marginfi Lending

Orange · 61/100

Executive summary

marginfi Lending is a Solana-native, overcollateralized lending protocol (score: 74/100, green band) that enables permissionless borrowing and lending of SOL, stablecoins, and LSTs through pool-based markets.

  • Security: Multiple audits by Accretion Labs (April–September 2025), OtterSec (2023), and Sec3 (2023–2025) covering core lending, eMode, and cross-venue integrations; detailed findings and fix status are not verifiable as of September 2026. Active bug bounty program (up to $500k for critical issues) successfully caught and patched a critical flash-loan vulnerability in April 2024 before exploitation, with no funds lost.
  • Incidents: April 2024 saw a confluence of events—founder resignation, missed BLZE emissions, stale-oracle withdrawal failures, and LST liquidations during temporary depegs—triggering ~$155–300M capital flight (not protocol loss); marginfi committed insurance-fund refunds for affected liquidations, but total reimbursement completeness is not verifiable. A second flash-loan bug was disclosed and patched in September 2025, again with zero losses.
  • Governance & custody: Non-custodial protocol with foundation/company control, not token-DAO governance. Group admins hold broad authority over risk parameters, oracles, fees, and emergency functions (including super-deposit/withdraw for loss socialization and 30-minute pause powers); admin keys reportedly use a Squads 5/17 multisig with zero timelock, creating material privileged-key risk. No binding on-chain governance or executable DAO process was identified.
  • Top risks: Oracle dependency (Pyth, Switchboard, Scope) with staleness/mispricing risk; cross-venue counterparty exposure to Kamino, Drift, and Jupiter Lend; rapid liquidity deterioration and bad-debt socialization via insurance fund; privileged admin powers with emergency bypass; Solana execution/congestion dependency; and smart-contract/integration complexity across multiple audited modules.
  • Strengths: Permissionless Solana-native design with low fees and fast settlement; robust risk framework (overcollateralization, health-factor monitoring, partial liquidations with 5% penalty split between liquidator and insurance fund); capital-efficient multi-asset collateral and eMode support; active security program with successful bug-bounty track record; and broad product scope (global/isolated markets, cross-venue integrations).
  • Unverified: Audit findings detail and deployed-code coverage; current TVL, reserve balances, and exposure concentration; live admin/upgrade-key activity and signer identities; insurance-fund adequacy and liquidation-reimbursement completeness; native token status and tokenomics (MFI airdrop paused/unscheduled); and exact legal entity domicile, ToS, KYC/AML posture, and data-protection compliance.
  • Recommended exposure: Conservative allocation (≤5% of DeFi portfolio) given elevated admin risk, oracle/venue dependencies, and April 2024 operational stress; limit to short-duration lending of liquid Solana assets (SOL, USDC) in global pools; avoid isolated or cross-venue banks until counterparty and reserve verification improves; monitor account health closely and maintain >150% collateralization buffer; exit immediately if admin-key compromise, oracle outage, or governance crisis signals emerge.
  • Open questions: Verify current admin multisig signers, threshold, and timelock; confirm insurance-fund balance and coverage ratio vs. outstanding borrows; obtain full audit reports with findings/fix status and deployed-code hash matching; validate cross-venue (Kamino, Drift, JupLend) reserve health and withdrawal mechanics; clarify legal entity structure, ToS enforceability, and regulatory posture; assess live oracle configuration per bank and staleness/circuit-breaker settings; and confirm April 2024 liquidation reimbursement completeness and any outstanding user claims.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 11 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2025-09-01 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $36,739,653 = 0% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 15/43 verified facts; 43/43 fresh (180d)

Identification

protocol identification

two sources

marginfi (often styled marginfi or mrgnlend) is a Solana-native, overcollateralized lending/borrowing protocol (DeFi money market) built by Mrgn Labs. It lets users lend and borrow Solana assets via pool-based, peer‑to‑pool markets. Protocol identification

  • Name: marginfi (mrgnlend / marginfi v2).
  • Category: Decentralized overcollateralized lending/borrowing protocol / money market.
  • Website / App: Commonly referenced simply as *marginfi*’s official web app; users “visit marginfi's official website and connect [a] wallet.” (exact URL not reproduced per instructions).
  • Docs: marginfi documentation at docs.marginfi.com, including “Introduction” and “marginfi v2 Program Documentation.”
  • Chains: Solana only; consistently described as “Solana-native” or “built on the Solana blockchain.”
  • Launch date: Eco’s guide states marginfi has been live since mid‑2023 as a Solana lending protocol. A 2023 Solfate podcast describes its evolution from a prime brokerage model to borrow‑lend, consistent with that timeframe.
  • Native / governance token: Public sources primarily describe marginfi as a protocol, not a token; some project reviews mention a token section but do not clearly define a widely‑used native governance token for the lending protocol itself. As specific token details are fragmented, major token parameters are Not verifiable as of 2026-09-03. Main contract / program addresses & verification status Because direct on‑chain tooling is unavailable for this run, exact Solana program IDs cannot be safely confirmed or cross‑checked across independent sources and explorers. Several reviews mention “mrgnLend v2” as the core borrow‑lending program and reference it as “battle‑tested” and open‑source. However, the canonical program address(es), their deployment history, and explorer verification status are Not verifiable as of 2026-09-03. Fork lineage & upstream relationship
  • Multiple independent sources describe marginfi as a non‑custodial, Solana‑native lending protocol with a global account model, isolated pools, and a custom risk/liquidation engine. None clearly identify it as a fork of a specific Ethereum money market (e.g., Aave/Compound) or a direct port; instead it is portrayed as a purpose‑built Solana implementation.
  • The mechanism is said to be “similar to other generic lending protocols” (peer‑to‑pool, overcollateralized), but with distinctive liquidation logic using oracle price adjustments and asset weights. This suggests conceptual lineage from standard DeFi money markets but not a straightforward contract fork.
  • Audit status: Public discovery for “marginfi lending smart contracts audit” did not surface a clearly labeled, independent audit report from a major auditor (e.g., OtterSec, Neodyme, Trail of Bits) directly tied to the current mrgnLend v2 program. Given that absence, formal audit coverage of the latest version is Not verifiable as of 2026-09-03.
  • Malicious‑modification history in similar forks: Because marginfi does not present itself as a direct fork of a named upstream protocol, and there is no consolidated database of marginfi‑related fork exploits, any history of malicious changes in closely related forks is Not verifiable as of 2026-09-03. Overall, independent sources consistently treat marginfi as a Solana‑native, overcollateralized lending protocol with its own program architecture and risk engine, rather than a simple fork of a pre‑existing money market on another chain.
Evidence (15)

maturity

one source

marginfi Lending appears to have evolved from a live app into a migrated product: the former app domain now says “marginfi has moved to Project 0” and directs active positions to the Project 0 dApp, which indicates the original portal is no longer the primary user-facing venue. The docs still describe mrgnlend flows for lending and borrowing on Solana, including supply, borrow, and withdrawal steps, which supports that the product was a real functioning lending app rather than a static landing page. For maturity, the documentation shows a coherent UX with specific user guides for the web app and mobile/PWA use, which is stronger than a template-only site.

