HyperLend Pooled

Orange · 61/100

Executive summary

HyperLend Pooled is an Aave v3.2-derived overcollateralized lending protocol on Hyperliquid L1, scoring 66/100 (orange band) with a -10 penalty for unresolved incident remediation.

  • Security: Three independent audits (Ackee, Cantina, Pashov) identified 1 Critical (stale Chainlink price), 1 High (locked tokens), and 17 Medium findings across core, isolated, and looping contracts; Ackee's final report marked most issues fixed, but M13 acknowledged and bytecode match to deployed contracts is not verifiable as of 2026-09-04. Kann's May 2026 leveraged-lending review found only Low/Informational issues.
  • Incidents: March 2026 Resolv USR depeg ($25M exploited via compromised AWS KMS) affected HyperLend's USR market; protocol froze the market, disabled USR borrowing/collateral, enabled Escape Hatch, and scheduled liquidations at $0.50/USR, but remediation remains in progress with no verified closure or reimbursement as of 2026-09-06.
  • Governance & custody: Materially centralized; Governance Multisig controls upgradeable proxies via 168-hour (core) and 6-hour (risk) timelocks; no operational DAO voting or verified signer identities. Non-custodial for users (hToken accounting), but admin roles can pause, configure parameters, and upgrade implementations.
  • Top risks: Pooled bad-debt contagion across shared reserves; critical dependence on Hyperliquid L1 infrastructure, HLP vault, and weighted-median oracle (CEX + validator aggregation); oracle/liquidation failure on low-liquidity assets; young chain with unverified on-chain reserve composition and borrower concentration.
  • Strengths: Native Hyperliquid integration; modular core/isolated pool design; $530M TVL as dominant L1 lending venue; capital-efficient Aave architecture; multiple audits with no verified exploits of core contracts; active bug bounty ($250k program, unverified payouts).
  • Unverified: Deployed-contract bytecode match, multisig signer identities/thresholds, reserve composition, borrower concentration, TVL/loan on-chain verification, DAO governance mechanics, and final USR incident loss/reimbursement all not verifiable as of 2026-09-04–06 due to unavailable Dune/on-chain tooling.
  • Recommended exposure: Conservative allocation only; limit to <5% of portfolio given unresolved incident, centralized control, single-chain/HLP dependency, and unverified on-chain state; prefer isolated pools over core for tail-risk mitigation; monitor USR market closure and any further governance/oracle incidents before increasing.
  • Open questions: Verify deployed bytecode matches audited commits; confirm Governance Multisig signer count, identities, and threshold; obtain current reserve composition, top-10 borrower concentration, and health-factor distribution; validate USR incident final loss, reimbursement plan, and closure completion; assess HLP vault stress scenarios and oracle latency/manipulation risk for low-cap collateral.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 10 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2025-06-16 is older than a year
Incidents 20% 100 20.0 1 open incident(s), $0 at risk (1 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 3 0.6 TVL $529,688,881 = 3% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 20/38 verified facts; 38/38 fresh (180d)

Identification

protocol identification

one source

HyperLend Pooled appears to be a perpetuals‑L1–native pooled lending/yield product on Hyperliquid, but key technical and on‑chain details are currently Not verifiable as of 2026‑09‑04 under your constraints. Because Dune MCP is unavailable, no on‑chain facts can be verified; all below is based on web sources only and must be treated as aggregator / descriptive data, not on‑chain truth. ### 1. Protocol identification

  • Name / slug: The yield product referenced as “HyperLend Pooled” / slug hyperlend-pooled is listed in DeFi/yield aggregators as a strategy on Hyperliquid L1, not as a standalone multi‑chain DeFi protocol.
  • Category: Likely a lending / pooled yield product integrated with Hyperliquid’s native L1 perps / money‑market ecosystem.
  • Chains: Only Hyperliquid L1 is referenced for this slug; no credible evidence of Ethereum, L2, or other chains.
  • Website / docs: No clearly independent website or documentation specifically branded “HyperLend Pooled” can be matched with high confidence to this slug while confirming contract addresses and chain. Any links would be Not verifiable as of 2026‑09‑04 under the name‑collision rule.
  • Native token: No reliable evidence of a distinct HLEND‑style native token tied specifically to “HyperLend Pooled” on Hyperliquid L1. Many Hyperliquid products use HL‑style internal accounting, but mapping that to a standalone protocol token is Not verifiable as of 2026‑09‑04.
  • Main contracts & explorer verification:
  • Without Dune and with Hyperliquid L1 being a custom chain, contract addresses, their roles, and verification status on an explorer cannot be cross‑checked with ≥2 independent sources in a non‑speculative way.
  • Therefore all specific contract‑level details are Not verifiable as of 2026‑09‑04.
  • Launch date: Aggregators list Hyperliquid L1 yield products beginning in 2024–2025, but do not give a precise launch date per product; for “hyperlend-pooled” this is Not verifiable as of 2026‑09‑04. ### 2. Fork lineage & code provenance
  • Is it a fork? No credible public source now clearly states that “HyperLend Pooled” is a fork of Aave, Compound, Morpho, or other major lending protocol. Any such claim is Not verifiable as of 2026‑09‑04.
  • Changes vs. upstream / audits:
  • No identified audit reports (from major auditors’ sites or GitHub) that explicitly name HyperLend Pooled on Hyperliquid L1.
  • Therefore whether it is a fork, which modules were changed, and whether those changes were audited is Not verifiable as of 2026‑09‑04.
  • Malicious‑modification history in similar forks:
  • Generic lending‑fork incident history (e.g., malicious parameters in Compound/Aave forks) exists, but cannot be tied specifically or even generically to HyperLend Pooled without addresses.
  • Any association of this product with past malicious forks is Not verifiable as of 2026‑09‑04. Risk‑analysis takeaway: for this slug on Hyperliquid L1, you currently lack verified contracts, audits, fork lineage, and on‑chain TVL/exposure. Treat this as high information‑risk and do not rely on marketing or aggregator labels without independent technical verification.
Evidence (3)

maturity

two sources

HyperLend Pooled appears to be a real, active product rather than a pure landing page: the official site presents the protocol brand, while the docs describe a functional Pool contract as the primary user interface with supply, withdraw, borrow, repay, collateral, liquidation, and flash-loan actions. The documentation also exposes contract addresses and a developer API page, which is a strong sign of product maturity and developer support. That said, live deposit/withdrawal functionality cannot be independently verified here, and the site/app was not directly tested in this run; therefore, live user-flow status is Not verifiable as of 2026-09-04.

Likewise, broken links, fake metrics, and template reuse cannot be confirmed from the available evidence alone, so those checks are Not verifiable as of 2026-09-04. The strongest evidence of maturity is the presence of protocol docs, contract-address pages, source-code references on GitHub, and an API page, which together indicate more than a marketing landing page. An external ecosystem guide also describes a working app flow for supplying assets via a wallet on the HyperLend app, suggesting the front end is intended for live use.

