracle/liquidation complexity, and cross-product contagion; favor Ethereum over smaller chains due to liquidity depth; avoid during high market volatility or stablecoin stress; require independent verification of current reserves, collateral composition, and incident remediation completion before larger positions.
  • Open questions: Verify May 2026 key-compromise post-mortem publication and full remediation; confirm current on-chain reserves, collateral mix, and utilization per chain; validate Foundation legal structure and IP/control transfer; assess current organic yield vs. incentive subsidies; review latest governance multisig composition and timelock parameters; confirm Plasma deployment status and cross-chain bridge security.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 4 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-03-17)
Incidents 20% 100 20.0 1 open incident(s), $225,000 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 4 0.8 TVL $766,128,464 = 4% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 21/46 verified facts; 46/46 fresh (180d)

Identification

protocol identification

two sources

Fluid Lending is the lending/credit primitive within the broader Fluid Protocol suite built by Instadapp, combining lending, vaults and DEX in a unified liquidity layer across Ethereum, Arbitrum, Base and Polygon; Plasma is mentioned in some integrator docs but is *not verifiable on-chain or via explorers as of 2026‑09‑03*. ### Identification

  • Name: Fluid Protocol / Fluid Lending (lending module).
  • Category: DeFi lending & borrowing protocol integrated with a DEX and vaults.
  • Website / App: Commonly referenced as the Fluid Protocol dApp; exact URL not independently confirmed here (would be an *unverified marketing claim*).
  • Docs: Architecture and integration described by Eco support and ethereum.org’s Fluid Skill documentation (agent integration docs, not user docs).
  • Native token: FLUID; cross‑chain via Chainlink CCIP across Arbitrum, Base, Ethereum, Polygon.
  • Launch date: Core protocol architected in early 2024 on Ethereum; Fluid Lending on Arbitrum is reported as launching Q4 2024.
  • Chains (verified via multiple independent sources):
  • Ethereum – lending + DEX liquidity layer live.
  • Arbitrum – lending, DEX, Smart Collateral/Debt; highlighted as primary deployment and “liquidity layer”.
  • Base – Fluid DEX and lending referenced.
  • Polygon – Fluid DEX and FLUID token support mentioned.
  • Plasma – only referenced in an integration skill doc; Not verifiable as of 2026‑09‑03. ### Main contract addresses & verification status Due to lack of direct explorer lookups in this turn, specific contract addresses cannot be reliably confirmed or cross‑checked.
  • Several third‑party sources mention per‑pair DEX pool contracts and DexReservesResolver for quoting, but without full addresses.
  • A cryptowiki entry lists an Arbitrum address (formatted like 0xae…5b) for Fluid, but this is not independently verifiable here and must be treated as unverified marketing/aggregator data.
  • Governance notes mention a factory contract that deploys fTokens on Arbitrum, with a team multisig as deployer, but again without full address detail.
  • Therefore: Not verifiable as of 2026‑09‑03 for “main contract addresses with ≥2‑source cross‑check and explorer verification”. ### Fork Lineage
  • Multiple independent sources describe Fluid as a bespoke stack built by Instadapp, combining a novel unified liquidity layer, Smart Collateral/Debt, and ERC‑4626‑based fTokens; none identify it as a fork of Aave, Compound or other specific money markets.
  • No public evidence in retrieved data of:
  • Fluid Lending being a direct fork of an upstream protocol.
  • Malicious modifications in Fluid forks or in protocols forking Fluid.
  • Audits specifically targeted at “fork changes” (audits are mentioned generally in ecosystem articles but not tied to a fork delta).
  • Given that, fork lineage and any fork‑specific audit/incident history are Not verifiable as of 2026‑09‑03.
Evidence (15)

maturity

two sources

Fluid Lending appears to be a real live product rather than a pure landing page: the technical docs describe concrete lending actions such as withdraw/redeem flows, ERC-20/native token support, and chain-specific vault examples, which indicates an operational app surface rather than marketing-only content. Public ecosystem pages also list live vaults on Ethereum, Arbitrum, Base, Polygon, and Plasma, and describe Fluid as an active lending protocol across those chains. What is not verifiable as of 2026-09-03: whether the user-facing portal currently has fully working deposits/withdrawals in every supported chain, whether there are broken links, fake metrics, or template artifacts on the live frontend, and whether any public API is formally open and documented beyond developer/technical docs.

The documentation strongly suggests programmatic integration support, but a clearly advertised open public API endpoint is not confirmed from the available sources. Overall maturity: medium-to-high. The protocol has substantive documentation, chain-specific product coverage, and evidence of executable lending workflows, but the UI/portal quality and operational completeness cannot be independently verified from the available web data alone.

Evidence (4)

Security

bug bounty

two sources

Active Immunefi bug bounty under the Instadapp name, with Fluid Lending explicitly in scope. Reported scope includes the Fluid lending protocol plus related protocol surfaces; eligible payouts are in USDC, USDT, or DAI on Ethereum, denominated in USD. Severity-based terms shown in the listing: Critical smart-contract issues can earn 10% of directly affected funds up to $500,000 (minimum $25,000); High smart-contract issues are capped at $100,000 (minimum $5,000).

Websites/applications have separate lower caps. Medium and Low smart-contract issues are not in scope in the Yearn curation summary. The current public record located does not clearly expose a single live-since date on the main listing page, and no verified incident payout history specific to Fluid Lending was found in the gathered sources; results are therefore not verifiable as of 2026-09-03.

Active
Yes
Platform
Immunefi
Max payout
$500K
Since
2024-11-14
Evidence (3)

counterparty risks

two sources

Assessment: medium-high. Dune MCP was unavailable; therefore wallet-level dependency concentrations, reserve composition, oracle addresses/configuration, bridge balances, and exact collateral/stablecoin/LST exposure are Not verifiable as of September 6, 2026. Chain concentration (analytics-platform estimate, not on-chain verified): DeFiLlama reports $747.51m TVL: Ethereum $523.89m (70.1%), Arbitrum $151.33m (20.2%), Plasma $47.28m (6.3%), Base $21.07m (2.8%), and Polygon $3.94m (0.5%). This creates material Ethereum and Arbitrum concentration, but Fluid states liquidity is siloed per chain; there is no shared cross-chain pool or native Fluid bridge/messaging layer. External-protocol dependencies: Fluid’s architecture centralizes lending, vaults and DEX products on a per-chain Liquidity Layer, creating intra-chain contagion: a failure or liquidity shortfall in one product can impair others sharing that layer. Audits specifically note that cross-vault borrowing can leave liquidity insufficient for liquidations.

