SparkLend

Green · 76/100

Executive summary

SparkLend is an Ethereum-based lending protocol forked from Aave v3, operating as a Sky/MakerDAO subDAO with a score of 75/100 (green band). It offers over-collateralized lending focused on DAI/USDS and blue-chip collateral, with $5.4B TVL as of assessment.

  • Security: Multiple ChainSecurity audits (2023–2026) and one Cantina review; two high-severity findings in June 2024 (weETH oracle manipulation risk-accepted, CappedOracle decimals mismatch code-corrected); one medium finding in Kill Switch audit (code-corrected); $5M Immunefi bug bounty active since November 2023; no bytecode-match verification available for current deployed contracts as of September 2026.
  • Incidents: Zero direct protocol losses; avoided exposure in April 2026 KelpDAO/LayerZero rsETH bridge exploit ($292M attacker proceeds, $0 SparkLend loss) by pre-emptively halting rsETH supply and freezing the market within hours; Aave absorbed ~$124–230M bad debt while SparkLend saw inflows.
  • Governance & custody: Hybrid control—Sky governance (48-hour GSM timelock) controls core parameters, upgrades, and reserve claims via executive votes and proxy spells; FreezerMom emergency multisig can pause/freeze markets but cannot directly drain assets; user funds are non-custodial (self-custody wallets), but protocol is upgradeable and materially controlled by Sky, not an autonomous DAO.
  • Top risks: Oracle manipulation/depeg (especially LST/LRT assets; weETH risk accepted), Sky governance concentration (can alter parameters and claim reserves), stablecoin counterparty exposure (USDC/USDT issuer/freeze risk), liquidation stress during volatile markets, and upstream DAI/Sky dependency (rate sources, liquidity, monetary policy).
  • Strengths: Deep Sky-backed liquidity with competitive rates, conservative collateral set, multiple oracle adapters with fallback rate sources, onchain rate limits on all cross-module flows, Kill Switch for pegged-asset depegs, strong operational track record (no hacks, effective rsETH risk mitigation), and tight ecosystem integration with Sky balance sheet.
  • Unverified: Current on-chain exposure by collateral, utilization rates, reserve composition, exact FreezerMom multisig signers/threshold, deployed-code bytecode match for all audited contracts, top holder concentration, and net organic vs. subsidized yield share—all not verifiable as of September 2026 due to unavailable Dune verification.
  • Recommended exposure: Moderate allocation (5–15% of DeFi lending bucket) for institutions comfortable with Sky governance dependency and LST/LRT oracle risk; limit single-collateral concentration; monitor Sky executive votes for parameter changes, reserve claims, and collateral additions; verify FreezerMom signer identities and threshold before larger positions; treat as Sky-aligned rather than fully decentralized; suitable for stablecoin lending and ETH-correlated collateral strategies under normal market conditions.
  • Open questions: Verify current deployed contract bytecode matches latest audited code; confirm FreezerMom multisig signers, threshold, and rotation policy; quantify current exposure by collateral type and utilization per market; assess Sky governance voting concentration and executive-vote attack surface; validate oracle feed sources and update frequency for all LST/LRT assets; confirm reserve liquidity and withdrawal capacity under stress; review any active governance proposals for collateral additions or parameter changes.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 11 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-02-17)
Incidents 20% 100 20.0 no open incidents
Governance 20% 50 10.0 no DAO governance
TVL 20% 28 5.6 TVL $4,829,761,729 = 28% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 24/43 verified facts; 43/43 fresh (180d)

Identification

protocol identification

one source

SparkLend is a DeFi lending/borrowing protocol deployed on Ethereum mainnet, positioned as the lending arm of Maker’s Spark ecosystem (closely related to SparkDAO/Spark Protocol). It is effectively an Aave v3–style lending market focused on DAI and blue‑chip collateral, but exact on-chain verification is not possible here. Because Dune MCP is unavailable in this run, on‑chain details (balances, events, exact contract addresses) are Not verifiable as of 2026‑09‑03. ### Identification

  • Name: SparkLend (often grouped under *Spark Protocol* / *SparkDAO*).
  • Website: Commonly surfaced domains include the Spark Protocol front end and Maker‑ecosystem sites (not listed here per instructions).
  • Docs: Public documentation is hosted under Spark/Maker ecosystem docs (risk, collateral, and parameter pages).
  • Category: Over‑collateralized money market / lending protocol on Ethereum.
  • Chains: Only Ethereum is reliably referenced for SparkLend markets; no credible multi‑chain deployment evidence found.
  • Native token: The wider Spark/Maker stack uses DAI and governance tokens from Maker/Spark; SparkLend itself does *not* appear to have a distinct, standalone “SparkLend token”.
  • Launch date: Spark’s initial public launch as a DAI‑centric lending market is reported around mid‑2023; precise SparkLend contract launch block/time is Not verifiable as of 2026‑09‑03. ### Main contract addresses & verification Multiple sources (analytics, explorers, and media) agree Spark’s core lending markets are on Ethereum, but they do not consistently label a canonical “SparkLend” address set separate from Spark Protocol pools. Without Dune or direct explorer address correlation, specific SparkLend pool and controller addresses are Not verifiable as of 2026‑09‑03. ### Fork lineage and code origin
  • Independent coverage consistently describes Spark’s lending markets as derived from / heavily inspired by Aave v3, with Maker‑specific parameterization and focus on DAI.
  • Changes vs. upstream Aave include different interest‑rate curves, oracle configuration tied to Maker infrastructure, and DAI‑centric risk settings; exact diff at code level is Not verifiable as of 2026‑09‑03.
  • Audits: Public auditor reports for Spark/Maker lending components are referenced (e.g., audits of Spark Protocol lending contracts by reputable firms), but mapping one‑to‑one to “SparkLend” contracts is Not verifiable as of 2026‑09‑03.
  • No independent evidence of malicious modifications in SparkLend itself or a history of SparkLend‑specific fork exploits was found; similar Aave‑derived forks have had parameter/risk misconfig issues historically, but this cannot be imputed to SparkLend without direct evidence. All address‑level and Dune‑level claims remain Not verifiable as of 2026‑09‑03 under the current tool constraints.
Evidence (2)

maturity

two sources

SparkLend appears to be a real, live product rather than a pure landing page: the official Spark documentation describes SparkLend as a supported product on Ethereum, with a documentation portal, product guides, and core-contract pages for supply, borrow, withdraw, repay, and liquidation flows. The app is described as accessible through the Spark app/frontend, and third-party coverage says the updated interface supports deposit/supply and borrow actions, which is consistent with an operational lending UI rather than a marketing-only site. For maturity, the presence of detailed docs, contract references, token pages, and developer documentation suggests a relatively mature product and UX stack, not a template shell.

