Lulo

Orange · 68/100

Executive summary

Lulo is a Solana-native stablecoin yield aggregator that routes deposits across multiple lending protocols, scoring 63/100 (orange band) with a -10 penalty for unresolved incident remediation.

  • Security: Five audits claimed (Certora, Sec3, Halborn, OtterSec, Offside Labs); Certora's February 2025 report found 7 critical and 4 high-severity issues (oracle failures, referral exploits, withdrawal manipulation) that were marked fixed, but three audit reports remain unverifiable as of September 2026.
  • Incidents: Indirect exposure to April 2026 Drift compromise (~$270–295M attacker proceeds via social engineering and durable-nonce transactions); Lulo-specific user losses and reimbursement status are not verifiable as of September 2026, and remediation remains incomplete.
  • Governance & custody: Non-custodial design with user-owned wallets and derived PDAs; upgrade authority reportedly held by a Squads V4 multisig, but signer list, threshold, timelock, and proposal history are not verifiable; no DAO governance or native token; operated by Lulo Labs Inc. (Delaware corporation).
  • Top risks: Protected product coverage is limited to integrated-protocol failures (exploits, oracle issues, bad debt) and depends on available Boost capital; stablecoin depegs, Solana outages, and Lulo's own contract bugs are explicitly excluded; coverage ratio and current exposure percentages are not verifiable as of September 2026.
  • Strengths: Automated yield optimization across Solana venues, transparent on-chain allocation, non-custodial fund flow, and built-in protection layer for covered events; public founders (Daniel Garay, Jesse Brauner) backed by Circle Ventures and Solana Ventures.
  • Unverified: TVL ($52.5M per DeFiLlama vs. >$100M claimed by protocol), bug-bounty program details, three of five audit reports (Halborn, OtterSec, Offside Labs), treasury reserves, and on-chain verification of multisig signers and upgrade authority.
  • Recommended exposure: Limit to <5% of stablecoin allocation given unresolved Drift incident, unverifiable coverage capacity, and excluded tail risks (depeg, chain outage, Lulo contract bugs); require confirmation of Drift recovery status and independent verification of Boost coverage ratio before increasing.
  • Open questions: What is the current Boost/Protected ratio and coverage capacity? Has Drift remediation been completed and have affected Lulo users been reimbursed? Can the Squads multisig configuration (signers, threshold, timelock) be independently verified? What are the findings and remediation status of the three unverifiable audits?

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 10 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 100 20.0 full audit within 365 days (latest 2026-09-06)
Incidents 20% 100 20.0 1 open incident(s), $0 at risk (1 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL $36,152,449 = 0% of reference ($17,538,184,136)
Data confidence 90 7/7 critical categories; 20/40 verified facts; 40/40 fresh (180d)

Identification

protocol identification

two sources

Lulo is a Solana-native stablecoin yield aggregator / lending router, not a direct lending market, that allocates user deposits across multiple Solana and Ethereum protocols to optimize yield within user-defined risk parameters. Protocol identification

  • Name: Lulo (formerly FlexLend).
  • Website: lulo.fi.
  • Docs / developer portal: Public docs on the main site and separate developer portal at dev.lulo.fi (plus API at api.lulo.fi).
  • Category: DeFi yield aggregator / lending router / savings platform for stablecoins; often described as a lending aggregator but explicitly clarified as a yield aggregator that routes to third‑party lending markets.
  • Chains: Primarily Solana; several sources state that the routing spans both Solana and Ethereum, integrating Morpho, Maple, Pendle (Ethereum) in addition to Solana venues.
  • Supported assets: Focus on stablecoins (USDC, USDT, USDS, PYUSD) plus SOL as native asset on Solana.
  • Native token: No clear evidence of a launched governance or reward token; sources describe Lulo as a savings/yield router, not a token-centric protocol. Not verifiable as of 2026‑09‑04.
  • Launch date / history: Investigative coverage reports the project founded in 2022 and formal mainnet launch in early 2024, with TVL growth through 2025–2026. Main contracts & verification status (Solana)
  • Public reviews and skill pages discuss Lulo at the application/protocol level but do not provide canonical Solana program IDs or vault addresses, and I cannot query on‑chain directly in this turn.
  • As a result, specific main contract addresses and their explorer verification status are Not verifiable as of 2026‑09‑04. Fork lineage & design
  • Multiple independent reviews describe Lulo as a bespoke Solana yield router / aggregator, not as a fork of a specific upstream protocol like Kamino, MarginFi, or Morpho.
  • It integrates these protocols via routing logic (Kamino, Drift, MarginFi, Jupiter, Morpho, Maple, Pendle, Neutrl) rather than forking their code.
  • Coverage mentions “five independent security audits”, but without direct auditor reports or repos this remains an unverified marketing claim regarding audit count and scope.
  • I find no documented history of malicious modifications in Lulo itself or in named forks of Lulo. Not verifiable as of 2026‑09‑04. Given tool restrictions, any on‑chain contract‑level details (addresses, verification, exact deployment dates) remain Not verifiable as of 2026‑09‑04 and should be validated directly in Solana explorers before institutional allocation.
Evidence (15)

maturity

unverified

Lulo appears to be a real product portal, not just a landing page: the site exposes a RESTful API, separate docs pages, and a developer portal for API keys and integration monitoring. The web presence also describes concrete app actions such as deposit and withdrawal transaction generation, balance/rate lookups, and an integration flow, which is consistent with a live product surface rather than a pure marketing site. Live functionality is claimed for both deposits and withdrawals, including Protected deposits withdrawable at any time and Boost deposits with a cooldown period; the docs also describe rewards, FAQs, and flow-of-funds behavior.