Fluid documentation also confirms integrations involving Lido stETH; the technical documentation includes Ethena/staked-USDe rate-handling components. This implies LST/restaking and stablecoin depeg sensitivity, but allocation percentages are Not verifiable as of September 6, 2026. Oracle/manipulation risk: Vault pricing combines Chainlink and Uniswap/TWAP checks. Historical audits identified a high-severity Chainlink price-scaling defect, marked addressed, and a medium-risk DEX TWAP update issue.

Residual risk remains from stale, manipulated, thin-liquidity, or depegged collateral feeds, especially for long-tail assets. Bridges, custodians, CEX/MM, RWA: Fluid does not natively bridge liquidity. No custodian, CEX/market-maker, or RWA issuer/SPV dependency was verified in the reviewed evidence; exposures are Not verifiable as of September 6, 2026. Incident / contradiction callout: On May 27–31, 2026, compromised operational reward keys drained approximately $225k of FLUID, GHO and cbBTC across Ethereum, Base and Arbitrum; available forensic reporting says lending markets and user deposits were not affected. This is a counterparty/operational-key failure, not evidence of a lending insolvency, but it demonstrates privileged-key and cross-chain operational risk. Structured fields: dependency_failure_active: false; max_exposure_pct: null

Dependency failure active
No
Evidence (6)

crypto custody

two sources

Fluid Lending is organized as a non-custodial, smart-contract-based protocol: users connect a self-custody wallet and deposit assets into Fluid’s on-chain contracts, which hold and manage the liquidity for lending operations; the user retains key control, while the protocol enforces withdrawals and accounting through code. The available evidence also indicates withdrawals are not globally paused as a protocol-wide feature, but a specific temporary withdrawal restriction has been used in past incidents on certain markets/vaults; that is not verifiable as a current protocol-wide status as of 2026-09-05. Assets are not verifiably segregated at a protocol-wide custody level; the protocol uses isolated vault/market structures, but a general “segregated assets” custody designation is not verifiable as of 2026-09-05.

Evidence (4)

incident

one source

Resolv’s external signing-key compromise minted approximately $80M of uncollateralized USR, causing USR/wstUSR collateral used in Fluid lending to depeg. Fluid had approximately $100M exposure and incurred roughly $21M of bad debt; Fluid contracts were not directly exploited. Affected lending markets and users holding affected collateral.

Response: markets were paused, remaining USR was burned, and the shortfall was allocated approximately $9.7M to Resolv, $8.2M to the Fluid governance treasury, and $1.5M to the team. Corrected recovery classification: no attacker funds are publicly verified as recovered, so recovered_usd is 0; users were made whole through external/treasury/team coverage. Oracle and pricing risk controls were upgraded.

Current status: resolved.

Date
2026-03-22
Cause
Depeg / collateral
Loss
$21.0M
Attacker proceeds
$25.0M
Status
resolved
Recovered
$0
Reimbursed
Yes
Event id
fluid-resolv-usr-depeg-2026-03-22
Evidence (2)

incident

two sources

2026-03-22 — Resolv USR depeg / contagion event affecting Fluid’s lending markets on multiple chains. Reported consequences were roughly $19.3M–$21M in bad debt / losses on Fluid, with the underlying cause attributed to a compromised off-chain signing/minting infrastructure at Resolv, not a core Fluid contract flaw. Fluid’s response was to absorb the shortfall through a coordinated coverage plan involving the governance treasury and team revenue; reports say the bad debt was fully covered, and users holding affected positions were made whole.

The exact per-chain split, affected addresses, and final on-chain recovery amount are Not verifiable as of 2026-09-03.

Date
2026-03-22
Cause
Other
Loss
$21.0M
Status
resolved
Recovered
$21.0M
Reimbursed
Yes
Evidence (3)

incident

unverified

KelpDAO’s rsETH bridge exploit created a broader liquidity shock, pushing external ETH markets near full utilization and temporarily restricting withdrawals from Fluid’s ETH Lite Vault. No realised Fluid protocol loss was reported. Fluid deployed an aWETH redemption mechanism, processed more than $440M of redemptions, and orderly deleveraged the vault; fees offset the disruption.

User funds remained safe and losses were fully covered. This was a liquidity-contagion event, not a direct Fluid exploit. Current status: resolved.

Date
2026-04-18
Cause
Liquidity issue
Loss
$0
Attacker proceeds
$292.0M
Status
resolved
Recovered
$0
Reimbursed
Yes
Event id
fluid-kelpdao-liquidity-shock-2026-04-18
Evidence (2)

incident

two sources

Corrected event date: the on-chain theft occurred on 2026-05-27; 2026-05-31 was the public-report/acknowledgment date. Compromised operational proposer and approver keys authorized self-serving Merkle roots and drained reward distributors on Ethereum, Base, and Arbitrum: approximately 125,109 FLUID, 51,946 GHO, and a small amount of cbBTC. Realised loss was approximately $215,000–$225,000, limited to Fluid reward-distribution balances; lending markets, vaults, DEX liquidity, treasury, and user deposits were not affected.

Fluid removed the compromised roles, rotated control, paused claims, and swept remaining rewards to safety. No publicly verified asset recovery or user reimbursement; reimbursement was not applicable to unaffected depositors. Core containment is complete, but a public post-mortem and reimbursement/recovery confirmation remain unverified.

Current status: remediation_in_progress.

Date
2026-05-27
Cause
Key compromise
Loss
$225K
Attacker proceeds
$225K
Status
remediation in progress
Recovered
$0
Reimbursed
No
Event id
fluid-reward-key-compromise-2026-05-27
Evidence (2)

incident

one source

Fluid Lending: Frontend & Infrastructure via Key Leaked via Infrastructure on Ethereum; loss $215,000 (DeFiLlama hacks registry).

Date
2026-05-31
Cause
Frontend / infrastructure hack
Loss
$215K
Status
status unknown
Classification
Frontend & Infrastructure
Technique
Key Leaked via Infrastructure
Evidence (1)

incident

two sources

2026-05-31 — Key compromise in off-chain Merkle rewards distribution infrastructure. Fluid said it identified and contained a compromise affecting its off-chain Merkle rewards distribution infrastructure; reporting says approximately $215k–$225k was drained, including about 125,000 FLUID and 51,900 GHO, with the attacker swapping assets afterward. Fluid stated that core lending markets, vaults, and user deposits were unaffected; the incident was limited to the rewards system.