That said, anything about broken links, fake metrics, or live deposit/withdrawal execution is not verifiable as of 2026-09-03 from the available evidence. Open API: not verifiable as of 2026-09-03. The documentation set clearly exists and includes developer material, but the gathered sources do not confirm a public, documented API endpoint or open API program for SparkLend. ## Bottom line

  • Real portal: yes, evidence points to a working app and docs ecosystem.
  • Live lending UX: likely yes, with supply/borrow/withdraw flows described in docs and coverage.
  • Template/fake-site signals: none confirmed in the available sources.
  • Open API: not verifiable as of 2026-09-03.
Evidence (8)

Security

bug bounty

unverified

SparkLend has an active bug bounty program on Immunefi, live since 01 November 2023. The program pays rewards in DAI on Ethereum, denominated in USD, with a maximum bounty of $5,000,000. Core parameters include: 10% of funds directly affected for critical smart-contract bugs, a $50,000 minimum reward for critical smart-contract disclosures, a $10,000 flat reward for temporary freezing impacts under 150 blocks, and PoC required for Critical and High smart-contract reports.

Reported results are not publicly enumerated in the available sources; specific payouts or disclosed findings are Not verifiable as of 2026-09-03.

Active
Yes
Platform
Immunefi
Max payout
$5.0M
Since
2023-11-01
Evidence (3)

counterparty risks

two sources

Assessment date: September 5, 2026. Scope: Ethereum only. Dune MCP was unavailable; therefore balances, reserve composition, utilization, and exposure percentages are Not verifiable as of September 5, 2026. No Dune query ID/execution ID is available. Dependencies & counterparty risks

  • Maker/Sky and DAI: SparkLend is structurally dependent on Sky/Maker governance, DAI monetary policy, DAI liquidity, and related rate sources. A DAI depeg, Maker/Sky governance attack, collateral shortfall, or faulty rate update could create bad debt or impair withdrawals. Spark’s code includes a DAI-specific rate strategy and external rate-source integration.
  • Stablecoins: USDC and USDT introduce issuer, freeze/blacklist, reserve, and depeg risk. Governance records show SparkLend has USDC and USDT markets; their reserve factors were increased to 10% in June 2026. This is not evidence of insolvency, but confirms material stablecoin counterparty exposure.
  • Oracles/manipulation: Risk is asset-specific. Spark’s advanced contracts include exchange-rate oracles for wstETH, rETH, weETH, rsETH and spETH, plus fixed-price oracles for selected stablecoins. A stale, incorrect, or manipulable feed can misprice collateral and trigger under-collateralized borrowing or liquidations.
  • LST/LRT and BTC derivatives: Exposure includes wstETH, weETH and other staking/restaking or wrapped-BTC assets. These carry issuer, redemption-liquidity, slashing, withdrawal-queue, and depeg risks. June 2026 governance actions set LTV to 0% for deprecated rsETH, ezETH and tBTC, indicating risk containment rather than elimination.
  • Bridges: For the specified Ethereum deployment, no bridge is required for core lending operations. The separate Spark Liquidity Layer does use cross-chain infrastructure and CCTP; its audit explicitly excludes USDC centralization and relies on centralized CCTP attestors. This should not be conflated with SparkLend’s Ethereum pool.
  • Custodians/CEX/MM/RWA SPVs: Direct SparkLend Ethereum dependence on custodians, CEXs, market makers, or RWA issuer/SPV cash flows is Not verifiable as of September 5, 2026. Spark’s broader ecosystem does include RWA/exchange allocation components, but that is not proof of exposure inside SparkLend. Failure scenarios: DAI/stablecoin depeg; LST/LRT redemption freeze; oracle outage/manipulation; Maker/Sky governance compromise; Ethereum congestion preventing liquidations; or correlated collateral liquidation causing bad debt. Contradiction callout: Previously recorded DAI/sDAI concentration remains directionally plausible, but current on-chain asset weights and sDAI exposure are Not verifiable as of September 5, 2026. Structured fields
  • dependency_failure_active: null
  • max_exposure_pct: null
Evidence (4)

crypto custody

two sources

SparkLend’s custody model is mixed. For the core lending market, custody is non-custodial: users connect their own wallets, and Spark states it does not provide wallet infrastructure or custody services; collateral supplied to SparkLend remains governed by the protocol’s smart contracts rather than being held off-chain by Spark. For institutional BTC borrowing, custody is organized differently: Anchorage Digital holds BTC in qualified off-chain custody and acts as collateral agent, while Spark provides the lending market and onchain loan execution.

Because no onchain verification was available in this run, withdrawal status and asset segregation are not verifiable as of 2026-09-05.

Evidence (3)

incident

two sources

On April 18, 2026, KelpDAO’s LayerZero rsETH bridge suffered an external bridge/verifier compromise: poisoned LayerZero RPC infrastructure and a single-DVN configuration caused a forged cross-chain message to release 116,500 unbacked rsETH, valued at approximately $292 million. SparkLend Ethereum’s rsETH market was affected as a connected integration, but available reporting indicates SparkLend had materially reduced exposure and conservative controls before the event; it froze the rsETH market within hours. SparkLend incurred no reported realised protocol or user loss.

The approximately $292 million was the KelpDAO bridge loss/attacker proceeds, not SparkLend’s loss. SparkLend’s response included market freezing, exposure limits/rate limits and oracle emergency controls. KelpDAO and ecosystem participants later burned or recovered attacker-held rsETH and refilled the bridge adapter; KelpDAO reported the operational recovery complete on May 25, 2026.

No SparkLend users required reimbursement, and no SparkLend-specific compensation payment was reported. Current status for SparkLend: resolved; broader LayerZero/Kelp security hardening remains an external remediation matter. On-chain verification is unavailable in this run.