However, live operational status is not verifiable as of 2026-09-03 from the available web evidence: the docs describe deposits, borrows, and withdrawals, but I cannot confirm current live execution, broken links, or whether the old portal still processes transactions. On open API: the protocol docs include a “Quickstart” that says users need an API key before making requests to the Protocol API, and third-party developer documentation states marginfi exposes no hosted REST API and instead integrates on-chain via the Solana program and SDKs. So the best-supported answer is that marginfi has developer interfaces/SDKs and protocol APIs behind keys, but not a clearly public open REST API.

Overall: real protocol, real docs, mature UX history, but current portal status is migrated and live functionality is not fully verifiable as of 2026-09-03.

Evidence (6)

Security

bug bounty

one source

marginfi has an active security disclosure / bug bounty program for on-chain program code. Reported parameters on GitHub: UI-only bugs are out of scope; Critical pays 10% of hacked value up to $500,000; High pays $10,000-$50,000 per bug; Medium/Low pays $1,000-$5,000 per bug; payouts are case-by-case; payment is in USDC or equivalent; critical/high submissions require a reproducible PoC on a privately deployed mainnet contract; response expected within 1 business day. A separate 2022 marginfi ecosystem bounty post advertised a $25k incentive program, but that appears to be an older program rather than the current security bounty.

Reported result: a critical flash-loan vulnerability was privately disclosed through the bounty program and patched before any exploit, with no funds lost.

Active
Yes
Platform
GitHub Security Advisory / email-based disclosure (security@mrgn.group)
Max payout
$500K
Since
2025-01-01
Evidence (3)

counterparty risks

unverified

As of September 5, 2026. The protocol identity is confirmed: marginfi-v2 / Project 0 on Solana, program MFv2hWf31Z9kbCa1snEPYctwafyhdvnV7FZnsebVacA. The former marginfi SDK was deprecated in March 2026, indicating an active Project 0 transition rather than a separate namesake. Key dependencies and counterparty risks

  • Oracles — high importance: Current documentation no longer supports describing Pyth as the sole or necessarily primary dependency. Banks may use Switchboard, Pyth, Scope, exchange-rate, or fixed-price oracles; configurations are bank-specific and administrator-selected. Confidence bounds, EMA, staleness controls, and circuit breakers reduce—but do not eliminate—stale-price, feed outage, bad configuration, or manipulation risk. A feed failure can block risk-increasing actions; a mispriced feed can cause unfair liquidations or bad debt.
  • External DeFi venues — newly material: Project 0 has live cross-venue collateral integrations with Kamino and Drift; Jupiter Lend is documented as coming soon. Deposits into these banks represent venue receipt/share tokens, and the external venue’s reserve, market, oracle, withdrawal, and insolvency risks become dependencies. The protocol states these positions are collateral-only and not borrowable on Project 0.
  • LST/restaking exposure: Native-stake banks use single-validator LSTs backed by Project 0 validators. Risks include SOL volatility, LST discount/depeg, validator/slashing or stake-pool failure, and delayed unstaking. No verified restaking-specific exposure was found.
  • Stablecoins: USDC/USDT and other stable assets are supported as standard assets, creating issuer-reserve, freeze/blacklist, depeg, and liquidity risks. Stablecoin composition and exposure weights are Not verifiable as of September 5, 2026 without on-chain data.
  • Bridges/custodians/CEX/MM/RWA: No direct custodian, RWA issuer/SPV, or CEX/market-maker balance-sheet dependency was verified. The SDK can construct bridged swap/loop routes, but this is execution-path exposure rather than evidence that protocol TVL is held by a bridge. Exact bridge usage and exposure are Not verifiable as of September 5, 2026. Failure scenarios: oracle outage or manipulation; Kamino/Drift insolvency or withdrawal halt; LST discount; stablecoin depeg/issuer insolvency; Solana congestion delaying oracle refresh or liquidations; correlated liquidity loss causing bad debt. Contradiction / change: Prior evidence characterized Pyth as the primary oracle and found no external-venue exposure. Current documentation shows multi-oracle support and live Kamino/Drift integrations; this is a material dependency expansion. Dune/on-chain verification was unavailable; therefore exposure percentages and active-failure status are not confirmed.
Evidence (5)

crypto custody

two sources

marginfi Lending’s custody is best described as non-custodial: users supply assets into on-chain lending pools/accounts on Solana and do not surrender asset custody to a centralized intermediary. The protocol’s risk model is overcollateralized lending: borrowers must post supported collateral, and withdrawals/repayments are enforced by the program logic rather than by a custodian. I could not verify any on-chain custody segregation structure beyond this pooled, programmatic model from the available web sources, so segregated_assets is Not verifiable as of 2026-09-05.

Withdrawal pauses are also Not verifiable as of 2026-09-05; the available support pages discuss withdrawal failures caused by Solana congestion or stale-oracle issues, not a protocol-wide withdrawal pause.

Evidence (4)

incident

one source

Mid-March 2024 withdrawal failures occurred when stale oracle data during Solana congestion blocked oracle-dependent withdrawals. Affected users could not initiate some withdrawals; no protocol exploit or realised loss was reported. Marginfi used stale-price safeguards and coordinated with oracle providers; later documentation continues to require fresh oracle data for withdrawals.

Current user-level loss and any compensation: Not verifiable as of September 5, 2026.

Date
2024-03-15
Cause
Oracle manipulation
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$0
Reimbursed
No
Event id
marginfi-2024-stale-oracle-withdrawals
Evidence (2)

incident

two sources

April 10–12, 2024: operational/governance crisis following founder Edgar Pavlovsky’s resignation, compounded by withdrawal-function/oracle-staleness issues and an eight-day failure to distribute BLZE emissions. Users withdrew approximately $155–300 million, but this was capital flight rather than a protocol loss or exploit. Marginfi and SolBlaze said the emissions issue was resolved and Marginfi committed to refund missed emissions.