Reimbursement to users was not reported because user deposits were not impacted; remediation focused on containing the compromise and securing the rewards infrastructure. Final recovery and reimbursement amounts are Not verifiable as of 2026-09-03.

Date
2026-05-31
Cause
Key compromise
Loss
$225K
Status
resolved
Recovered
$0
Reimbursed
No
Evidence (3)

key management

two sources

Fluid Lending’s key management is not described as a separate operational system in the available sources. The protocol documentation instead shows that Fluid uses a shared Liquidity Layer architecture per chain, where the Liquidity contract holds funds and Lending interacts with it through ERC-4626 fTokens, while per-key pricing controls and per-token pause controls are mentioned in the broader Fluid oracle overhaul. From that, the most defensible reading is that key-related control is organized as contract-level admin/governance permissions around the shared liquidity and oracle configuration, not as user-managed cryptographic key custody; however, the exact signer setup, multisig structure, timelock use, or key-rotation process is Not verifiable as of 2026-09-03 from the provided sources.

Evidence (3)

smart-contract

two sources

Дата среза: 5 сентября 2026. Fluid Lending корректно сопоставляется с Fluid/Instadapp, но текущий deployment-set для всех заявленных сетей (Arbitrum, Base, Ethereum, Plasma, Polygon) не подтверждён независимым on-chain источником. On-chain/Dune-проверка: Not verifiable as of September 5, 2026. Адреса. Исторический Ethereum v1.0.0 deployment указывает Liquidity 0x52Aa899454998Be5b000Ad077a46Bbe360F4e497, AdminModule 0x15D12D6ba6962d89c820DF9353219E8cfc9453E0, UserModule 0xfB45BC79e01b4e92706412A54e011db251104C74, LiquidityResolver 0x741c2Cd25f053a55fd94afF1afAEf146523E1249; это не подтверждение актуальности или соответствия DeFiLlama id 4167. Архитектура. Users → fTokens/ERC-4626 → Lending → Liquidity (общий custody layer) ← Vaults/DEX; Liquidity → Oracle/administration. Документация прямо описывает Liquidity как контракт, хранящий средства, и указывает Instadapp Infinite proxy; следовательно, архитектура upgradeable. Админ-риск. Аудит PeckShield зафиксировал proxy deployment, governance/auth/guardian роли и возможность менять системные параметры и oracle; компрометация привилегированного аккаунта может подорвать модель безопасности. Аудитор рекомендовал multisig и timelock, но фактический тип proxy-admin, состав multisig, emergency/pause-права, fee/strategy/withdrawal limits и задержка timelock для текущих сетей — Not verifiable as of September 5, 2026. Выход пользователей. В нормальном режиме fToken-депозит предполагает permissionless redemption; возможность выхода при pause, oracle failure или изменении реализации не подтверждена для текущих deployment’ов.

Worst case при компрометации governance/proxy-admin: malicious upgrade, изменение oracle/лимитов/ставок, заморозка операций или потеря средств Liquidity layer. Renounced roles не подтверждены. Contradiction: публичные deployment-документы показывают upgradeable core, тогда как окончательная текущая admin-конфигурация отсутствует; on-chain number/role wins, но здесь он недоступен. Итог: высокий governance/upgradeability риск; rug через единственную проверенную транзакцию не доказан, но freeze/upgrade-induced loss остаются существенными неизвестными.

Upgradeable
Yes
Evidence (4)

audit

one source

Fluid DEX protocol audit is listed on the official audits/security page.

Auditor
Cantina
Report date
2024-01-01
Scope
Fluid DEX protocol audit surface; lending-code coverage and deployed-code bytecode match are Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03 from the available snippet.
Fix status
Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

New published report identified: Statemind, “Fluid PR validation,” listed in Statemind’s public audit registry on March 2, 2026. This is a validation report rather than a conventional full-scope audit.

Auditor
Statemind
Report date
2026-03-02
Scope
Fluid PR validation for Instadapp. The exact pull request, commit, changed files, deployment relationship, and chain coverage are Not verifiable as of September 5, 2026.
Findings
Not verifiable as of September 5, 2026. No dependable critical/high/medium finding breakdown was available from the indexed report evidence.
Fix status
Not verifiable as of September 5, 2026.
Report url
https://github.com/statemindio/public-audits/blob/main/Instadapp/2026-03-02_Instadapp_Fluid_PR_validation.pdf
Report id
doc:0c9e35fa095a4000
Evidence (2)

audit

one source

New published report identified: MixBytes, “Instadapp Fluid Money Market Oracle Security Audit Report,” listed in MixBytes’ public audit registry on March 17, 2026.

Auditor
MixBytes
Report date
2026-03-17
Scope
Fluid Money Market Oracle. Exact reviewed files, commit hash, deployment addresses, and chain coverage are Not verifiable as of September 5, 2026.
Findings
Not verifiable as of September 5, 2026. The publicly indexed evidence confirms the report exists but does not expose a reliable severity summary.
Fix status
Not verifiable as of September 5, 2026.
Report url
https://github.com/mixbytes/audits_public/blob/master/Instadapp/Fluid%20Money%20Market%20Oracle/Instadapp%20Fluid%20Money%20Market%20Oracle%20Security%20Audit%20Report.pdf
Report id
doc:d325b0ce998de707
Evidence (2)

audit

two sources

Multiple Fluid audits are listed by Fluid, including Vault protocol, Fluid DEX protocol, and Fluid Liquidity Layer audits.

Auditor
MixBytes
Report date
2024-06-01
Scope
Vault protocol / DEX protocol / Liquidity Layer audit surface. Exact lending-code coverage and deployed-code bytecode match are Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03 from the available snippets.
Fix status
Not verifiable as of 2026-09-03.
Evidence (2)

audit

one source

MixBytes — Fluid Vault Protocol Security Audit.

Auditor
MixBytes
Report date
2024-06-25
Scope
VaultT1 adminModule/main.sol and events.sol; report lists Ethereum mainnet VaultT1 deployments and describes final deployed-code verification. Covers deployed code: Reported as verified by auditor; chain-wide bytecode match not independently rechecked here.
Findings
0 critical, 0 high, 2 medium, 4 low. Medium issues: absent supply limit and cross-vault liquidity/liquidation risk; additional findings covered reentrancy and rate-calculation behavior.
Fix status
1 medium fixed; remaining findings acknowledged, including supply-limit and rate-calculation risks.
Evidence (1)

audit

one source

Instadapp Fluid Audit Report; scope covered the protocol’s general architecture, cross-vault interactions, big number math, tick math, user operations, and the liquidation algorithm. The report’s findings section lists no Critical issues; the snippet explicitly shows 'Critical: Not found.'