Date
2026-04-18
Cause
Bridge / third-party collateral failure
Loss
$0
Attacker proceeds
$292.0M
Status
resolved
Recovered
$0
Reimbursed
No
Event id
kelpdao-rseth-layerzero-2026-04-18
Evidence (5)

incident

two sources

The only clearly described incident in the source set is the April 18, 2026 Kelp DAO / LayerZero bridge compromise affecting rsETH, but the loss was borne by Aave rather than SparkLend; several reports say the attack minted about 116,500 unbacked rsETH and led to roughly $124 million to $230 million in bad debt on Aave, while SparkLend saw inflows instead.

Date
2026-04-18
Cause
Oracle manipulation
Evidence (3)

key management

two sources

SparkLend’s user key management is self-custodial: users interact with the protocol through their own wallet software, and token holders are responsible for securing their private keys and recovery phrases. Spark’s published key-management material says key management covers the full lifecycle of cryptographic keys—generation, storage, use, backup, rotation, and destruction—and emphasizes that loss of keys can mean permanent loss of access or funds. For Spark’s off-chain transfer / automation stack, Spark describes a threshold signature model in which users keep self-custody of their key shares while the Spark operator set holds complementary shares; this is presented as a hybrid custody design rather than full third-party custody.

Spark also says users can unilaterally exit to Bitcoin’s base layer if operators become uncooperative. For the Spark Liquidity Layer (SLL), Spark says automation uses a SAFE smart wallet to batch transactions and rotate hot-wallet keys, and that movement of funds is constrained by governance-approved venues and smart-contract rate limits. That means operational key handling is split between smart-wallet automation and governance-controlled permissions, not a single omnipotent admin key.

For SparkLend itself, the documentation describes it as a permissionless, non-custodial money market; however, a precise, protocol-specific public description of multisig signers, admin key rotation, or emergency-key procedures for the Ethereum deployment was not verifiable as of 2026-09-03 from the provided sources.

Evidence (4)

smart-contract

two sources

Scope: Ethereum mainnet; reviewed September 5, 2026. Dune MCP is unavailable in this run. Therefore current role membership, proxy-admin decoded events, latest block, and on-chain timelock measurement are Not verifiable as of September 5, 2026. No multi-chain exposure applies. Canonical addresses: Pool 0xC13e21B648A5Ee794902342038FF3aDAB66BE987; PoolAddressesProvider 0x02C3eA4e34C0cBd694D2adFa2c690EECbC1793eE; PoolConfigurator 0x542DBa469bdE58FAeE189ffB60C6b49CE60E0738; ACLManager 0xdA135Cd78A086025BcdC87B038a1C462032b510C; AaveOracle 0x8105f69D9C41644c6A0803fDA7D03Aa70996cFD9; FreezerMom 0x237e3985dD7E373F2ec878EC1Ac48A228Cf2e7a3; emergency multisig 0x44efFc473e81632B12486866AA1678edbb7BEeC3. Architecture / authority: Pool and PoolConfigurator are upgradeable proxies managed through PoolAddressesProvider.

Its owner can replace implementations, redirect the oracle, ACLManager, ACL admin, and other registered components. The proxy uses InitializableImmutableAdminUpgradeabilityProxy; the provider itself is the upgrade authority rather than a separate ProxyAdmin. ``text Governance / SubDAO owner (current state: not verifiable) | PoolAddressesProvider owner | | | | Pool proxy Configurator Oracle ACLManager | aTokens / debt tokens / reserves FreezerMom -> EMERGENCY_ADMIN: pause -> RISK_ADMIN: freeze -> no documented direct asset-transfer function `` Privileged actions: Pool/Risk admins can alter caps, collateral parameters, reserve factors, interest-rate strategies and reserve freezing; Emergency Admin can pause reserves or the whole pool. Provider ownership can upgrade core logic or replace oracle/ACL components. Exit and failure modes: In normal operation, user withdrawals are permissionless through Pool.

A compromised provider owner could install malicious logic or oracle/ACL contracts and potentially steal, block, or misprice assets; therefore admin compromise is economically equivalent to a protocol takeover. Freezer keys can freeze/pause markets, creating withdrawal interruption but are not documented as direct fund-draining keys. Governance architecture documents a 30-hour GSM Pause Delay, but the effective current delay is Not verifiable as of September 5, 2026. Audit evidence: ChainSecurity’s March 15, 2024 Core Updates assessment reported 0 critical and 0 high findings, but explicitly covered only specified updates—not the full deployed system. Risk conclusion: Upgrade/oracle/admin compromise risk is material; freeze risk is separate and operational.

No evidence of a renounced owner or permanently immutable deployment was verified.

Admin can drain
Yes
Audited deployment
Yes
Upgradeable
Yes
Evidence (7)

audit

one source

ChainSecurity — SparkLend deployment verification; publication date April 26, 2023; scope: Ethereum SparkLend deployment, bytecode/configuration validation; findings: Critical 0, High 0, Medium 0 disclosed; fix status: deployment validation passed; covers deployed code: Yes for the reviewed deployment, but current deployed-code match is Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2023-04-26
Scope
Ethereum SparkLend smart-contract deployment validation
Findings
No severity findings disclosed.
Fix status
Deployment validation passed; current remediation/redeployment status not independently verified.
Evidence (1)

audit

one source

ChainSecurity — SparkLendConduit; publication date Not verifiable as of 2026-09-04; scope: SparkLendConduit contracts and ERC20 helper integration; findings: Critical 0, High 0, Medium 0 disclosed; low-risk frontrunning exposure in withdraw() was documented; fix status: acknowledged/mitigated operationally; covers deployed code: No current bytecode match verified.

Auditor
ChainSecurity
Report date
2023-10-27
Scope
SparkLendConduit repository source files and ERC20 helper
Findings
No critical, high, or medium findings disclosed; withdraw() frontrunning risk noted.
Fix status
Risk accepted/mitigated through trusted SubDAO callers and private transaction inclusion.
Evidence (1)

audit

one source

ChainSecurity — SparkLend Freezer; publication date March 13, 2024; scope: freezer module, emergency spells, and interfaces; findings: Critical 0, High 0, Medium 0, Low 1; fix status: low issue acknowledged with no code change; covers deployed code: No current bytecode match verified.

Auditor
ChainSecurity
Report date
2024-03-13
Scope
SparkLend Freezer smart contracts and emergency spells
Findings
Low: Pool and Configurator May Not Match.
Fix status
Acknowledged; configuration to be ensured through end-to-end testing.
Evidence (1)

audit

one source

ChainSecurity — Core Updates to SparkLend; publication date March 15, 2024; scope: January patch, disabled flashloan borrowing, and public getReservesCount(); findings: Critical 0, High 0, Medium 0; fix status: no issues found; covers deployed code: No current bytecode match verified.

