Suilend

Green · 70/100

Executive summary

Suilend is a lending protocol on Sui, built by the Solend team, scoring 55/100 (orange band) with high data confidence (88%) and a -10 penalty for unresolved incident remediation.

  • Security: Audited by Certora (March 2026, 15 of 17 findings fixed), Zellic (March 2024, 2 medium findings), and OtterSec (March 2024, details unverified); bug bounty up to $250,000; however, on-chain bytecode matching and current package ownership are not verifiable as of September 2026.
  • Incidents: September 2025 IKA price spike caused ~$379,000 loss socialized across IKA depositors (~6% haircut); remediation status is "in progress" and permanent fixes are unverified. November 2025 Elixir market suspension (resolved, no user loss). March 2026 frontend outage (funds safe, resolved).
  • Governance & custody: Company-controlled by Bluewater Labs (acquired June 2026); SEND DAO is not operational. UpgradeCap custody, multisig signers, timelock, and admin authority over user funds are not verifiable. Non-custodial for users; isolated markets limit contagion but can be paused.
  • Top risks: Oracle failure (Pyth/Switchboard) could trigger wrongful liquidations or leave bad debt; smart-contract exploit despite audits; liquidity stress in isolated markets can socialize losses; bridge (Wormhole) and LST (SpringSui sSUI) dependencies create counterparty risk; pseudonymous founder and undisclosed treasury/reserve controls.
  • Strengths: Largest lending protocol on Sui with broad DeFi suite (lending, staking, swap, bridge); isolated-market design limits cross-contamination; Sui-native performance; experienced team (Solend background); multiple audits and active bounty.
  • Unverified: Current TVL, collateral composition, utilization, reserve fund size, circulating SEND supply, top-holder concentration, exact admin/multisig setup, and all on-chain contract state (Dune unavailable). Legal entity, jurisdiction, ToS, and KYC/AML policies are not disclosed.
  • Recommended exposure: Limit to <5% of portfolio in isolated, liquid markets (e.g., USDC/SUI main pool) with conservative LTV; avoid isolated/exotic assets until IKA remediation is verified and oracle/liquidation improvements are confirmed on-chain; monitor utilization and exit if >80% to preserve liquidity; treat as higher-risk given unresolved incident, unverified governance, and Sui ecosystem concentration.
  • Open questions: Verify current UpgradeCap and LendingMarketOwnerCap custody (signers, threshold, timelock); confirm IKA incident root cause and permanent oracle/risk-parameter fixes; obtain independent reserve attestation and treasury policy; assess SEND token unlock schedule and insider holdings on-chain; clarify legal entity, jurisdiction, and user agreement; evaluate SpringSui and Wormhole risk in detail; check real-time utilization and bad-debt history across all markets.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 3 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-03-24)
Incidents 20% 100 20.0 1 open incident(s), $379,000 at risk = 0.3% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 1 0.2 TVL $117,065,425 = 1% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 15/36 verified facts; 36/36 fresh (180d)

Identification

protocol identification

unverified

Suilend is a lending/borrowing DeFi protocol on Sui, with official docs at docs.suilend.fi and the main site at suilend.fi; the docs describe it as part of Sui’s DeFi suite and say it launched in March 2024. The protocol introduced its native token SEND in December 2024. The upstream team is the Solend team, which Sui’s official blog says launched Suilend as its first project outside Solana.

The docs list audits from Zellic (March 5, 2024) and OtterSec (March 20, 2024). The docs also point to Sui package addresses, and independent listings / market pages surface the SEND contract as 0xb45fcfcc2cc07ce0702cc2d229621e046c906ef14d9b25e8e4d25f6e8763fef7::send::SEND; however, because on-chain/explorer verification was not available in this run, that address is Not verifiable as of 2026-09-03. Fork lineage: Suilend is a fork/extension of Solend’s lending design, but I could not verify the exact code deltas, whether every change was independently audited, or any malicious-modification history in related forks, so those parts are Not verifiable as of 2026-09-03.

Evidence (6)

maturity

one source

Suilend appears to be a real, live product portal rather than a pure landing page: the main site is an active app shell with product navigation (“Lend”, “SEND”, wallet, Docs) and the docs site includes concrete SDK methods for deposits and withdrawals such as depositLiquidityAndGetCTokens, depositIntoObligation, withdraw, and withdrawAndSendToUser. The documentation also exposes API-style event references and a dynamic Q&A endpoint, which is a strong signal of a maintained developer-facing surface. Live deposits/withdrawals are not verifiable as of 2026-09-03 from the available web evidence alone, because the material confirms callable deposit/withdraw methods in docs but does not independently prove current mainnet transaction success or uptime.