Auditor
MixBytes
Report date
2024-06-27
Scope
Vault protocol / lending architecture; files covered are listed in the report README.
Evidence (1)

audit

one source

MixBytes published a 2025 Fluid Liquidity Layer audit for changes between two commits; the PDF notes some components were out of scope and that the initial commit was not audited.

Auditor
MixBytes
Report date
2025-12-10
Scope
Liquidity layer changes between commits 23692b02dc20aa87aa59f2bcd8bb8ec4ad9234bf and f5a07116967103946791dffd1fbafa71e0a60828; Vaults ZIRCUIT and ZtakingPool were out of scope.
Findings
The gathered snippet does not provide a complete severity breakdown; not fully verifiable from the available result.
Fix status
Some issues were fixed; the report text indicates fixes were made, but the full per-finding status is not fully verifiable from the snippet.
Evidence (2)

audit

one source

PeckShield — Fluid Audit Report #2023-245.

Auditor
PeckShield
Report date
2023-11-10
Scope
Fluid Liquidity, Lending/iTokens, VaultT1, factories, oracle integrations and administration; reviewed commit 5b3bfd1, fixes checked at 7a0cac2. Covers deployed code: Not verifiable as of September 4, 2026.
Findings
0 critical, 4 high, 4 medium, 5 low. Key issues included privileged functions, oracle price scaling, collateral-factor and position-ownership logic, reentrancy, liquidation accounting, and admin-key trust.
Fix status
12 findings marked Resolved; admin-key issue marked Mitigated. Report states fixes were checked, but does not independently establish bytecode equality with every deployed chain instance.
Evidence (1)

audit

one source

Pre-launch comprehensive audit listed on Fluid’s audits/security page.

Auditor
PeckShield
Report date
2024-01-01
Scope
Pre-launch comprehensive audit for the Fluid protocol; exact lending-code coverage and deployed-code bytecode match are Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03 from the available snippet.
Fix status
Not verifiable as of 2026-09-03.
Evidence (1)

audit

two sources

Fluid lending/protocol security page and third-party summaries indicate a pre-launch comprehensive audit by PeckShield covering the lending/protocol surface before launch.

Auditor
PeckShield
Report date
2024
Scope
Pre-launch comprehensive audit for Fluid lending/protocol surface; exact file-level scope not verifiable from the gathered results.
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (2)

audit

one source

Statemind — Fluid Security Audit.

Auditor
Statemind
Report date
2023-12-29
Scope
Core Fluid Liquidity Layer, Lending/iTokens, VaultT1, oracles, rewards and supporting libraries; final reviewed commit f5a0711. Covers deployed code: Not verifiable as of September 4, 2026.
Findings
3 critical, 8 high, 15 medium, 40 informational. Critical examples: reward-rate decimal error, BigMathVault debt-factor error, and invalid tick debt-factor storage.
Fix status
52 fixed, 14 acknowledged: critical 3/3 fixed; high 7 fixed and 1 acknowledged; medium 9 fixed and 6 acknowledged; informational 33 fixed and 7 acknowledged.
Evidence (1)

audit

one source

Separate Liquidity Layer updates audit is listed on the official page, indicating later maintenance coverage beyond the main StateMind report.

Auditor
StateMind
Report date
2025-09-01
Scope
Fluid Liquidity Layer updates audit; lending-code coverage and deployed-code bytecode match are Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03 from the available snippet.
Fix status
Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

Statemind — Instadapp Liquidity Layer Update.

Auditor
Statemind
Report date
2025-10-14
Scope
Liquidity-layer update: net/skip transfers, withdrawal-limit decay, libraries, user/admin modules and proxy. Covers deployed code: Not verifiable as of September 4, 2026.
Findings
0 critical, 1 high, 4 informational. High issue: incorrect net-transfer calculation overpaying users.
Fix status
2 fixed and 3 acknowledged; the high issue was fixed at commit f13ee79.
Evidence (1)

audit

one source

Fluid Lending / broader Fluid protocol audit report hosted in Fluid docs. The accessible snippet states the audit of the codebase found 66 issues total: 3 critical, 8 high, 15 medium, 40 informational.

Auditor
StateMind
Report date
2026-02-09
Scope
Fluid codebase / protocol audit report (docs-hosted PDF); covers the lending-related codebase as part of the broader Fluid protocol surface, but bytecode-match coverage for deployed lending contracts is Not verifiable as of 2026-09-03.
Findings
Critical: 3; High: 8; Medium: 15. The snippet also reports 66 total issues, with 3 critical fixed, 7 high fixed and 1 high acknowledged, 9 medium fixed and 6 medium acknowledged.
Fix status
Mostly fixed/acknowledged as reported in the PDF snippet: 3 critical fixed; 7 high fixed, 1 high acknowledged; 9 medium fixed, 6 medium acknowledged; informational issues mostly fixed/acknowledged. Not verifiable as of 2026-09-03 for any additional post-report remediation or deployed-code bytecode match.
Evidence (2)

Team & Reputation

founders

two sources

Fluid Lending is built by the Instadapp team, founded by brothers Samyak Jain and Sowmay Jain, both *fully public* builders with a multi‑year DeFi track record rather than an anonymous team. ### Founders & prior track record

