Sky Lending

Green · 81/100

Executive summary

Sky Lending is the CDP-style lending protocol within the Sky (formerly MakerDAO) ecosystem, scoring 76/100 (green band) with high data confidence (88/100).

  • Security: Multiple audits by ChainSecurity, Trail of Bits, PeckShield, and Quantstamp covering core contracts, liquidations, and governance; recent 2025–2026 audits show 0 critical/high findings in governance and token modules, though 3 high findings (all remediated) in Endgame Toolkit; bytecode match to deployed contracts and chain-specific coverage (Arbitrum, OP Mainnet, Unichain) are Not verifiable as of September 6, 2026. Active $10M bug bounty on Immunefi since February 2022.
  • Incidents: Three documented events, all resolved or remediation-in-progress with no user losses: November 2023 SparkLend interest-rate accounting discrepancy (~$297k treasury shortfall, recovery status unverified); May 2025 false-alarm market freeze (no loss); April 2026 external rsETH bridge exploit ($292M ecosystem-wide, Sky had deprecated exposure and reported zero protocol loss).
  • Governance & custody: Non-custodial smart-contract system; SKY token governance via Chief, GSM/Pause timelock, and executive spells; latest vote executed August 31, 2026; governance-security delay exists but numeric value Not verifiable; emergency bypass and authorized instant-access modules documented; voting concentration and top holders Not verifiable as of September 6, 2026.
  • Top risks: Smart-contract/oracle failure (one-hour oracle delay, Chronicle/OSM dependency); liquidation cascade and bad debt (collateral-auction limits mitigate but do not eliminate tail risk); counterparty exposure to USDC/USDT/PYUSD, RWA managers/SPVs, cross-chain bridges (Wormhole-to-LayerZero migration audit treated bridge security as out-of-scope), and Chainlink/Balancer rate providers; governance concentration (S&P notes effective control by co-founder due to low turnout); stablecoin depeg history (March 2023 USDC crisis); cross-chain TVL discrepancy (DeFiLlama shows 100% Ethereum vs. stated Arbitrum/OP/Unichain presence, unresolved).
  • Strengths: Decade-long MakerDAO lineage with $7.9B TVL and no core-protocol exploits; institutional credibility (S&P B- rating, $124M Q1 2026 revenue); Sky Savings Rate yield model removes borrower-utilization and liquidation risk for depositors; multichain access (Ethereum, Arbitrum, OP Mainnet, Unichain claimed); transparent on-chain reserves ($11.41B collateral, $98.42M liquid reserves as of August 2026) and governance.
  • Unverified: Chain-specific TVL, exposure, and contract deployments on Arbitrum, OP Mainnet, and Unichain; deployed-bytecode match for all audited contracts; governance timelock duration; top token holders and voting concentration; total/circulating SKY supply, emissions, and unlock schedule; organic vs. subsidized yield split; protocol-wide leverage ratio; RWA custody attestations; BTC and largest-collateral exposure by chain; primary yield-source composition.
  • Recommended exposure: Suitable for institutional allocators seeking blue-chip DeFi lending with transparent governance and audited contracts; position size should reflect elevated counterparty risk (oracles, bridges, RWA/stablecoin exposure) and governance concentration; limit exposure to a fraction of total portfolio until chain-specific TVL, voting concentration, and cross-chain contract verification are completed; monitor governance votes, oracle/bridge incidents, and S&P rating updates; consider Ethereum-only allocation until L2 deployments are independently verified.
  • Open questions: Verify deployed contract addresses, proxy admins, and bytecode match on all four chains; confirm governance timelock duration and emergency-bypass scope; obtain Dune dashboard for top SKY holders, voting concentration, and chain-by-chain TVL/collateral breakdown; verify RWA custody, attestations, and redemption mechanics; assess BTC and largest-collateral exposure, liquidation buffers, and auction performance under stress; confirm organic vs. subsidized yield sources and historical APY volatility; review latest S&P assessment and any post-April-2026 governance or security incidents.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 20 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-30)
Incidents 20% 100 20.0 1 open incident(s), $0 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 31 6.2 TVL $5,455,845,423 = 31% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 19/49 verified facts; 49/49 fresh (180d)

Identification

protocol identification

two sources

Sky Lending is a DeFi lending/CDP protocol in the Sky (ex‑MakerDAO) ecosystem, focused on over‑collateralised borrowing against assets like WETH and USDS; detailed on‑chain verification is Not verifiable as of 2026-09-04. Identification

  • Name / Category: Sky Lending, a CDP-style lending protocol (deposit collateral, borrow stablecoins) within Sky’s stack.
  • Website / Docs: Not verifiable as of 2026-09-04 (analytics sites link to protocol name only, no consistent official URL).
  • Launch date: Not verifiable as of 2026-09-04; analytics pages show historical data but do not state an explicit launch date.
  • Chains:
  • Ethereum: Multiple WETH/ETH-A CDP pools labelled “Sky Lending,” with large TVL (e.g., ~$940m and ~$540m).
  • Arbitrum & OP Mainnet: sUSDS yield pools tagged “sky-lending,” APY ~3.6%, TVL ~$360m (Arbitrum) and ~$5m (OP).
  • Unichain: Not verifiable as of 2026-09-04; no independent source listing Sky Lending on Unichain.
  • Native token: The broader Sky ecosystem uses SKY and USDS (upgraded DAI stablecoin), but a distinct “Sky Lending” token is Not verifiable as of 2026-09-04.
  • Main contracts / explorer status: Specific contract addresses for Sky Lending pools are Not verifiable as of 2026-09-04; current data comes from yield/analytics aggregators, which do not expose canonical addresses or explorer verification flags. Fork Lineage & Design
  • Relation to Maker/Sky: Sky Lending appears as a lending/CDP layer that uses USDS and sUSDS within the Sky ecosystem.
  • Aave V3 fork link: SparkLend (Sky’s primary money market) is an Aave V3 fork with governance-defined rates. Several aggregators treat Sky Lending and SparkLend as part of the same stack, but an explicit statement that “Sky Lending itself is an Aave fork” is Not verifiable as of 2026-09-04.
  • Key changes vs upstream (for SparkLend): governance‑defined base rates, integration with sDAI/sUSDS vaults, and a cross‑chain liquidity layer. Whether Sky Lending uses identical mechanics or a CDP-specific variant is not clearly documented in independent sources.
  • Audits: Audits specific to Sky Lending are Not verifiable as of 2026-09-04. SparkLend is described as inheriting Maker‑era audits and having a “Sky audit registry,” but these references are high‑level and not protocol‑specific.
  • Malicious-modification history in similar forks: No independent reports of malicious modifications or exploits specifically tied to Sky Lending are visible in retrieved media; broader Aave-fork incidents exist in the ecosystem but are not linked to this protocol. Not verifiable as of 2026-09-04 for Sky Lending itself. Contradiction callout > Chain coverage and exact TVL for Sky Lending differ across analytics platforms (e.g., one source calling it “deployed across 1 chain, led by Ethereum” vs others clearly listing Arbitrum and OP pools). Without on-chain queries, the multi-chain footprint and TVL distribution are Not verifiable as of 2026-09-04.
Evidence (9)

maturity

one source

Sky Lending appears to be a real DeFi lending product page rather than a pure marketing landing page, but the web evidence available here is limited. The only directly relevant result is DeFiLlama’s Sky Lending protocol page, which identifies it as a tracked lending protocol with 25 pools and an average APY, suggesting live product activity rather than a static brochure. That said, live deposits/withdrawals, app-level functionality, broken links, and template/fake-metric checks are not verifiable as of 2026-09-04 from the available evidence.