Likewise, broken links and template/fake-metric checks are not verifiable as of 2026-09-03 from the available evidence. On the open API question: yes, Suilend appears to have an open developer API/SDK surface via its published SDK documentation and repository, including typed methods and a public SDK guide. That is an open integration interface, though it is more accurately an SDK/API for program interaction than a generic public REST API.

Evidence (4)

Security

bug bounty

unverified

Suilend has an active bug bounty program covering its smart contracts only; UI bugs are out of scope. The program targets theft and freezing of funds, requires a proof of concept for Critical and High reports, and pays in vesting SEND on Sui. Rewards are structured as: Critical = 10% of value at risk up to $250,000; High = $50,000; Medium = $10,000.

The published scope also notes that the actual prize depends on severity, value at risk, and exploitability, and that reports should be emailed to security@solend.fi.

Active
Yes
Platform
protocol_own
Max payout
$250K
Since
2025-06-18
Evidence (2)

counterparty risks

two sources

As of 2026-09-05 — Dependencies & Counterparty Risk (Sui only) Primary dependencies

  • Oracles: Suilend states that liquidations use Pyth and Switchboard feeds. Incorrect, stale, or manipulated prices could trigger wrongful liquidations; the code documentation also shows owner-authorized price-feed changes and stale-price checks.
  • Bridges: Suilend’s built-in bridge uses Wormhole Connect and supports bridged USDC, USDT, WETH and SOL from other chains. This creates bridge-message, wrapped-asset backing, liquidity and redemption risks.
  • LST/restaking: Suilend Strategies and related products use SpringSui-issued sSUI and other Sui liquid-staking assets. A SpringSui smart-contract failure, validator/staking issue, or LST discount could impair collateral value and liquidations.
  • Stablecoins: USDC/USDT and bridged variants are supported or referenced in the bridge documentation. Depeg, issuer freeze/insolvency, or loss of cross-chain convertibility could create bad debt and withdrawal pressure. Exact stablecoin exposure is not available without on-chain balances.
  • Liquidity/market infrastructure: Liquidations depend on functioning Sui liquidity and third-party liquidators. A major Sui DEX incident, such as the May 22, 2025 Cetus exploit, demonstrates ecosystem-wide liquidity and price-discovery stress, but does not establish direct Suilend losses or a direct Cetus dependency. Counterparties not verified
  • No verified evidence of custodial balances, CEX/MM credit exposure, RWA issuer/SPV exposure, or external rehypothecation was found. Not verifiable as of 2026-09-05. > Contradiction / update: The prior finding said Suilend did not advertise bridges or external integrations. Current documentation explicitly describes Wormhole Connect bridging, SpringSui-linked strategies, and STEAMM integration; the prior statement is outdated. Stress scenarios: oracle error/manipulation → wrongful liquidations; Wormhole failure → wrapped-asset unbacking; USDC/USDT or sSUI depeg → collateral shortfall; liquidity shock → delayed liquidations and bad debt; isolated-market failure → losses concentrated in that market. Suilend states isolated assets and insurance/loss-socialization mechanisms are used, but coverage limits are not independently verified. On-chain exposure percentages and chain allocation are Not verifiable as of 2026-09-05 because Dune MCP is unavailable.
Evidence (5)

crypto custody

two sources

Suilend’s custody is organized as a non-custodial lending protocol: users keep control of their wallet, while deposits are supplied to on-chain smart-contract lending pools rather than a centralized custodian. The protocol uses separate main and isolated markets; isolated assets are kept in dedicated risk buckets so risk from a smaller or more volatile asset does not spill into the main market. Withdrawal status is not verifiable as of 2026-09-05 for the protocol overall; the available evidence shows that isolated-market withdrawals can be paused in specific incidents, while other markets may remain open.

Segregated assets
Yes
Evidence (3)

incident

two sources

No confirmed protocol-level exploit, oracle attack, governance attack, key compromise, or depeg event was identified in the provided sources. The clearest reported operational incident was a front-end outage caused by a third-party hosting/custody service provider issue; Suilend said funds were safe and the problem was being investigated and resolved.

Date
2025-03-06
Cause
Frontend / infrastructure hack
Evidence (2)

incident

two sources

An IKA price spike from approximately $0.04 to $0.47 caused some loans to be liquidated at inflated valuations. After prices normalized, the isolated IKA market had an approximately $379,000 shortfall. Suilend paused IKA lending/borrowing and socialized the loss across IKA depositors, reducing balances by approximately 6%; other markets were reportedly unaffected.

The loss was borne by users rather than Suilend. No attacker proceeds, recovery, or reimbursement were reported. Permanent oracle, risk-parameter, or liquidation-process remediation is Not verifiable as of September 5, 2026.

Current status: remediation_in_progress.