The amount actually refunded is Not verifiable as of September 4, 2026. Status: resolved.

Date
2024-04-10
Cause
Other
Attacker proceeds
$0
Status
resolved
Evidence (2)

incident

two sources

April 10–12, 2024 leadership/confidence crisis: founder resignation, missed BLZE emissions, and contemporaneous withdrawal/oracle concerns led users to withdraw approximately $155–300 million. This was capital flight, not an exploit or identified protocol loss; no attacker proceeds were reported. Marginfi and SolBlaze said the emissions issue was resolved, and Marginfi committed to refunding eligible missed emissions.

Amount actually refunded: Not verifiable as of September 5, 2026.

Date
2024-04-11
Cause
Other
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$0
Event id
marginfi-2024-confidence-crisis
Evidence (2)

incident

two sources

On 2024-04-11, marginfi disclosed and patched a critical flash-loan vulnerability that could have let an attacker borrow funds without repayment by abusing transfer_to_new_account during an active flash loan. The issue was reported privately through marginfi’s bug bounty program, fixed before any exploit, and reported to have caused no losses and no funds left at risk; the patch blocked account transfers during flash loans and prevented disabled accounts from repaying a flash loan.

Date
2024-04-11
Cause
Smart-contract exploit
Loss
$0
Evidence (2)

incident

one source

April 2024 LST liquidation incident: temporary LST depegs combined with oracle-system changes triggered mass liquidations, including reported liquidations of accounts with substantial health buffers. Marginfi committed insurance-fund refunds: full refunds for smaller eligible accounts and compensation for fewer than 10 larger accounts, and opened liquidation claims. Claims are now closed, but aggregate realised user loss, total paid, and reimbursement completeness are Not verifiable as of September 5, 2026.

Status is treated as resolved operationally, with reimbursement completeness unresolved.

Date
2024-04-19
Cause
Depeg / collateral
Attacker proceeds
$0
Status
resolved
Event id
marginfi-2024-lst-liquidations
Evidence (2)

incident

one source

April 2024: a series of LST-related liquidations during temporary depegs and oracle-system changes triggered user losses and community backlash. Marginfi committed to refunding eligible users from insurance funds and opened liquidation-reimbursement claims. Aggregate realised loss and amount reimbursed are Not verifiable as of September 4, 2026; the claims portal is now closed.

Status: resolved, with reimbursement completeness unverified.

Date
2024-04-19
Cause
Oracle manipulation
Attacker proceeds
$0
Status
resolved
Evidence (2)

incident

one source

September 17, 2025 disclosure: a critical flash-loan accounting flaw involving transfers to a new account could have enabled uncollateralized borrowing and placed more than $160 million of deposits at risk. It was privately disclosed and patched before exploitation. The fix blocked account transfers during flash loans and prevented disabled accounts from repaying.

No funds were lost, no attacker proceeds occurred, and no reimbursement was required. Current status: resolved.

Date
2025-09-17
Cause
Smart-contract exploit
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$0
Reimbursed
No
Event id
marginfi-2025-flashloan-accounting-bug
Evidence (2)

key management

two sources

marginfi’s user-level key management is organized around an on-chain marginfi account: the account’s current authority can set a new authority for that account, so control of a user position can be reassigned without moving the underlying position state. The protocol is non-custodial, and user balances/borrows are held in on-chain accounts rather than by the operator. For protocol-level control, an independent write-up says marginfi delegated program authority to a Squads multisig, so upgrades require multiple approvals instead of a single key; that reduces single-key compromise risk.

I could not verify the exact signer set, threshold, or current admin structure from the available sources, so those details are Not verifiable as of 2026-09-03.

Evidence (4)

smart-contract

one source

Assessment (as of September 5, 2026): elevated admin/upgrade risk; Solana-native, not an EVM proxy. Addresses & architecture

  • Mainnet program: MFv2hWf31Z9kbCa1snEPYctwafyhdvnV7FZnsebVacA; main group: 4qp6Fx6tnZkY5Wropq9wUYgtFxXKwE6viZxFHg3rdAG8.
  • Architecture: user wallet → mrgnLend Anchor/Solana program → MarginfiGroup/Bank/Account PDAs → token vaults; Pyth/Switchboard and integrated venues (Kamino, Drift, JupLend/Solend) are external dependencies. The deployment is upgradeable through Solana’s BPF upgrade mechanism, not an EVM proxy implementation/admin pattern. Recent documented program upgrades confirm upgradeability.
  • Program upgrade-authority address/type: Not verifiable as of September 5, 2026. An independent governance report describes a separate EOA, but does not provide its address. Privileged controls
  • Group admin, risk_admin, and emode_admin reportedly point to CYXEgwbPHu2f9cY3mcUkinzDoDcsSan7myh1uBvYRbEw, described as a Squads V4 PDA; the report identifies Squads account 74QKjjvoSrq2cGqFzzQNN8ox3gomYS1mBwcLsbiYaH8j and a 5/17 threshold with zero timelock. These details are not independently rechecked here because Dune is unavailable.
  • Admin functions include bank/group configuration, risk parameters, oracle setup, fees, rate limits, emissions, e-mode and role delegation. A risk administrator can configure or clear circuit breakers; release notes also document emergency “super withdraw/deposit” functions and account-freeze functionality.
  • Global fee-state admin can pause all groups/banks for up to 30 minutes, twice daily; paused banks block deposits, withdrawals, borrows and repayments. Reduce-only banks permit withdrawals/repayments. Exit / failure scenarios
  • Users cannot be assured of immediate exit during a global or bank pause, or where liquidity is unavailable. A compromised upgrade authority could deploy arbitrary logic; compromised risk/admin keys could freeze accounts, alter risk/oracle/fee parameters, socialize losses, or impair withdrawals. Direct administrator drainage of all vault assets is Not verifiable as of September 5, 2026.
  • Timelock delay, renounced roles, exact emergency-withdraw semantics, and unresolved audit findings: Not verifiable as of September 5, 2026. No Dune query/execution IDs are available. Contradiction callout: public representative claims of a 7/13 multisig conflict with the independent report’s stated 5/17 on-chain configuration; this requires direct on-chain re-verification. Structured fields: admin_can_drain=null; audited_deployment=null; upgradeable=true; unresolved_critical=null; unresolved_high=null.
Upgradeable
Yes
Evidence (5)

audit

one source

Auditor: Accretion Labs. Report: A25MRG1 — Marginfi. Publication date: April 2025.

Scope: Solana/Anchor lending program. Findings: Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026.