The protocol’s own site/documentation was not independently validated here, so any functionality claims from that source would remain unverified marketing claims. Open API: not verifiable as of 2026-09-04. No reliable evidence in the gathered results confirms a public API for Sky Lending specifically; the search results that mention “open API” refer to unrelated services, not this protocol.

Bottom line: moderately mature from the limited signal available, but a full portal-versus-landing, UX, and API assessment is not verifiable as of 2026-09-04.

Evidence (1)

Security

bug bounty

one source

Sky Lending has an active bug bounty program run on Immunefi. It started on 10 February 2022 and is currently listed as live. The program’s maximum payout is USD 10,000,000.

For critical smart-contract bugs, the reward is 10% of funds directly affected, capped at USD 10,000,000, with a minimum reward of USD 150,000. Critical website/application bugs can pay USD 100,000 if they cause direct loss without any user action; other critical theft cases pay USD 50,000. Published program materials do not show publicly disclosed incident results or paid bounty totals, so results are Not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$10.0M
Since
2022-02-10
Evidence (3)

counterparty risks

two sources

Assessment: elevated, multi-layered counterparty risk; no verified change to the prior assessment as of September 6, 2026.

  • Oracles/rate providers: Sky’s core collateral pricing uses Chronicle with a one-hour Oracle Security Module delay. This reduces some flash-crash risk but creates stale-price, outage, and delayed-liquidation risk. The cross-chain SSR oracle uses authorized message providers and documents Chainlink and Balancer rate providers on Arbitrum, OP Mainnet, and Unichain; Ethereum is the source chain for the mainnet SSR state. A compromised bridge, provider, or stale update could misprice sUSDS/USDS conversion.
  • Bridges/cross-chain governance: Sky migrated the Ethereum–Solana USDS bridge from Wormhole to LayerZero. The audit reported no critical/high/medium/low findings in the migration-library scope, but explicitly treated Wormhole, LayerZero V2, guardian honesty, DVN/executor configuration, and deployed settings as out of scope or trusted assumptions. This leaves message censorship, misconfiguration, compromised-validator, and governance-takeover scenarios.
  • Stablecoin, RWA, and external-protocol exposure: USDS/DAI are exposed to USDC/USDT/PYUSD liquidity, crypto collateral, on-chain lending, Sky Agents, and real-world-asset managers/SPVs. S&P’s December 8, 2025 assessment rated USDS/DAI peg stability 4 (constrained). Potential failure paths include stablecoin depeg, RWA-manager/SPV insolvency or redemption halt, impaired collateral liquidation, Sky Agent losses, oracle failure, or governance misconfiguration.
  • LST/restaking, custodians, CEX/MM: Specific current balances, counterparties, custodians, market makers, CEX positions, LST/restaking allocations, utilization, and exposure percentages are Not verifiable as of September 6, 2026 because Dune/on-chain verification was unavailable. No independently verified active dependency failure was identified in the reviewed sources; this is not proof that none exists. Contradiction / data gap: Protocol-published collateral and supply figures are marketing/management disclosures, not independently verified here. On-chain exposure percentages win under the methodology, but are Not verifiable as of September 6, 2026.
Evidence (5)

crypto custody

one source

Sky Lending is organized as a non-custodial smart-contract lending system: users interact with the protocol directly from their own wallets, and neither the frontend operator nor an intermediary is said to hold user cryptoassets. The available evidence also indicates withdrawals are not paused in normal operation; users can redeem supplied assets back to USDS in a single transaction or withdraw collateral from vaults when loan conditions permit. Asset segregation is only partially verifiable: the core protocol is described as non-custodial and vault-based, but whether all assets are held in separate, segregated accounts versus pooled in protocol contracts is not verifiable as of 2026-09-06.

The strongest support comes from the Sky legal terms and Sky/Maker documentation describing the protocol as fully non-custodial and stating users retain exclusive control over their cryptoassets.

Withdrawal paused
No
Evidence (3)

incident

unverified

Older finding confirmed, with treasury-recovery status unchanged. On November 20, 2023, SparkLend discovered a DaiInterestRateStrategy accounting/configuration bug introduced after the September 17 borrow-spread change. Protocol assets exceeded recorded liabilities by more than $214,000 and later approximately $297,000.

The discrepancy represented undercounted treasury earnings, not an end-user loss or realized protocol loss. A corrected interest-rate strategy was deployed through governance and executed December 4, 2023, stopping further material growth. The post-mortem states that recovering the residual amount for the Maker/Sky treasury required a separate accounting update, but no later confirmation of that recovery was found.

Current status: remediation_in_progress. Treasury recovery: Not verifiable as of September 6, 2026.

Date
2023-11-20
Cause
Other
Loss
$0
Status
remediation in progress
Reimbursed
No
Evidence (1)

incident

unverified

May 28, 2025; operational false alarm affecting SparkLend’s Ethereum DAI market. An unusual Spark Liquidity Layer withdrawal appeared to burn only about 58 spDAI while withdrawing roughly $500,000. The market was frozen for approximately six hours while the team investigated; the behavior was valid rebasing/interest accounting, not an exploit.

Markets were reactivated after confirmation. No loss, affected-user impairment, or reimbursement was reported. Status: resolved.

Date
2025-05-28
Cause
Other
Loss
$0
Status
resolved
Recovered
$0
Evidence (1)

incident

two sources

Corrected scope/status: this was an external KelpDAO/LayerZero rsETH bridge failure, not a Sky/SparkLend contract exploit. On April 18, 2026, a forged LayerZero message released 116,500 unbacked rsETH, valued at approximately $292 million, which was subsequently used mainly against Aave positions. SparkLend had deprecated/frozen rsETH exposure on Ethereum on January 29, 2026; available reporting indicates Sky/SparkLend had no realized protocol loss, although a small residual frozen position was reported.

Response: exposure was exited/deprecated, and the wider ecosystem froze markets and coordinated DeFi United recovery. Sky Lending users were not reported to require reimbursement. Current Sky status: resolved.

Contradiction: an April 30 recovery summary states rsETH backing, withdrawals, and affected lending markets were fully restored, while the current DeFi United site still describes recovery as dependent on pending third-party technical/governance actions. Broader recovery status is therefore not fully independently verifiable; Sky-specific loss status remains resolved.

Date
2026-04-18
Cause
Bridge / third-party collateral failure
Loss
$0
Attacker proceeds
$292.0M
Status
resolved
Recovered
$292.0M
Reimbursed
No
Evidence (4)

key management

unverified

Key management for Sky Lending is not verifiable as of 2026-09-04 from the provided sources. The search results do not identify the Sky Lending protocol’s actual contracts, multisigs, custody model, or admin-key setup on Arbitrum, Ethereum, OP Mainnet, or Unichain, so I cannot reliably state whether control is centralized, multisig-based, timelocked, or decentralized. The only retrieved results are generic key-management articles and unrelated companies/patents, which are not evidence for this protocol.