Date
2025-09-09
Cause
Liquidity issue
Loss
$379K
Status
remediation in progress
Recovered
$0
Reimbursed
No
Evidence (3)

incident

two sources

Suilend paused deposits and withdrawals in its Elixir isolated market after Stream Finance disclosed an approximately $93 million loss tied to an external fund manager, creating deUSD counterparty/depeg risk. Affected users were Elixir-market depositors and borrowers; Suilend stated other markets were unaffected. Elixir subsequently repaid all outstanding USDC debt, and Suilend restored withdrawals on November 5, 2025.

No realised loss to Suilend users was reported, no attacker or attacker proceeds were identified, and no reimbursement was required. Fix: containment through market isolation, suspension, and debt repayment; no additional permanent code fix was reported. Current status: resolved.

Date
2025-11-04
Cause
Depeg / collateral
Loss
$0
Status
resolved
Recovered
$0
Reimbursed
No
Evidence (3)

incident

one source

A March 2026 liquidity/market-imbalance event on the IKA market was reported as a $379,000 gap after IKA price surged and some loans were liquidated at inflated valuations. Suilend reportedly paused IKA lending, and losses were borne by IKA depositors via an approximately 6% principal reduction; the source set does not provide an independent primary confirmation of reimbursement or a detailed technical fix.

Date
2026-03-06
Cause
Liquidity issue
Loss
$379K
Evidence (1)

incident

one source

A later update stated Suilend said all functions were operating normally while it monitored a prior Volo Protocol security incident and that user funds were safe. The provided sources do not verify any direct loss at Suilend from that incident, nor any reimbursement action or code fix attributable to Suilend itself.

Date
2026-04-22
Cause
Other
Evidence (1)

key management

unverified

Suilend’s public materials do not describe a dedicated cryptographic key-management program (for example, whether it uses an HSM, multisig, MPC, a KMS, or specific rotation/recovery policies). Based on the available sources, the key-management setup is not verifiable as of 2026-09-03. What *is* visible is that Suilend provides an SDK for client integration, and external integrations can be built with either wallet integration or private-key support, which indicates user-side signing flexibility rather than protocol-side key governance.

Suilend’s docs also state that certain actions in the STEAMM integration are admin-gated, with bank.init_lending() described as toggleable only by Suilend, but they do not explain how those admin credentials are secured or who controls them. So, for institutional risk purposes, the current conclusion is: key custody and operational key controls are undisclosed in the sources reviewed. The protocol may have internal controls, but they are not verifiable from the available documentation and third-party material.

Evidence (3)

smart-contract

one source

As of September 5, 2026. Sui only; Dune MCP unavailable. On-chain verification, decoded admin events, current package/UpgradeCap ownership, timelock delay, and current object state are Not verifiable as of 2026-09-05. Therefore, previously recorded uncertainty remains unresolved. Address evidence (documented, not on-chain-verified): the Suilend SDK documents mainnet package 0xf95b06141ed4a174f239417323bde3f209b972f5930d8521ea38a52aff3a6ddf, main market 0x84030d26d85eaa7035084a057f2f11f701b7e2e4eda87551becbc7c97505ece1, and owner capability 0xf7a4defe0b6566b6a2674a02a0c61c9f99bd012eed21bc741a069eaa82d35927; these are documentation/SDK values, not independently confirmed current deployment values. Architecture / controls: Move package modules include lending_market, reserve, oracles, rate_limiter, liquidity mining, and staking integrations.

A LendingMarketOwnerCap authorizes reserve creation, reserve-configuration changes, price-feed changes, rate-limiter changes, fee-receiver changes, reward administration, staker operations, and recovery creation of obligation owner caps. User deposits/withdrawals are capability-based through ObligationOwnerCap; withdrawals can still fail under 100% utilization. ``text User -> ObligationOwnerCap -> LendingMarket -> Reserve liquidity ^ OwnerCap/admin |-- reserve config/oracle |-- fees/rewards/rate limits |-- staker/recovery actions Package -> [UpgradeCap?] -> versioned Move package `` Risk assessment: No EVM proxy is evidenced; Sui package upgradeability and UpgradeCap custody remain Not verifiable as of 2026-09-05. Admin key compromise could plausibly alter risk parameters/oracles, redirect fees, add/cancel rewards, rate-limit withdrawals, or issue replacement obligation capabilities; direct arbitrary draining is not established from the reviewed source.

Timelock, multisig, role renunciation, emergency pause, and withdrawal-exit guarantees are Not verifiable as of 2026-09-05. Audits by Zellic and OtterSec are documented, and Certora lists Suilend audit/formal-verification work dated March 24, 2026, but deployment/version coverage is not independently matched here.

Evidence (5)

audit

two sources

Suilend core lending protocol — Certora Security Assessment & Formal Verification Final Report. Auditor: Certora. Final-report page date: March 24, 2026; PDF states February 2026.