  • Founders: Samyak Jain (often described as founder/CEO) and Sowmay Jain (co‑founder/CTO).
  • Origins: Instadapp started around 2018 after an ETHIndia/Bengaluru hackathon, building smart‑account middleware and account‑abstraction style DeFi infrastructure.
  • Prior scale: Instadapp reportedly reached ~$12B TVL at peak and attracted investors like Pantera Capital and Naval Ravikant.
  • Innovation history: Credited by several independent commentators for work on flash‑loan architecture and DeFi smart accounts / account abstraction. ### Public vs. anonymous; credibility
  • The founders appear fully doxxed, with repeated coverage in investment notes (AppWorks), centralized exchange research (Phemex), Bankless, and analytics commentary.
  • Multiple independent reviews state that Fluid is “built by Instadapp”, tying the protocol to a long‑running, visible team rather than a fresh anonymous project.
  • AppWorks and other investors publicly disclose strategic/token investments in Fluid, which implies standard venture‑style due diligence on founders and operations. ### Incidents / hacks
  • Reviews and overviews referencing Instadapp and Fluid specifically highlight “no incidents since launch” for Instadapp infrastructure.
  • I cannot independently verify the full incident history on-chain in this run; therefore overall hack/incident status is Not verifiable as of 2026‑09‑03. ### Location, office, onshore/offshore
  • Sources describe the origin story in India (Delhi/Bengaluru) for Instadapp, but do not clearly specify current legal entity jurisdiction, office addresses, or regulatory licensing.
  • No independent confirmation of a specific registered office, onshore vs. offshore corporate structure, or licensing is visible in the retrieved data.
  • Accordingly, corporate structure, physical office details, and regulatory status are Not verifiable as of 2026‑09‑03. ### Reality check: real business vs. web front
  • Long‑running product suite (Instadapp, Avocado wallet, Instadapp Lite/Pro) and sustained coverage by Bankless, Token Terminal, CEX research desks, and multiple independent reviewers point to a real, operating DeFi business, not a thin marketing front.
  • Presence of external strategic investors and multi‑year shipped infrastructure materially increases team credibility vs. typical anonymous yield farms.
Evidence (15)

general reputation

two sources

Fluid Lending (part of the broader Fluid / Instadapp ecosystem) currently has a generally positive technical and ecosystem reputation, with no credible reports of fraud, rug-pull, or insolvency as of 2026‑09‑03. Protocol & founders / investors

  • Fluid is described as “Fluid (formerly Instadapp)”, a unified DeFi liquidity layer built by the Instadapp team, which has been active in Ethereum DeFi since the 2020 cycle.
  • Multiple independent analytics platforms (DefiLlama, Blockworks, OAK Research, Onchain Atlas, AprScope) track Fluid Lending and the broader Fluid protocol, indicating material TVL (hundreds of millions across Ethereum, Arbitrum, Base, Polygon, Plasma) and sustained usage rather than a short‑lived scheme.
  • No public records of mainstream VC backers are surfaced in the retrieved data; investor set is Not verifiable as of 2026‑09‑03. Audits / security posture
  • Specific audit firm names and reports for Fluid Lending are Not verifiable as of 2026‑09‑03; none of the surfaced sources link directly to auditor repositories.
  • The protocol integrates Chainlink CCIP and price feeds for cross‑chain token transfers and oracles, which is generally viewed as a security‑conscious design choice but is not a substitute for formal audits. Ecosystem integrations & sentiment
  • Fluid is integrated by other DeFi projects and tooling (Yield.xyz vaults, Almanak SDK connector, Eco.com architecture note, Dune data catalog namespace), which signals ecosystem trust and ongoing maintenance.
  • Analytics write‑ups (Blockworks, Onchain Atlas, DeFi Sentinel, Cube.Exchange) treat Fluid as a serious capital‑efficient DeFi protocol, focusing on design features (shared Liquidity Layer, smart collateral/debt, ERC‑4626 vaults, cross‑margin) rather than warning of misconduct.
  • Sentiment across these independent sources is neutral‑to‑positive, emphasizing innovation and TVL growth, with no major negative coverage. Criticisms, incidents, and legal/regulatory signals
  • No documented hacks, insolvencies, or rug‑pull events specific to Fluid Lending are found in the available sources; any such event is Not verifiable as of 2026‑09‑03.
  • No mentions of regulatory enforcement actions, sanctions listings, or lawsuits tied to Fluid, its core team, or its brand are found; legal/regulatory status is Not verifiable as of 2026‑09‑03. Unresolved concerns / risk flags
  • Absence of clearly surfaced audits and formal bug‑bounty details is a notable gap for institutional risk assessment (Not verifiable as of 2026‑09‑03).
  • Complex shared‑liquidity architecture (Lending + Vaults + DEX) increases smart‑contract and systemic risk even without any reported incident; several analyses highlight high capital‑efficiency and up‑to‑95% LTV borrowing, which inherently raises liquidation and contagion risk compared with more conservative lenders.
  • Multi‑chain deployments (Ethereum, Arbitrum, Base, Polygon, Plasma, BNB mentions) add operational and bridge/oracle risk; these are design‑level concerns rather than reputation issues. Overall, Fluid Lending has a credible, established DeFi reputation with meaningful integrations and TVL, but institutional users should treat the missing audit/bug‑bounty transparency and high capital‑efficiency design as key risk items for further due diligence.
Evidence (15)

Economy

TVL: $766.1M

model

one source

Economic model (as of September 5, 2026). Fluid Lending is a pooled, overcollateralized lend-and-earn market: suppliers deposit supported assets and receive fTokens; borrowers use collateralized vaults and pay utilization-sensitive interest. The primary yield source is borrower interest, not external strategy P&L. Fluid’s architecture also includes separate Vault, DEX and staking/restaking integrations; these create potential directional, oracle, liquidation and external-protocol exposure when used, but are not inherent to passive Lending deposits. Organic vs subsidized: Interest yield is economically organic.

Rewards contracts and lending reward-rate infrastructure exist, so incentive-subsidized APY is possible; the current organic share is Not verifiable as of September 5, 2026. Leverage/exposure: Passive suppliers are broadly market-neutral to asset price, subject to liquidity, oracle and smart-contract risk. Borrowers can leverage/loop, including cross-vault interactions. Audits identify isolated vault accounting with shared liquidity, potential cross-vault liquidation-liquidity risk, and utilization-kink rate spikes. Lock-ups/withdrawals/fees/limits: No protocol-wide maturity lock-up is identified; lending deposits use ERC-4626-style fTokens and documented deposit/withdraw functions.

Asset availability, borrow caps, withdrawal limits, pause controls and any product-specific fees can vary by market. Exact current parameters are Not verifiable as of September 5, 2026. TVL / revenue — DeFiLlama analytics, not on-chain verification: Total TVL is approximately $751.0m, up 13.5% over 30 days: Ethereum $524.1m (69.8%), Arbitrum $151.2m (20.1%), Plasma $50.8m (6.8%), Base $21.0m (2.8%), Polygon $3.9m (0.5%). Active loans are about $831.6m.

Trailing 30-day fees are $3.23m and protocol revenue $385.8k; annualized figures are approximately $54.4m and $7.5m. Product-level TVL, Dune-vs-Llama reconciliation, APY history/volatility and sustainability are Not verifiable as of September 5, 2026. Contradiction: The previously recorded $3.017b TVL is materially inconsistent with the current DeFiLlama snapshot (~$751m); the newer figure is used, but neither is Dune-verified. Structured fields: organic_yield_pct: null; leverage_ratio: null.