If you want, I can next map the protocol’s deployed contracts and then determine who can upgrade, pause, mint, or otherwise control privileged functions.

Evidence (3)

smart-contract

two sources

As of September 6, 2026, Sky Lending is primarily the Ethereum Maker/Sky CDP system; DeFiLlama reports $5.929B TVL on Ethereum and no tracked TVL on Arbitrum, OP Mainnet, or Unichain. Deployments, balances, proxy-admin events, and role state on those three chains: Not verifiable as of September 6, 2026. Ethereum address map (known): Chainlog 0xdA0Ab1e0017DEbCd72Be8599041a2aa3bA7e740F; GSM/Pause 0xbE286431454714F511008713973d3B053A2d38f3; DSPauseProxy 0xBE8E3e3618f7474F8cB1d074A26afFef007E98FB; SKY Chief V3 0x929d9A1435662357F54AdcF64DcEE4d6b867a6f9; legacy Chief V2 0x0a3f6849f78076aefadf113f5bed87720274ddc0; core Vat 0x35D1b3F3D7966A1DFe207aa4514C12a259A0492B; USDS 0xdC035D45d973E3EC169d2276DDab16f1e407384F; ESM 0x09e05fF6142F2f9de8B6B65855A1d56B6cfE4c58; End 0x0e2e8f1D1326A4B9633D96222Ce399c708B19c28. Architecture: SKY holders → Chief → GSM/Pause timelock → DSPauseProxy (delegatecall) → authorized core modules (Vat, Vow, Jug, Join adapters, oracles, and newer Star/subDAO modules). Pause plans use plot, exec, and drop; execution is permissioned by governance but callable by anyone after expiry. Upgradeability/admin risk: Core Vat accounting rules are immutable, but governance can authorize new Vat modules; this can enable collateral theft or unbacked Dai minting if governance/security fails.

USDS and sUSDS use UUPS/ERC-1967 upgradeable designs. Exact implementation-admin/UPGRADE events and whether any role is renounced: Not verifiable as of September 6, 2026. Timelock / emergency: Current GSM delay is reported as 48 hours; exact on-chain measurement is Not verifiable as of September 6, 2026. Emergency spells exist and may bypass ordinary delay.

Users generally retain direct withdrawal paths; cage can disable new joins while permitting exits, but global settlement or compromised governance can impair liquidity. Worst case: compromised governance authority can change fees, debt ceilings, oracles, authorizations, and upgradeable token logic; authorize malicious adapters; mint unbacked USDS; drain collateral; or freeze/impair withdrawals. No direct EOA “admin drain” was independently verified.

Upgradeable
Yes
Evidence (8)

audit

one source

Audit of Sky stUSDS (staked USDS) smart contracts, which are part of the Sky savings / yield path often used in conjunction with Sky Lending.

Auditor
ChainSecurity
Report date
2018-06-12
Scope
stUSDS contract system and its integration with Sky/Maker components on Ethereum. Coverage of any forks/ports on Arbitrum, OP Mainnet, or Unichain is Not verifiable as of 2026-09-03. Bytecode match to currently deployed stUSDS or equivalent contracts is Not verifiable as of 2026-09-03.
Findings
Summary states security is high for functional correctness, access control, arithmetic precision, and integration with other Sky system components; no explicit enumeration of critical/high/medium findings is available in the public summary.[4] Not verifiable as of 2026-09-03 whether any issues were internally classified as critical/high/medium and subsequently fixed.
Fix status
Public text indicates a "high level of security" with no unresolved issues mentioned; line-by-line fix status for any discovered findings is Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

ChainSecurity — MakerDAO Liquidations 2.0

Auditor
ChainSecurity
Report date
2020-04-16
Scope
Liquidations 2.0 contracts supporting collateral liquidation and auction flows.
Findings
Critical/high/medium counts: Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Audit of Sky smart contracts related to the core Sky/Maker architecture (lending and stablecoin system). Focus on security, functional correctness, and integration with the existing system.

Auditor
ChainSecurity
Report date
2026-05-26
Scope
Sky (formerly MakerDAO) smart contracts underpinning the Sky Lending ecosystem on Ethereum (core protocol layer). Exact contract list and chain coverage beyond Ethereum are Not verifiable as of 2026-09-03. Bytecode match to currently deployed contracts on Ethereum/Arbitrum/OP Mainnet/Unichain is Not verifiable as of 2026-09-03.
Findings
Report summary states a "high level of security" and emphasizes functional correctness, security, and seamless integration; no explicit list of critical/high/medium issues is visible in the summary, nor post-audit issue log.[10] Not verifiable as of 2026-09-03 whether any critical/high/medium issues were raised internally and their exact count or classification.
Fix status
Public summary implies no outstanding critical vulnerabilities at publication; detailed issue-by-issue fix status is Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

Audit of Dss Flappers module referenced in Sky’s bug bounty registry, relevant to collateral management/liquidations; supports Sky Lending’s broader system security.

Auditor
ChainSecurity
Report date
2026-07-10
Scope
Dss Flappers module within Sky’s collateral/liquidation framework on Ethereum (potentially affecting Sky Lending risk parameters across chains).
Findings
The specific report exists, but critical/high/medium findings are not summarized in accessible snippets; Not verifiable as of 2026-09-04.[7]
Fix status
Bug bounty listing implies deployed audited code; exact remediation status of individual findings Not verifiable as of 2026-09-04.[7]
Evidence (1)

audit

one source

Audit of Sky "Chief" smart contracts, covering governance/executive control components that set parameters for the Sky Lending stack.

Auditor
ChainSecurity
Report date
2026-08-05
Scope
Sky Chief (governance) smart contracts, likely on Ethereum, influencing risk parameters for Sky Lending. Coverage of deployments on Arbitrum, OP Mainnet, or Unichain is Not verifiable as of 2026-09-03. Bytecode match to current governance contract deployments is Not verifiable as of 2026-09-03.
Findings
Summary reports a "high level of security" for functional correctness, front‑running protections, and suitability for governance; no public breakdown of critical/high/medium issue counts is visible.[5] Not verifiable as of 2026-09-03 whether any critical/high/medium findings existed and how they were remediated.
Fix status
No outstanding critical issues are mentioned in the public summary, but detailed remediation status by finding ID is Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

New published report: ChainSecurity — Sky Wormhole NTT Migration Updates.

Auditor
ChainSecurity
Report date
2025-10-20
Scope
Diff review of EVM NttManager/INttManager and Solana NTT migration code; removal of transfer initiation and mint-authority migration. Bridge infrastructure, not direct lending code.
Findings
Critical 0; high 0; medium 0; low 0.
Fix status
No severity-rated findings reported. Report notes reliance on unaudited existing bridge code; deployed bytecode match is Not verifiable as of 2026-09-06.
Report url
https://reports.chainsecurity.com/Sky/ChainSecurity_Sky_SkyWormholeNTTMigrationUpdates_Audit.pdf
Report id
doc:7e1dd1917f42584e
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New published report: ChainSecurity — Chief Smart Contracts.