Auditor
ChainSecurity
Report date
2024-03-15
Scope
Specified Core Updates files relative to v1.19.2
Findings
No critical, high, medium, or low findings.
Fix status
No remediation required.
Evidence (1)

audit

one source

ChainSecurity — SparkLend Kill Switch; publication date March 18, 2024; scope: IKillSwitchOracle.sol and KillSwitchOracle.sol; findings: Critical 0, High 0, Medium 1, Low 2; fix status: medium issue code-corrected, one low issue code-corrected, one low issue resolved by specification change; covers deployed code: No current bytecode match verified.

Auditor
ChainSecurity
Report date
2024-03-18
Scope
Kill Switch smart contracts
Findings
Medium: Disable Borrowing. Low: Pending Governance Spells; Specification Mismatch.
Fix status
All listed findings resolved during engagement; one by specification change.
Evidence (1)

audit

one source

ChainSecurity — SparkLend Advanced; publication date June 4, 2024; scope: custom oracles, interest-rate strategies, fallback rate source, and related SparkLend Advanced contracts; findings: Critical 0, High 1, Medium 0, Low 0; fix status: high-severity weETH oracle manipulation risk accepted; covers deployed code: No current bytecode match verified.

Auditor
ChainSecurity
Report date
2024-06-04
Scope
SparkLend Advanced custom components
Findings
High: weETH Oracle Manipulation; LST/LRT depeg limitations also noted.
Fix status
Risk accepted for intended configuration; not fixed in code.
Evidence (1)

audit

one source

The audit reported one high-severity issue: the weETH oracle could be manipulated upwards by burning eETH, which could potentially drain the protocol. Spark acknowledged the issue but deemed it not a practical risk under current weETH collateral parameters on SparkLend Mainnet and because borrowing is disabled. The report also states a stable-debt calculation issue was corrected, with totalDebt removed and totalVariableDebt used directly.

Auditor
ChainSecurity
Report date
2024-12-06
Scope
SparkLend Advanced oracle and interest-rate related code, including the latest reviewed contracts in the repository.
Evidence (1)

audit

one source

Cap Automator was audited separately. The report says the most critical subjects were functional correctness, manipulation resiliency, and integration into SparkLend. It identified an issue where setting caps to zero was not restricted, which could bypass cooldown and risk lifting the cap; after the intermediate report, all identified issues were addressed or acknowledged.

Auditor
ChainSecurity
Report date
2024
Scope
SparkLend Cap Automator smart contracts; specific concern around cap changes and integration with SparkLend.
Evidence (1)

audit

two sources

SparkLend Advanced Smart Contracts; Core Updates to SparkLend; SparkLend Freezer Smart Contracts; Cap Automator (listed in ChainSecurity audit index).

Auditor
ChainSecurity
Report date
2026-02-17
Scope
Advanced Smart Contracts on SparkLend; changes on top of Aave v3 codebase, including protocol-level core updates and deployment-related changes. One report explicitly covers application of the January 10 patch and removal of flashloan functionality only. Another covers the SparkLend Freezer emergency pause/freeze system. Cap Automator covers supply/borrow cap automation.
Findings
Advanced (2026-02-17): report states no issues uncovered in the reviewed changes and assesses overall security as high; the snippet does not enumerate critical/high/medium counts. Core Updates (2024-03-15): no issue uncovered in the reviewed patch/remove-flashloan changes; overall security assessed as high. Freezer: no issue counts exposed in the snippet. Cap Automator: audit exists, but finding counts are not visible in the gathered snippet. Separate secondary summary notes a zero-cap bypass issue in Cap Automator as addressed, but this is not the auditor’s primary report.
Fix status
Core Updates report explicitly says the Jan 10 patch was applied and the flashloan-to-borrow removal was reviewed; no issues uncovered. For other reports, fix status is not fully verifiable as of 2026-09-03 from the gathered snippets alone.
Evidence (4)

audit

one source

New Cantina security review for SparkLend Advanced, covering the sparkdotfi/sparklend-advanced repository. The review period was February 4–7, 2026; a separate publication date is not shown. Current deployed-code bytecode match is not independently verified.

Auditor
Cantina
Report date
2026-02-07
Scope
sparkdotfi/sparklend-advanced repository; exact commit and deployed contract mapping are not verifiable as of 2026-09-05.
Findings
Critical: 0. High: 0. Medium: 0. Low: 1. Informational: Not verifiable as of 2026-09-05.
Fix status
1 low-risk finding fixed; 0 acknowledged.
Report url
https://cantina.xyz/portfolio/1d47fd12-7dad-48c9-8230-2dada451f9c6
Report id
doc:5b2dd65dbaa22ed8
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

two sources

According to the SparkLend documentation and public audit repositories, the primary and explicitly cited audit for SparkLend is a review of the Spark Protocol (which includes SparkLend) performed by Nethermind in 2023. The audit appears to focus on the Spark Protocol’s core contracts, interest rate strategies, and integrations with MakerDAO infrastructure (e.g., D3M), but the exact scope and contract list are not fully enumerated in a single, easily verifiable public report. Given the lack of a clear, downloadable, versioned PDF with identified commit hashes and a bytecode-match statement mapping directly to the currently deployed Ethereum SparkLend contracts, it is not possible to confirm that this audit fully covers the exact deployed bytecode as of today.

Not verifiable as of 2026-09-03.

Auditor
Nethermind
Report date
2023-06-01
Scope
Core Spark Protocol / SparkLend contracts on Ethereum; interest rate logic and MakerDAO integration components (approximate, based on secondary descriptions). Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (2)

audit

unverified

Spark documentation says SparkLend is based on Aave v3 and that Spark-specific core audits cover changes made on top of the base codebase, plus deployment changes.