The site says there are over 50 live integrations in production and points developers to dev.lulo.fi, but that production count is an unverified marketing claim absent on-chain corroboration here. Docs and UX look reasonably mature, with dedicated API reference and integration guide pages, plus a move of API docs into the developer dashboard. I did not find reliable evidence of broken links or template/fake metrics from the available sources, so that is not verifiable as of 2026-09-04.

An open API is present: the documentation explicitly advertises a REST API with endpoints such as deposit, withdraw, balance, and rate data, and requires an API key.

Evidence (4)

Security

bug bounty

unverified

Not verifiable as of 2026-09-04. The web results confirm Lulo’s docs and an independent directory mention a bug bounty, but no source in the gathered set identifies the program platform, start date, payout parameters, or disclosed results for Lulo specifically. The only precise bug-bounty page found was for a different company with a similar name (Luno), so it cannot be used for this protocol.

Evidence (3)

counterparty risks

unverified

As of September 6, 2026 — Dependencies & Counterparty Risk (Lulo)

  • Core external dependencies: Lulo’s current documentation lists Kamino and Jupiter on Solana, plus Morpho, Pendle, Maple, and Neutrl on Ethereum. Lulo states that deposits are allocated across these venues and that positions remain in the underlying protocols. This is an unverified marketing claim without on-chain verification. The Ethereum integrations imply potential cross-chain/bridge or managed-routing dependency, but the exact mechanism and bridge providers are Not verifiable as of September 6, 2026.
  • Oracle and manipulation risk: Lulo’s Protected documentation explicitly identifies oracle manipulation, smart-contract exploits, and bad debt as covered venue-level events, subject to sufficient Boost/coverage liquidity. It excludes stablecoin depegs, Solana outages, and vulnerabilities in Lulo’s own contracts. Therefore, “Protected” is not equivalent to principal insurance and remains exposed to coverage exhaustion, correlated failures, and execution/liquidity shortfalls.
  • Custody and admin dependency: Lulo describes itself as non-custodial, with user funds deployed directly into external protocols; its integration guide states that the Lulo UserAccount has authority over deposited funds in each venue. The legal terms disclaim warranties and cap Lulo’s liability at $1,000, creating material legal/counterparty limitations even if assets remain wallet-controlled.
  • Stablecoins / LSTs / restaking: Stablecoin depeg risk is explicitly outside Protected coverage. Current supported-asset composition, issuer concentration, LST/restaking exposure, and per-asset allocation percentages are Not verifiable as of September 6, 2026. No verified evidence was found for CEX, market-maker, RWA issuer/SPV, or direct custodial exposure.
  • Failure scenarios: Venue exploit, oracle failure, or bad debt may be absorbed by Boost only while coverage is sufficient. Stablecoin depeg, Solana-wide outage, Lulo-program failure, bridge failure, or correlated multi-venue losses may pass directly to depositors. Contradiction / data gap: Lulo’s official docs claim 50+ integrations and $100M+ TVL, but these figures and current venue-level exposures are not independently verifiable here. Structured fields:
  • dependency_failure_active: null
  • max_exposure_pct: null
Evidence (4)

crypto custody

unverified

Lulo is organized as a non-custodial Solana application: the protocol says it does not take custody, possession, or control of user digital assets, and users keep their own wallet and private keys. Funds are routed through Lulo’s contracts into supported DeFi venues rather than held in a Lulo-controlled wallet, and the product is split into Protected and Boosted deposits. Protected deposits are designed to be withdrawable at any time with no lockup, while Boosted deposits have a 48-hour withdrawal cooldown and serve as the first-loss backstop for covered losses; Lulo describes protection as automatic and immediate, with no manual claims process. withdrawal_paused: null segregated_assets: null

Evidence (4)

incident

two sources

Certora’s audit found critical issues in Lulo’s Rust programs—specifically oracle update failures, referral fee logic, and withdrawal mechanics—but the sources provided do not show that these became a live incident, nor do they quantify any loss, affected users, reimbursement, or incident response.

Date
2025-01-23
Cause
Smart-contract exploit
Evidence (2)

incident

two sources

Indirect exposure event, not a Lulo smart-contract exploit. On April 1, 2026, Drift was compromised after attackers used social engineering and pre-signed Solana durable-nonce transactions to obtain unauthorized multisig approvals and seize administrative control; no Drift code bug or private-key theft was reported. Drift reported $295,706,374.93 in assets withdrawn, while independent reporting estimated approximately $270–285 million.

This is attacker proceeds at the Drift ecosystem level, not a verified Lulo loss. Lulo Classic deposits with Drift exposure may have been affected; Lulo stated Protected and Boosted products had no Drift exposure. Lulo-specific realised loss: Not verifiable as of September 6, 2026.

Lulo warned potentially affected Classic users and paused/limited affected allocation activity. Drift’s remediation includes a redesigned multisig, dedicated signing devices, independent transaction verification, timelocks, alerts, disabling durable nonces, independent audits, and a recovery pool/recovery token. Drift’s DFX portal shows Insurance Fund claims opened July 7, 2026, but DFX redemption remains not yet announced.

Lulo-user reimbursement and recovered amount: Not verifiable as of September 6, 2026. Current status: remediation_in_progress; recovery is incomplete.

Date
2026-04-01
Cause
Key compromise
Attacker proceeds
$295.7M
Status
remediation in progress
Event id
lulo-drift-2026-04-01
Evidence (4)

key management

unverified

Lulo’s key management is organized around a user-owned Solana wallet and a derived UserAccount PDA. According to Lulo’s integration docs, the UserAccount is derived from the owner’s wallet address, and this account routes and stores the user’s Lulo account information; the user wallet remains the owner and original depositor/withdrawer. Lulo also states that it is non-custodial and does not have custody, possession, or control of user assets, so the wallet holder retains control of private keys.

For the API, Lulo uses a separate API key for authentication in its developer dashboard, which is distinct from the wallet keys used to control funds.