Auditor
ChainSecurity
Report date
2025-03-21
Scope
src/Chief.sol, the continuous-approval governance contract replacing MCD DSChief; governance infrastructure rather than direct lending logic.
Findings
Critical 0; high 0; medium 0; low 0.
Fix status
No severity-rated findings reported. Deployment/bytecode match is Not verifiable as of 2026-09-06.
Report url
https://reports.chainsecurity.com/Sky/ChainSecurity_Sky_Chief_Audit.pdf
Report id
doc:81213edc669016c1
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New published report: ChainSecurity — Sky Smart Contracts.

Auditor
ChainSecurity
Report date
2025-06-06
Scope
MkrSky.sol, Sky.sol, and deployment scripts SkyDeploy.sol, SkyInit.sol, SkyInstance.sol; SKY/MKR conversion and token contracts, not direct lending-market code.
Findings
Critical 0; high 0; medium 0; low 1.
Fix status
Low finding: code corrected. Issue-level details and production deployment status are otherwise Not verifiable as of 2026-09-06.
Report url
https://reports.chainsecurity.com/Sky/ChainSecurity_Sky_Sky_Audit.pdf
Report id
doc:86f9bf83f6c754b0
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New published report: ChainSecurity — Lockstake Smart Contracts.

Auditor
ChainSecurity
Report date
2025-09-26
Scope
LockstakeClipper, LockstakeEngine, LockstakeMkr, LockstakeUrn, Multicall and related deployment/configuration code for governance-token collateral borrowing.
Findings
Critical 0; high 0; medium 0; low 2.
Fix status
One low finding code-corrected; one low finding acknowledged. Exact deployed-code status is Not verifiable as of 2026-09-06.
Report url
https://reports.chainsecurity.com/Sky/ChainSecurity_Sky_Lockstake_Audit.pdf
Report id
doc:a1ebb02dccc315f9
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New published report: ChainSecurity — Endgame Toolkit Smart Contracts.

Auditor
ChainSecurity
Report date
2026-01-16
Scope
SDAO, SubProxy, VestedRewardsDistribution, StakingRewards and deployment scripts for SubDAO governance, proxy execution and farming.
Findings
Critical 0; high 3; medium 0; low 4.
Fix status
High: 2 code-corrected, 1 specification-changed. Low: 3 code-corrected, 1 risk-accepted. Deployment/bytecode match is Not verifiable as of 2026-09-06.
Report url
https://reports.chainsecurity.com/Sky/ChainSecurity_Sky_EndgameToolkit_Audit.pdf
Report id
doc:b0f87c37d51da9e3
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected prior record: PeckShield — MCD Smart Contract Audit Report.

Auditor
PeckShield
Report date
2019-10-04
Scope
Multi-Collateral Dai core smart contracts and related CDP functionality.
Findings
Critical 0 reported; high 1; medium 1; low 4; informational 10.
Fix status
High issue was previously identified through the bug bounty; issue-level remediation and deployed-bytecode match are Not verifiable as of 2026-09-06.
Report url
https://raw.githubusercontent.com/sky-ecosystem/mcd-security/c3d94cdd9b307ca42b4000e8d5027ef5db133ed8/Audit%20Reports/PeckShield_Final_Audit_Report.pdf
Report id
doc:bd00027bc054e661
Unresolved critical
0
Evidence (1)

audit

one source

Corrected prior record: Trail of Bits — MCD Core Smart Contracts Final Report.

Auditor
Trail of Bits
Report date
2019-08-30
Scope
Multi-Collateral Dai core smart contracts.
Findings
Critical 0 reported; high 0 reported; medium 2; low 4; informational 8.
Fix status
Repository summary says issues were evaluated/mitigated, but per-finding remediation and deployed-bytecode match are Not verifiable as of 2026-09-06.
Report url
https://raw.githubusercontent.com/sky-ecosystem/mcd-security/2875d8cb8191ebcf1a587b1205ee7959740bd09f/Audit%20Reports/TOB_MakerDAO_Final_Report.pdf
Report id
doc:fbffb04fc6c23c5d
Unresolved critical
0
Evidence (1)

audit

one source

Gauntlet — Liquidations 2.0 Economic Simulation

Auditor
Gauntlet
Report date
2021-03-01
Scope
Economic simulation and liquidation-system risk analysis; not a conventional code audit.
Findings
Critical/high/medium findings: Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Secondary sources state that Sky’s lending stack and aligned protocols (notably Spark, the Sky‑aligned lending protocol) are audited by multiple firms including ChainSecurity and OpenZeppelin, with formal verification by Certora on components like LitePSM and USDS/SKY converters. These relate to the broader Sky lending ecosystem rather than a single monolithic "Sky Lending" contract set.

Auditor
Multiple (ChainSecurity, OpenZeppelin, Certora – attribution via secondary sources)
Report date
2024-01-01
Scope
Broader Sky protocol and Sky‑aligned lending components (e.g., LitePSM, USDS converters, Spark-based lending stack). Exact contract list, chains, and whether this fully covers Sky Lending deployments on Arbitrum, OP Mainnet, and Unichain are Not verifiable as of 2026-09-03. All such coverage is therefore treated as unverified marketing claim when sourced only from Sky-facing materials.
Findings
Specific critical/high/medium findings and their counts are not disclosed in the secondary summaries.[8][12][14] Not verifiable as of 2026-09-03 which exact issues were found, how they were categorized, and their remediation status.
Fix status
Secondary sources imply audits were completed and used in production, but provide no issue‑level fix tracking. Fix status for any findings is Not verifiable as of 2026-09-03.
Evidence (3)

audit

two sources

I could not verify any protocol-security audit reports for Sky Lending from independent auditor sources in the provided search results. The results returned DeFiLlama analytics and unrelated Sky corporate audit material, but no confirmed Sky Lending smart-contract audit report with scope, findings, or fix status.

Auditor
Not verifiable as of 2026-08-30
Report date
2026-08-30
Scope
Not verifiable as of 2026-08-30
Evidence (3)

audit

two sources

Security audit of Sky/Maker smart contracts around 2020, focusing on protocol security and integration during major upgrades.

Auditor
PeckShield
Report date
2020-03-01
Scope
Core lending/CDP modules and related components active on Ethereum (and later extended to L2 deployments such as Arbitrum/OP Mainnet).[9][14]
Findings
Specific critical/high/medium findings are not disclosed in retrieved sources; only general references to high security and absence of exploits.[14]
Fix status
Secondary sources imply identified issues were fixed and the protocol has had no code exploits since, but this is not directly traceable to a public findings/fix matrix; thus Not verifiable as of 2026-09-04.[14]
Evidence (2)

audit

one source

Quantstamp — MakerDAO Liquidations 2.0 Final Report

Auditor
Quantstamp
Report date
2021-03-10
Scope
Liquidations 2.0 implementation and related liquidation mechanisms.
Findings
Critical/high/medium counts: Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Formal verification / audit of Sky (MakerDAO) smart contracts; cited as part of Sky’s formal verification track record.