Scope: repository https://github.com/suilend/suilend, commits f132da4 through f253cfb1; all contracts/suilend, emphasizing lending_market.move, obligation.move, reserve.move and staker.move. Covers deployed code: Not verifiable as of September 4, 2026; audited commits are identified, but on-chain package-bytecode matching is unavailable because Dune MCP is unavailable.

Auditor
Certora
Report date
2026-03-24
Scope
Suilend Move contracts; commits f132da4–f253cfb1; lending market, obligations, reserves and staker.
Findings
Critical: 0. High: 0. Medium: 4 discovered; 3 fixed and 1 acknowledged. Medium findings: double-rounding cToken over-minting; liquidation worsening LTV; liquidation not prioritizing highest borrow-weight collateral; relayer could substitute ObligationOwnerCap. Low: 10 discovered; 9 fixed and 1 acknowledged. Informational: 3 discovered; all 3 fixed.
Fix status
15 of 17 discovered findings marked fixed; 2 acknowledged (M-04 and L-05). Certora performed fix review for fixed items. Deployed-code status remains Not verifiable as of September 4, 2026.
Evidence (2)

audit

one source

Suilend core lending protocol — OtterSec audit report. Auditor: OtterSec. Publication date: March 20, 2024 per Suilend’s audit index.

Report: direct PDF URL was not exposed by the accessible OtterSec index; protocol report page: https://docs.suilend.fi/security/suilend-audit. Covers deployed code: Not verifiable as of September 4, 2026. Contradiction: OtterSec’s public audit index appears to show a Suilend entry dated April 20, 2024, while Suilend documentation states March 20, 2024; the discrepancy is unresolved.

Auditor
OtterSec
Report date
2024-03-20
Scope
Suilend core lending contracts on Sui; exact audited commit not exposed in accessible sources.
Findings
Critical: Not verifiable as of September 4, 2026. High: Not verifiable as of September 4, 2026. Medium: Not verifiable as of September 4, 2026. The accessible OtterSec index does not provide the report’s detailed finding text in this retrieval.
Fix status
Not verifiable as of September 4, 2026. No public remediation matrix or deployed-code mapping was located.
Evidence (2)

audit

unverified

Suilend documentation states OtterSec audited Suilend, but the accessible snippet did not expose the report date, scope, or findings breakdown.

Auditor
OtterSec
Report date
2024
Scope
Not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03.
Fix status
Not verifiable as of 2026-09-03.
Evidence (2)

audit

one source

Suilend security assessment covering Suilend code reviewed by Zellic from February 14, 2024 to February 26, 2024; report published March 5, 2024.

Auditor
Zellic
Report date
2024-03-05
Scope
Suilend code review for security vulnerabilities, design issues, and general weaknesses in security posture.
Findings
Critical 0, High 0, Medium 2, Low 0, Informational 0.
Fix status
Report indicates the two medium findings were included in the published assessment; public summary does not provide a per-finding remediation matrix. Not verifiable as of 2026-09-03 whether every finding remained fixed at deployment without a bytecode-match check.
Evidence (3)

Team & Reputation

founders

two sources

Founding reality: Suilend is built by the team behind Solend/Save on Solana and led by a pseudonymous founder “Rooter”, not a fully doxxed founding team. As of 2026-09-03, on‑chain verification of any of this is Not verifiable as of 2026-09-03. ### Founders & team

  • Founder: “Rooter”, the pseudonymous founder of Solend, is repeatedly cited as the leader/founder of Suilend.
  • Team composition: Bybit and Backpack profiles state Suilend is built by the Save (formerly Solend) team, with around 15 team members, including 11 developers with prior experience at Morgan Stanley, Bell Labs, IBM. These are secondary-analytics descriptions, not independently verified CVs.
  • Named individuals: A data profile lists Rooter (Founder), Gidwell (Head of Growth), Ripleys (Engineer). These appear to be handles, not full legal names.
  • Public vs anon: Founder is explicitly pseudonymous; much of the team is represented by aliases. No independent source provides a complete, fully doxxed org chart. ### Prior projects, outcomes, incidents
  • Track record: The team’s prior project is Solend / Save, a major Solana lending protocol with high historical TVL, widely referenced as “successful”. No independent source in this set reports a protocol‑level hack or insolvency event for Solend or Suilend; however, without on‑chain review this remains Not verifiable as of 2026-09-03.
  • Funding: Suilend reportedly raised $2M + $4M in rounds led by funds including Delphi Ventures, Robot Ventures, Mechanism Capital, DeFi Alliance, Karatage, plus angels (Mert, Balaji, DCFGod). These are reported in profiles and media; underlying deal documents are not surfaced. ### Corporate structure, offices, jurisdiction
  • A June 2026 acquisition report states Bluewater Labs is acquiring Suilend and its products from Concurrent C, Inc., with Bluefin co‑founder Zabi Mohebzada becoming CEO of Suilend.
  • The same piece notes SUI Group Holdings (a NASDAQ‑listed investment company) financing the acquisition and being headquartered in Wayzata, Minnesota; Suilend itself is described as continuing to operate independently under Bluefin leadership.
  • No source provides a clear registered corporate entity name for “Suilend” or a dedicated office address; current reality is an integration into a corporate ownership stack (Bluewater/Bluefin/SUI Group) rather than a standalone DAO. ### Reality check
  • Founder anonymity and multi‑layer corporate ownership (Concurrent C → Bluewater Labs → SUI Group financing, CEO shared with Bluefin) materially increase key‑man, governance, and conflict‑of‑interest risk for an institutional allocator.
  • There is no live DAO; SEND governance token is reportedly being wound down, leaving centralized control.
  • Claims about team pedigree and “largest lending protocol on Sui” are based on marketing/docs and analytics narratives, so should be treated as unverified marketing claims unless independently checked on‑chain or via corporate registries.
Evidence (14)