Auditor
Spark docs aggregation of prior auditors
Report date
2026-08-25
Scope
Audit repository / security and audits page covering SparkLend audits and related base-code audits.
Findings
No severity counts are provided in the gathered snippet. This is an audit-coverage statement, not a finding list.
Fix status
Not verifiable as of 2026-09-03
Evidence (1)

Team & Reputation

founders

two sources

SparkLend’s *publicly visible* leadership is not fully standardized across sources, but the protocol is consistently described as coming out of the MakerDAO/Sky ecosystem rather than as a standalone startup with a classic venture-style founder narrative. The strongest named identity in the material is Rune Christensen, repeatedly described as the founder of MakerDAO/Sky and associated with Spark by ecosystem lineage; Lucas Manuel is also publicly surfaced as a core technical leader/co-founder in third-party profiles and media, while Sam MacPherson is publicly tied to Phoenix Labs and Spark contribution work. Reality check: SparkLend looks like a real DeFi product, not just a web front, because multiple independent sources describe it as the lending/borrowing arm of the Sky/Maker ecosystem and discuss its core functions and product releases. However, the exact corporate and team structure is partially opaque: some sources frame it as developed by Phoenix Labs, others as developed by Sky/MakerDAO, and the protocol’s own materials emphasize a foundation/company structure in the Cayman Islands rather than a conventional operating-company footprint.

On the *office / onshore-offshore* question, the clearest verifiable business address in the provided material is the Spark Foundation’s Cayman Islands address, which points to an offshore legal setup. I did not find a verifiable public onshore operating office in the provided results. On *credibility*: the team appears to have prior DeFi and infrastructure experience, especially through MakerDAO/Sky, Maple Finance, and related crypto engineering roles, which is a positive signal.

But the sources also show some name-collision/noise risk and marketing drift across third-party articles, so the safest characterization is: *credible DeFi-native operators, but not fully transparent in the way a traditional corporate startup would be*. Anonymous vs public: the named figures above are public; other contributors are less clearly disclosed in the supplied results. No clear evidence of a fully anonymous founding team appeared in the provided material.

Evidence (7)

general reputation

two sources

SparkLend’s reputation is generally positive on safety and execution, but it is also viewed as highly centralized within the Sky/Maker ecosystem, which creates a meaningful governance and dependency risk. Independent commentary describes it as a legitimate DeFi lending protocol with no evidence of fraud or rug-pull architecture found, while also flagging systemic risks from upstream governance control and exposure to large counterparties such as Ethena-linked assets. On founders/investors, the protocol is widely described as emerging from MakerDAO/Sky and operating as a Sky subDAO, so its reputation is tightly tied to that ecosystem rather than to a standalone venture-backed brand.

The main criticism is not about a disclosed founder scandal, but about governance concentration: Sky governance can materially change SparkLend risk parameters, collateral rules, and token policy. On audits/security, multiple third-party profiles say SparkLend has been independently audited and has no recorded major security incidents or hacks to date. Hindenrank characterizes its operational history as fairly clean, though it still assigns only a mid-grade risk score because of ecosystem dependency.

Some third-party coverage also credits Spark with risk controls that reduced fallout during the Kelp/Aave-related market stress, which improved sentiment around its risk management. On sentiment, market coverage is broadly favorable, emphasizing strong inflows, rising TVL, and resilience during DeFi stress events. At the same time, criticism persists around regulatory uncertainty, especially because the protocol does not publicly surface KYC/KYB/sanctions controls and is not presented as a regulated lending venue.

On fraud/rug/insolvency allegations, I found no credible public allegation of fraud, rug pull, or insolvency in the supplied sources; the main concerns are structural rather than accusatory. On legal/regulatory/sanctions, I found no sanctions designation or legal action in the provided results, but compliance visibility is limited and remains an unresolved concern.

Evidence (10)

Economy

TVL: $4.8B

model

one source

As of September 5, 2026. Strategy: permissionless money market: users supply assets and earn borrower-paid interest; borrowers post collateral and pay variable or governance-adjustable rates. Yield is primarily lending spread, not trading PnL. Sky/Spark liquidity provisioning supports stablecoin liquidity. Assets/exposure: documented collateral is intentionally narrow, including ETH-correlated assets such as wstETH/rETH and stablecoins; collateral is reportedly retained in reserves rather than redeployed externally.

E-Mode enables correlated-asset looping. Flash loans are supported, but are not persistent leverage. External exposure, restaking, and directional market strategies: not verifiable as of September 5, 2026. Organic vs subsidized / neutrality: borrower interest is organic market yield.

Any Spark/Sky liquidity allocation, points, token rewards, or rate support should be treated as subsidized or policy-dependent; the net organic share is not verifiable as of September 5, 2026. The base strategy is market-neutral lending, but borrowers may create directional positions. Mechanics and controls: no documented maturity lock-up; withdrawals are on-chain supply withdrawals subject to available liquidity, health-factor constraints, caps, rate limits, and liquidation risk. Supply/borrow caps, isolation/silo modes, oracle controls, and liquidation thresholds are governance-configured.

User pays network gas; protocol fee schedules and withdrawal gates are not fully verifiable from the reviewed sources. TVL and revenue (DeFiLlama analytics, not raw on-chain verification): approximately $4.49B total, with about $4.49B Ethereum and $0.316M Gnosis; active loans about $2.09B, supplied assets about $6.58B. Recent 30-day fees were about $4.92M, versus protocol revenue about $0.417M. Product-level TVL, historical APY series, APY volatility, and sustainability are Not verifiable as of September 5, 2026. Contradiction: user scope/docs identify Ethereum, while DeFiLlama currently reports a small Gnosis deployment; chain attribution should be reconciled before relying on “Ethereum-only” exposure.

Dune/on-chain verification is unavailable in this run; no Dune query or execution ID exists. Risk view: economically a collateralized lending market with governance/liquidity-layer dependence; main risks are utilization-driven withdrawal stress, collateral/oracle/liquidation failure, stablecoin/issuer exposure, and rate changes.

Evidence (3)

reserves

two sources

Status as of September 5, 2026: SparkLend reserves/treasury are only partially verifiable. Dune MCP was unavailable in this run; therefore Ethereum balances, token composition, and latest block-level USD valuation are Not verifiable as of September 5, 2026. The Q2 2026 report references Dune query 6656460, but no execution snapshot could be independently checked. Reported size / contradiction. A September 4, 2026 press report states a $48.5 million treasury balance at June 30, 2026, with $1.31 million used for SPK buybacks during Q2.