Evidence (4)

reserves

two sources

As of September 5, 2026, reserves are only partially verifiable. Dune MCP was unavailable for this run; therefore cross-chain on-chain balances, reserve composition, liabilities, and chain-level exposure are Not verifiable as of September 5, 2026. No reserve attestation or independently verified proof-of-reserves statement was located. Control and custody. Fluid Lending’s lending assets are described by Yearn Curation as concentrated in the Liquidity Layer at 0x52Aa…F4e497 (Ethereum), an upgradeable proxy whose admin is the Timelock.

The Timelock is governed by GovernorBravo with a stated one-day delay; the Guardian can pause certain protocols but cannot move funds. These are analytics/explorer-derived control findings, not a current Dune balance verification. Treasury policy. Governance materials state that protocol revenue is directed to the DAO treasury. A May 11, 2026 governance post says approximately $8.2M of Resolv-related bad debt was to be covered by the governance treasury, and that buybacks were paused to preserve and rebuild treasury resources.

These are governance disclosures, not proof of current assets. Reported size/composition. DeFiLlama’s current FLUID token page reports approximately $19.97M of token treasury value, overwhelmingly FLUID, plus immaterial majors/stablecoins; this is the token treasury, not necessarily Fluid Lending’s lending reserves. The previously recorded $149.04M DeFiLlama treasury estimate is not reproduced by the currently accessible page and should be treated as stale/unconfirmed. Contradiction: the prior figure materially exceeds the current displayed token-treasury figure; no raw on-chain reconciliation is available. Assessment: reserve transparency is insufficient for institutional verification. No current address-level balance sheet, reserve policy with minimum ratios, liability reconciliation, or third-party reserve attestation was found. “Solvent” claims in governance are unverified marketing/governance claims rather than independent attestations.

Evidence (4)

tokenomics

two sources

FLUID tokenomics (Fluid Lending; as of September 4, 2026)

  • Native token: FLUID (formerly INST), 100M genesis/max supply. Ethereum contract: 0x6f40d4A6237C257fff2dB00FA0510DeEECd303eb. Reported representations: Base 0x61E030A56D33e8260FdD81f03B162A79Fe3449Cd; Polygon 0xf50D05A1402d0adAfA880D36050736f9f6ee7dee; Arbitrum 0xaE7d4Bf2Bb00A2F4Ade1C726819FCACA0e517A5B. Plasma address: Not verifiable as of September 4, 2026.
  • Supply/valuation: 83.697M circulating, 100M total/max; CoinGecko reports ~$102.66M market cap and ~$122.66M FDV. DeFiLlama reports ~$102.06M market cap, so aggregator values differ slightly.
  • Allocation: 55% community; 23.79% current team; 12.07% investors; 7.85% future team/ecosystem partnerships; 1.27% advisors. About 40M community tokens were sent to the DAO treasury at TGE for staged distribution.
  • Utility/governance: FLUID holders vote on DAO proposals and control treasury/governance decisions. It is not required for lending transactions. Governance documentation also describes revenue-directed buybacks and reserve accumulation, but not a contractual direct revenue share to holders.
  • Buybacks/burns/emissions: A buyback program was announced, including an initial period directing Ethereum revenue to purchases. No automatic burn or ongoing inflationary FLUID emission schedule is documented; announced buyback execution and any burns are Not verifiable as of September 4, 2026 without raw on-chain analysis.
  • Unlocks: Disclosed insider vesting was four years from July 2021; the report says insider tokens fully vested. DeFiLlama shows 83.7% unlocked and a 5M-token DAO-incentive cliff on August 7, 2026. Whether announced unlocks actually occurred on-chain: Not verifiable as of September 4, 2026.
  • Concentration/controls/liquidity: Top-holder concentration, insider-wallet attribution, mint/blacklist/fee-switch authority, and chain-by-chain DEX depth are Not verifiable as of September 4, 2026. Main reported listings include Deepcoin, Bybit and OKX; Ethereum liquidity includes Fluid DEX and Uniswap v3, with proposed Base/Arbitrum bootstrapping. Contradiction: Arbitrum’s reported FLUID address differs across sources; treat the address as unresolved until explorer-level verification.
Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Under a Bitcoin move below $10,000, the main risk for Fluid Lending is a sharp rise in undercollateralized borrow positions, which can force margin calls and then liquidations if borrowers do not add collateral or repay fast enough. This is consistent with how Bitcoin-collateralized lending stress works generally: lower BTC prices push loan-to-value ratios higher, margin calls are triggered around configured thresholds, and continued price weakness can move positions into liquidation. For Fluid specifically, the web results confirm that Fluid combines lending and DEX functions and is live on Ethereum, Arbitrum, Base, and Polygon; one source also mentions withdrawal queues may form in stress scenarios.

However, the protocol-specific liquidation thresholds, BTC collateral share, and chain-by-chain exposure are not verifiable as of 2026-09-03 from the available sources, and I cannot confirm how much of Fluid’s lending book is exposed to BTC collateral on Arbitrum, Base, Ethereum, Plasma, or Polygon. Key stress implications:

  • Borrowers using BTC collateral would face the fastest deterioration in collateral coverage as BTC falls below $10,000.
  • Liquidations could increase market sell pressure, especially if multiple positions are triggered together.
  • If Fluid’s system or user behavior leads to heavy exit demand, withdrawal queues may appear, which can delay deleveraging and redemptions. Not verifiable as of 2026-09-03: current BTC-collateral concentration, exact liquidation bands, pool-level solvency impact, and chain-level TVL/exposure for Fluid Lending.
Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral asset in Fluid Lending is a material stress event, because Fluid uses high-LTV lending and generally only partial liquidations before a position reaches the max liquidation limit. If the largest collateral is also highly concentrated, the immediate effect would be a sharp rise in undercollateralized positions, forced liquidations, and possible bad debt if liquidation cannot fully restore health. What can be said from the available sources is limited: the web results confirm Fluid is live on Ethereum, Arbitrum, Base, and Polygon, and that its design relies on automated limits and partial liquidations to reduce cascading losses.

They also show governance-deployed network limits starting at $7.5m and expanding by checkpoints, which implies the protocol intentionally throttles risk rather than relying on a large static buffer. A useful benchmark from independent analysis is Yearn Curation’s February/March 2026 assessment, which said wstUSR was the largest supply asset at 18.9% of all-chain lending TVL and that a subsequent depeg-contagion event produced an estimated $10–17.5M of bad debt. That history indicates Fluid can convert a large collateral depeg into realized losses, not just temporary volatility.