Open API: Yes, likely. The docs include a dedicated API page under developer documentation, which indicates an exposed developer interface rather than only a closed consumer UI. ## Bottom line

  • Real protocol/product surface: yes, likely
  • Mere landing page: no strong evidence of that
  • Live deposits/withdrawals: Not verifiable as of 2026-09-04
  • Broken links / fake metrics / template signs: Not verifiable as of 2026-09-04
  • Open API: yes, likely
Evidence (7)

Security

bug bounty

unverified

HyperLend Pooled has an active bug bounty program. The program is documented in HyperLend’s bug bounty page and mirrored in the project’s GitHub bounty repository; the docs say submissions should include a detailed report, PoC/reproduction steps, and be emailed to fbslo@hyperlend.finance, with first-to-report rewards and exclusions for theoretical issues, UI-only issues, third-party integrations Hyperlend does not control, and ordinary market risk. Rewards are paid in USDC or protocol-native tokens on Hyperliquid, with severity-based discretion by the Hyperlend team.

The earliest public evidence of the program appears in the GitHub repository dated 2024-07-24. A later HyperLend post states the mainnet bug bounty became eligible after a 7-day timelock/review period and mentions a $250k program, but that is an unverified marketing claim unless cross-checked elsewhere. Publicly visible results are not clearly enumerated; no confirmed disclosed payouts or resolved findings were found in the gathered sources, so results are Not verifiable as of 2026-09-04.

Active
Yes
Platform
GitHub / direct submission to HyperLend (email); referenced alongside Hyperliquid payout rail
Max payout
$250K
Since
2024-07-24
Evidence (4)

counterparty risks

one source

Дата проверки: 6 сентября 2026 г. Dune MCP недоступен; ончейн-состав резервов, доли активов и концентрация контрагентов — Not verifiable as of September 6, 2026. ### Оценка зависимостей и контрагентского риска

  • Критическая зависимость — Hyperliquid L1/HyperEVM. HyperLend Pooled не является независимым кредитным рынком: его инфраструктура, ликвидации и доступ к ликвидности зависят от Hyperliquid. Документация описывает HLP как пул, который передаёт USDC в Hyperliquid L1 и получает доходы/убытки от торговли; следовательно, остановка matching/clearing engine, сбой L1, ликвидаций или HLP может вызвать задержку выводов, bad debt или потерю средств.
  • Oracle/manipulation risk — высокий для низколиквидных активов. Hyperliquid использует weighted-median цены от Binance, OKX, Bybit, Kraken, KuCoin, Gate, MEXC и Hyperliquid; итоговая цена дополнительно агрегируется между валидаторами с учётом их стейка. Это снижает риск одной площадки, но оставляет зависимость от внешних CEX, валидаторов, качества spot-ликвидности и задержек обновления. Для тонких рынков возможны ценовая манипуляция, резкий mark-price разрыв и каскадные ликвидации.
  • HLP/market-maker exposure. HLP выступает экономическим контрагентом ликвидности для торгового потока Hyperliquid и несёт торговые убытки/прибыль. Поэтому доходность пула зависит не только от кредитного спроса, но и от PnL трейдеров, ликвидаций и способности системы закрывать позиции в стрессовом рынке.
  • Bridges/custodians/CEX custody. Подтверждённой зависимости от стороннего моста, кастодиана, RWA-эмитента или отдельного централизованного market maker не найдено. Однако Hyperliquid L1/HLP является фактическим single-venue custody и execution dependency. Точный процент средств, связанный с каждым внешним CEX или активом, — Not verifiable as of September 6, 2026.
  • Stablecoin/LST/restaking risk. USDC явно участвует в HLP/wHLP-механике; наличие и доли других stablecoin, LST или restaking-токенов в Pooled-резервах не подтверждены. USDC depeg или невозможность погашения HLP ухудшит collateral value и ликвидность. > Противоречие: DeFiLlama классифицирует продукт как Hyperliquid L1 и показывает $554.08 млн TVL, тогда как документация HyperLend описывает основную lending-инфраструктуру как Hyperliquid EVM. Без Dune это расхождение нельзя разрешить; TVL и распределение по активам не принимаются как on-chain verified. Стресс-сценарии: сбой Hyperliquid, oracle dislocation/manipulation, HLP trading loss, USDC depeg, массовые ликвидации, невозможность погашения wHLP или ликвидационный backlog. Основной риск — концентрация в одном экосистемном контрагенте, а не диверсифицированная DeFi-зависимость. Structured fields:
  • dependency_failure_active: nullNot verifiable as of September 6, 2026.
  • max_exposure_pct: nullNot verifiable as of September 6, 2026.
Evidence (4)

crypto custody

unverified

HyperLend Pooled appears non-custodial: the interface terms say users remain responsible for their private keys and the application does not take custody of deposited crypto between transactions. The pooled market’s core pool docs describe deposits minting hTokens as on-chain receipt tokens and withdrawals burning those hTokens to redeem the underlying asset from the reserve, which indicates assets are held in smart contracts rather than by a centralized custodian. I found no evidence here that assets are segregated per user beyond normal accounting of pooled shares, so segregated_assets is null.

I also found no verified pause condition for withdrawals, so withdrawal_paused is null. Not verifiable as of 2026-09-06 for any deeper on-chain custody edge cases beyond the published docs.

Evidence (3)

incident

two sources

The only incident-like reference in the search results is a third-party mention of the March 2025 HLP incident on Hyperliquid, but that is about Hyperliquid’s HLP fund, not clearly HyperLend Pooled; the name-collision makes it not attributable to this protocol from the available evidence.

Date
2025-03-01
Cause
Other
Evidence (2)

incident

two sources

On March 22, 2026, the Resolv USR issuance incident affected HyperLend Pooled’s USR market on Hyperliquid L1. A compromised Resolv AWS KMS/SERVICE_ROLE signing key allowed approximately 80 million unbacked USR to be minted; attackers converted roughly $25 million into ETH and other assets. HyperLend was not directly exploited.

Affected parties were USR suppliers and two borrowers with more than 100 USR debt. HyperLend reported less than $2,000 total USR debt and no loans collateralized by USR. It froze the market, disabled USR borrowing and collateral use, enabled an Escape Hatch, and scheduled market closure and borrower liquidation at $0.50 per USR.

The remaining debt below $10 was to be covered by the treasury. The market page still described USR as frozen when checked, and no reliable post-closure confirmation or HyperLend-specific reimbursement accounting was found. HyperLend’s remediation therefore remains in progress.

Protocol/user realised loss: Not verifiable as of September 6, 2026. Recovered amount: Not verifiable as of September 6, 2026. User reimbursement: Not verifiable as of September 6, 2026.

Fix: market freeze, removal of USR borrowing/collateral functionality, Escape Hatch, planned closure and liquidation of residual borrowers. Current status: remediation_in_progress.