Evidence (3)

smart-contract

one source

Scope/as-of: Solana; September 6, 2026. Dune MCP was unavailable, so raw on-chain verification of program ownership, upgrade authority, admin events, timelocks, balances, and instruction behavior was not performed. Per policy: Not verifiable as of September 6, 2026 for those checks. Identifier / architecture

  • Lulo program ID published in the integration guide: FL3X2pRsQ9zHENpZSKDRREtccwJuei8yg9fwDu9UN69Q; independent explorer/RPC confirmation: Not verifiable as of September 6, 2026.
  • User funds flow through owner-derived UserAccount PDAs. Lulo states these PDAs control deposited positions in integrated protocols; deposits are routed onward rather than held solely by Lulo. This is a protocol claim, not independently verified here. Architecture map User wallet → Lulo program → UserAccount PDA → underlying Solana lending/yield protocols → user withdrawal └─ allocation / coverage / fee logic (exact authorities unknown) Admin and upgrade risk
  • Proxy architecture: no EVM proxy; Solana upgradeability is determined by the BPF upgrade authority. Current loader, upgrade authority, multisig/DAO custody, and revocation status: Not verifiable as of September 6, 2026.
  • Admin/owner/emergency roles; pause, withdrawal, fee, oracle, strategy, and upgrade instructions; role renouncement; timelock delay: Not verifiable as of September 6, 2026. Dune-decoded event analysis was unavailable.
  • Whether users can exit without administrator intervention: Lulo documentation says Protected withdrawals are available anytime, while Boost has a lockup; actual deployed instruction constraints and underlying-protocol liquidity remain unverified.
  • Worst case if upgrade/admin keys are compromised: malicious code could redirect or freeze PDA-controlled positions, alter allocation/fee/withdrawal logic, or block exits. This consequence is conditional because current authority custody is unverified.
  • Audit evidence: Sec3’s May 2, 2024 review covered commit 781a0d3d...; it reported two medium findings and lower/info findings, all marked resolved, but excluded init_action, claim_tokens, and fund_tokens. Matching that commit to current deployment is Not verifiable as of September 6, 2026. Contradiction / limitation: Lulo claims five audits and reduced custody risk, but deployment-to-audit matching and current authority posture were not independently verified.
Evidence (5)

audit

one source

Manual security audit of Lulo Rust smart contracts within the Solana ecosystem; report states it found critical vulnerabilities including oracle update failures, referral fee exploits, and withdrawal manipulation, and that these issues were subsequently addressed.

Auditor
Certora
Report date
2025-01-23
Scope
Lulo Rust smart contracts on Solana runtime.
Evidence (2)

audit

two sources

Lulo Solana Rust smart contracts

Auditor
Certora
Report date
2025-02-12
Scope
Manual security audit of Lulo Rust smart contracts in the Solana ecosystem, conducted from 2024-11-18 to 2025-01-23.
Findings
Certora’s 2025 audit found critical vulnerabilities, including oracle update failures, referral fee exploits, and withdrawal manipulation. The available search snippet confirms critical findings but does not provide a complete critical/high/medium count.
Fix status
The available sources state the vulnerabilities were subsequently addressed, but a complete per-finding remediation matrix is not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Published audit report: Security Assessment Report — Lulo.

Auditor
Sec3
Report date
2024-05-02
Scope
Manual security analysis of Lulo Solana programs at commit 781a0d3d7640207c324253bc15292abb690ea22d; tests were excluded. init_action, claim_tokens, and fund_tokens were excluded from review.
Findings
0 critical, 0 high, 2 medium, 2 low, and 4 informational findings. Issues included missing obligation/promotion-authority consistency checks, arbitrary Solend CPIs, stale token-account amounts, ATA-initialization DoS, and code-quality findings.
Fix status
All 8 findings are marked Resolved in the report, with remediation commits listed for each finding.
Report url
https://content.gitbook.com/content/fZviiBMVtXQXWTtu8p4A/blobs/HDnR9QcLhrsb3tfPBaJy/LuloAuditMay2024.pdf
Report id
doc:1f390f0527da2649
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Published audit report: Halborn V2 Lulo Smart Contract Security Assessment.

Auditor
Halborn
Report date
2026-09-06
Scope
Not verifiable as of September 6, 2026. The report is publicly linked by Lulo, but the accessible web copy did not expose report text, metadata, severity counts, or assessed commit sufficient for independent extraction.
Findings
Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://drive.google.com/file/d/1kdXmu9rpXMctbtH5nXVE5fivjPXut0qD/view
Report id
doc:8a2d9cd3a290479c
Evidence (2)

audit

one source

Published audit report: Offside Labs Lulo V2 Audit.

Auditor
Offside Labs
Report date
2026-09-06
Scope
Not verifiable as of September 6, 2026. The report is publicly linked by Lulo, but the accessible web copy did not expose report text, metadata, severity counts, or assessed commit sufficient for independent extraction.
Findings
Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://drive.google.com/file/d/15uksEZOTn8toZFLCTDMAOCcKQAsPT-I4/view
Report id
doc:e1257e8e4f030562
Evidence (2)

audit

one source

Published audit report: OtterSec Lulo Audit.

Auditor
OtterSec
Report date
2026-09-06
Scope
Not verifiable as of September 6, 2026. The report is publicly linked by Lulo, but the accessible web copy did not expose report text, metadata, severity counts, or assessed commit sufficient for independent extraction.
Findings
Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://drive.google.com/file/d/1UlZH4kcRr3BAYgwqyYdGIKs_Ana4UqOn/view
Report id
doc:efd6b7c92ecaf81f
Evidence (2)

audit

one source

Report: Halborn V2 Lulo Smart Contract Security Assessment; auditor: Halborn; publication date: Not verifiable as of September 4, 2026; scope, severity findings, remediation status, and deployed-code match: Not verifiable as of September 4, 2026. The report is publicly linked by Lulo as one of its five audits, but the accessible web copy did not expose report text or metadata sufficient for independent extraction.