general reputation

two sources

Suilend’s reputation appears broadly positive but still young and lightly battle-tested. It is presented as the lending protocol built by the team behind Solend/Save, with founder “Rooter” described as pseudonymous; multiple sources also say it raised $6 million and list backers including Robot Ventures, Delphi Ventures, Alliance DAO, Mechanism Capital, Karatage, and other crypto investors. Reported auditors/security firms include Zellic and OtterSec, and one source says Suilend has a bug bounty program.

The main sentiment in the sources is that Suilend is viewed as a major Sui lending venue, but this is mostly ecosystem-positive coverage rather than independent due diligence. I did not find credible reports of fraud, rug-pull, insolvency, or sanctions involving Suilend in the gathered material. No legal or regulatory action was surfaced in the available sources.

Unresolved concerns remain: the founder is pseudonymous, much of the investor/audit information is repeated across marketing, ecosystem, and aggregator coverage rather than primary disclosures, and the protocol is still relatively new (launched in 2024). Because on-chain verification was unavailable in this run, claims about TVL, liabilities, or solvency are Not verifiable as of 2026-09-03.

Evidence (8)

Economy

TVL: $117.1M

model

two sources

Assessment (as of September 5, 2026). Suilend is a Sui-only, pool-based, overcollateralized money market. Users supply supported assets to per-token reserves and receive cTokens; borrowers draw assets against multi-asset collateral through obligation positions. Interest accrues through reserve utilization and dynamic rates; cToken value increases with earned interest. Yield source / sustainability. Base depositor yield is primarily borrower-paid interest, less a protocol spread; Suilend documentation describes the spread as typically 20% of borrow interest.

Pool rewards can add temporary external incentives, so advertised APY may be partly subsidized. The organic/subsidized split is Not verifiable as of September 5, 2026. APY history, volatility, and sustainability are also Not verifiable as of September 5, 2026. Risk and strategy. The core product is generally market-neutral for suppliers only in token terms; USD returns remain exposed to supplied-asset prices.

Borrowers can create directional or leveraged positions, but aggregate leverage/looping is Not verifiable as of September 5, 2026. No evidence reviewed establishes protocol-level restaking or material external market exposure. Suilend also operates liquid-staking and AMM-related products; those introduce staking, liquidity, and impermanent-loss risks beyond the base lending pool. Withdrawals / constraints. Deposits are redeemable by burning cTokens, but liquidity can be constrained when reserves are highly utilized; the code includes withdrawal rate-limit controls.

Borrowing is limited by collateral LTV, reserve liquidity, borrow limits, oracle freshness, and rate limits. Liquidations use oracle prices and a liquidator bonus. There is no fixed lock-up identified; withdrawal mechanics and limits are not equivalent to guaranteed instant liquidity. Fees and revenue. Borrowing charges fees; liquidation fees can be split between protocol and liquidator.

Fee receivers are admin-configurable. DefiLlama currently reports approximately $124.13m TVL, $64.87m active loans, and $332,328 fees versus $74,970 revenue over 30 days; Sui represents 100% of reported TVL. Contradiction / data quality. DefiLlama pages show conflicting snapshots ($124.13m versus $135.58m TVL), likely timing or product-scope differences. Dune TVL, product attribution, trend, and on-chain APY verification: Not verifiable as of September 5, 2026.

Evidence (4)

reserves

unverified

As of September 5, 2026, Suilend’s treasury/reserves are Not verifiable as of 2026-09-05 from publicly retrievable web evidence. Dune/on-chain verification was unavailable for this run; therefore no Dune query ID, execution ID, block height, balances, or USD valuation is reported. What is verifiable is the protocol’s lending-market architecture, not treasury size: a LendingMarket contains one Reserve per supported token, with deposits, borrows, liquidity, and user CTokens.