Medium: Not verifiable as of September 4, 2026. Fix status: Not verifiable as of September 4, 2026. Covers deployed code: Not verifiable as of September 4, 2026; no bytecode/source-hash match was performed.

The report is publicly listed by Accretion as a Marginfi audit.

Auditor
Accretion Labs
Report date
2025-04
Scope
Marginfi lending program; Solana/Anchor
Findings
Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026. Medium: Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Auditor: Accretion Labs. Report: A25MRG2 — Project 0 / mrgn Kamino integration. Publication date: June 2025.

Scope: Solana/Anchor Kamino integration. Findings: Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026.

Medium: Not verifiable as of September 4, 2026. Fix status: Not verifiable as of September 4, 2026. Covers deployed code: Not verifiable as of September 4, 2026; no bytecode/source-hash match was performed.

Auditor
Accretion Labs
Report date
2025-06
Scope
Project 0 / mrgn Kamino integration; Solana/Anchor
Findings
Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026. Medium: Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Auditor: Accretion Labs. Report: A25MRG3 — Project 0 / mrgn Drift and Solend integration. Publication date: September 2025.

Scope: Solana/Anchor Drift and Solend integrations. Findings: Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026.

Medium: Not verifiable as of September 4, 2026. Fix status: Not verifiable as of September 4, 2026. Covers deployed code: Not verifiable as of September 4, 2026; no bytecode/source-hash match was performed.

Auditor
Accretion Labs
Report date
2025-09
Scope
Project 0 / mrgn Drift and Solend integrations; Solana/Anchor
Findings
Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026. Medium: Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

A separate security disclosure reported a flash-loan vulnerability in marginfi that was privately reported through the bug bounty program and quickly patched before any funds were lost. This is not presented as a formal audit, but it is relevant to fix status for at least one identified issue in the protocol’s history.

Auditor
Asymmetric Research (disclosure, not audit)
Report date
2025-09
Scope
Flash-loan repayment logic / transfer restrictions in marginfi
Evidence (1)

audit

one source

Newly verified public report listing; detailed findings and remediation status were not verifiable from the available web representation.

Auditor
Accretion Labs
Report date
2025-06-19
Scope
eMode functionality; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/June_19_2025_accretion_emode.pdf
Report id
doc:0c4df91c006c26c4
Evidence (1)

audit

one source

Newly verified public report listing; report findings, remediation, and deployed-code match were not extractable from the available web representation.

Auditor
OtterSec
Report date
2023
Scope
Marginfi v2 general lending program; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/2023_ottersec_general.pdf
Report id
doc:63e724bb549014da
Evidence (1)

audit

one source

Newly verified public report listing; auditor identity, detailed findings, remediation status, and deployed-code coverage were not verifiable from the available web representation.

Auditor
Not verifiable as of September 6, 2026
Report date
2025-06-25
Scope
Kamino-related functionality; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/June_25_2025_Kamino.pdf
Report id
doc:95065e7b26718ac4
Evidence (1)

audit

one source

Newly verified public report listing; detailed findings and remediation status were not verifiable from the available web representation.

Auditor
Sec3
Report date
2025-06-30
Scope
eMode functionality; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/June_30_2025_sec3_emode.pdf
Report id
doc:a2394ec72434938f
Evidence (1)

audit

one source

Newly verified public report listing; detailed findings and remediation status were not verifiable from the available web representation.

Auditor
Sec3
Report date
2023-12-13
Scope
Marginfi v2 general lending program; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/December_13_2023_sec3_general.pdf
Report id
doc:c16531256c3db55b
Evidence (1)

audit

one source

Newly verified public report listing; detailed findings and remediation status were not verifiable from the available web representation.

Auditor
Sec3
Report date
2023-12
Scope
Marginfi v2 liquidation logic; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/December_2023_sec3_liquidations.pdf
Report id
doc:c2fa8ce88415619d
Evidence (1)

audit

one source

Newly verified public report listing; detailed findings and remediation status were not verifiable from the available web representation.

Auditor
Sec3
Report date
2025-01-28
Scope
Staked-collateral functionality; Solana/Anchor
Findings
Critical: Not verifiable as of September 6, 2026. High: Not verifiable as of September 6, 2026. Medium: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026.
Report url
https://github.com/0dotxyz/marginfi-v2/blob/main/audits/January_28_2025_sec3_stakedCollateral.pdf
Report id
doc:d070e86300861636
Evidence (1)

audit

unverified

Marginfi v2 lending program on Solana; official docs state the protocol has been audited by OtterSec and include a link to the audit resources page.

Auditor
OtterSec
Report date
2026-09-01
Scope
marginfi v2 program documentation references the core lending program; whether the report covers all currently deployed code is not verifiable from the available source alone.[1]
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (1)

Team & Reputation

founders

two sources

Marginfi is a Solana lending protocol originally built by MRGN Labs / MRGN, Inc., with founding leadership centered on Edgar Pavlovsky and MacBrennan Peet (Mac Brennan / MacBrennan Peet). Founders & backgrounds

  • Edgar Pavlovsky – described as founder of Mrgn Labs and creator of Marginfi. Prior experience includes Goldman Sachs and Uber plus work in ML/AI and data science; he previously founded a company called Jia. Publicly visible and not an anonymous founder.
  • MacBrennan Peet – widely cited as co‑founder and head of growth/institutional relationships. Background in traditional finance (Morgan Stanley, MedEquity Capital) and as founder of hedge fund Katalpa Capital Management. Also non‑anonymous and active in media/podcasts. Corporate entity, location, and “real business” check
  • Multiple profiles state that Marginfi is built by MRGN, Inc. / Mrgn Labs, incorporated as a company that raised a $3M seed round in 2022 from Pantera, Multicoin, Solana Ventures, and Sino Global.
  • A company profile lists location as Solana Beach, United States for Marginfi, which suggests an onshore U.S. footprint rather than purely offshore, though exact legal domicile of all entities is not fully disclosed in public sources.
  • The team is covered by venture firms (Pantera, Multicoin, etc.) and investment memos, and appears in mainstream crypto media and podcasts, which is consistent with a real operating business rather than a pseudonymous web front. Public vs. anon; credibility signals
  • Core founders and several team members (e.g., growth lead) are named and present on LinkedIn, podcasts, and VC blogs. This is a public, doxxed team, not an anon collective.
  • Track record includes prior institutional finance and software roles plus a VC‑backed raise, which provides positive credibility signals, but there is no formal regulatory licensing indicated in sources (e.g., not a registered broker‑dealer or bank). Controversies & governance reality check
  • In April 2024, founder Edgar Pavlovsky publicly resigned from mrgn/marginfi, citing “internal operational disagreements” and dissatisfaction with internal/external practices. The company confirmed his departure but stated protocol operations continued.
  • The resignation, plus public disputes over airdrop/emission practices with SolBlaze and others, triggered a large but temporary TVL outflow and reputational hit. What is *not* verifiable now
  • Exact current legal entity structure (including any offshore entities), current physical office addresses, and any subsequent corporate reorganization are Not verifiable as of 2026‑09‑03 based on accessible public data alone.
Evidence (15)

general reputation

two sources

Marginfi is a Solana lending protocol built by the company mrgn Labs; it is backed by major Solana-focused investors and has no public fraud/rug allegations, but it has experienced one major reputational event in 2024 around user withdrawals and communications. Team, investors, auditors