Auditor
Runtime Verification
Report date
2019-12-01
Scope
Core Sky/Maker CDP contracts and system integration, with emphasis on formal verification of critical components.[14]
Findings
Sources note formal methods applied and classify the system as near "adamantine" from a smart-contract security perspective, but concrete issue lists and severities are Not verifiable as of 2026-09-04.[14]
Fix status
Described as contributing to a long record of zero smart‑contract exploits; per‑finding remediation detail Not verifiable as of 2026-09-04.[14]
Evidence (1)

audit

two sources

Multiple audits of Sky (formerly MakerDAO) core smart contracts and liquidations system; part of Sky’s documented "robust smart contract audits" cited by S&P Global and independent risk oracles.

Auditor
Trail of Bits
Report date
2019-08-01
Scope
Sky/Maker core CDP smart contracts and Liquidations 2.0 modules; governance integration and liquidation mechanics.[3][14]
Findings
Detailed vulnerability findings are not publicly summarized in the sources retrieved. Public descriptions state focus on security, functional correctness, liquidations and integration, with no disclosed unresolved critical issues.[3][14]
Fix status
Reports and secondary sources describe issues as remediated and the system as having "high" security and no code exploits over 78 months, but specific per‑finding fix tracking is Not verifiable as of 2026-09-04.[14]
Evidence (3)

audit

one source

Trail of Bits — MakerDAO Liquidations 2.0 Final Report

Auditor
Trail of Bits
Report date
2021-03-19
Scope
Liquidations 2.0 contracts and liquidation mechanisms.
Findings
Critical/high/medium counts: Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

Team & Reputation

founders

two sources

Sky Lending is not a standalone startup; it is part of the Sky / MakerDAO ecosystem (rebranded from MakerDAO), which is a long‑running, blue‑chip DeFi lender centered around the USDS/DAI stablecoins and the Sky Savings Rate. On‑chain verification of specific contracts/founders is Not verifiable as of 2026‑09‑04. ### Founders & Team

  • Origins: Sky Protocol (including Sky Lending/Spark) was *created by the MakerDAO community*, not by a new anonymous team.
  • Key historical founders: MakerDAO was founded by Rune Christensen and early contributors dating back to 2015–2017, with a long governance and development history; Sky is the continuation of that project.
  • Current governance: Sky is governed via MKR/SKY token holders and the Sky Frontier Foundation, which publishes financials and governance reports.
  • Public vs. anon: MakerDAO/Sky has a mix of publicly known contributors (e.g., foundation leadership, core units) and broader pseudonymous governance participants; it is *not* an anonymous meme protocol. ### Track record, prior projects, and incidents
  • Prior outcomes: MakerDAO is one of the longest‑running DeFi lenders, with multi‑year operation across major market cycles and significant RWA exposure.
  • Revenue & scale: Q1 2026 gross revenue of about $124m and net revenue around $61m for a ~$13B lender; annualized revenue run rate around $419m by mid‑2026.
  • Hacks/major failures: No credible sources report protocol‑level catastrophic hacks of MakerDAO/Sky lending itself; risk has historically arisen more from collateral and RWA counterparties than smart‑contract exploits. (On-chain confirmation: Not verifiable as of 2026‑09‑04.) ### Jurisdiction, office, and business reality
  • Onshore vs. offshore: Sky operates via entities such as the Sky Frontier Foundation, typical of crypto foundations, but sources emphasize its interaction with regulated RWA issuers and even an S&P Global B‑ credit rating for the protocol’s stablecoin exposure.
  • This suggests a hybrid structure: decentralized governance plus legal entities engaging with traditional credit markets, not a pure offshore web shell.
  • Real business vs. web front: Multiple independent outlets (DLNews, Yahoo Finance, CryptoRank, Kiln) treat Sky as a large‑scale, revenue‑generating lender with institutional RWA strategies, not just an interface routing to another protocol. ### Name‑collision / protocol scope
  • "Sky Lending" on Ethereum, Arbitrum, OP Mainnet, and Unichain refers to the Sky/Spark lending stack and associated pools (e.g., sUSDS), plugged into the broader Sky ecosystem. No distinct, unrelated "Sky Lending" team was identified.
Evidence (15)

general reputation

two sources

Sky Lending appears to have strong, blue‑chip reputation signals with no credible public allegations of fraud, rug, insolvency, or sanctions as of 2026‑09‑04. Origin and governance

  • Sky Lending is described as “the lending engine of the Sky ecosystem…with a decade of governance history behind it,” referring to Sky as the rebranded MakerDAO ecosystem.
  • Governance is SKY‑token based, using executive votes and a “Sky Savings Rate” (SSR) set by protocol governance.
  • This MakerDAO/Sky lineage gives it an association with one of the longest‑running, institutionally followed DeFi governance systems. Audits and security reputation
  • Crypto Almanac Daily notes two audits recorded for Sky Lending, with independent audit reports publicly linked, and assigns it a top rubric score in its comparison.
  • Eco’s lending comparison mentions “Sky audit registry, Maker‑era audits inherited,” implying reuse of prior Maker/Spark security work plus dedicated Sky Lending audits.
  • No reports of critical vulnerabilities, exploit events, or emergency shutdowns are mentioned across the comparison/review sources. Scale, usage, and sentiment
  • Multiple analytics and comparison articles place Sky Lending TVL around $5.6–5.7B, ranking it among the top DeFi protocols by TVL.
  • DeFi Garden lists a sky-lending sUSDS pool on Arbitrum with hundreds of millions in TVL and mid‑single‑digit yield, suggesting active L2 usage.
  • A separate product listing describes Spark Savings vaults (part of the Sky ecosystem) as “one of the largest DeFi savings products” with ~$1B AUM and medium risk.
  • The Sky Frontier Foundation’s operational update highlights a $419M annualized revenue run rate and growing reserves, indicating strong profitability and treasury buffers. Integrations and external risk views
  • Sky’s SSR/sUSDS is integrated into external protocols (e.g., Morpho isolated markets on Arbitrum and Summer Protocol USDC vaults) and classified as “lower risk (pending final review)” in Summer governance materials.
  • Independent research pieces on DeFi lending list Sky Lending among “best DeFi lending protocols 2026,” with a focus on RWA‑backed collateral and governance‑set rates. Regulatory, legal, and sanctions
  • No search result indicates regulatory enforcement actions, sanctions listings, or formal fraud/insolvency proceedings against Sky Lending, its core protocol entities, or named foundations as of 2026‑09‑04. Unresolved concerns / caveats
  • Precise on‑chain holdings per chain (Arbitrum, Ethereum, OP, Unichain) and any chain‑specific incidents are Not verifiable as of 2026‑09‑04 under current data access.
  • Reliance on RWA and governance‑set base rates introduces policy and counterparty risk, frequently noted in stablecoin and RWA discussions, though no specific default event is cited in the gathered sources.
Evidence (10)

Economy

TVL: $5.5B

model

two sources

Economic model (reviewed September 6, 2026). Sky Lending is primarily a CDP/stablecoin system: approved crypto and real-world-asset collateral supports USDS issuance; borrowers pay stability fees, and liquidations can generate additional revenue. The collateral/borrowing layer is directional, with liquidation and collateral-price risk—not market-neutral. sUSDS itself is designed as pooled exposure to aggregate Sky surplus rather than to one borrower, collateral pool, or strategy. Yield sources and products. The Sky Savings Rate (SSR) is governance-set and paid from aggregate protocol surplus, principally revenue from Sky Agents and other lending/RWA/treasury allocations; therefore it is economically revenue-backed, but the exact organic-versus-subsidized split is Not verifiable as of September 6, 2026. Current interface indications: sUSDS 3.60% APY, stUSDS 5.41% variable APY from SKY-backed lending/utilization, fixed-yield sUSDS 4.99% through a Pendle integration, and Sky Vaults up to 5.05% through Morpho markets.