These are pooled user-asset reserves and should not be treated as protocol-owned treasury assets. The Move documentation shows that each market has a fee_receiver and a configurable fee-receiver list. Market creation initially assigns the creator as fee receiver, while set_fee_receivers requires the LendingMarketOwnerCap.

This indicates administrative control over fee destinations, but the public materials reviewed do not establish the current mainnet market ID’s fee-receiver address, signer set, custody arrangement, or balances. Composition / custody / control: Not verifiable as of 2026-09-05. No verified treasury address list, multisig threshold, reserve policy, segregation policy, or independent reserve attestation was located. The SEND DAO address page lists DAO wallets, but it does not establish that they custody Suilend protocol reserves or fee revenues. Attestations: Not verifiable as of 2026-09-05. Contradiction check: No protocol treasury figure was found that could be reconciled against on-chain data.

Any third-party lending-market deposit/borrow snapshot would describe user liabilities and liquidity, not independently verified treasury reserves; it is therefore excluded. Structured fields: liquid_reserves_usd = null; liabilities_usd = null. [On-chain balances via Dune: Not verifiable as of 2026-09-05.]

Evidence (4)

tokenomics

two sources

Suilend appears to have a native token, SEND, on Sui; however, the contract address is Not verifiable as of 2026-09-03 from the available sources, and I cannot confirm a canonical address without on-chain verification. Public market pages list SEND and commonly show a max/total supply of 100,000,000 SEND. The protocol docs say SEND has a 100M total supply and describe its utility as a governance mechanism plus ecosystem incentive token; they also say users can redeem allocations via mSEND and that early claims pay a penalty in SUI.

The docs further state the allocation is Community 65% / Investors 20% / Team 15%, while a separate tokenomics page breaks that into Community 55%, Investors 20%, Insiders 15%, Foundation 10%; this is a contradiction and the on-chain/primary-source version is Not verifiable as of 2026-09-03. Announced unlocks in the docs are: Mdrops day 1, Investors over 2 years, Team over 4 years; whether these unlocks actually happened on-chain is Not verifiable as of 2026-09-03. I found no reliable evidence in the gathered sources for revenue share, buybacks, burns, staking rewards, mint/blacklist/fee-switch controls, top-holder concentration, insider wallets, or DEX liquidity depth/main listings beyond general exchange/market-listing pages, so each of those items is Not verifiable as of 2026-09-03.

Because Dune/on-chain checks were unavailable in this run, I cannot confirm circulating supply, actual market cap, FDV, insider concentration, or whether any promised unlock schedule matched on-chain reality.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Suilend on Sui, a Bitcoin move below $10,000 is not directly verifiable as a protocol-specific stress trigger from the available sources. Suilend’s documented risk model focuses on collateral price declines, over-collateralized loans, liquidations, and bad debt, not Bitcoin as a native systemwide trigger; if collateral values fall below liquidation thresholds, positions can be liquidated and shortfalls can become bad debt. What can be said with confidence is that Suilend is exposed to market volatility stress through its lending markets: large liquidations can fail to fully cover loans, creating bad debt, and in uninsured/isolated pools the loss can be socialized among depositors.

The protocol also warns that when an asset is fully utilized, withdrawals and borrows can fail, which can amplify stress during fast market moves. However, I cannot verify from the provided sources that Suilend has material direct Bitcoin-collateral exposure, nor can I verify the share of BTC-related lending, borrows, or TVL on Sui as of today. Therefore, a BTC crash below $10,000 should be treated as a general crypto risk shock that could pressure Suilend only insofar as BTC-linked assets, correlated collateral, or broader market liquidity tighten.

The direct protocol impact is Not verifiable as of 2026-09-03. A related documented precedent on Suilend is that abrupt price shocks in a listed asset can produce real losses and depositor haircuts: reporting on the IKA market described a $379,000 loss and about a 6% balance reduction for affected depositors after a sharp price surge caused abnormal liquidations. That shows the mechanism by which an extreme market move can transmit losses, but it is not evidence that BTC below $10,000 would cause the same outcome on Suilend.

Bottom line: Bitcoin below $10,000 is a plausible macro stress scenario, but its direct effect on Suilend is not verifiable from the available evidence. The key risk channels are collateral liquidations, bad debt, and possible withdrawal stress in affected pools.

Evidence (4)

stress scenario - largest collateral depegs 20%,

one source

Under a 20% depeg of Suilend’s largest collateral asset, the protocol’s main risk is a rapid rise in liquidations that overwhelms available liquidators and on-chain liquidity, creating bad debt if collateral sales do not fully cover loans. Suilend itself describes that, in large-scale liquidations or market turmoil, liquidated assets may be insufficient to repay loans and the shortfall is treated as bad debt. The exact impact is not verifiable as of 2026-09-03 because the current collateral composition, largest collateral concentration, and chain-specific exposure data were not available in the provided sources and on-chain verification is unavailable in this run.