  • Marginfi is developed by mrgn Labs, whose co‑founders include Edgar Pavlovsky and other Solana-native engineers; Pavlovsky was the most visible public face until his 2024 resignation.
  • Public investors include Multicoin Capital, Solana Ventures and Pantera among others, positioning marginfi as a “blue‑chip” Solana DeFi name in many ecosystem narratives.
  • Independent security reviews have been conducted by firms such as OtterSec and Trail of Bits (on earlier mrgn/margin-related codebases), but comprehensive audit coverage for the current marginfi lending V2/V3 stack is not consolidated in one place and is not verifiable as of 2026‑09‑03 from auditor primary sources. Reputation & sentiment
  • Through 2023–early 2024, marginfi generally enjoyed a positive reputation as a leading Solana money market, often cited alongside Kamino and Solend in ecosystem overviews, with strong TVL growth during the Solana revival.
  • In April 2024, users reported withdrawal delays and confusion around solvency/liquidity, triggering a wave of concern on X and Discord; some users partially compared the situation to previous CeFi failures, although on‑chain insolvency was not demonstrated by independent analysts.
  • Around the same time, founder Edgar Pavlovsky resigned publicly, citing internal disagreements and expressing dissatisfaction with how user concerns were handled, which sharply worsened sentiment and led to large user outflows and negative social media coverage. Criticisms & unresolved concerns
  • Main criticisms focus on:
  • Crisis communications: users complained about slow, defensive, or unclear messaging during the April 2024 episode, damaging trust even after withdrawals normalized.
  • Centralized control / off‑chain dependencies: some community critics argue the protocol relies heavily on the core team and opaque risk management processes, raising questions about decentralization and governance durability. Not verifiable as of 2026‑09‑03.
  • There are no substantiated public claims of an outright rug pull or fraud, but the 2024 episode left a reputational scar; for some institutional participants, marginfi is now viewed as higher communications/governance risk than pure-codebase risk. Legal / regulatory / sanctions
  • As of 2026‑09‑03, there are no known sanctions listings, criminal charges, or major regulatory enforcement actions specifically naming marginfi, mrgn Labs, or its core founders. This is based on checks of major English‑language reporting and crypto‑regulatory coverage; absence of evidence is not proof of absence.
Evidence (2)

Economy

TVL: $36.7M

model

one source

Economic model — Marginfi Lending (Solana)

  • Strategy / assets in-out: Overcollateralized lending markets. Users supply supported Solana assets—typically SOL/LSTs, stablecoins and other listed tokens—and receive the same asset plus variable interest. Borrowers post collateral and receive another supported asset. Interest rates are utilization-based and asset-specific.
  • Yield source: Primarily borrower interest and, for liquidated positions, liquidation-related economics. This is organic credit-market yield, not inherently external farming or restaking. Any campaign/points incentives would be subsidized and are not included in the base lending yield.
  • Organic vs subsidized: Exact organic-yield share: Not verifiable as of September 5, 2026. organic_yield_pct = null.
  • Market exposure: Lending a volatile asset retains directional exposure to that asset; lending stablecoins is closer to market-neutral but remains exposed to stablecoin, oracle, smart-contract and liquidity risk. Borrowers can create directional long/short or hedged positions.
  • Leverage / looping / external exposure: Users can manually loop collateral and borrowing, and Marginfi supports flash-loan/composable leveraged strategies. Isolated-pool assets generally cannot serve as collateral; global-pool assets can. No protocol-level restaking requirement was verified. Maximum leverage depends on collateral/liability weights, caps and liquidity. leverage_ratio = nullNot verifiable as of September 5, 2026.
  • Lock-ups / withdrawals: No fixed maturity or lock-up identified. Withdrawals are health-checked and constrained by available liquidity; borrowers must repay or maintain sufficient collateral. Full-withdrawal/repayment functions include accrued interest.
  • Fees / gates / limits: Borrow interest, origination/insurance parameters, bank deposit/borrow caps, rate limiters and liquidation penalties. A support page describes a 5% liquidation penalty, split between liquidator and insurance fund; parameters may vary by deployment/version.
  • Protocol revenue: DeFiLlama attributes revenue to the spread between borrower interest and depositor interest. Current snapshot: TVL $9.87m, all on Solana; 30-day fees $41.0k and revenue $516.64.
  • Collateral / liquidation: Collateral weights, liability weights and oracle prices determine health; unhealthy accounts can be permissionlessly liquidated at a discount. > Data gap / contradiction: Dune MCP was unavailable, so no raw on-chain verification, chain/product decomposition beyond DeFiLlama, or Dune-vs-DeFiLlama reconciliation is possible. TVL trend, product-level TVL, APY history/volatility and sustainability: Not verifiable as of September 5, 2026.
Evidence (4)

reserves

two sources

As of September 5, 2026 — Solana only. Finding: Marginfi’s reserve/treasury position is not fully verifiable. Dune MCP was unavailable for this run; therefore no on-chain balances, reserve-wallet inventory, asset composition, liabilities, or block-height snapshot can be reported. Not verifiable as of September 5, 2026.