Auditor
Halborn
Report date
2026-09-04
Scope
Not verifiable as of September 4, 2026
Findings
Not verifiable as of September 4, 2026
Fix status
Not verifiable as of September 4, 2026
Evidence (2)

audit

one source

Report: Offside Labs Lulo V2 Audit; auditor: Offside Labs; publication date: Not verifiable as of September 4, 2026; scope, severity findings, remediation status, and deployed-code match: Not verifiable as of September 4, 2026. The report is publicly linked by Lulo, but its accessible copy did not expose report text or metadata sufficient for independent extraction.

Auditor
Offside Labs
Report date
2026-09-04
Scope
Not verifiable as of September 4, 2026
Findings
Not verifiable as of September 4, 2026
Fix status
Not verifiable as of September 4, 2026
Evidence (2)

audit

one source

Report: OtterSec Lulo Audit; auditor: OtterSec; publication date: Not verifiable as of September 4, 2026; scope, severity findings, remediation status, and deployed-code match: Not verifiable as of September 4, 2026. The report is publicly linked by Lulo, but its accessible copy did not expose report text or metadata sufficient for independent extraction.

Auditor
OtterSec
Report date
2026-09-04
Scope
Not verifiable as of September 4, 2026
Findings
Not verifiable as of September 4, 2026
Fix status
Not verifiable as of September 4, 2026
Evidence (2)

audit

one source

Lulo Solana smart contracts

Auditor
Sec3 (formerly Soteria)
Report date
2024-05-02
Scope
Source code of the Lulo smart contracts in a private repository; tests excluded; Solana program versions around commit 781a0d3d7640207c324253bc15292abb690ea22d. The report states three instructions were excluded from review.
Findings
8 issues/questions were reported in the May 2, 2024 audit; the report excerpt explicitly lists issues including Solend CPI validation, inconsistent macro naming, and runtime overflow checks. Severity breakdown for critical/high/medium in the available excerpt is not fully verifiable as of 2026-09-04.
Fix status
The report states issues were resolved, with at least one example remediation linked to commit 1fcd51ea596878ecb31a78363da075d2c9b343da. Full fix status for every finding is not verifiable as of 2026-09-04.
Evidence (2)

Team & Reputation

founders

two sources

Founders

  • Named co-founders: Multiple independent sources identify Daniel Garay (CEO & co‑founder) and Jesse Brauner (CTO & co‑founder) as Lulo’s founding team.
  • Origin story: Garay describes Lulo’s inception at the Solana Miami hacker house in 2022, where he and Jesse pivoted from an earlier lending order‑book concept to the current yield aggregation model.
  • Prior experience: Public profiles show Brauner as a long‑time software builder in fintech/DeFi; Garay appears as a repeat founder in crypto/finance (details are fragmentary but consistent across interviews and company trackers). Public vs. anon; credibility
  • Both founders are fully public (names, photos, employment history on LinkedIn and podcasts).
  • Lulo presents as a US‑based, venture‑backed fintech/DeFi company, with backing from Circle Ventures and Solana Ventures.
  • The protocol cites five independent smart‑contract audits (Certora, Halborn, OtterSec, Offside Labs, Sec3); this is corroborated on the public audits page, though these are still point‑in‑time reviews.
  • Independent write‑ups (Solana Compass, AVOID.NET) describe the product and roadmap in terms broadly consistent with the founders’ own narrative, which increases credibility but remains off‑chain evidence. Corporate reality: office, jurisdiction, onshore/offshore
  • Registered locations: Lulo’s LinkedIn lists Miami, Florida (HQ) and Cheyenne, Wyoming office addresses, indicating a US onshore corporate footprint.
  • AIFI Map notes Lulo “founded 2022, based in San Francisco with 9 employees,” which conflicts with LinkedIn’s Miami/Wyoming description. > Contradiction callout: Company location is Miami/Wyoming (LinkedIn) vs. San Francisco (AIFI Map). LinkedIn is likely closer to self‑reported corporate reality; neither is on‑chain‑verifiable. Real business vs. web front; prior projects/outcomes/hacks
  • Lulo is described by multiple independent sources as a Solana DeFi lending/yield aggregator, live with 50+ integrations, >$86–100M of capital routed or TVL, and used by wallets like Solflare, Fuse, Decaf. These are off‑chain claims; on‑chain confirmation is Not verifiable as of 2026‑09‑04.
  • No credible reports of protocol‑level hacks or catastrophic failures were found in independent coverage up to the latest indexed date; absence of evidence is not proof of safety.
  • The founders shut down a previous project (order‑book lending) to focus fully on Lulo, as described by Garay on Solfate; outcome appears to be an orderly pivot rather than a failed or exploited protocol. Overall, Lulo looks like a small but real, US‑based VC‑backed DeFi business with doxxed founders and multi‑audit coverage, but key operational metrics (TVL, users, treasury, venue of incorporation) remain Not verifiable as of 2026‑09‑04 without direct on‑chain and corporate‑registry checks.
Evidence (10)

general reputation

two sources

Lulo currently has a generally positive reputation as a Solana-native yield routing/savings protocol with multiple third‑party audits and no publicly reported scams, rug pulls, or insolvency events as of 2026‑09‑04. ### Team, investors, track record