The closest public risk assessments say Suilend relies heavily on SUI and especially sSUI as collateral, and that a peg event in sSUI could trigger correlated liquidations across the lending system. What can be said with confidence is that Suilend’s liquidation process repays only 20% of a loan at a time, with a 5% liquidation bounty/penalty mechanism, which helps in normal conditions but may be insufficient in a fast, shallow-liquidity shock. Hindenrank specifically flags that a sharp SUI crash could overwhelm thin on-chain liquidity and that liquidators may stop bidding when unprofitable, allowing bad debt to accumulate.

So, in this stress scenario, the likely outcome is:

  • Higher liquidation volume across affected markets
  • Potential bad debt if collateral cannot be sold fast enough at fair prices
  • Depositor impairment or withdrawal pressure if losses exceed available buffers For a precise loss estimate, the missing inputs are the size of the largest collateral bucket, its loan concentration, and the liquidation depth available on Sui. Without those, a numeric worst-case loss is Not verifiable as of 2026-09-03.
Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Suilend on Sui, the top counterparty is a large borrower against pooled lenders’ deposits. If that borrower becomes insolvent, the loss is transmitted via the protocol’s lending and liquidation logic. ### 1. Expected loss path

  • Trigger: Borrower position falls below required collateralization and cannot be fully liquidated (e.g., collateral becomes illiquid or gaps down in price).
  • Mechanics: The protocol attempts liquidation via on-chain markets; if collateral sale proceeds + borrower collateral are insufficient to cover the debt, the pool is left with a bad debt shortfall.
  • Result: The lending pool’s assets < user deposits; a portion of depositor claims is effectively under‑backed by on-chain assets. Because Dune is unavailable and core contracts/parameters (e.g., insurance fund, reserve factor, backstop module) cannot be reliably confirmed from independent technical docs or audits, the precise accounting path is Not verifiable as of 2026‑09‑03. ### 2. Who absorbs the loss In typical pool‑based lending designs (Aave/Compound‑style), the loss is borne by all lenders in the affected pool pro‑rata, and possibly by:
  • Protocol reserve/treasury, if a reserve fund is implemented and funded.
  • Backstop/insurance mechanisms, if such exist and are active. For Suilend specifically, the actual existence, size, and priority of any reserve or insurance fund is Not verifiable as of 2026‑09‑03; treat depositor pools as the primary loss absorbers. ### 3. Compensation
  • If there is no external insurance/coverage, lenders suffer an economic loss: their claim on the pool remains nominally unchanged, but pool assets are lower, so effective recoverable value drops.
  • If there is protocol or third‑party coverage, it could:
  • Inject assets into the pool to fill the shortfall.
  • Distribute compensation directly to affected depositors. Presence and structure of any such coverage for Suilend are Not verifiable as of 2026‑09‑03. ### 4. Impact path through smart contracts
  • Risk engine / oracle: Under‑collateralization detected via price feeds; if oracles fail or are manipulated, insolvent positions may not be timely liquidated.
  • Lending pool contract: Records the shortfall and adjusts pool accounting (income, reserves, utilization). Lenders’ tokenized claims (e.g., interest‑bearing tokens) become backed by fewer underlying assets.
  • Liquidation contracts / routers: Execute collateral sales; failed or partial liquidations leave residual bad debt.
  • Governance / admin: May upgrade parameters, inject funds, or pause markets in response. Net effect: in a severe insolvency of the top borrower with inadequate liquidation, lenders in the affected Suilend market are the first line of loss, with any protocol insurance/backstop only reducing that loss if it actually exists and is funded (currently Not verifiable as of 2026‑09‑03).
Evidence (2)

stress scenario - committed fraud by the DAO or owners

one source

For Suilend, I found no verified evidence in the provided sources that the DAO or the owners committed fraud. The available materials only show that Suilend acknowledges generic smart-contract and governance risks, and that it offers a bug bounty covering theft, freezing, or governance-fund loss scenarios; those are *risk disclosures*, not allegations or findings of fraud. Because the question asks about a stress scenario—fraud by the DAO or owners—the correct evidence standard here is whether there is a confirmed incident, enforcement action, court finding, audit finding, or credible investigative report tying Suilend’s DAO/owners to fraudulent conduct.

I did not find such confirmation in the supplied results, so this is Not verifiable as of 2026-09-03. The strongest related source is Suilend’s own documentation, which says its contracts can be exploited to steal or freeze funds and that the bug bounty covers loss of user funds, governance funds, and unclaimed yield. However, that establishes only operational and security risk, not fraud by the DAO or owners.

If you want, I can next assess adjacent stress cases for Suilend such as admin-key abuse, governance capture, or smart-contract exploit, each separated by chain and with an explicit evidence threshold.