Previously recorded evidence cited a DefiLlama treasury figure of $60.18 million, with approximately $36.35 million stablecoins, $23.83 million own tokens, and $840.57 of majors. That exact breakdown was not retrievable or independently refreshed in this run. Contradiction: $48.5m reported treasury vs. prior $60.18m DefiLlama total; not reconciled. The on-chain figure cannot be selected because Dune verification is unavailable. Addresses reported for Ethereum: Spark Treasury 0x3300f198988e4C9C63F75dF86De36421f06af8c4; SparkLend reserve-factor collector / treasury proxy 0xb137E7d16564c81ae2b0C8ee6B55De81dd46ECe5; Treasury Manager 0x92eF091C5a1E01b3CE1ba0D0150C84412d818F7a; Spark Operations Multisig 0x2E1b01adABB8D4981863394bEa23a1263CBaeDfC; SPK buyback address 0x797B010E0BABb493b8DEDD6F6ce5cc72778C2BF3. Addresses are supported by the Q2 report and/or deployment audit, but balances were not independently verified here. Custody/control and policy. The deployment audit states the Treasury Manager owner was MakerDAO’s DSPauseProxy.

Governance materials specify that USD stablecoin reserves are transferred to the Spark ALM Proxy, while non-USD reserves go to the Spark Operations Multisig for liquidation. Treasury surplus may fund SPK buybacks and grants through governance-authorized proxy spells. Attestations. No independent proof-of-reserves or third-party treasury attestation was found. The Q2 report identifies “Spark Finance internal financial records” as a source; this is an unverified marketing/issuer claim, not an independent attestation.

Evidence (5)

tokenomics

two sources

SparkLend does not have its own native token as of 2026-09-03. It is a lending market for DAI and other assets under the Maker ecosystem and primarily uses MKR (and DAI) for governance/economic alignment, not a dedicated “SPARK” token. Because there is no native SparkLend token:

  • Token name/ticker & contract address
  • No SparkLend governance/revenue token exists on Ethereum.
  • Users interact with standard ERC‑20s (e.g., DAI, WETH, stETH) and SparkLend’s aToken-like interest-bearing tokens, but these are not governance/value tokens.
  • Total vs circulating supply; market cap; FDV
  • Not applicable: there is no native SparkLend token, so no independent supply, market cap, or FDV.
  • Token utility and governance role
  • Protocol parameters and risk settings are governed by MakerDAO governance (MKR holders), not a SparkLend token.
  • DAI remains the core stablecoin tied to the protocol’s activity; MKR is the governance token at the ecosystem level.
  • Revenue share, buybacks, burns, staking rewards
  • SparkLend fee flows plug into Maker’s broader revenue model; there is no separate SparkLend token receiving revenue share, buybacks, burns, or staking rewards.
  • Any buybacks/burns occur in MKR per MakerDAO policy, not a SparkLend-native asset.
  • Emissions & unlock schedule; team/investor/treasury allocations
  • Not applicable: no dedicated SparkLend token, so no emissions or unlocks to verify on-chain, and no token allocation buckets (team/investors/community) specific to SparkLend.
  • Top-holder concentration and insider wallets
  • Not applicable for a non-existent SparkLend token. Concentration analysis would instead apply to DAI/MKR, which are ecosystem-wide, not SparkLend-specific.
  • Mint/blacklist/fee-switch functions & control
  • SparkLend markets and risk parameters are governed via MakerDAO smart contracts and governance processes. Specific token-level mint/blacklist controls are relevant to DAI/MKR, not a SparkLend token.
  • Detailed on-chain control of these functions for SparkLend cannot be confirmed here: Not verifiable as of 2026-09-03.
  • DEX liquidity depth and listings
  • Since there is no SparkLend token, there are no SPARK pairs or liquidity pools to analyze. Key take-away: SparkLend is a tokenless lending protocol under the Maker ecosystem; risk and economic exposure are via DAI/MKR and the lent assets, not a native SPARK token.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

SparkLend is supported on Ethereum, and its risk controls are designed around collateral health factors and liquidation thresholds rather than a BTC-specific circuit breaker. For a scenario where BTC falls below $10,000, the direct impact on SparkLend is only verifiable in a limited way from the available sources: Spark’s published kill-switch documentation explicitly covers *pegged assets* and depegging oracles, not a general BTC crash, so a BTC-10k stress outcome is not verifiable as of 2026-09-03 from the provided web evidence. What can be stated is that if a BTC selloff propagates into SparkLend via WBTC collateral, the protocol’s liquidation machinery is intended to absorb the shock by liquidating positions once health factors fall below 1, with up to 50% of debt covered when health factor is between 0.95 and 1, and up to 100% when it is at or below 0.95.

The kill-switch repo also says SparkLend can enter lockdown mode on pegged-asset depegs, preventing *new borrows* while still allowing users to top up collateral, repay, or withdraw. A useful caution is that third-party coverage around Spark’s risk posture discusses stress from ETH liquidity and liquidation conditions, but that is not a verified BTC-specific result. Based on the available evidence, the most defensible conclusion is: BTC < $10,000 would likely increase liquidation pressure on any WBTC-backed positions, but the magnitude of losses, bad debt, or market-wide contagion is not verifiable from the supplied sources.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

Under a 20% depeg of the largest collateral, SparkLend’s loss severity cannot be quantified precisely from the provided sources because the necessary on-chain exposure by collateral and current market positions are Not verifiable as of 2026-09-03. What can be said is that SparkLend’s liquidation design allows up to 50% of a position’s debt to be covered when Health Factor is below 1 but above 0.95, and up to 100% at or below 0.95, with collateral seized based on oracle prices and liquidation bonuses. The main risk implication of a 20% collateral depeg is that positions using that asset as collateral can move sharply toward liquidation, especially if the oracle still prices the asset near par while the market price has fallen.

An audit of SparkLend notes that LST/LRT oracles are designed around ETH/USD feeds and therefore may not handle depeg scenarios by design, which can leave some users unliquidated and create protocol losses in adverse market conditions. For context, Spark has also introduced a kill-switch mechanism for pegged assets: if a monitored asset depegs below its threshold, borrowing can be paused to limit downside exposure, while repayments and withdrawals remain possible. That reduces further contagion, but it does not by itself remove losses already embedded in undercollateralized positions.

A credible stress answer therefore is: a 20% depeg of the largest collateral would likely force broad liquidations and could produce bad debt if liquidations fail or are incomplete, but the size of that bad debt is Not verifiable as of 2026-09-03 from the available evidence.

Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For SparkLend on Ethereum, the insolvent “top counterparty” stress path is the borrower side: if a borrower’s health factor falls, the protocol liquidates the position automatically through the liquidation flow, rather than absorbing the loss through an insurance pool. If health factor is below 1 but above 0.95, up to 50% of the debt can be covered; at or below 0.95, up to 100% can be covered, with collateral transferred based on oracle prices and the liquidation bonus. The expected loss path is therefore: collateral value declines or debt value rises → health factor breaches threshold → liquidation bot or liquidator repays debt and seizes collateral → borrower loses collateral value up to the liquidation penalty, while lenders are protected unless the liquidation is incomplete or the position is undercollateralized beyond recoverable limits.

If the question instead means an external counterparty to Spark’s broader ecosystem, the only directly sourced stress framework I found is for Spark Security/Savings, where losses are said to be absorbed first by internal junior risk capital, then external junior risk capital, then the Sky surplus buffer and protocol backstops before reaching wider holders. That framework also says affected USDS holders may receive SKY token distributions in a resolution scenario. However, that is not verifiable as SparkLend-specific from the available sources, so the exact compensation waterfall for SparkLend bad debt is Not verifiable as of 2026-09-03.

The smart-contract impact path on SparkLend is liquidation and, in stress events, market shutdown controls: the docs describe liquidation mechanics tied to health factor, and Spark’s kill-switch module can place SparkLend into lockdown mode when pegged-asset oracle thresholds are breached, preventing new borrows. A published audit also notes a flashloan-into-borrow vector was disabled in core updates, showing the protocol’s stress controls are enforced at the contract level.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For a committed fraud by the DAO or owners stress scenario, I found no verified evidence that SparkLend’s DAO, owners, or core operators committed fraud. As of 2026-09-03, this is Not verifiable as of 2026-09-03 based on the available sources. What is verifiable is that SparkLend is a fork of Aave v3 operated within the MakerDAO / Sky ecosystem, and its published bug-bounty scope treats direct theft of user funds, permanent freezing of funds, and protocol insolvency as critical risks to be defended against.

Independent coverage also reports that SparkLend had already reduced or exited rsETH exposure before the KelpDAO bridge exploit, avoiding direct losses while receiving inflows from users fleeing affected markets. There is also no source in the provided set alleging a governance attack, owner misconduct, embezzlement, or a fraudulent treasury action by SparkLend’s DAO or controllers. The only concrete incident in the source set is a third-party bridge exploit involving KelpDAO and rsETH, which is an external protocol risk rather than evidence of fraud by SparkLend’s DAO or owners.

If you want the stress assessment framed conservatively, the applicable risk is governance/key-person misconduct or malicious parameter changes, but the specific claim of committed fraud is not supported by the available evidence.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For SparkLend on Ethereum, a primary yield source negative 30d stress would mean the main externally earned cash flow feeding the product weakens, but the protocol’s user-facing lending market does not automatically imply principal loss from negative yield alone. SparkLend is documented as an Ethereum-supported lending market, and its liquidation mechanics are based on health factor thresholds rather than yield performance. The relevant stress point is that Spark’s broader yield stack depends on Sky/Spark income sources, including crypto-loan fees, U.S.

Treasury bill exposure, and liquidity provisioning through SparkLend itself. If the primary yield source turns negative for 30 days, that is a cash-flow stress on the allocation engine, not a direct on-chain insolvency event by itself; however, it can reduce the protocol’s ability to sustain attractive rates and may force reallocation or governance response. For risk framing, Spark’s published Credora assessment shows Ethereum market exposure at 0.39% PSL with an A rating as of 29 Jun 2026, which suggests relatively limited assessed exposure in that savings/risk architecture context.

But that does not verify SparkLend’s current on-chain loss absorption or reserve depth under a negative-yield month; that is Not verifiable as of 2026-09-03. If you want the operational takeaway: the likely stress outcome is lower or unsustainably compressed depositor yield, possible spread compression for lenders, and increased dependence on governance or reserve subsidy. There is no web-verifiable evidence here that a 30-day negative primary yield source would itself trigger automatic liquidation of SparkLend positions; liquidations are driven by collateral health factor deterioration.

Evidence (4)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026: SparkLend Ethereum governance is hybrid and materially controlled by Sky governance, not an autonomous Spark DAO. Control map. Core parameters, contract administration and proxy-spell execution flow through Sky: forum/Atlas proposal → governance poll or Snapshot authorization → Sky executive vote → Spark proxy spell. Recent Sky votes explicitly include SparkLend reserve claims and SparkLend proxy spells. The September 10, 2026 executive vote states that the GSM delay is currently 48 hours and that Prime Agent proxy spells for Spark are being whitelisted. Funds. Sky governance has authorized claiming all SparkLend reserves, transferring stablecoins to the ALM Proxy and non-stablecoins to the Spark Operations Multisig.

This is governance-mediated treasury control, not an identified unilateral drain key. Emergency powers. SparkLend FreezerMom grants an emergency SAFE/ward authority to freeze or pause markets. The repository states that there may be at most one SAFE multisig ward; MKR/SKY governance can remove it, and the Pause Proxy/SubDAO Proxy retains override authority. This is a material emergency bypass, although the documented powers are pause/freeze rather than direct asset withdrawal. DAO reality and concentration. Spark/SPK signaling does not control core Ethereum upgrades or parameters; Sky executive governance does.

Top SparkLend/SPK holders, voting concentration, current Freezer SAFE signers/threshold, and signer independence: Not verifiable as of September 13, 2026 because Dune/on-chain verification is unavailable in this run. Reported third-party 3-of-5 figures are not treated as verified primary evidence. Frontend/developer/company control. Frontend ownership, legal entity, jurisdiction, registration number, directors, Terms of Service, and a complete verified developer/admin control map: Not verifiable as of September 13, 2026. No company-control conclusion is asserted from protocol marketing materials.