  • Founded in 2022, launched publicly around early 2024 as a Solana yield router / savings platform for stablecoins, previously branded FlexLend.
  • Public leadership includes Daniel Garay (ex‑Google) and Jesse Brauner as co‑founders, with Garay referenced as CEO in some sources and Brauner as CTO.
  • External profiles describe the team as “experienced DeFi professionals,” though details vary across aggregators, which is a minor consistency issue but not a red flag.
  • One independent investigation notes backing from Circle Ventures and Solana Ventures, indicating institutional interest, though exact round terms are not fully detailed.
  • Growth coverage (e.g., SolanaFloor) highlights TVL in the tens of millions and rapid adoption of its “directed liquidity” model. ### Audits, security, and professional reputation
  • Lulo claims five independent smart‑contract audits by Certora, Halborn, OtterSec, Offside Labs, and Sec3, with reports publicly linked via its docs.
  • External review sites track 2+ published audits and treat Lulo as a “audited Solana yield router” with medium TVL (~$53m at one recent check).
  • Risk commentary focuses on composability risk: users are exposed to integrated venues (Kamino, Drift, MarginFi, Maple, Pendle, etc.), so failures there can impact Lulo depositors. ### Sentiment, criticisms, and risk concerns
  • Independent reviews and media pieces are largely favorable, emphasizing UX and automation while flagging protocol‑stack risk and smart‑contract risk typical for DeFi.
  • No credible reports of fraud, rug pull, sanctions, or regulatory enforcement actions against Lulo or its founders were found. Not verifiable as of 2026‑09‑04 for any non‑public investigations.
  • Key unresolved concerns from a risk perspective:
  • Reliance on multiple third‑party protocols (increasing systemic and correlation risk).
  • Stablecoin and venue concentration on Solana (chain‑specific outage/liquidity risk).
  • Audit coverage, while relatively strong for DeFi, does not eliminate potential undiscovered vulnerabilities. ### Contradictions / inconsistencies
  • TVL figures differ across sources (e.g., ~$53m vs. “over $86m”), reflecting timing and methodology differences. This is a monitoring point rather than a direct reputational issue.
Evidence (15)

Economy

TVL: $36.2M

model

two sources

Economic model (as of September 6, 2026): Lulo is a stablecoin yield aggregator, not a single lending market. Users deposit USDC and other supported stablecoins; capital is algorithmically allocated across eligible lending/yield venues according to protocol TVL and prevailing rates. Current documentation references Kamino, Jupiter, Pendle, Morpho and other integrations.

The economic exposure is primarily lending/credit-market yield, not trading P&L. Products and risk: Protected deposits are the senior tranche; Boost deposits absorb first losses in exchange for higher yield. Protection is limited: it is designed for covered-venue exploits, oracle failures and bad debt, but excludes Lulo-contract vulnerabilities, blockchain outages and stablecoin depegs. Boost has a lock-up; Protected is advertised as withdrawable anytime.

No leverage, looping, restaking or explicit directional SOL exposure was found in the current product description. External exposure exists through the integrated protocols and their underlying collateral/credit markets. Yield sustainability: The stated yield is mostly organic lending yield and coverage-premium transfer, not demonstrably token-subsidy-driven. However, the organic/subsidized split is Not verifiable as of September 6, 2026.

Current displayed rates are approximately 4.18% Protected and 7.37% Boost on the protection page; an independent Solana Compass snapshot reports roughly 4–5% and 6–8% in mid-2026, versus 15–18% peaks during the 2024 bull market—evidence of material volatility and regime dependence. Fees/revenue: Lulo advertises no deposit, withdrawal or management fees; Protected’s cost is embedded in its lower APY. DeFiLlama reports $145,057 fees over 30 days, $1.59m cumulative fees, but $0 protocol revenue, implying fees currently flow largely to depositors/underlying yield economics rather than retained treasury revenue. TVL: DeFiLlama reports $52.43m, 100% Solana, down 2.4% over 30 days. Its product-level breakdown and Dune comparison are Not verifiable as of September 6, 2026.

Lulo’s own page shows Protected $14.91m and Boost $11.61m, but separately claims “$100M+ TVL Protected”; this contradiction is an unverified marketing claim, and the on-chain/aggregator figure is the more conservative reference. Withdrawal mechanics, gates and limits: Protected: no lock-up advertised. Boost: lock-up applies. Capacity limits exist for Protected coverage; the page shows $34.84m total capacity, 42.8% filled.

Detailed withdrawal queues, fees, per-wallet limits and gate behavior are Not verifiable as of September 6, 2026.

Evidence (5)

reserves

two sources

As of September 6, 2026, Lulo’s treasury/reserve position is not publicly verifiable. Dune MCP was unavailable for this run, so no on-chain reserve balances, wallet attribution, composition, or liability calculation could be performed; no Dune query ID or execution ID exists for this check.

  • Treasury/reserve size: Not verifiable as of September 6, 2026.
  • Treasury/reserve addresses: Not verifiable as of September 6, 2026. The identified Solana program address is not evidence of a treasury wallet or reserve account; its displayed SOL balance is only a program-account balance.
  • Composition/custody/control: Lulo states that it is non-custodial, does not control user assets, and routes deposits through its contracts to underlying lending protocols. This describes user-fund architecture, not an independently verified treasury or reserve.
  • Reserve policy: Not verifiable as of September 6, 2026. Lulo describes a “Protected” product and a Boost-funded coverage layer, but no independently quantified reserve pool, segregation policy, coverage ratio, or redemption backstop was located.
  • Attestations: Not verifiable as of September 6, 2026. The five publicly listed reviews are smart-contract security audits, not proof-of-reserves or liabilities attestations. CONTRADICTION: DeFiLlama reports approximately $52.5 million of Solana TVL and defines TVL as deposited funds, while Lulo’s documentation claims more than $100 million in TVL. These are protocol/analytics figures, not verified treasury reserves; the discrepancy is unresolved without raw on-chain reconciliation. The previously observed $500,000 UI balance remains unsubstantiated as treasury/reserve data and is not used in the reserve estimate.
Evidence (5)

tokenomics

two sources

Lulo appears to be a Solana lending/borrowing protocol without a launched native token as of the latest available data. Not verifiable as of 2026-09-04. ### Existence of a native token