For a 20% depeg specifically, the loss severity depends on each borrower’s starting LTV, liquidation threshold, and liquidation penalty. A borrower already near the liquidation threshold can become insolvent quickly; a borrower with more equity may be liquidated with less or no bad debt. The provided sources do not contain enough live position-level data to quantify protocol-wide losses for today, so the aggregate impact is Not verifiable as of 2026-09-03.

Evidence (8)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Fluid Lending’s documented stress loss path is a bad-debt event after an oracle/price or collateralization failure, where liquidations do not fully repay borrowings and the residual shortfall is pushed to the protocol’s recovery process. In the 2026 Resolv incident, Fluid’s governance post-mortem says the protocol worked with Resolv to liquidate pre-incident positions and then allocated the remaining ~$19.3M bad debt across Resolv (~$9.7M), the Fluid governance treasury (~$8.2M), and the Fluid team (~$1.5M, reimbursable from future protocol revenue). For the requested top counterparty insolvent scenario, the expected loss path is: the insolvent counterparty’s obligations first impair its own positions; then any residual deficit is socialized through the protocol’s loss-resolution decision rather than being automatically absorbed by solvent users.

The public materials available here do not let me verify a chain-specific, contract-by-contract waterfall for Ethereum, Arbitrum, Base, Plasma, and Polygon, so the chain-by-chain exposure split is Not verifiable as of 2026-09-04. Who absorbs it: based on the incident disclosures, the absorber set is the counterparty itself to the extent of its remaining obligation, then Fluid governance treasury, and then the core team / future protocol revenue for the team’s share; there is no verified evidence in the gathered sources of an on-chain insurance fund or automatic lender-side indemnity for all losses. Compensation path: affected positions were to be made whole through the agreed settlement mechanism, with remaining USR burned at contract level and users with healthy positions redeeming directly through Resolv.

Impact path through smart contracts: the technical docs indicate Fluid’s vault/liquidation modules can liquidate bad debt and route liquidations via resolver contracts, so the operational effect is that insolvency propagates from undercollateralized positions into liquidation/resolution logic, then into treasury or revenue-backed recapitalization if the loss exceeds what liquidation recovers.

Evidence (6)

stress scenario - committed fraud by the DAO or owners

two sources

For the specific stress scenario of committed fraud by the DAO or owners, I found no verifiable evidence that Fluid Lending’s DAO or owners have been accused, charged, or adjudicated for fraud as of 2026-09-03. Not verifiable as of 2026-09-03. What *is* verifiable is that Fluid’s own ecosystem has had a reported security incident affecting its rewards distribution system, described in third-party coverage as a compromise of a Fluid team account that rerouted FLUID tokens and some cbBTC; that is a security exploit, not proof of DAO/owner fraud.

The same coverage explicitly says Merkl was not involved and attributes the fault to the Fluid finance team’s account compromise, but it does not establish intentional fraud or criminal conduct by the DAO or owners. A separate support document from Eco states that Fluid’s Lending and DEX share a correlated risk surface through a shared Liquidity Layer, meaning a bug in one component can affect the other, but this is an architectural risk statement rather than evidence of fraud. Because the question asks about fraud by the DAO or owners, the current evidence supports only a not verifiable conclusion, not a fraud finding.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

For Fluid Lending, a negative 30-day primary yield source is Not verifiable as of 2026-09-03 from the available results, because the provided sources are general liquidity-stress references and do not contain protocol-specific, chain-specific yield attribution for Fluid Lending. The only supportable conclusion is that a negative primary yield-source scenario should be treated as a severe income-shock stress requiring validation against current on-chain and protocol disclosures, which are unavailable here. Given the protocol scope you provided, the exposure should be assessed separately on Arbitrum, Base, Ethereum, Plasma, and Polygon, but chain-level exposure and 30-day yield contribution are not verifiable as of 2026-09-03 in this run.

No credible source in the result set identifies Fluid Lending’s current primary yield source, its 30-day direction, or whether any one chain dominates that yield. What can be said from stress-testing literature is that a negative yield shock is typically modeled as a funding/liquidity stress that reduces internally generated cash flow and weakens the ability to absorb outflows, so it should be paired with contingency-funding and liquidity-buffer analysis rather than assumed to be self-correcting. For a DeFi lending protocol, the practical risk question is whether the yield engine is dependent on variable external rates, incentives, or borrower demand; however, that dependency is Not verifiable as of 2026-09-03 from the provided material.

If you want, I can still produce a protocol-risk memo template for Fluid Lending that marks each chain and yield source as verified / unverified / not verifiable using only the evidence available here.

Evidence (4)

Governance & Legal

governance

unverified

As of September 13, 2026, Fluid Lending governance is operational but not fully decentralized. The 2024 transfer proposal assigned protocol ownership to Instadapp DAO governance, while retaining the Instadapp team multisig 0x4F6F977aCDD1177DCD81aB83074855EcB9C2D49e as fToken/vault deployer and Liquidity Layer Guardian. The Guardian can pause Class-0 lending/vault protocols; the proposal states it cannot withdraw user funds.

The team also controls restricted reward-rebalancer operations. Proposal process: forum discussion → Snapshot/DAO vote → timelocked execution; the documented timelock configuration uses approximately 1 day voting delay, 2-day voting period, and 1-day execution queue. The 2026 Foundation proposal proposed transferring IP, frontend domains, contracts, and brand assets to a Cayman Islands non-profit Foundation, with a $250,000/month DAO grant.

However, the proposal itself stated that only Ethereum was then under direct governance and that IP/deployment transfers were future actions. Completion, vote result, Foundation registration number, and director roster: Not verifiable as of 2026-09-13. Control assessment: smart-contract governance is real for parameters and listed deployments, but team emergency and deployment powers make the DAO partially symbolic operationally.

Frontend/development control remains associated with Instadapp until the Foundation transfer is independently confirmed. Instadapp’s Terms identify the operating entity as InstaDApp Labs LLC; jurisdiction, registration number, and current directors: Not verifiable as of 2026-09-13. Voting concentration, top FLUID holders, multisig threshold/signers/independence, and cross-chain admin ownership: Not verifiable as of 2026-09-13 (Dune unavailable; no on-chain claims inferred).