Date
2026-03-22
Cause
Key compromise
Attacker proceeds
$25.0M
Status
remediation in progress
Event id
hyperlend-pooled-resolv-usr-2026-03-22
Evidence (4)

key management

two sources

HyperLend Pooled’s key management is organized as a permissioned, role-based admin model rather than a user-custodied setup. The docs say the PoolConfigurator’s write methods can only be called by addresses with permissioned system roles managed by the ACLManager, while the PoolAddressesProvider acts as a registry for core components and can update proxy implementations. In practice, this means ordinary users manage their own funds through the Pool contract, but sensitive protocol administration is separated into privileged roles for configuration, oracle setup, and contract upgrades.

The protocol also describes itself as non-custodial, meaning user assets are managed by smart contracts rather than a central operator. For this specific slug, the documentation available in the provided sources is enough to describe the access-control structure, but it does not expose the exact multisig signers, threshold, or operational key rotation policy. That part is Not verifiable as of 2026-09-04 from the supplied sources.

Evidence (5)

smart-contract

two sources

Assessment date: September 6, 2026. The supplied “Hyperliquid L1” label is imprecise: the contracts are deployed on HyperEVM, Hyperliquid’s EVM-compatible chain. The current canonical addresses are now verifiable through HyperLend documentation and HyperEVMScan, correcting the prior finding. Core architecture ``text Governance multisig │ Timelock A/B/C ── Executor │ PoolAddressesProvider (owner-controlled registry) ├── Pool proxy ──> Pool implementation ├── PoolConfigurator ├── ACLManager ──> role-based admins └── Price Oracle Pool ──> hTokens / VariableDebtTokens `` Addresses

  • Pool proxy: 0x00A89d7a5A02160f20150EbEA7a2b5E4879A1A8b; implementation shown by explorer as 0xBEBb62C7…A92d49B06.
  • PoolAddressesProvider: 0x72c98246a98bFe64022a3190e7710E157497170C.
  • PoolConfigurator: 0x8CB4310dD38F6fD59388C9DE225f328092bdC379.
  • ACLManager: 0x10914Ee2C2dd3F3dEF9EFFB75906CA067700a04A.
  • ProxyAdmin: 0xdb3Bf3e22380780F75D7F57C772e71fCa7EBA027.
  • Governance multisig: 0x2110E7B8e925C387A88259CEac9bd82c47868E9C; Timelocks A/B/C and Executor are documented, but their live ownership, signer threshold, and delay are Not verifiable as of September 6, 2026. Controls and worst case The deployment is upgradeable: the Pool is an InitializableImmutableAdminUpgradeabilityProxy, while the provider exposes owner-only registry and implementation setters. ACL roles include Pool Admin, Risk Admin, Emergency Admin, Asset Listing Admin, Bridge, Flash Borrower, and Default Admin. These roles can change reserves, caps, interest-rate strategies, oracle addresses, token implementations, and pause/freeze status. Exact live role holders and whether any role is renounced are Not verifiable as of September 6, 2026. Users can normally withdraw permissionlessly while reserves have liquidity and are not paused; this does not protect against an upgrade, oracle replacement, malicious parameter change, or liquidity freeze. A compromised upgrade/admin path could alter accounting, block withdrawals, manipulate risk parameters, or redirect protocol-controlled funds. Direct arbitrary draining of all user deposits by an admin is Not verifiable as of September 6, 2026. Contradiction / finding: Explorer verification exists, but several linked libraries remain unverified. The Ackee audit is public, yet audit coverage of the currently deployed implementation is Not verifiable as of September 6, 2026. Dune decoded-event checks and on-chain timelock measurement were unavailable in this run; no values are inferred.
Upgradeable
Yes
Evidence (5)

audit

one source

Ackee published the clearest public audit summary for HyperLend. It states HyperLend engaged Ackee for an initial review from 2025-01-10 to 2025-02-07, a fix review from 2025-02-17 to 2025-02-24, and a third review from 2025-03-12 to 2025-03-18. The review covered hyperlend-core, hyperlend-isolated, looping-contracts, core-config-engine, and cross-chain-lending-deposits; the third review covered hyperlend-core-new and changes in src relative to Aave v3.2.

Ackee reported 44 findings total, including 1 Critical (C1: No revert on stale Chainlink price), 1 High (H1: Possible locked tokens), and several Medium issues such as arbitrary token transfer through unrestricted refund function. Ackee’s summary says the fix review and third review were performed, but the provided snippet does not fully enumerate which findings were fixed, so final fix status is only partially verifiable here.

Auditor
Ackee Blockchain Security
Report date
2025-03-18
Scope
hyperlend-core, hyperlend-isolated, looping-contracts, core-config-engine, cross-chain-lending-deposits; third review on hyperlend-core-new and src diffs vs Aave v3.2
Evidence (1)

audit

two sources

Ackee Blockchain Security — Hyperlend Protocol

Auditor
Ackee Blockchain Security
Report date
2025-03-24
Scope
Final report revisions covering hyperlend-core, hyperlend-isolated, looping-contracts, core-config-engine and cross-chain-lending-deposits; final revision reviewed hyperlend-core-new commit 0c2b14 and found no new issues.
Findings
Across revision 1: 1 critical, 1 high, 13 medium, 8 low, 11 warning and 10 informational findings. Critical: no revert on stale Chainlink price. High: possible locked tokens. Final status table marked the critical/high and almost all medium findings fixed; M13 acknowledged; several low/warning/info items acknowledged or partially fixed.
Fix status
Fix review (revision 2) recorded remediation statuses; revision 3 reported no new findings. Covers deployed code: Not verifiable as of September 5, 2026; the report notes missing deployment addresses and inability to test under real Hyperliquid conditions.
Evidence (2)

audit

two sources

Ackee performed a multi-round security review of the HyperLend core protocol (Aave v3.2–based), including pooled and isolated lending, configuration, cross-chain deposits and related contracts. The engagement ran January 10–February 7, 2025, with fix reviews February 17–24 and a third review March 12–18, 2025. Scope covered repositories hyperlend-core, hyperlend-isolated, looping-contracts, core-config-engine, and cross-chain-lending-deposits, plus a later hyperlend-core-new codebase.

This audit is on the protocol’s GitHub under the audits directory, but exact URL cannot be re-verified from on-chain. Bytecode/code match to the currently deployed HyperLend Pooled contracts on Hyperliquid L1 is Not verifiable as of 2026-09-04.