These rates are variable or market-set unless held to fixed-product maturity; historical APY volatility and sustainability are Not verifiable as of September 6, 2026. Leverage/external exposure. The protocol supports borrowing and can create recursive/leveraged exposure, but a protocol-wide leverage ratio is Not verifiable as of September 6, 2026. External exposure includes Sky Agents, RWA/credit/treasury strategies, Spark/Morpho integrations, and Pendle for fixed-yield access. Restaking exposure is Not verifiable as of September 6, 2026. Liquidity, fees, gates. sUSDS has no stated lock-up, is redeemable to USDS at any time, and has no interface fee; fixed-yield positions may require selling before maturity at market price.

Borrowers face stability fees, collateralization thresholds, and liquidation risk. Revenue. DeFiLlama attributes revenue to stability fees and liquidation/PSM fees, net of the savings rate. Its displayed figures are stale relative to this review (page crawl roughly two months old): $5.32B TVL, all shown on Ethereum; annualized fees $412.28M and revenue $243.1M. Contradiction / data gap. DeFiLlama shows Ethereum-only TVL, while another aggregator lists Arbitrum, Ethereum, OP Mainnet, and Unichain. No Dune verification is available; therefore TVL by product, chain percentages, trend, and Dune-vs-DeFiLlama reconciliation are Not verifiable as of September 6, 2026. Structured fields: organic_yield_pct: null; leverage_ratio: null.

Evidence (5)

reserves

one source

Assessment (as of September 6, 2026) Reported size / composition. Sky’s financial dashboard reports $98.42M of “Sky Reserves” (Sky Capital plus Operating Cash Balance) as of August 21, 2026. Its balance sheet, as of block 25,693,062 (August 6, 2026, 02:58 UTC), reports $11.41B collateral/reserves, $11.33B obligations, and $390.75M Sky capital. This is an analytics/dashboard figure, not a Dune-verified result.

The balance-sheet methodology identifies the treasury as the Ethereum Pause Proxy’s holdings of SKY, MKR, GROVE and SPK. It lists these addresses: 0x5607…d9279 (SKY), 0x9f8f…579a2 (MKR), 0xb30f…e9406 (GROVE) and 0xc200…b066 (SPK). Governance-buffer addresses are 0x37fc…a3a3 and 0x210c…4364. Reserve policy / control. S&P describes Sky capital as a surplus reserve buffer plus treasury, with a 70M USDS target for the surplus buffer; it excludes governance-token treasury value from capital in stress scenarios.

Sky documentation says the surplus buffer is protocol-owned DAI/USDS reserves. Control is exercised through SKY governance, with execution delays via the Pause Proxy/Governance Security Module. Custody and attestations. Core collateral and surplus are smart-contract-held and observable on Ethereum. RWA exposure introduces off-chain counterparty/custody risk; tokenized Treasury positions are visible on-chain, but underlying Treasury-bill existence depends on issuers, agents and custodians.

A conventional reserve attestation was not identified. Not verifiable as of September 6, 2026 whether independent attestations cover the full reserve set. > Contradiction / change: the prior finding cited $985M in BUIDL/JTRSY allocations in July 2025; the current Sky dashboard shows approximately $1.57B in JTRSY ($856.5M) and BUIDL-I ($717.0M). These may reflect different scopes or dates, so the change is not fully reconcilable from available sources. Dune/on-chain verification: Not verifiable as of September 6, 2026; Dune MCP was unavailable. Structured fields:

  • liquid_reserves_usd: 98,420,000 (reported dashboard proxy; not Dune-verified)
  • liabilities_usd: 11,330,000,000 (reported balance-sheet snapshot; not Dune-verified)
Liquid reserves usd
$98.4M
Liabilities usd
$11.3B
Evidence (7)

tokenomics

two sources

Sky Lending does have a native token: SKY (the governance token). CoinDesk’s token page identifies it as an ERC-20 on Ethereum with contract address 0x56072C95FAA701256059aa122697B133aDEd9279. Sky’s own materials state SKY is the protocol’s governance token and that protocol rewards accrue to it, but that is an unverified marketing claim without on-chain corroboration here.

I cannot verify total supply, circulating supply, market cap, FDV, holder concentration, insider wallets, emissions, unlock schedule, or whether announced unlocks actually happened on-chain as of 2026-09-04 because on-chain verification is unavailable in this run; these are Not verifiable as of 2026-09-04. The same applies to mint/blacklist/fee-switch controls, team/investor/treasury/community allocations, and DEX liquidity depth / main listings. What can be stated from the gathered web data is limited: the token is positioned as a governance token, and multiple sources describe a legacy conversion from MKR to SKY at 1 MKR = 24,000 SKY.

CoinDesk also identifies SKY as an ERC-20 on Ethereum. A Cointelegraph summary reports that Sky governance voted to make SKY the core token and described a deflationary tokenomics direction with a burn mechanism, but that remains secondary reporting rather than protocol-state verification. No reliable, chain-verified evidence was gathered here for revenue share mechanics, buybacks, burns, staking rewards, or the present control surface over token-admin functions.

Those items are Not verifiable as of 2026-09-04.

Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

unverified

A BTC move below $10,000 would most likely create severe liquidation pressure on any Sky Lending positions collateralized by Bitcoin, with the exact loss severity depending on each vault’s collateral ratio and liquidation threshold. Sky’s documented mechanism is automatic liquidation of insufficiently collateralized vaults, with collateral transferred and an auction started to cancel the debt; if auctions are too slow or reset repeatedly, bad debt can remain. What can be said with confidence is limited because the available sources do not expose Sky Lending’s live BTC exposure by chain, vault, or current liquidation buffer.