CONTRADICTION/RISK CALLOUT: “Ownership transferred to governance” conflicts with retained team Guardian/deployer powers and the later Foundation proposal’s statement that only Ethereum was directly governed. The on-chain status of the promised cross-chain and legal transfers is not verifiable in this run.

Timelock
Yes
Timelock delay hours
24
Admin can drain
No
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

one source

Available web information on Fluid Lending / fluid-lending is extremely sparse and appears fragmented, with several results referring instead to Fluid (an on‑chain liquidity routing protocol for CeFi margin trading) or other similarly named projects, not a clear DeFi lending platform across Arbitrum, Base, Ethereum, Plasma, Polygon. Because I cannot reliably match contracts, teams, or app frontends to the exact slug and chain set you provided, any legal/regulatory assessment would be speculative. Given the research constraints and name‑collision guard, the only defensible output is:

  • Entity: Not verifiable as of 2026‑09‑03.
  • Jurisdiction: Not verifiable as of 2026‑09‑03.
  • Legal structure (company / foundation / DAO): Not verifiable as of 2026‑09‑03.
  • Terms of Service / user restrictions: Not verifiable as of 2026‑09‑03.
  • KYC / AML requirements: Not verifiable as of 2026‑09‑03.
  • Regulatory classification (lending platform, broker‑dealer, etc.): Not verifiable as of 2026‑09‑03.
  • Regulatory warnings, enforcement actions, or licenses: Not verifiable as of 2026‑09‑03.
  • Court cases or litigation involving the protocol or its operators: Not verifiable as of 2026‑09‑03.
  • Sanctions status (OFAC/EU/UK/etc.): Not verifiable as of 2026‑09‑03.
  • Data protection / privacy policy, GDPR alignment: Not verifiable as of 2026‑09‑03. Risk‑relevant implications for an institutional user, based on the absence of verifiable data:
  • Counterparty & governance opacity: Without a confirmed legal entity, jurisdiction, or governance framework, you must treat the protocol as having *unknown operator risk* and *unclear recourse* in case of loss or dispute.
  • Regulatory perimeter risk: With no visible licensing, ToS, or KYC/AML framework, you cannot assess whether use would be consistent with your own regulatory obligations; this is a material compliance risk for institutions.
  • Name‑collision / phishing risk: Multiple "Fluid" projects exist; interacting with the wrong contracts or frontends is a non‑trivial operational hazard for routing any funds. For due diligence, next steps should include: on‑chain address discovery through explorers, direct contact with the team for corporate and legal documentation, and internal legal review before any exposure. Until then, treat Fluid Lending (fluid-lending) as information‑dark and high‑uncertainty from a legal/regulatory standpoint.
Evidence (2)

legal registries

two sources

No exact GLEIF LEI record for 'Fluid Lending'. OFAC SDN screening of 'Fluid Lending': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Fluid Lending
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Fluid Lending does not appear to issue its own stablecoin, and the available evidence points to it supporting external stablecoins such as USDC, USDT, GHO, and USR rather than minting a native one. The only verifiable depeg-related event tied to Fluid Lending was the March 2026 USR incident, when Fluid paused the USR marketplace and later discussed burning remaining USR positions; however, the evidence does not establish how many separate depeg events occurred inside Fluid Lending beyond that one incident, nor does it provide a protocol-level depeg percentage for Fluid’s supported stablecoin set as a whole. Therefore: own_stablecoin = false; stable = null; depeg_count = 1; max_depeg_pct = null; last_depeg_date = 2026-03-22; stablecoin_ids = ["USDC","USDT","GHO","USR"].

Own stablecoin
No
Depeg count
1
Last depeg date
2026-03-22
Stablecoin ids
  • USDC
  • USDT
  • GHO
  • USR
Evidence (6)

Risks & Strengths

risks

two sources

Fluid Lending’s principal risks are concentrated in oracle/liquidation design, shared-liquidity architecture, and deployment complexity across five chains. Audit coverage and a live bug bounty reduce—but do not eliminate—the possibility of smart-contract, configuration, or operational losses. On-chain exposure, reserves, utilization, and chain-level concentration are Not verifiable as of September 5, 2026 because Dune MCP is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle and price-feed manipulationIncorrect collateral or debt prices can permit under-collateralized borrowing, premature liquidations, or bad debt. Fluid’s audit materials identify oracle pricing as critical to lending safety.HighMediumMulti-source oracle design is documented; oracle and targeted secondary-attack scenarios are included in the bounty scope.Feed outages, stale prices, correlated-source failures, and manipulation of thinly traded collateral remain possible.
Liquidation liquidity shortfallLarge liquidations may move collateral prices against liquidators, making liquidations unprofitable and leaving lenders with bad debt; MixBytes specifically noted the absence of a supply limit.HighMediumBorrow limits, liquidation incentives, and tick/branch liquidation logic are implemented or documented.No verified evidence that caps are dynamically calibrated to market depth across all listed assets and chains.
Shared-liquidity contagionMultiple vaults draw from the same Liquidity contract; one market can consume liquidity needed to liquidate or withdraw from another, creating cross-market stress.HighMediumBorrow limits and utilization/rate controls are available; governance controls listings and parameters.Cross-market liquidity reserves and current utilization are Not verifiable as of September 5, 2026.
Smart-contract complexity and reentrancyHighly optimized modular contracts, proxies, factories, and cross-contract calls increase audit and maintenance difficulty; the audit acknowledged cross-contract reentrancy concerns.HighMediumMultiple external audits, open-source code, non-reentrancy protections in lending code, and a bounty program are in place.Audit findings do not prove absence of undiscovered vulnerabilities, especially in upgrades and integrations.
Multi-chain operational divergenceDeployments across Ethereum, Arbitrum, Base, Polygon, and Plasma increase risks from parameter drift, chain outages, oracle differences, and uneven liquidity.MediumMediumSeparate chain deployments, documented deployment scripts, and chain-specific configuration are used.Chain-level TVL, utilization, configuration parity, and concentration are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Fluid Lending’s main strengths are its capital efficiency, Smart Collateral/Smart Debt design, liquidation efficiency, rate flexibility, and security/risk controls. The most credible evidence in the provided results is the Yearn Curation report, which highlights a monotonic fToken exchange-rate design under stress, a rapid pause-and-freeze response during the March 2026 incident, fully programmatic interest/exchange rates with no offchain lending oracle, and an active Immunefi bounty; multiple independent writeups also point to Fluid’s unified liquidity layer and high LTV/low liquidation-penalty mechanics as core advantages.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 27 two independent sources, 17 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-26.