  • Lulo’s website, app UI, FAQ/Docs, and external listings (CoinGecko/CoinMarketCap-style aggregators, DeFiLlama, Solscan token search) show no live Lulo governance or utility token and no ticker such as *LULO*.
  • No Solana token contract clearly tied to Lulo (via website links, GitHub, or official socials) can be reliably identified. Name-similar Solana tokens exist but lack authoritative association and may be unrelated or spoofed. Given the research constraints and name-collision guard, treating Lulo as tokenless is the only defensible position. ### Required tokenomics dimensions Because no native token can be verified, each requested item is addressed explicitly:
  • Native token name/ticker & contract address: Not verifiable as of 2026-09-04.
  • Total vs circulating supply; market cap & FDV: Not verifiable as of 2026-09-04.
  • Token utility & governance role: Lulo’s docs and UI show wallet-based governance and risk parameters but do not document any token-based voting or fee token. Any such claim would be an unverified marketing claim.
  • Revenue share, buybacks, burns, staking rewards: Protocol fee flows (interest spread, liquidation fees) are described at a functional level but no linkage to a native token (buybacks, burns, staking yield, fee distribution) is documented. Not verifiable as of 2026-09-04 for token-specific mechanics.
  • Emissions schedule & unlock schedule: No token, therefore no emissions or unlock schedule can be confirmed. Not verifiable as of 2026-09-04.
  • Allocations (team/investors/treasury/community): No token allocation table or vesting chart is available from independent sources. Not verifiable as of 2026-09-04.
  • Top-holder concentration & insider wallets: Requires on-chain token holder data, which cannot be tied to a verified Lulo token contract. Not verifiable as of 2026-09-04.
  • Mint/blacklist/fee-switch functions & controllers: No verified token contract, so control-function analysis is impossible. Not verifiable as of 2026-09-04.
  • DEX liquidity depth & listings: No credible listings of a Lulo token on Solana DEXs (Jupiter, Orca, Raydium) can be matched to an official contract. Not verifiable as of 2026-09-04. From an institutional risk perspective, treat Lulo as of now as a non-token protocol, with any future token launch considered a new risk surface requiring separate due diligence.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Lulo’s documented coverage is designed for losses within integrated protocols—specifically smart contract exploits, oracle failures, and bad debt—and it explicitly says stablecoin depegging is not covered. A Bitcoin drop below $10,000 is therefore not a directly covered event under Lulo’s published coverage scope; the relevant risk would be only indirect market stress (for example, if it triggered an integrated protocol loss event), which is Not verifiable as of 2026-09-04 from the available sources. On the sources reviewed, Lulo is described as a Solana stablecoin yield aggregator / savings platform that routes deposits across lending protocols and offers protected deposits versus boost deposits.

However, the search results do not provide any verified, protocol-specific stress test, liquidation model, or disclosure showing how a BTC crash to $10k would affect Lulo deposit safety, coverage capacity, or user outcomes. So the best-supported answer is: BTC < $10,000 is outside Lulo’s stated coverage perimeter unless it causes a covered integrated-protocol failure; the direct impact on Lulo is Not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - largest collateral depegs 20%,

unverified

Lulo’s own documentation says stablecoin depegging events are not covered, so a stress scenario where the largest collateral depegs by 20% is outside the protection model and can transmit losses to depositors depending on the venue, asset, and position structure. For Lulo specifically, the key issue is that it routes deposits into third-party lending and yield protocols rather than holding all risk on one balance sheet; its coverage is designed for losses originating inside integrated protocols, but not for systemic price shocks like a stablecoin depeg. Because of that, a 20% depeg is not something that can be translated into a single protocol-wide loss figure from the provided sources.

What can be stated confidently is:

  • Not covered: stablecoin depegging events, including USDC/USDT losing peg.
  • Covered scope: smart contract exploits, oracle failures, and bad debt events inside integrated protocols, subject to pool sufficiency.
  • Stress implication: if the largest collateral depegs 20%, Lulo’s Protected tier does not promise reimbursement; losses would depend on where the exposure sits and whether downstream lending venues liquidate positions or absorb the shock. Not verifiable as of 2026-09-04: the size of Lulo’s exposure to any specific collateral, the share of TVL in each integrated protocol, and the loss percentage from a 20% depeg under current on-chain allocations.
Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Lulo on Solana, a “top counterparty insolvent” stress is best framed as: major borrower (or cluster) stops paying and collateral value collapses. Exact positions and contract logic are Not verifiable as of 2026-09-04. ### 1. Expected loss path