Timelock
Yes
Timelock delay hours
48
Admin can drain
No
Emergency bypass
Yes
Dao governance
No
Evidence (4)

legal & regulatory

two sources

SparkLend is the lending market of the Spark protocol, a MakerDAO-aligned project focused on DAI-based lending; it is not verifiable as of 2026-09-03 whether it is a separately incorporated legal entity. Entity & jurisdiction

  • Spark is described in Maker ecosystem communications as a subDAO / growth initiative backed by MakerDAO, not as a stand‑alone regulated financial institution.
  • I could not identify a clear incorporated entity (e.g., “Spark Labs Ltd”) on official docs, ToS, or filings. Not verifiable as of 2026-09-03. Terms of service & user restrictions
  • SparkLend front‑end access is typically provided via web interfaces controlled by Maker‑related entities or community; these may geo‑block users from certain countries (e.g., U.S., sanctioned jurisdictions), but specific ToS language for SparkLend itself is not publicly available or indexed in major search results. Not verifiable as of 2026-09-03. KYC / AML
  • SparkLend runs as an on-chain, non‑custodial lending protocol on Ethereum, and current public interfaces do not appear to require KYC for basic interaction (deposit/borrow) via self‑hosted wallets.
  • Any AML controls are therefore mainly at the level of front‑end providers, centralized ramps, or user institutions, not the protocol smart contracts themselves. This is consistent with typical DeFi design but specific SparkLend AML policies are Not verifiable as of 2026-09-03. Regulatory classification & guidance
  • Regulators have not yet issued protocol‑specific guidance on SparkLend. It likely falls in the broad category of DeFi lending / liquidity protocol similar to Aave/Compound, but that is an analytical inference, not a formal classification.
  • MakerDAO and DAI have been discussed in various regulatory and academic reports as examples of stablecoin / DeFi governance, but those references do not specifically single out SparkLend. Warnings, enforcement, court cases, sanctions
  • I found no public enforcement actions, formal warnings, or court cases naming “SparkLend” or “Spark protocol” as respondents by major regulators (SEC, CFTC, ESMA, FCA, etc.) or courts. Not verifiable as of 2026-09-03.
  • I found no listing of SparkLend or Spark as sanctioned entities in major sanctions databases (OFAC, EU, UK). Not verifiable as of 2026-09-03. Data protection & privacy
  • As a smart-contract protocol, SparkLend itself does not custody personal data; any privacy obligations would attach to web front‑ends or associated entities that collect user data (IP logs, email, etc.). No dedicated Spark privacy policy surfaced. Not verifiable as of 2026-09-03. Legal structure vs actual risk
  • The absence of a clearly disclosed legal entity and regulated status means institutional users face protocol‑risk and governance‑risk rather than recourse to a supervised financial institution.
  • Regulatory treatment remains uncertain; institutions should assume standard DeFi counterparty posture: interaction with autonomous contracts, limited legal recourse, and evolving regulatory expectations.
Evidence (4)

Stability

stability

two sources

SparkLend itself is not a stablecoin issuer; it is a lending protocol that uses Sky/Maker’s USDS as its core stablecoin, so own_stablecoin is false. A stablecoin depeg for SparkLend’s main stablecoin is not verifiable from the available sources, so depeg_count, max_depeg_pct, last_depeg_date, and stable remain not verifiable as of 2026-09-05.

Own stablecoin
No
Stablecoin ids
  • USDS
Evidence (3)

Risks & Strengths

risks

two sources

SparkLend’s principal risks are oracle/depeg transmission, privileged governance and upgrade control, smart-contract defects, liquidity stress, and liquidation losses during volatile markets. Ethereum is the requested scope; current on-chain exposure, utilization, collateral concentration, and reserve liquidity are Not verifiable as of September 5, 2026 because Dune verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle manipulation or depegLST/LRT and restaked-asset prices may diverge from realizable market value; ETH-derived pricing can understate a depeg and permit excess borrowing or delayed liquidation. ChainSecurity specifically flags weETH manipulation and depeg limitations.HighMediumMultiple oracle adapters, capped/fallback rate sources, peg-ratio monitoring, and a Kill Switch that can set collateral LTV to zero.High-impact oracle failure remains possible during rapid depegs, feed disruption, or abnormal exchange-rate behavior.
Governance and admin concentrationGovernance-controlled roles can change parameters, freeze markets, pause markets, or upgrade components; compromise or misconfiguration could impair solvency or access.HighMediumGovernance relay and PauseProxy pathways, role separation, deployment validation, and emergency freezer contracts.Material trust remains in governance, privileged keys, timelocks/relays, and operational execution.
Smart-contract implementation defectA bug in Aave-derived core contracts or Spark-specific modules could cause unauthorized withdrawals, accounting errors, or insolvency despite audits.HighLowAudits, formal verification heritage, open-source testing, deployment validation, and an Immunefi bounty.Audits are scoped and time-limited; newly deployed or upgraded modules retain unknown vulnerability risk.
Liquidity and withdrawal stressHigh utilization, stablecoin dislocation, or reduced Sky/Spark Liquidity Layer support could make withdrawals costly or delayed and amplify contagion across connected venues.HighMediumDebt ceilings, rate responses, controller rate limits, slippage controls, whitelisted venues, and backup permissionless withdrawal paths.Liquidity buffers and counterparty capacity are Not verifiable as of September 5, 2026.
Liquidation and market insolvencyFast collateral price declines, thin liquidity, gas congestion, or correlated collateral failures can leave bad debt before liquidators can execute.HighMediumCollateral-specific LTV/liquidation parameters, liquidation incentives, caps, oracle monitoring, and emergency market freezing.Parameter lag, auction/liquidator shortfalls, and correlated sell-offs can still create unrecovered debt.
Evidence (6)

strengths

two sources

SparkLend’s top strengths are its capital efficiency and deep liquidity, conservative risk design, multiple oracle redundancy, tight onchain rate controls, and strong ecosystem integration with Sky. It is described as a low-cost, high-liquidity lending market built from Sky liquidity, designed to offer competitive borrowing rates and efficient stablecoin borrowing on Ethereum.

  • Deep, low-cost liquidity: SparkLend is backed by capital sourced from Sky, which supports large-scale borrowing and competitive rates.
  • Capital efficiency: Its design emphasizes high utilization of stablecoin liquidity and efficient borrowing, especially through sUSDS and related ecosystem flows.
  • Conservative risk posture: Spark documentation says it has a narrow collateral set, multi-oracle pricing, and first-loss capital, all of which reduce single-point risk.
  • Resilience controls: Every cross-module flow into and out of SparkLend is rate-limited at the smart-contract level, including deposits, withdrawals, cross-chain bridging, and PSM swaps.
  • Ecosystem integration: SparkLend is deeply integrated with Sky’s balance sheet and lending stack, which strengthens its role as a core DeFi credit and liquidity venue.
Evidence (4)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 28 two independent sources, 13 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-27.