Auditor
Ackee Blockchain Security
Report date
2025-06-16
Scope
Core HyperLend lending protocol (pooled and isolated), looping contracts, configuration engine, cross-chain deposits; Aave v3.2-derived code changes.[1] Chain-specific deployment on Hyperliquid L1 and HLP-collateral integration are referenced in secondary sources but precise contract list for pooled products is Not verifiable as of 2026-09-04.
Findings
Ackee reports **44 findings** from Informational to **Critical** severity.[1][9] The most severe issue (C1) allowed theft of all collateral from isolated pools.[1] Public summary indicates at least one Critical and multiple non-trivial issues across lending logic and configuration. Detailed per-issue severities and IDs are in the full report hosted in the HyperLend audits GitHub, but that file is Not verifiable as of 2026-09-04.
Fix status
Ackee’s blog states that the critical C1 and other significant findings were addressed across subsequent fix reviews.[1] A later summary and secondary research pieces describe HyperLend’s codebase as "solid and ready for production" with mitigation measures in place for all significant findings.[4][11] However, exact per-issue status (Resolved vs Acknowledged) for all 44 findings and whether the final audited commit matches deployed pooled contracts on Hyperliquid L1 is Not verifiable as of 2026-09-04.
Evidence (4)

audit

one source

Cantina Competition — Hyperlend

Auditor
Cantina
Report date
2025-01-12
Scope
HyperLend P2P lending contracts, including LendingP2P.sol and related pricing/liquidation logic; competition ran November 13–December 4, 2024.
Findings
0 critical, 1 high, 4 medium. High: unrestricted repayLoan could pull repayment funds from a borrower. Medium findings included liquidation-accounting errors, precision loss, incorrect EMA timestamp and stale-price handling.
Fix status
The published report is a competition report and does not provide a remediation/fix-review status. Not verifiable as of September 5, 2026.
Evidence (2)

audit

two sources

Cantina was one of HyperLend’s three independent security reviews, but the publicly indexed results provided here do not include a standalone report with a finding list, so the exact critical/high/medium counts, fix status, and deployed-code coverage are not verifiable as of 2026-08-29. HyperLend’s own security page lists a V1 audit by Cantina Competition dated 2024-12-04, alongside Ackee and Pashov reviews.

Auditor
Cantina Competition
Report date
2024-12-04
Scope
Not verifiable as of 2026-08-29
Evidence (2)

audit

two sources

Previously recorded Pashov review rechecked; no independently verifiable remediation update was located.

Auditor
Pashov Audit Group
Report date
2025-01-11
Scope
Lending core, isolated pools, configuration, cross-chain deposits, HyperlendPair, Oracle, FlashLoanLogic, StrategyManager, and related looping functionality.
Findings
0 High, 4 Medium, and 5 Low were previously recorded from the published review. Exact issue-by-issue severity mapping is Not verifiable as of September 6, 2026.
Fix status
Secondary reporting states all Medium findings were resolved before publication and most Low findings addressed, with some acknowledged. Complete remediation status and deployed-code match are Not verifiable as of September 6, 2026.
Report url
https://github.com/hyperlendx/audits/blob/master/hyperlend/2025-01-11-pashov-security-review-hyperlend.pdf
Report id
doc:41072d1b518578f4
Covers deployed code
No
Unresolved high
0
Evidence (2)

audit

one source

Previously recorded Cantina competition report rechecked; no remediation update was located.

Auditor
Cantina Competition
Report date
2025-01-12
Scope
HyperLend P2P lending contracts, including LendingP2P.sol and related pricing and liquidation logic; competition period November 13–December 4, 2024.
Findings
0 Critical, 1 High, 4 Medium. High: unrestricted repayLoan could pull repayment funds from a borrower. Medium findings included liquidation-accounting errors, precision loss, incorrect EMA timestamp, and stale-price handling.
Fix status
The published competition report does not provide a remediation or fix-review status. Not verifiable as of September 6, 2026.
Report url
https://github.com/hyperlendx/audits/blob/master/hyperlend/2025-01-12-cantina-competition-hyperlend.pdf
Report id
doc:d87504d4d8fc7110
Covers deployed code
No
Unresolved high
1
Evidence (1)

audit

one source

Corrected Kann report status and finding accounting. This is a distinct published report and is not merged with the core pooled-lending audits.

Auditor
Kann Audits
Report date
2026-05-26
Scope
StrategyManagerFactory, StrategyManager, Looping, GluexAdapter, and LiquidSwapAdapter at commit 4f5deaf; leveraged-lending infrastructure on Hyperliquid.
Findings
0 Critical, 0 High, 0 Medium, 1 Low, and 4 Informational. Low: swap adapters wrap the entire native balance, inflating swap output. Informational findings concerned redundant transient-storage checks, full-position closure with unrelated debt, native refunds, and stale factory ownership indexing.
Fix status
I-01 was Resolved. L-01 and I-02 through I-04 were Acknowledged. No Critical, High, or Medium findings were reported. Whether remediation is deployed in current HyperLend Pooled contracts is Not verifiable as of September 6, 2026.
Report url
https://kannaudits.com/audits/hyperlend-leveraged-lending-may-2026
Report id
doc:f148c3cd39fa0c0d
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

two sources

Pashov Audit Group — HyperLend Security Review

Auditor
Pashov Audit Group
Report date
2025-01-17
Scope
Lending core, isolated-pool systems, configuration contracts, cross-chain deposit mechanisms, HyperlendPair, Oracle, FlashLoanLogic and StrategyManager; exact reviewed commits are not stated in the indexed summary.
Findings
0 high, 4 medium, 5 low; issues primarily concerned StrategyManager and Looping functionality, including swap/strategy logic, approvals, validation and oracle-related handling.
Fix status
Independent reporting states all medium findings were resolved before publication; most low findings were addressed, with some acknowledged and left open. The complete finding-by-finding remediation status is Not verifiable as of September 5, 2026.
Evidence (2)

audit

two sources

Community research and social posts attribute a full smart contract audit of HyperLend (including pooled lending) on Hyperliquid L1 to Pashov Audit Group in January 2025. Scope reportedly covered lending core modules, isolated pools, configuration contracts, cross-chain deposit mechanisms, and components like HyperlendPair, Oracle, FlashLoanLogic, and StrategyManager. The detailed report is said to be available in the HyperLend audits GitHub, but the exact file and bytecode match for HyperLend Pooled are Not verifiable as of 2026-09-04.

Auditor
Pashov Audit Group
Report date
2025-01-31
Scope
Full HyperLend smart contract suite on Hyperliquid, including core lending modules, isolated pools, configuration, cross-chain deposits, and selected strategy/flashloan-related contracts.[4][12] Precise coverage of the current HyperLend Pooled production addresses is Not verifiable as of 2026-09-04.
Findings
The community research summary notes that **all medium severity issues were resolved prior to publication**, most low-severity issues were fixed, and a few minor items remained acknowledged due to low impact.[4] Specific counts of Critical/High/Medium findings are not given; the text implies no remaining medium-or-higher issues at publication, but this is not independently confirmed from the original report and is therefore partly an unverified marketing claim.[4] Exact issue list and severity distribution are Not verifiable as of 2026-09-04.
Fix status
According to the community write-up, all medium findings were resolved, most low issues fixed, and remaining minor issues acknowledged, with the overall conclusion that the codebase was ready for production.[4] A social post by auditor researcher Hals claims "absolutely all issues are resolved" for a Hyperliquid lending audit of Hypurr/Hyperlend in April 2025.[10] Because these statements are not cross-checked against the original Pashov PDF, their completeness is an unverified marketing claim. Bytecode-match to deployed pooled contracts on Hyperliquid L1 is Not verifiable as of 2026-09-04.
Evidence (3)

Team & Reputation

founders

two sources

HyperLend Pooled appears to be a Hyperliquid ecosystem lending protocol, not a standalone company, and is closely tied to the Hyperliquid founding team rather than having a separately branded founding group. ### Founders & Team Linkage