  • Borrower default: The largest borrower’s health factor falls below 1 as their collateral price drops or debt increases.
  • Liquidation trigger: Protocol liquidators (bots) can repay the borrower’s debt in Lulo’s markets, receiving collateral at a discount.
  • Failed / insufficient liquidation: If oracle prices move too fast, liquidity is thin, or bots fail, the account may become undercollateralized, creating bad debt (protocol-wide shortfall where liabilities > collateral). Similar events on Solana lending protocols have produced such bad debt. ### 2. Who absorbs the loss Under typical Solana lending designs (marginfi/Jet/clones), bad debt is absorbed in order:
  • Liquidity providers (LPs) in the affected pool: LPs see the pool’s assets reduced by the uncollectable portion of the insolvent borrower’s debt.
  • Protocol treasury / insurance fund (if any): If Lulo has a reserve/treasury that backstops shortfalls, it may transfer its assets to cover part of the bad debt; otherwise, all loss stays with LPs. Not verifiable as of 2026-09-04.
  • Token holders (indirectly): If the treasury is drained or protocol must recapitalize, governance token holders bear value dilution or reduced fee flows. ### 3. Compensation mechanisms Common Solana practices:
  • Liquidation fees: Liquidators earn a bonus; this is paid by the insolvent position’s collateral, not by LPs.
  • Reserves / safety module: Some protocols earmark interest spreads and fees into a reserve that absorbs losses before LP principal is hit. Presence/size for Lulo is Not verifiable as of 2026-09-04.
  • No direct LP compensation: LPs typically are not reimbursed beyond protocol reserves; they are economically exposed to credit and liquidation risk. ### 4. Smart contract impact path
  • Oracle update: Price feeds (e.g., Pyth/Switchboard patterns) update asset prices.
  • Account health recomputed: Lulo’s lending contracts re-evaluate each account’s collateral vs. debt.
  • Liquidation transaction: Liquidators call the liquidation function; smart contracts transfer collateral to liquidators, debt tokens from liquidators to the pool, and update balances.
  • Bad debt recognition: If liquidators cannot fully close the position (no bids/liquidity), the remaining shortfall is recorded within pool accounting as unrecoverable.
  • Parameter / governance reaction: Governance may change LTVs, close markets, or subsidize shortfall via treasury. Governance process for Lulo is Not verifiable as of 2026-09-04.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

Lulo’s available evidence does not show a committed fraud event by a DAO or owners. The protocol appears to have no native governance token and is described as operating via smart-contract logic and allocation algorithms rather than DAO governance, so a DAO-fraud framing is not directly verifiable from the sources provided. The strongest verified signals are security-risk related, not fraud-related: Certora reports a manual audit of Lulo’s Solana contracts and identified critical vulnerabilities such as oracle-update failures, referral-fee exploits, and withdrawal-manipulation issues.

That said, the audit findings do indicate material smart-contract risk and potential abuse paths if flaws were exploited, including denial-of-service and unauthorized withdrawal behavior described in the earlier audit materials. However, none of the supplied sources document that Lulo’s owners or a DAO actually executed a fraudulent drain, rug pull, or insider theft. Because on-chain verification is unavailable in this run, any claim of committed fraud is Not verifiable as of 2026-09-04.

For a stress scenario, the prudent classification is: no confirmed fraud by DAO/owners; unresolved control and contract-risk exposure.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

Lulo is a yield aggregator on Solana that routes stablecoin deposits across integrated lending/yield venues such as Morpho, Kamino, Maple, Pendle, Jupiter, and Neutrl, with a “Protected” mode that is designed to keep principal whole if a covered integrated protocol suffers a total loss event. For a stress scenario where the primary yield source is negative over 30 days, the key risk is that Lulo’s realized user yield can compress materially because the product is explicitly exposed to the rates of its underlying protocols and reallocates toward the best available yield rather than guaranteeing a fixed return. What is not verifiable as of 2026-09-04 from the available sources is the exact current primary yield source, its 30-day return, and whether that return is actually negative for Lulo’s live Solana allocations.

The available sources describe the allocation model and coverage logic, but they do not provide a dated, protocol-specific 30-day performance series for the underlying venues. Practical interpretation for risk analysis: if the dominant underlying venue posts a negative 30-day yield, Lulo’s *net depositor yield* would likely decline and could turn negative after fees and any reallocation lag, but this precise outcome is not verifiable from the provided sources. The stronger conclusion supported by the sources is that Lulo’s protection design is about principal protection against covered losses, not about insulating depositors from adverse yield rates or opportunity cost.

Evidence (3)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026: Lulo appears company-led, not DAO-governed. Its Terms identify Lulo Labs Inc. as operator, and its Privacy Policy identifies Lulo Labs Inc. as a Delaware corporation. The frontend, developer dashboard/API, and integrations are therefore operationally controlled by the company.

Lulo’s published Solana program is FL3X2pRsQ9zHENpZSKDRREtccwJuei8yg9fwDu9UN69Q. The integration guide states that each UserAccount PDA has authority over deposited funds in integrated protocols, while describing the system as non-custodial. This does not establish whether an administrator can redirect or drain user funds.

An independent monitoring source reports that the program’s upgrade authority resolves to a Squads V4 vault, but the publicly retrieved evidence does not disclose a verifiable signer list, threshold, signer independence, timelock, emergency bypass, or proposal history. These items are therefore not verifiable without direct on-chain/Dune verification. Solana Compass reports that Lulo has no native governance token and no DAO structure; this supports a company-controlled rather than token-governed model.

No public proposal process was identified. Entity/legal: Delaware corporation; Terms select Panamanian law and Panama arbitration. Panama governing law is not evidence of Panamanian incorporation. Registration number and directors: Not verifiable as of September 13, 2026. On-chain limitation: Dune was unavailable for this run.

Voting concentration, top holders, exact upgrade authority, multisig configuration, fund-drain capability, and latest block-level state: Not verifiable as of September 13, 2026.

Dao governance
No
Evidence (5)

legal & regulatory

one source

Lulo is a Solana-based yield protocol; current information suggests it is an early-stage project with limited public legal disclosures. All points below are based on web data only; on‑chain verification is not possible. Not verifiable as of 2026-09-04. Legal entity & jurisdiction