  • Liquid reserves (USD): Not verifiable as of September 5, 2026.
  • Liabilities (USD): Not verifiable as of September 5, 2026.
  • Known protocol addresses: The official documentation identifies the marginfi v2 program as MFv2hWf31Z9kbCa1snEPYctwafyhdvnV7FZnsebVacA and the main group as 4qp6Fx6tnZkY5Wropq9wUYgtFxXKwE6viZxFHg3rdAG8; these are protocol accounts, not confirmed treasury or reserve wallets.
  • Reserve mechanism: Marginfi documentation states that 50% of the stated liquidation penalty goes to the liquidator and 50% to the insurance fund of the relevant bank. This describes a bank-level insurance mechanism, not a disclosed centralized treasury balance or proof of reserves.
  • Custody/control: No independently verified reserve-wallet list, multisig configuration, signers, custody provider, or governance-controlled treasury address was located. Not verifiable as of September 5, 2026.
  • Composition: No reliable current breakdown of SOL, stablecoins, liquid-staking tokens, MRGN, or other treasury assets was located. Not verifiable as of September 5, 2026.
  • Policy/attestations: Publicly listed security audits concern program security, not reserve sufficiency, solvency, liabilities, or financial attestations. No proof-of-reserves report or independent reserve attestation was located. > Contradiction / qualification: The previously recorded 52.5% “Community DAO reserves” figure relates to MRGN token allocation, not a measured treasury balance, reserve custody arrangement, or liquid-reserve policy. It should not be treated as evidence of current reserves. This remains an unverified marketing/tokenomics claim. Risk conclusion: Reserve transparency is insufficient for institutional verification. The insurance-fund mechanism is documented, but its current balances, coverage relative to depositor liabilities, and control framework remain unverified.
Evidence (6)

tokenomics

two sources

marginfi Lending on Solana does not have a clearly verifiable native token tokenomics package from the gathered sources. The protocol documentation confirms the lending program address and main group on Solana, but the sources do not provide a confirmed native token contract address, total supply, circulating supply, market cap, FDV, allocation breakdown, or an on-chain unlock/emissions record for a live token. The only token-related claim found is that marginfi ran a points program in 2023–2024 that was widely expected to convert into an MFI governance token airdrop, but the launch was delayed and later paused; this is best treated as an unscheduled/paused plan, not a live tokenomics system.

I did not find a verifiable, live Solana token contract for marginfi Lending, so the correct answer is that no native token is currently verifiable as of 2026-09-03. Because no live native token is verifiable, the following are Not verifiable as of 2026-09-03: total vs circulating supply, market cap and FDV, revenue share, buybacks, burns, staking rewards, emissions schedule, unlock schedule, whether unlocks occurred on-chain, team/investor/treasury/community allocations, top-holder concentration/insider wallets, mint/blacklist/fee-switch functions and controller, and DEX liquidity depth/main listings. If you want, I can next produce a non-tokenomics risk note on marginfi’s lending protocol design, admin surface, and Solana program addresses from the available sources.

Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

unverified

A Bitcoin move below $10,000 would be a severe stress event for marginfi borrowers who post BTC as collateral, because marginfi liquidates accounts when health reaches 0% or below and uses partial liquidation to restore health to 1. The exact impact on the protocol cannot be quantified from the provided sources, because no BTC-collateral exposure, user-level LTV distribution, or Solana on-chain position data is verifiable as of 2026-09-03. What can be said with confidence is the mechanism: as BTC falls, collateral value declines while debt stays fixed, so LTV rises and health falls.

If a position breaches the liquidation threshold, marginfi applies a 5% liquidation penalty, split 2.5% to the liquidator and 2.5% to the insurance fund, and liquidates only the minimum amount needed to restore health. The support docs also note that stale oracles on Solana network congestion can affect liquidation behavior, so a sharp crash could be compounded if oracle updates lag. For this stress scenario, the key risk is not that every BTC-backed position is automatically liquidated at $10,000, but that positions with low collateral buffers would likely be pushed into liquidation rapidly, especially if the price drop is abrupt and oracle/liquidity conditions are stressed.

Not verifiable as of 2026-09-03: the share of marginfi TVL/exposure on Solana tied specifically to BTC collateral, and the expected protocol-wide loss or insurance-fund draw under a BTC < $10,000 scenario.

Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

Marginfi is a Solana overcollateralized lending protocol, so a 20% depeg in the largest collateral asset mainly translates into a lower account health for users who have that asset posted as collateral. The exact solvency impact cannot be quantified from the web results alone because the largest collateral by TVL and the current collateral distribution are Not verifiable as of 2026-09-03. What can be stated is the liquidation mechanics: when account health reaches 0% or below, the position becomes subject to liquidation, and marginfi charges a 5% liquidation penalty split 2.5% to the liquidator and 2.5% to the insurance fund.

The docs also state that marginfi uses weighted prices and risk parameters, and that borrowing outside supported e-mode pairings reverts an account to normal collateral weights, which means a depeg can hit accounts more severely if they were relying on boosted e-mode weights. For stress analysis, the key consequence of a 20% drop in the largest collateral is that accounts with thin buffers can cross the liquidation threshold, triggering partial liquidation and penalty extraction from collateral. Accounts with health factors already near the liquidation line are the most exposed; users with larger cushions may absorb the shock without immediate liquidation.

Because on-chain exposure data is unavailable in this run, the prudent conclusion is: a 20% depeg of the largest collateral would materially increase liquidations and reduce account health, but the portfolio-wide impact is Not verifiable as of 2026-09-03. If you want, I can next provide a scenario template showing how to estimate worst-case liquidations once collateral weights and TVL by asset are supplied.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

In marginfi’s overcollateralized design, “top counterparty insolvent” generally manifests as bad debt on the lending pool when liquidations fail to fully cover a large borrower’s liabilities; the protocol’s insurance fund and, ultimately, depositors absorb the loss via reduced pool value. ### Stress path: large borrower (“top counterparty”) defaults 1. Trigger condition

  • Health factor is calculated at the *account level* across all deposits and borrows; when it drops below 1, positions become eligible for liquidation.
  • Insolvency occurs if, after attempted liquidations, the borrower’s liabilities exceed the realizable value of their collateral (e.g., extreme price gap, oracle failure, liquidity crisis). 2. Liquidation mechanics
  • Liquidations are automatic and permissionless; any keeper can repay part of the debt in exchange for discounted collateral.
  • Marginfi uses partial liquidations, selling only enough of the least-healthy asset to restore account health to ≥1 under normal conditions.
  • A 5% liquidation penalty on the liquidated amount is charged to the borrower and split 2.5% to the liquidator, 2.5% to the protocol’s insurance fund—this is the main ex-ante compensation mechanism for liquidation risk. 3. Expected loss path if liquidation fails (true insolvency)
  • If market moves are too fast or liquidity too thin, liquidators may not be able to clear the full position at the oracle prices; residual undercollateralized debt becomes bad debt in the pool.
  • The insurance fund, funded over time by liquidation penalties, is the first-loss buffer, absorbing bad debt to protect lenders as long as it has sufficient balance.
  • If insurance is depleted, depositors (lenders) effectively absorb losses via:
  • Lower claimable assets vs. notional balances (pool shortfall).
  • Potential write-downs of specific asset pools if implemented at the contract level (Not verifiable as of 2026-09-03). 4. Impact path through smart contracts (Solana)
  • The borrower’s margin account becomes insolvent → liquidation instructions attempt to repay debt and transfer collateral in the lending program.
  • Insurance fund program receives its share of penalties; if used to cover bad debt, it transfers assets back into the affected reserve(s).
  • Reserve states (interest rates, utilization, total deposits) update reflecting the shortfall; future lenders face altered APYs and risk. 5. Compensation and who bears the loss
  • Liquidators are compensated via discounts + 2.5% fee, but do not bear structural loss if they price risk correctly.
  • Insurance fund is compensated ex ante via penalties and bears first-loss. If exhausted, pool depositors become the residual risk-bearers (Not verifiable as of 2026-09-03). No chain-level guarantees or external bailout mechanisms are documented; all loss absorption appears internal to the protocol’s contracts and insurance fund.
Evidence (15)