  • HyperLend is described as the primary lending/money-market protocol on Hyperliquid’s HyperEVM chain, launched in March–April 2025.
  • Hyperliquid itself was founded by Jeff Yan (Jeffrey Yan), a Harvard math/CS graduate and former Hudson River Trading quant, who is publicly identified as founder/CEO in multiple independent profiles.
  • Articles and research on the Hyperliquid stack list HyperLend explicitly as one of the core products built under the Hyperliquid umbrella, alongside the derivatives DEX and HLP pool, implying shared engineering and product leadership rather than an unrelated team.
  • Hyperliquid Labs is reported to have been founded by Jeff Yan and his classmate “iliensinc”, a pseudonymous engineer, indicating the presence of at least one anon/pseudo core contributor. ### Public vs. Anonymous, Credibility
  • Jeff Yan is fully public: real name, educational background (Harvard), prior firm (Hudson River Trading), and prior venture (Chameleon Trading, a crypto market-making firm) are all documented across independent media and research sites.
  • The broader Hyperliquid team is described as an 11‑person, mostly technical group recruited from top math/science competitions, with no VC backing and funded from Chameleon Trading profits, suggesting a tight, trader‑engineer culture rather than a dispersed DAO structure.
  • HyperLend’s codebase is reviewed in external technical research (Token Metrics), with attribution to well-known, audited designs (Aave v3, FraxLend v3) rather than bespoke unaudited logic. ### Jurisdiction, Office, Business Reality
  • None of the independent profiles give a clear registered corporate jurisdiction, office address, or onshore vs. offshore structure for HyperLend specifically. Not verifiable as of 2026-09-04.
  • For Hyperliquid/Hyperliquid Labs, media note a low‑profile, security‑conscious posture, but do not specify a legal domicile or physical headquarters. Not verifiable as of 2026-09-04.
  • Several sources emphasize that Hyperliquid (and by extension HyperLend) is operated as a lean, profit-generating trading/engineering business, funded by trading profits and protocol revenue rather than VC, supporting the view that this is a real operating business with sustained product delivery, not a pure marketing front. ### Prior Projects / Outcomes / Hacks
  • Founders’ prior project Chameleon Trading is repeatedly cited as a major crypto market maker whose profits funded Hyperliquid; no credible sources mention major hacks or catastrophic failures tied to that entity as of the latest reporting.
  • For HyperLend itself, available third‑party research and risk reviews discuss protocol design and audits but do not report any major exploits or insolvency events. Not verifiable on-chain as of 2026-09-04. Overall reality check: HyperLend Pooled should be treated as a Hyperliquid-native product with founder exposure primarily to Jeff Yan and the Hyperliquid core team, featuring at least one pseudonymous co‑founder, an undocumented legal domicile, and limited public corporate scaffolding, but substantial evidence of real economic activity and engineering output tied to the broader Hyperliquid stack.
Evidence (15)

general reputation

two sources

HyperLend Pooled currently has a moderately positive but cautious reputation: seen as the core lending market on Hyperliquid L1, with no public fraud/rug/insolvency or sanctions allegations, but flagged as higher-risk due to its young chain, complex integrations, and evolving security track record. ### Overall sentiment & positioning

  • Multiple independent analytics sites describe HyperLend Pooled as the dominant lending protocol on Hyperliquid’s HyperEVM, with several hundred million USD in TVL and 100% of activity on Hyperliquid L1.
  • Ecosystem guides and research pieces frame it as the primary money market / credit layer for Hyperliquid, porting Aave‑style architecture with isolated pools and wHLP collateral integrations.
  • Coverage from DeFi media and ecosystem guides is generally neutral-to-positive, emphasizing capital efficiency and Hyperliquid-native design rather than speculative promotion. ### Security, audits, and risk grades
  • An independent risk-rating site (Hindenrank) gives HyperLend Pooled a Grade B, citing proven lending mechanics but “unique risks from HLP vault collateral integration and single-chain HyperEVM dependency.”
  • Hindenrank notes audits by Cantina, Ackee Blockchain, and Pashov, which improves perceived technical robustness but does not reach top-tier (A/A+) assurance.
  • Token Metrics’ code review describes a modular design with multiple pool types (core, isolated, P2P), signalling non-trivial complexity that can expand attack surface. ### Criticisms & unresolved concerns
  • Key structural concerns highlighted by independent analysts:
  • Single-chain concentration: all exposure on Hyperliquid L1; risk tightly coupled to Hyperliquid’s security and economic model.
  • wHLP / HLP collateral integration: using Hyperliquid LP vault positions as collateral introduces dependency on trading PnL, vault accounting, and liquidations across layers.
  • Young ecosystem: HyperEVM and Hyperliquid are comparatively new, with less battle-tested history than Ethereum mainnet; this is repeatedly flagged as a contextual risk.
  • No credible sources report major exploits, systemic insolvency, or governance crises as of the latest updates, but several risk reviews explicitly caution that tail risks around leveraged staking, ERC‑4626 vault strategies, and isolated pools remain largely unproven over full market cycles. ### Legal / regulatory / sanctions / fraud
  • Public corporate communication from Hyperion DeFi (a listed company) references using HyperLend for a permissioned lending pool, which implicitly signals institutional comfort but is not a regulatory endorsement.
  • Across available sources, there are no documented allegations of fraud, rug pull, sanctions listings, or formal regulatory enforcement actions against HyperLend Pooled or its team as of 2026‑09‑04. ### Data gaps
  • On‑chain verification (exact holders, incident timelines, insurance coverage, team entities) is Not verifiable as of 2026‑09‑04 under current constraints.
  • Founder identities, investor roster, and detailed corporate structuring are only indirectly referenced (e.g., ecosystem articles) and remain partially opaque, which is a residual reputational risk in institutional settings.
Evidence (12)

Economy

TVL: $529.7M

model

two sources

As of 2026-09-06 — Economic Model

  • Strategy / assets: HyperLend Pooled is pooled, overcollateralized lending—not a documented trading vault. Suppliers deposit supported single assets and receive interest-bearing hTokens; withdrawals burn hTokens and return the underlying. Observed markets include KHYPE, wstHYPE, WHYPE, PT-KHYPE, USDC, UBTC, beHYPE, UETH, USD₮0, USOL and USDE.
  • Yield source: Borrower interest is the primary source; rates vary by utilization and supply/demand. Suppliers may also receive a share of 0.04% flash-loan fees. Current reward APY is reported as 0% across listed pools, so the visible yield appears predominantly organic rather than emissions-subsidized.
  • Risk posture: The pooled product is not inherently market-neutral: lending is asset-denominated, and volatile collateral creates liquidation/oracle/market risk. It does not itself establish perp, restaking, looping or external-vault exposure. Borrowers can use leverage, but supplier leverage is not documented. The separate “Liquid Perpetual Positions” product should not be attributed to Pooled.
  • Withdrawals / gates: No deposit or withdrawal fee and no stated time lock. Withdrawals are subject to available reserve liquidity, supply caps, and—where the user has debt—health-factor constraints; withdrawals can therefore be delayed during high utilization.
  • Fees / revenue: Protocol revenue is a reserve-factor share of borrower interest, plus liquidation and flash-loan fees. DeFiLlama reports 30-day fees of $884,397 and revenue of $110,354, with $300.03m active loans.
  • TVL / chain: One chain only—Hyperliquid L1 (100%). DeFiLlama reports $554.08m TVL, +26% over 30 days; average supply APY 1.72%. Pool APYs range from 0% to 5.68% in the current snapshot. > Contradiction: DIA reports $841.5m TVL, versus DeFiLlama’s $554.08m. Both are aggregators; the discrepancy is unresolved. On-chain TVL, flows, APY history/volatility, and exact utilization are Not verifiable as of 2026-09-06 because Dune MCP is unavailable. organic_yield_pct: null leverage_ratio: null
Evidence (4)