Therefore, the protocol-wide loss outcome under a BTC crash below $10k is Not verifiable as of 2026-09-04. Risk implications from the sources:

  • Sky states that liquidations are triggered when collateral falls below minimum overcollateralization, and Dutch auctions are used to sell collateral quickly.
  • Sky’s own docs warn that fast price declines can cause auctions to end without bids or require repeated resets, which can leave bad debt.
  • S&P notes that Sky’s credit risk can arise when credit losses exceed available capital, and specifically identifies liquidation performance as a key part of resilience in stress.
  • In a BTC crash to $10k, positions with high leverage would be the first to liquidate; positions already near threshold could be liquidated even if BTC only falls modestly from stressed levels. Per-chain exposure for Arbitrum, Ethereum, OP Mainnet, and Unichain is Not verifiable as of 2026-09-04 because no chain-level on-chain data was available in this run.
Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral would be a high-severity liquidation event for Sky Lending, but the exact portfolio impact is Not verifiable as of 2026-09-04 because no chain-level exposure data was provided and on-chain verification is unavailable in this run. Sky’s own docs state that liquidation transfers collateral out of an insufficiently collateralized vault and auctions it to cancel the assigned debt; if the debt covered by the transferred collateral plus penalty cannot be fully offset, the protocol absorbs the shortfall structure rather than the vault remaining whole. A useful stress interpretation from external analysis is that a 20% collateral value drop can make a previously safe loan undercollateralized, and in a 90% LTV example a 20% decline leaves collateral worth only $80 against a $90 loan, so liquidation cannot fully repay the lender.

That same mechanism is the relevant failure mode here: if the largest collateral asset is also the dominant backing asset, a 20% depeg would push many vaults closer to liquidation thresholds and increase bad-debt risk if auction proceeds are insufficient. For this protocol and these chains (Arbitrum, Ethereum, OP Mainnet, Unichain), the key unanswered items are: the largest collateral asset, its share of total collateral by chain, and whether liquidation buffers are concentrated enough to absorb a 20% shock. Not verifiable as of 2026-09-04. If you want, I can turn this into a chain-by-chain stress note once exposure data is supplied.

Evidence (2)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Sky Lending, the insolvent top-counterparty path is not verifiable as of 2026-09-04 for Arbitrum, Ethereum, OP Mainnet, and Unichain at the chain-by-chain exposure level. What is verifiable from Sky/Maker-style protocol docs is the generic loss waterfall: an undercollateralized position is liquidated, collateral is auctioned, and any shortfall becomes bad debt at the protocol level; the protocol then attempts to absorb or reconcile that debt through system surplus, debt queues, and, if needed, debt-covering mechanisms such as surplus cancellation or debt auctions. The expected loss path is: counterparty insolvency  -> liquidation trigger  -> collateral auction  -> auction proceeds first repay the vault debt and liquidation penalty  -> any residual shortfall becomes bad debt recorded by the protocol  -> bad debt is ultimately absorbed by the protocol’s system-level balance sheet rather than by the insolvent borrower. Who absorbs it: the first absorber is the protocol system, not the borrower.

In the Sky/Maker accounting model, the shortfall sits in protocol debt accounting and is offset against surplus if available; if surplus is insufficient, the protocol must use its own recapitalization machinery. Compensation: recoveries come from collateral auction proceeds, then from accumulated protocol surplus; if that is not enough, the protocol’s governance/system mechanisms cover the gap. The borrower does not compensate once insolvent unless additional collateral is recovered. Impact path through smart contracts: insolvency is handled by liquidation contracts that confiscate collateral, enqueue or record bad debt, and route it into the protocol’s debt-management modules; auction contracts sell collateral, while system-management contracts reconcile bad debt against surplus or trigger recapitalization actions. Important limitation: the web evidence available here does not let me verify the live, chain-specific contract addresses, deployed liquidation modules, or current exposure split across Arbitrum, Ethereum, OP Mainnet, and Unichain. Not verifiable as of 2026-09-04.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For the DAO/owner fraud stress scenario, Sky shows non-zero governance and centralization risk, but I found no verified evidence in the provided sources of an actual committed fraud by the DAO or owners. S&P Global’s assessment says Sky’s governance is effectively controlled by co-founder Rune Christensen due to low voter turnout, which is a structural concentration risk, and the protocol’s governance has also been described as contentious in recent reporting. The most relevant adverse event in the sources is a governance-attack allegation, not a confirmed fraud: Christensen said a group of token holders attempted to take over Sky, while the accused party denied it.

That means the scenario of malicious governance action is *plausible in threat modeling*, but the available evidence does not establish that the DAO or owners actually committed fraud. Independent risk signals point to governance fragility rather than proven misconduct: S&P assigned Sky a B- rating with a stable outlook and highlighted weak governance/centralization; meanwhile, Sky’s bug bounty program explicitly treats governance and smart-contract failures as critical-risk categories, implying the protocol recognizes this attack surface. Assessment: committed DAO/owner fraud is not verifiable as of 2026-09-04. The credible finding is a governance-concentration and takeover risk, not confirmed fraud.

Evidence (5)

stress scenario - primary yield source negative 30d,

one source

For Sky Lending, I cannot verify a protocol-specific 30-day *primary yield source negative* stress result from the provided web sources. The available results are macro stress-test materials about bank yield curves and interest-rate scenarios, not evidence about Sky Lending’s on-chain or reported yield composition, so the correct status is Not verifiable as of 2026-09-04. What can be said from the sources is only that severe stress frameworks can feature sharply lower Treasury yields and negative/near-zero rate environments, and that supervisory models explicitly discuss yield-curve shocks rather than DeFi protocol yield performance.

However, none of the sources identify Sky Lending, its chain-specific exposure on Arbitrum, Ethereum, OP Mainnet, or Unichain, or whether its primary yield source was negative over the last 30 days. Because the request is for a protocol-specific stress scenario, the missing piece is an authenticated yield breakdown for Sky Lending; that is absent here, so I cannot responsibly infer a negative-yield conclusion from macro scenario documents alone. Not verifiable as of 2026-09-04.

Evidence (3)

Governance & Legal

governance

two sources

Assessment — as of September 13, 2026. Sky Lending is governed by the broader Sky Protocol, not a separate lending DAO. Contracts and protocol funds: SKY-holder governance selects executable Spell contracts through the Chief; the Pause/GSM proxy enforces execution delay and holds administrative authority over core contracts and treasury-controlled balances. Governance can change parameters, authorize modules, upgrade components, and transfer protocol-controlled funds. This makes token governance operational, not merely symbolic: the August 27, 2026 Executive passed August 28 and executed August 31. Proposal process: forum discussion and review precede on-chain Governance Polls and Executive Votes.

SKY holders vote directly or delegate; a successful Executive is scheduled through the GSM/Pause delay and then executed on-chain. Timelock and emergency powers: current operational documentation states a 48-hour GSM Pause delay for executive changes, although execution windows and exceptions may affect elapsed wall-clock time. Instant-access modules can bypass ordinary governance delay within predefined bounds. Emergency spells are documented as pre-deployed bypass mechanisms.

The security documentation simultaneously says Global Settlement and Emergency Shutdown are disabled/deprecated; this is a material governance contradiction, so emergency authority should be treated as configuration-dependent rather than assumed absent. Frontend/company: Skybase International operates the Sky.money interface and owns the interface IP under its Terms. It is described as a Cayman Islands exempted company, registered at 9 Forum Lane, c/o Leeward Management Ltd., Grand Cayman. The Terms state the interface is separate from, and does not control, the non-custodial Sky Protocol; Skybase may modify, suspend, or discontinue the interface.