stress scenario - committed fraud by the DAO or owners

two sources

For the DAO/owners committed fraud stress case, I found no verifiable evidence that marginfi’s DAO or owners have been accused or found guilty of fraud. The available material instead shows a prior technical vulnerability in flash loans that was privately disclosed and patched before exploitation, which is a security issue, not evidence of fraud. The protocol documentation and third-party descriptions characterize marginfi as a non-custodial, overcollateralized Solana lending protocol, but those are not proof against insider fraud and should be treated as descriptive only.

What can be said for risk analysis is that a committed-fraud scenario would likely present as governance/admin abuse, malicious parameter changes, unauthorized fund redirection, or misappropriation of reserves/insurance funds. However, based on the sources provided, there is no confirmed case of such conduct. The earlier flash-loan bug demonstrates smart-contract risk and rapid incident response, not malicious owner behavior. Not verifiable as of 2026-09-03: whether marginfi DAO or owners have committed fraud, because the provided sources do not contain regulator, court, or independently documented allegations substantiating that claim.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario where the primary yield source is negative over the last 30 days, the key risk for marginfi Lending on Solana is that lender returns can compress to near zero or negative in net terms if the asset’s embedded yield component underperforms while borrow demand remains weak. Marginfi’s rates are variable and depend on market conditions and utilization, so the protocol does not guarantee a positive 30-day yield floor. The main exposure depends on the asset type:

  • For plain lending markets like SOL or USDC, yield is primarily the lending APY set by utilization, so a negative primary yield source would mainly show up as a sharp decline in realized return rather than protocol insolvency.
  • For yield-bearing collateral markets such as LST-style assets, the embedded staking component is part of the return profile; if that primary yield turns negative, the user can face underperformance versus expectations even if the lending leg still accrues some interest. Marginfi’s documented risk controls focus on account health, liquidation, and an insurance fund that absorbs bad debt before losses are socialized if needed. That means a negative 30-day yield source is primarily a yield-risk event, not automatically a solvency event, unless it coincides with collateral deterioration, stale oracle conditions, or forced liquidations. Practical stress conclusion: in this scenario, the protocol’s user-facing risk is negative or sharply reduced net APY, with secondary risk of liquidation for leveraged users; the protocol-level backstop is the insurance fund and its bankruptcy handling process.
Evidence (5)

Governance & Legal

governance

one source

Assessment — as of September 13, 2026. Governance is operationally foundation/company controlled, not demonstrably token-DAO controlled. The current architecture states that each lending Group has one administrator with broad authority, delegate admins with narrower powers, and that all assets shown in the current frontend belong to a Group overseen by the foundation. No binding token-holder governance, proposal forum, voting module, or executable DAO process was identified. DAO is therefore assessed as symbolic/absent for protocol control. Contracts/admin powers. Admins can configure Groups and Banks, select or change oracles, alter risk parameters, fees, caps and operating modes, and create/close Banks.

The release notes also document admin-only super-deposit/withdraw functionality for socializing losses, plus risk-manager ability to bypass pauses during deleveraging/bankruptcy handling. The Global Fee State Admin can pause the protocol for up to 30 minutes, twice daily. This creates material privileged-key and emergency-governance risk. Frontend/dev/funds. The public frontend and principal deployment are described as foundation-overseen.

Development is maintained through the 0dotxyz/marginfi-v2 repository. A company association is reported by Crunchbase as MRGN, Inc., a for-profit company based in Austin, Texas; registration number, governing jurisdiction filing, directors, and authoritative Terms of Service were not independently verified. Voting concentration/top holders via Dune: Not verifiable as of September 13, 2026. Dune was unavailable in this run; no holder or voting-concentration figures are inferred. Multisig signers/threshold/independence: Not verifiable as of September 13, 2026.

Documentation says “typically” a governance multisig, but does not identify the wallet, signers, threshold, or signer independence. Timelock/delay: Not verifiable as of September 13, 2026. Contradiction/finding: “Governance multisig” terminology exists, but current documentation simultaneously places the active frontend Group under foundation oversight; no evidence shows token holders can bind or replace that control. On-chain verification was skipped and must not be inferred.

Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Entity & jurisdiction

  • Marginfi is developed by MRGN, Inc.; a company profile lists MRGN, Inc. as the associated legal entity for Marginfi.
  • The corporate domicile is not stated in the retrieved data. *Jurisdiction: Not verifiable as of 2026-09-03.*
  • The protocol itself is a non‑custodial lending protocol on Solana built by Mrgn Labs, live since mid‑2023. Terms of service / user restrictions
  • Public docs describe Marginfi as a permissionless prime broker / non‑custodial lending protocol on Solana and emphasize that it is protocol infrastructure, not a traditional financial intermediary.
  • No detailed ToS, user eligibility criteria (e.g., US persons, sanctioned jurisdictions), or age/location restrictions are visible in the surfaced support/docs pages. *Not verifiable as of 2026-09-03.*
  • Help Center and FAQ material focus on product mechanics (liquidations, fees, LST treatment) rather than legal terms or risk disclosures. KYC / AML and data protection
  • Marginfi is described as non‑custodial and permissionless, which typically implies no account-based onboarding and no KYC/AML checks at the protocol smart-contract level.
  • There is no evidence in the surfaced documentation of formal KYC/AML procedures, customer due diligence, or transaction monitoring frameworks. *Not verifiable as of 2026-09-03.*
  • No explicit privacy policy or GDPR/DP law compliance statement is visible in the accessible documentation. *Data protection posture: Not verifiable as of 2026-09-03.* Regulatory classification and legal structure vs. actual risk
  • Marginfi markets itself as a permissionless prime broker / lending protocol, structurally closer to a decentralized margin/lending venue than a regulated broker‑dealer or bank.
  • As a smart‑contract protocol, users interact directly with Solana programs (e.g., marginfi‑v2 program address listed in docs), which reduces custody‑style risk but concentrates smart‑contract, liquidation, oracle, and governance risks.
  • There is no indication that Marginfi or MRGN, Inc. holds broker‑dealer, exchange, or bank licenses in any jurisdiction based on the surfaced data. *Not verifiable as of 2026-09-03.* Warnings, enforcement actions, court cases, sanctions
  • No regulator warnings, license revocations, or enforcement actions specifically naming Marginfi or MRGN, Inc. were surfaced. *Active enforcement: false as of 2026-09-03 (subject to new actions).*
  • No court cases or formal litigation records tied to Marginfi or MRGN, Inc. were found. *Not verifiable as of 2026-09-03.*
  • No evidence that Marginfi or MRGN, Inc. itself is on sanctions lists. *Sanction status: false as of 2026-09-03.* Compliance blocking of sanctioned wallets at protocol or integrator level is not evidenced either. *Not verifiable as of 2026-09-03.* Governance / disclosures
  • Public narrative emphasizes Marginfi as a protocol by Mrgn Labs, but there is limited formal governance, legal, or regulatory disclosure in the surfaced docs compared with mature DeFi protocols.
  • CEO resignation and public controversy are reported in crypto media, indicating internal organizational issues but not direct regulatory action. Key institutional risk takeaway: legal structure and regulatory posture are lightly documented, with no visible licensing, KYC/AML framework, or explicit regulatory classification, increasing counterparty/regulatory risk for institutional use despite the non‑custodial technical design.
Sanctioned
No
Entity
MRGN, Inc.
Evidence (6)

legal registries

two sources

No exact GLEIF LEI record for 'MRGN Inc', 'marginfi Lending'. OFAC SDN screening of 'MRGN Inc', 'marginfi Lending': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • MRGN Inc
  • marginfi Lending
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Marginfi Lending appears to issue its own stablecoin, YBX, which is described by multiple sources as a marginfi-issued, USD-soft-pegged, LST-backed stable asset. A depeg event for the stablecoin used by marginfi Lending is not verifiable as of 2026-09-05 from the available web evidence, so depeg_count, last_depeg_date, and max_depeg_pct remain unknown. The protocol is therefore not confirmed stable or unstable from this evidence alone.

Own stablecoin
Yes
Stablecoin ids
  • YBX
Evidence (3)

Risks & Strengths

risks

unverified

Marginfi’s principal risks are oracle and Solana execution dependency, rapid liquidity deterioration, bad-debt socialization, privileged administration, and smart-contract/integration complexity. The protocol documents meaningful controls—conservative oracle pricing, isolation modes, liquidation, audits, and a bug bounty—but these reduce rather than eliminate loss risk. TVL, reserve coverage, exposure concentration, and live administrator/upgrade-key activity are Not verifiable as of September 5, 2026 because Dune on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle pricing and stalenessIncorrect, delayed, or divergent Pyth/Switchboard prices can misvalue collateral and debt, trigger premature liquidations, or permit undercollateralized borrowing during fast markets. Switchboard-dependent actions can fail when feeds are stale.HighMediumConservative confidence bounds, Pyth EMA pricing for borrowing, 60-second freshness checks, multiple oracle support, and mandatory feed updates where required.Material residual risk remains during oracle outages, feed-provider failure, extreme volatility, or correlated oracle errors.
Liquidity freeze and withdrawal riskAt very high utilization, especially near 100%, lenders may be unable to withdraw immediately. A borrower rush or market stress can therefore convert an apparently liquid deposit into a delayed claim.HighMediumUtilization-based interest-rate curves sharply increase borrowing costs at high utilization, while reduce-only bank states and administrative controls can restrict new risk.Rate incentives may not restore liquidity quickly during panic, borrower insolvency, or thinly traded asset markets.
Bad-debt socializationIf collateral prices gap, liquidators cannot execute, or collateral is illiquid, insurance may be insufficient. Losses can reduce asset-share value for depositors or permanently disable a bank in super-bankruptcy.HighMediumPermissionless liquidation, liquidation premiums, insurance-fee allocation, conservative health weights, isolated-risk tiers, and a bankruptcy settlement process.Insurance adequacy and bad-debt capacity are Not verifiable as of September 5, 2026; depositor loss remains possible.
Privileged administration and upgradesA group administrator can configure banks, oracle assignments, risk parameters, and operational states; privileged changes or program upgrades can introduce censorship, parameter, or loss-of-funds risk.HighMediumMultisig-style governance is described for administration, delegated roles separate some functions, and the code is open source with public security reporting.Key compromise, insider action, governance error, or absent timelock protection can still affect users before exit is possible.
Smart-contract and integration bugsErrors in accounting, liquidation, flash-loan flows, Token-2022 handling, or integrated venues could cause loss, stuck positions, or incorrect health calculations despite audits.HighMediumMultiple audits, fuzz testing, open-source code, release testing, and a public bug-bounty program are in place.Audits are point-in-time and do not cover every deployment, upgrade, integration, economic exploit, or off-chain component.
Evidence (5)

strengths

two sources

marginfi Lending’s main strengths are: (1) decentralized, permissionless borrowing and lending on Solana, with no intermediaries; (2) strong risk management, including overcollateralization and health-factor/liquidation controls; (3) high capital efficiency and composability, enabling multi-asset collateral and leverage-oriented workflows; (4) Solana-native performance, benefiting from low fees and fast settlement; and (5) a broad market design and UX focus, with global/isolated market structures and a single interface for multiple lending markets. The most consistently supported strengths across the results are decentralization, risk controls, and capital efficiency. Several sources also highlight that marginfi is built natively on Solana, which gives it speed and low transaction costs relative to slower chains.

Some sources additionally emphasize a wider catalog of isolated markets and a cleaner global-account user experience.

  • Permissionless access: users can supply or borrow liquidity without intermediaries.
  • Risk management: overcollateralization, health-factor monitoring, liquidation design, and configurable asset risk parameters.
  • Capital efficiency: multi-asset collateral and leverage-friendly position management.
  • Solana-native performance: low-cost, high-throughput execution and fast settlement.
  • Product breadth / UX: global and isolated markets, plus a single interface for multiple lending markets.
Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 18 two independent sources, 21 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-28.