reserves

one source

As of 2026-09-06, reserves/treasury balances are Not verifiable as of 2026-09-06. Dune MCP was unavailable for this run, so no on-chain balance, token-composition, latest-block, or execution-ID verification was performed. Do not treat DefiLlama TVL as treasury reserves. Known addresses: HyperLend’s published contract list identifies a Treasury contract at 0xA9A7e0E91689C49bf9F2A15a768cAebBA6A5EEC5, Treasury implementation 0x6A14A52bC00F60F6f13b960790Cf9a3D90267503, and Treasury Multisig 0xCBF400610DBF462fE316D8A7db6Ba78d57E43d7b.

Governance-related addresses include a Governance Multisig, multiple timelocks, Executor, and EmergencyAdmin Multisig. These establish published control endpoints, but not current ownership, signer set, quorum, or balances. Composition / custody: Not verifiable as of 2026-09-06. No reliable public reserve schedule or attestation was located.

HyperLend documentation states that reserve-factor interest is allocated to an insurance fund and treasury, and liquidation fees also flow to the treasury; this describes policy, not accumulated assets. Liabilities: Not verifiable as of 2026-09-06. DefiLlama reports approximately $554.08m TVL and $300.03m active loans, but these are analytics-platform figures, not an on-chain liabilities calculation and not a substitute for Dune verification. Attestations / assurance: Public materials reference smart-contract audits and a public audit repository, but the located audit evidence concerns code security, not proof of reserves or liabilities. Contradiction / limitation: Prior reports cited materially different aggregator TVL values. The current DefiLlama snapshot is $554.08m, but this cannot resolve treasury size or reserve coverage.

The gap remains a finding: no independently verified reserve/liability statement was located.

Evidence (4)

tokenomics

one source

HyperLend Pooled on Hyperliquid L1 does not have a clearly documented, widely traded native token under the slug *hyperlend-pooled* that can be reliably tied to this protocol as of 2026‑09‑04. Most search results for “HyperLend” or “Hyperliquid L1 lending” refer either to:

  • The Hyperliquid perpetuals DEX ecosystem and its own tokens/features, not a distinct “HyperLend Pooled” token.
  • Generic lending pools, strategy vaults, or copy-trade products using Hyperliquid infrastructure, without a separate ERC‑20‑style protocol token. Because the query specifies Hyperliquid L1 (a custom chain) and a slug *hyperlend-pooled*, but there is no independently verifiable contract address, token page, or listing matching that name:
  • Native token name/ticker & contract address: Not verifiable as of 2026‑09‑04.
  • Total vs circulating supply; market cap; FDV: Not verifiable as of 2026‑09‑04.
  • Token utility & governance role: No credible evidence of a dedicated governance token for “HyperLend Pooled” distinct from Hyperliquid ecosystem tokens. Not verifiable as of 2026‑09‑04.
  • Revenue share, buybacks, burns, staking rewards: Any such mechanisms would be implemented at the level of Hyperliquid or specific strategies; no independent confirmation for a “HyperLend Pooled” token. Not verifiable as of 2026‑09‑04.
  • Emissions schedule & unlock schedule; whether unlocks happened on-chain: Not verifiable as of 2026‑09‑04.
  • Allocations (team/investors/treasury/community): Not verifiable as of 2026‑09‑04.
  • Top-holder concentration & insider wallets: Not verifiable as of 2026‑09‑04.
  • Admin/mint/blacklist/fee-switch controls: No confirmed token contract, so these functions cannot be assessed. Not verifiable as of 2026‑09‑04.
  • DEX liquidity depth & main listings: There is no clearly matched token listing on major DEXes or CEXes under “HyperLend Pooled” on Hyperliquid L1 or other chains. Not verifiable as of 2026‑09‑04. Given the absence of independent, chain-confirmed evidence, the prudent institutional stance is:
  • Treat HyperLend Pooled as a *product/strategy* within the Hyperliquid ecosystem without its own native token, unless the protocol can supply auditable contract references.
  • Flag all marketing claims about a “HyperLend” token (if presented only in protocol UI/docs) as unverified marketing claim until corroborated via explorer records or Dune/on-chain data.
Evidence (1)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For HyperLend Pooled on Hyperliquid L1, a Bitcoin drop below $10,000 would only create stress for positions where BTC is used as collateral or as a correlated collateral proxy; the protocol’s liquidation logic is based on a borrower’s health factor, and positions become liquidatable when health factor falls below 1. A BTC collapse this severe would materially increase the likelihood of forced liquidations, but the exact impact on this protocol’s pool is Not verifiable as of 2026-09-04 because the provided sources do not include live pool composition, borrower leverage, or BTC-collateral exposure. What can be stated from the docs is that liquidators can repay debt and seize collateral, with a 50% close factor applying in some cases, and that liquidation occurs when collateral value no longer covers debt value.

That means the main stress channel is not Bitcoin price alone, but whether BTC-related collateral in the pool falls enough to push accounts below maintenance thresholds. Independent commentary also flags a broader tail-risk scenario for HyperLend Pooled: a vault loss or chain halt during market volatility could trigger cascading liquidations or bad debt, but this is a third-party risk assessment rather than on-chain verification.

Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

For a 20% depeg in the largest collateral, the protocol impact is not verifiable as of 2026-09-04 because no on-chain position, collateral mix, or liquidation-exposure data is available in the provided results. What can be stated is that HyperLend liquidates positions when health factor falls below 1, and its liquidation system can seize collateral at a discount to repay debt. The main stress mechanism is straightforward: if the largest collateral asset falls 20%, borrower health factors on positions using that asset as collateral would decline, potentially pushing some accounts below liquidation thresholds.

HyperLend’s documented liquidation mechanics allow up to 50% close factor in the standard case, meaning liquidators can repay up to half of the debt for many undercollateralized positions; in deeper distress, the protocol documentation also notes cases where up to 100% may be liquidated for very low-health positions. A relevant protocol-specific risk signal is that third-party analysis highlights HyperLend’s exposure to HYPE-related collateral, with one report stating that HYPE and related liquid-staking assets represented a large share of deposits and that a depeg in HLP/wHLP-style collateral could trigger cascading liquidations. However, that is an external risk assessment, not a verified on-chain exposure figure, and it does not substitute for actual protocol balances.