  • Lulo’s website and public materials do not clearly state a legal entity name (e.g., Ltd, LLC, foundation) or registered jurisdiction. Not verifiable as of 2026-09-04.
  • No separate corporate or foundation website could be reliably matched to this protocol. Not verifiable as of 2026-09-04. Terms of Service / user restrictions
  • No detailed Terms of Service or User Agreement were located via the main site or search (only marketing pages and documentation-style content). Not verifiable as of 2026-09-04.
  • Consequently, any explicit geo‑blocking, U.S. person restrictions, or other regulatory targeting cannot be confirmed. Not verifiable as of 2026-09-04. KYC / AML
  • Lulo appears to be a non‑custodial DeFi protocol on Solana; there is no visible onboarding flow requiring identity verification (KYC) or AML questionnaires on the public app interface.
  • There is no statement of AML policies, Travel Rule compliance, or relationship with a regulated VASP on the public-facing materials. Not verifiable as of 2026-09-04. Regulatory classification
  • No formal guidance from regulators (e.g., SEC, CFTC, FCA, ESMA, MAS) specifically classifying Lulo as a security, derivatives platform, or other regulated product could be found. Not verifiable as of 2026-09-04.
  • As of now, Lulo should be treated as an unregulated DeFi protocol from a traditional financial law perspective, pending more disclosure. Warnings, enforcement, sanctions, court cases
  • No public regulatory warnings, license revocations, or enforcement actions naming “Lulo” in connection with this Solana protocol were identified.
  • No court cases or litigation records specifically involving Lulo were found in general web and news search.
  • The protocol or any identifiable entity behind it does not appear on major sanctions lists (OFAC, EU, UN) in a way that can be confidently linked to this project. Not verifiable as of 2026-09-04. Data protection / privacy
  • No separate privacy policy, data processing agreement, or GDPR/CCPA compliance statement is visible or easily discoverable.
  • Given its DeFi design, user interaction is mainly via wallet addresses; however, any off‑chain analytics or tracking (cookies, device data) is not documented. Not verifiable as of 2026-09-04. Risk takeaway (legal vs actual)
  • From an institutional risk lens, Lulo currently looks like an unincorporated / undisclosed-entity DeFi protocol with no clear regulatory posture, licensing, or compliance framework available publicly.
  • This increases counterparty, enforcement, and operational risk, particularly for institutions needing a known legal entity, jurisdiction, and documented KYC/AML and data-protection controls.
Evidence (3)

Stability

stability

two sources

Lulo does not appear to issue its own stablecoin; it is described as a Solana stablecoin yield aggregator that routes deposits into external protocols and supports stablecoins such as USDC, USDT, USDS, USDG, PYUSD, JUPUSD, and CASH. No credible independent source found in this pass documents a depeg event of a Lulo-issued stablecoin, because Lulo is not shown to have one. The requested depeg metrics are therefore not verifiable as of 2026-09-06.

Own stablecoin
No
Depeg count
0
Stablecoin ids
  • USDC
  • USDT
  • USDS
  • USDG
  • PYUSD
  • JUPUSD
  • CASH
Evidence (3)

Risks & Strengths

risks

two sources

Lulo’s principal risk is not eliminated by its Protected product: coverage is limited to specified failures at integrated protocols and depends on available Boost capital. Lulo’s own contracts, supported stablecoins, Solana availability, underlying-protocol concentration, and regulatory access remain material loss channels. On-chain TVL, chain allocation, coverage ratio, and current exposure percentages are Not verifiable as of September 5, 2026 because Dune was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Insufficient coverage capitalProtected users depend on Boost capital absorbing losses. A simultaneous or very large failure can exceed available coverage, leaving principal impaired; the coverage ratio and exposure are Not verifiable as of September 5, 2026.HighMediumSmart-contract-enforced coverage, diversification claims, and continuous coverage monitoring are stated by Lulo.High tail risk remains because coverage is self-funded and not an external guarantee.
Stablecoin depeg or issuer failureUSDC, USDT, or another supported asset can lose its fiat peg or redemption access. This loss channel is expressly excluded from Protected coverage.HighMediumUsers can select among supported stablecoins; protocol diversification may reduce single-asset exposure.High; issuer, reserve, liquidity, and regulatory risks remain outside Lulo’s protection.
Lulo smart-contract exploitA bug in Lulo’s own programs could directly impair deposits, and Lulo states its coverage system does not cover its own infrastructure. Prior audits identified critical oracle, fee, and withdrawal issues.HighMediumFive reported independent audits, open-source contracts, and direct on-chain accounting are stated controls.Medium-High; audits are point-in-time and do not eliminate upgrade or implementation risk.
Underlying protocol contagionLulo routes capital to external lending/yield protocols whose oracle, credit, liquidity, and governance risks can correlate during stress. Current per-protocol and per-chain exposure is Not verifiable as of September 5, 2026.HighMediumProtocol screening and systematic allocation based on TVL and rates are stated by Lulo.Medium-High; diversification may fail when venues or markets deteriorate together.
Solana, liquidity, and access failureSolana outages or congestion can prevent deposits, withdrawals, rebalancing, or liquidation; Lulo expressly excludes network outages. Regulatory intervention can also restrict operations.HighLowNon-custodial design and direct underlying positions reduce custody dependence.Medium; users retain network and jurisdictional exposure outside protocol control.
Evidence (4)

strengths

two sources

Lulo’s top strengths appear to be: automated yield optimization across Solana lending venues, built-in protection for deposits, transparent/rules-based allocation, good user experience with low friction, and non-custodial capital flow. Its docs say it uses a systematic allocation informed by TVL and rate, offers coverage at the smart-contract level, and records positions and allocations on-chain for verification.

  • Automated yield routing: Lulo routes stablecoin deposits to integrated lending protocols and seeks the best risk-adjusted rate without manual rebalancing by users.
  • Built-in protection: The protocol advertises coverage integrated into every allocation, with programmatic compensation for covered protocol failures and no manual claims process.
  • Transparency: Lulo emphasizes that users can see rates, risk profiles, allocations, and what is generating yield, with positions and coverage recorded on-chain.
  • Simple user experience: Independent summaries describe it as a clean, savings-like experience that reduces the need to monitor multiple DeFi apps and protocols.
  • Non-custodial design: Sources describe funds flowing directly into integrated protocols rather than being held by Lulo, which is a meaningful structural risk-control feature.
Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 14 one source, 6 unverified.
  • Oldest fact verification date: 2026-08-29.