Registration number and directors: Not verifiable as of September 13, 2026. Voting concentration, top holders, multisig signers/threshold, and independence: Not verifiable as of September 13, 2026 because Dune MCP/on-chain verification was unavailable. No multisig threshold or signer set is asserted. The protocol’s governance can nevertheless move protocol-controlled funds through approved spells; therefore admin_can_drain is true in the stated risk sense, though not necessarily via a unilateral company key.

Timelock
Yes
Timelock delay hours
48
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
Yes
Evidence (7)

legal & regulatory

two sources

Entity / jurisdiction. The protocol itself is presented as decentralized, permissionless smart contracts rather than a conventional legal entity. The named interface operator is Skybase International, described in available token documentation as a Cayman Islands exempted company; its Terms are governed by Cayman Islands law, with Cayman arbitration/court jurisdiction. ToS / restrictions. Skybase disclaims being a broker, dealer, exchange, investment adviser, custodian, or financial-service provider, and limits aggregate contractual liability to KYD 100.

Users must comply with applicable law, sanctions and AML/CTF rules, and must not circumvent geoblocking with VPNs. The Terms list prohibited jurisdictions including China, Iran, Russia, North Korea, Syria, Venezuela, Yemen, Zimbabwe and others. Sky Savings Rate and Sky Token Rewards are unavailable in the United States; Trade is restricted in EU member states.

KYC / AML / sanctions. No customer-account KYC process for ordinary non-custodial protocol interaction is established by the reviewed Skybase materials. However, the interface collects wallet-submitted information, uses blockchain-analytics providers for illicit-activity detection, and requires user representations concerning AML/CTF and sanctions. This is interface-level compliance, not proof that the permissionless contracts enforce AML controls.

Classification / warnings. Skybase does not characterize USDS, SKY, staking, rewards, or lending as definitively non-regulated. Regulatory classification remains fact- and jurisdiction-dependent; a U.S. filing specifically identifies potential securities-classification and enforcement risk for SKY-related products. S&P also flags high regulatory risk and meaningful U.S. legal/economic ties despite the absence of a headquarters.

Enforcement, litigation, sanctions. No active regulator enforcement action against Skybase International or the Sky Protocol, and no sanctions designation of the protocol/entity, was identified in the reviewed sources. Legacy MakerDAO litigation exists, including True Return Systems’ patent case and earlier investor litigation against Maker Foundation-related entities; these are not clearly actions against Skybase International. Not verifiable as of September 4, 2026 for a complete worldwide court/enforcement search. Data protection. The privacy policy covers personal and wallet-related data, analytics, fraud/security monitoring, disclosures to authorities, retention, international transfers, and data-subject rights/complaints. Actual risk. Cayman incorporation and arbitration provide a contractual wrapper for the front end, not a comprehensive regulatory safe harbor for the DAO, governance participants, developers, token activities, stablecoin issuance, or lending markets.

Exposure remains multi-jurisdictional and potentially personal to identifiable operators or governance actors.

Active enforcement
No
Sanctioned
No
Entity
Skybase International (interface operator); Sky Protocol itself presented as decentralized smart contracts/governance
Jurisdiction
Cayman Islands
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Skybase International', 'Sky Lending'. OFAC SDN screening of 'Skybase International', 'Sky Lending': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Skybase International
  • Sky Lending
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Sky Lending uses USDS, Sky Protocol’s native stablecoin, so own_stablecoin is true and stable is true. A depeg event is documented: the clearest directly supportable episode in the gathered sources is the March 2023 USDC crisis, when DAI/USDS-related pricing moved below $1; the last supportable depeg date is 2023-03-11. The exact depeg count and maximum depeg percentage are not verifiable as of 2026-09-06 from the available sources, so those fields remain null. stablecoin_ids is USDS.

Own stablecoin
Yes
Stable
Yes
Last depeg date
2023-03-11
Stablecoin ids
  • USDS
Evidence (3)

Risks & Strengths

risks

two sources

Sky Lending’s principal risks are smart-contract/oracle failure, liquidation-driven bad debt, reserve and stablecoin counterparty exposure, governance concentration, and cross-chain/regulated-access uncertainty. Sky has meaningful safeguards—governance delays, oracle delays, auction limits and audits—but these reduce rather than eliminate tail risk. Dune was unavailable; chain-level exposure and on-chain TVL are Not verifiable as of September 5, 2026.

Contradiction: the supplied chain list includes Arbitrum, Ethereum, OP Mainnet and Unichain, while DeFiLlama currently attributes 100% of tracked TVL to Ethereum; the discrepancy is unresolved.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract and oracle failureA code defect, compromised dependency, or manipulated/stale price can misprice collateral, trigger wrongful liquidations, or create protocol losses. The one-hour oracle delay can also slow recognition of rapidly worsening conditions.HighMediumPublic audits, governance security delay, Chronicle/OSM price freeze, one-hour oracle delay and collateral-auction limits.High-severity exploit and oracle-tail risk remains.
Liquidation cascade and bad debtSharp collateral declines, thin exit liquidity or congested markets may prevent auctions from clearing at sufficient prices, leaving socialized losses or USDS under-collateralization.HighMediumOvercollateralization, Dutch auctions, debt ceilings and global/per-collateral auction-capacity limits.Material stress risk during correlated market selloffs.
Reserve and counterparty concentrationUSDS stability depends on eligible reserve assets, custodians and potentially RWA counterparties; impairment, freezing or delayed redemption could cause a peg deviation and liquidity shock.HighMediumGovernance-approved reserve eligibility, reported liquidity buffers and institutional custody arrangements.Centralized-custodian, legal-enforcement and redemption risk persists.
Governance capture and parameter riskConcentrated or coordinated voting can alter collateral, debt, oracle, reserve or upgrade parameters; the February 2025 takeover attempt demonstrates strategic-disruption risk.HighMediumVoting-lock protections, governance security delay, delegated voting and monitoring of proposed spells.Low-participation, concentrated-vote and privileged-module risk remains.
Cross-chain and regulatory fragmentationIf deployments exist across the supplied chains, bridges, relayers and differing liquidity can create inconsistent risk parameters or settlement failures; regulatory action may restrict interfaces, assets or counterparties. Chain-level deployment exposure is Not verifiable as of September 5, 2026.MediumMediumGovernance-controlled deployments, documented cross-chain infrastructure and non-custodial interface disclosures.Bridge, jurisdictional and access risk remains difficult to quantify.
Evidence (5)

strengths

two sources

Sky Lending’s top strengths are: battle-tested longevity, a large stablecoin/liquidity base, multichain access, yield simplicity, and institutional credibility. The protocol is described as the successor to MakerDAO, with a long operating history through multiple crypto cycles and a stablecoin ecosystem centered on USDS/sUSDS. It is also presented as multichain across Ethereum, Arbitrum, OP Mainnet, and Unichain, which improves accessibility and distribution across venues.

Sky’s yield model is a protocol-revenue share via the Sky Savings Rate, which removes borrower utilization risk and liquidation risk for depositors compared with traditional lending markets. Finally, external ratings and commentary point to meaningful institutional credibility, including S&P’s B- rating and references to reserve diversification, RWA exposure, and audited/transparent governance structures.

Evidence (7)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 25 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-30.