So the correct stress-scenario answer is: a 20% depeg of the largest collateral would likely increase liquidations and could create bad debt if liquidators are insufficient or collateral liquidity is thin, but the magnitude cannot be quantified from the available evidence.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

HyperLend Pooled is a pooled margin/lending system on Hyperliquid L1, so an insolvency of the largest borrower/top counterparty primarily manifests as a shortfall in the lending pool, not a direct OTC counterparty loss. 1. Insolvency trigger and loss path

  • Top borrower’s position value falls below debt plus required margin (e.g. due to extreme price move or oracle failure). Not verifiable as of [2026-09-04].
  • Liquidation bots/liquidators attempt to close the position against on-chain AMM/liquidity on Hyperliquid. If slippage/liquidity gaps are too large, the liquidated collateral does not fully cover the debt, creating bad debt in the pool. Not verifiable as of [2026-09-04].
  • Smart contracts record the shortfall as a negative equity position of the pool or affected market rather than an untracked hole. Not verifiable as of [2026-09-04]. 2. Who absorbs the loss?
  • Lenders/liquidity providers to the pool ultimately bear economic losses via:
  • Reduced pool equity / lower claim value versus deposited assets.
  • Potential haircut applied to all LPs in that market, proportional to share of the pool. Not verifiable as of [2026-09-04].
  • If a risk fund/insurance fund exists at protocol level, it may be tapped first to absorb bad debt before LPs are hit. This depends on protocol design; specific presence and size of such a fund for HyperLend Pooled is Not verifiable as of [2026-09-04]. 3. Compensation mechanics
  • In typical pooled margin systems, there is no ex-post compensation to lenders beyond predefined insurance mechanisms; losses are socialized.
  • If an insurance or safety module exists, LPs are compensated up to the fund balance; beyond that, losses remain with LPs. Not verifiable as of [2026-09-04]. 4. Smart-contract impact path
  • Liquidation contract: executes forced unwind, transfers collateral, and calculates residual bad debt. Not verifiable as of [2026-09-04].
  • Accounting/pool contract: updates pool assets, liabilities, and LP share balances to reflect realized loss; may trigger haircuts and disable new borrowing. Not verifiable as of [2026-09-04].
  • Governance/parameters: extreme event can lead to parameter changes (LTV, caps, delisting of collateral) through governance, affecting future risk but not retroactively fixing losses. Not verifiable as of [2026-09-04]. Given lack of verifiable technical documentation specific to HyperLend Pooled, all mechanism descriptions above are generic to pooled margin/lending designs and should be treated as structural risk expectations, not confirmed behavior. Not verifiable as of [2026-09-04].
Evidence (1)

stress scenario - committed fraud by the DAO or owners

two sources

For the stress scenario “committed fraud by the DAO or owners”, the available sources do not show a verified fraud event by HyperLend’s DAO or owners. The strongest supportable answer is that this risk is not verifiable as of 2026-09-04 based on the sources provided. What *is* documented is that HyperLend’s design requires users to trust the protocol and its operators in several ways: Ackee notes that users must trust Hyperlend not to lock funds or manipulate token prices, and that cross-chain gateways must relay messages correctly; it also highlights a critical pricing-related vulnerability in review, showing that governance/operator mistakes or abuse could materially affect users.

HyperLend’s own risk disclosure states that network control issues can interrupt block production and subvert funds, but that is a network risk, not evidence of DAO/owner fraud. The independent security/profile sources available here report no recorded security incidents to date. There is also a fake-website scam involving a lookalike domain, but that is an external phishing case, not fraud by HyperLend’s DAO or owners.

So, for an institutional stress test, the appropriate treatment is operator/governance fraud risk: present but unproven. The practical impact could include fund lockups, malicious parameter changes, oracle manipulation, or misleading disclosures, but the existence of such conduct is not verified in the supplied sources. If you need a binary classification, label this scenario Not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario with a negative 30-day primary yield source, HyperLend Pooled is best treated as a negative supplier-return case if the protocol’s core pool yield depends on borrower interest and that revenue source turns negative in the scenario. Public analytics show HyperLend Pooled’s average APY is currently positive, but the question asks for a stress case, and no source in the provided results verifies a 30-day primary yield source that is negative under current conditions. The key risk mechanism is straightforward: HyperLend’s lending pools generate yield from borrowing demand, so if the primary yield source becomes negative or fails to cover costs, supplier returns can compress to zero or below after fees and incentives.

However, the provided sources do not verify an actual negative 30-day yield for HyperLend Pooled, nor do they provide chain-level on-chain evidence for Hyperliquid L1 in this run. So the stress assessment is:

  • Primary yield source: borrowing-interest spread / pool revenue; could turn negative in a severe utilization or demand shock.
  • 30d outcome: Not verifiable as of 2026-09-04 for a negative primary-yield reading from the available sources.
  • Implication: if primary yield stays negative for 30 days, depositor APY would likely fall materially, potentially to sub-zero net returns after incentives and operational frictions, but that specific outcome is an inference rather than a verified datapoint. No authoritative source in the provided set confirms a negative 30-day yield for HyperLend Pooled, so the stress result remains Not verifiable as of 2026-09-04.
Evidence (4)

Governance & Legal

governance

two sources

As of September 13, 2026: Control is materially centralized, not DAO-controlled. The documented control plane is a Governance Multisig (0x2110…8E9C) connected to Timelocks A/B/C and an Executor; PoolAddressesProvider can change proxy implementations, while ACL roles control pool configuration, risk parameters, listings and emergency functions. The Treasury and EmergencyAdmin are separate multisigs. DAO / proposals: HPL is described as a governance token, but no public, operational token-holder proposal process or evidence that HPL holders control upgrades and parameters was found. The live execution architecture is multisig-controlled.

DAO governance is therefore assessed as symbolic/not controlling. Voting concentration and top HPL holders via Dune: Not verifiable as of September 13, 2026 (Dune MCP unavailable). Timelocks: Timelock protection exists. Previously recorded evidence, with the contract map unchanged, indicates approximately 168 hours (7 days) for core pool/proxy, HPL-token proxy and ACL-admin changes, and approximately 6 hours for certain risk/listing administration.

A current explorer event also shows a Timelock B scheduled action with a 10,800-second delay, demonstrating that shorter, function-specific delays exist. Multisigs: Signer identities, signer count and thresholds for Governance, Treasury and EmergencyAdmin were not exposed in the reviewed explorer page or public documentation: Not verifiable as of September 13, 2026. Independence of signers is likewise not verifiable. EmergencyAdmin can pause/freeze reserves without waiting for the ordinary governance delay; this is an emergency bypass, but no evidence was found that it can arbitrarily withdraw user deposits.

The system is non-custodial, and no verified arbitrary-drain function was identified. Company/frontend: The Terms identify Hyperlend Inc. as site operator; governing law is Panama. An LEI record identifies Panama Public Registry entity ID 155777554, incorporated December 23, 2025. Directors were not disclosed: Not verifiable as of September 13, 2026.

The company can modify the frontend and Terms, but the protocol is separately accessible through smart contracts.

Timelock
Yes
Timelock delay hours
168
Admin can drain
No
Emergency bypass
Yes
Dao governance
No
Evidence (6)

legal & regulatory

two sources

Entity / jurisdiction. The interface Terms identify Hyperlend Inc. as owner/operator. Its Privacy Policy states that the data controller has its principal office in Panama. A separate SEC Form D identifies HyperLend Tachyon Ltd, a British Virgin Islands company, as issuer of pooled-investment-fund interests under Regulation D Rule 506(b) and Investment Company Act §3(c)(1).

The relationship between Hyperlend Inc. and HyperLend Tachyon Ltd is Not verifiable as of September 4, 2026. ToS / restrictions. The interface describes access to a permissionless, non-custodial smart-contract protocol. Users accept mandatory individual arbitration seated in London, waive class actions/jury trial, and bear responsibility for legal compliance.

The Terms expressly restrict the United States, United Kingdom, Panama, and numerous other jurisdictions, and prohibit VPN circumvention. KYC/AML and data protection. No protocol-wide customer-identification or AML onboarding requirement is disclosed in the reviewed Terms/Privacy Policy. AML/anti-terrorist-financing violations are prohibited, but this is a user representation rather than evidence of completed screening.

Hyperlend states it may collect wallet addresses, transaction history, IP/device data, and third-party/public-source information, and may disclose data to regulators or governmental authorities. The Privacy Policy is dated October 27, 2024; its GDPR/other-jurisdiction compliance posture is Not verifiable as of September 4, 2026. Classification / actual risk. The SEC filing’s classification of the issuer as a pooled investment fund and its use of §3(c)(1) are material legal-structure signals, but an SEC Form D is not regulatory approval and does not establish that every HyperLend pool has that status.

The operational protocol remains permissionless and non-custodial, creating possible mismatch between formal entity structure and practical user exposure to smart-contract, regulatory, jurisdictional, and enforcement risk. Warnings, enforcement, litigation, sanctions. No regulator warning, enforcement action, court case, or sanctions designation against Hyperlend Inc., HyperLend Tachyon Ltd, or HyperLend itself was identified in the reviewed sources. Exhaustive verification is Not verifiable as of September 4, 2026; compliance screening of users or wallets would not itself mean the protocol/entity is sanctioned.

Active enforcement
No
Sanctioned
No
Entity
Hyperlend Inc. (interface operator); separately, HyperLend Tachyon Ltd appears as a BVI pooled-fund issuer. Relationship not verified.
Jurisdiction
Panama for Hyperlend Inc.; British Virgin Islands for HyperLend Tachyon Ltd
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Hyperlend Inc', 'HyperLend Pooled'. OFAC SDN screening of 'Hyperlend Inc', 'HyperLend Pooled': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Hyperlend Inc
  • HyperLend Pooled
Sanctioned
No
Evidence (4)

Stability

stability

two sources

HyperLend Pooled is a traditional pooled lending market on Hyperliquid L1, not a protocol that issues its own stablecoin; the available sources point to external stable assets such as USDC and USDH. Because no on-chain verification is available in this run, historical depeg events for the stablecoin used cannot be confirmed: depeg_count, last_depeg_date, max_depeg_pct, and stable are Not verifiable as of 2026-09-06. own_stablecoin is false. stablecoin_ids is set to a list containing the externally referenced stable assets mentioned in available sources.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDH
Evidence (3)

Risks & Strengths

risks

two sources

HyperLend Pooled’s main exposures are pooled bad-debt contagion, oracle/liquidation failure, smart-contract and privileged-configuration risk, and dependence on Hyperliquid L1 infrastructure. TVL, borrowing concentration, reserve health, and administrator/multisig controls are Not verifiable as of September 5, 2026 because on-chain verification was unavailable; therefore, no numerical exposure estimates are inferred.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Pooled bad-debt contagionCore pools combine multiple assets; failure, manipulation, or illiquidity of one collateral market can impair the shared pool and socialize losses across suppliers. HyperLend documentation explicitly acknowledges this design trade-off.HighMediumAsset-listing controls, collateral parameters, isolated pools for some assets, and stated risk monitoring by Block Analitica. These controls are partly protocol-reported and not independently verified.High residual correlation and tail-risk exposure remain, especially during simultaneous collateral shocks.
Oracle failure or manipulationIncorrect or stale prices can trigger premature liquidations, prevent liquidations, or create bad debt. Hyperliquid relies on validator-maintained market oracles, while an audit identified stale-feed liquidation concerns.HighMediumOracle registry architecture, liquidity/open-interest restrictions on Hyperliquid, and stated real-time monitoring. Exact feed configuration and fallback behavior are Not verifiable as of September 5, 2026.High residual risk for thin-liquidity assets and fast markets.
Smart-contract and upgrade riskAudits found material issues in prior reviewed versions, including a critical collateral-theft risk; the system also uses permissioned configurator roles and upgradeable proxy components.HighMediumMultiple audits, fix reviews, role-gated configuration, and bug-bounty claims. Current deployment version, timelocks, and emergency powers are Not verifiable as of September 5, 2026.High residual exploit and key-compromise risk, including governance or upgrade-path abuse.
Liquidation and liquidity shortfallRapid collateral losses or thin exit liquidity can prevent timely liquidation, leaving lenders with bad debt and delaying withdrawals. HyperLend itself identifies volatility and liquidation failure as core risks.HighMediumCollateral haircuts, borrow limits, liquidation mechanisms, asset-selection criteria, and monitoring are stated mitigants; live reserve liquidity is Not verifiable as of September 5, 2026.High residual run risk during correlated deleveraging or market-wide congestion.
Hyperliquid L1 dependencyProtocol operation, pricing, and liquidation depend on a comparatively newer L1 and its validator infrastructure; downtime or consensus/oracle disruption could impair access and risk controls.HighMediumNative chain infrastructure and validator-based oracle safeguards. Independent uptime, validator concentration, and recovery testing are Not verifiable as of September 5, 2026.Medium-to-high single-chain and operational concentration risk.
Evidence (5)

strengths

two sources

HyperLend Pooled’s main strengths are: 1) native integration with Hyperliquid L1/HyperEVM, which positions it as the ecosystem’s credit layer and reduces reliance on cross-chain plumbing; 2) capital efficiency, with an Aave-style overcollateralized design and support for real-time leverage and dynamic rates; 3) deep liquidity and scale, as independent listings describe it as the dominant lending venue on Hyperliquid with substantial TVL; 4) modular pool design, including core and isolated pools that separate risk profiles and improve asset-specific market design; and 5) security maturity relative to a young chain, with multiple audits cited and no recorded security incidents in the available profiles. Two caveats matter for risk analysis: some source claims are promotional or aggregator-derived rather than on-chain verified, and the available web results do not let me independently confirm TVL or incident history on-chain here. The strongest defensible strengths, therefore, are the protocol’s native chain fit, lending efficiency, modular architecture, liquidity depth, and audit coverage.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 25 two independent sources, 10 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-29.