Evidence (4)

stress scenario - primary yield source negative 30d,

unverified

For a stress scenario on Suilend, the most relevant *primary yield source* is borrowing interest paid by borrowers into the shared pool; Suilend states deposit yield comes directly from onchain borrowing activity, minus a protocol spread. If borrowing activity weakens sharply over 30 days, the deposit APY can compress materially and may approach near-zero or negative net carry after fees and incentives, but an exact negative 30d primary-yield outcome is not verifiable as of 2026-09-03 from the available web sources. Suilend also says some strategies use multiple yield components rather than just borrow interest, including staking rewards and token incentives; that means a negative shock to one source does not automatically imply the entire position’s yield is negative.

The protocol’s own risk docs acknowledge that large-scale liquidations or market turmoil can create bad debts and stress the pool, which is the main mechanism that would pressure yields in a downturn. Because Dune/on-chain verification is unavailable in this run, I cannot confirm 30-day realized yield, protocol revenue, or chain-level exposure. The on-chain metric is therefore Not verifiable as of 2026-09-03.

Evidence (3)

Governance & Legal

governance

one source

As of September 13, 2026, Suilend appears company-controlled rather than governed by an active DAO. A June 26, 2026 report states that Bluewater Labs acquired Suilend and would take over development and operation; Zabi became CEO. SEC-filed transaction documents corroborate the Suilend asset acquisition by Bluewater, a British Virgin Islands company, financed through BlueFin Labs Inc. Governance status: The SEND DAO is not evidenced as operational.

Suilend’s own documentation describes the DAO as “upcoming” and says its wallets will be governed by SEND holders only “once governance is enabled.” Therefore, DAO control is currently symbolic/deferred, not effective control of parameters or upgrades. No functioning proposal/voting process was verifiable. Control scope: Bluewater/management appears to control development and frontend direction. Contract-admin authority, UpgradeCap custody, treasury/fund custody, emergency powers, and whether any administrator or multisig can move user funds are Not verifiable as of September 13, 2026 because Dune/on-chain verification was unavailable.

Sui documentation confirms that UpgradeCap ownership authorizes package upgrades, but Suilend-specific custody was not verified. Concentration / signers: SEND voting concentration, top holders, multisig signers, threshold, independence, and timelock delay are Not verifiable as of September 13, 2026. The public announcement mentions institutional multisig custody, timelocked upgrades, audit-partner co-signers, and a guardian pause, but implementation and parameters were not independently verified; treat this as an unverified marketing/operational claim. Company details: Bluewater Labs Inc.: BVI; registration number, directors, and applicable Suilend Terms of Service entity/jurisdiction: Not verifiable as of September 13, 2026. BlueFin Labs Inc. is identified separately as Panama-incorporated; Sui Group Holdings Limited is the Minnesota lender/financier, not established as Suilend’s operator.

Dao governance
No
Evidence (6)

legal & regulatory

two sources

Suilend is a lending protocol on Sui originally incubated by the team behind Solend (Solana), but with its own branding and deployment on the Sui network. As of the latest available information, it appears to operate as a DeFi protocol without a publicly detailed legal entity structure on its website or mainstream registries. Not verifiable as of 2026-09-03. Entity & jurisdiction

  • The Suilend website and public documentation do not clearly state a specific operating company name, registration number, or governing jurisdiction.
  • Some ecosystem references link Suilend to the wider Solend/Suilend team, historically associated with entities in common crypto jurisdictions (e.g., BVI/Singapore for Solend), but a precise, current legal entity for Suilend on Sui is not explicitly disclosed in primary sources. Not verifiable as of 2026-09-03. Terms of Service / user restrictions
  • The main site provides product UI and docs but no easily accessible, detailed ToS or user agreement page specifying jurisdiction, governing law, or restricted countries.
  • There is no clearly visible geo-blocking or explicit exclusion list (e.g., U.S. persons) at the UI level from the public landing and app pages.
  • Because no ToS text can be reliably located, specific contractual clauses (disclaimers, arbitration, risk wording) are Not verifiable as of 2026-09-03. KYC / AML
  • The protocol is accessible via standard non-custodial wallets on Sui; there is no evidence of mandatory KYC onboarding or identity verification for normal lending/borrowing interactions.
  • No dedicated AML/KYC policy page or registration as a VASP/crypto service provider is visible in public materials. Regulatory classification & enforcement
  • There are no public regulator enforcement actions (SEC, CFTC, MAS, FCA, etc.) specifically naming Suilend or a clearly tied Suilend entity.
  • No listings appear in major sanctions or watchlist databases (OFAC SDN, EU sanctions) for "Suilend" as an entity or protocol.
  • Therefore, active_enforcement: false and sanctioned: false as of 2026-09-03. Warnings, court cases, and legal risk posture
  • No official consumer or investor warnings from regulators specifically mentioning Suilend were found.
  • No court cases or litigation records tied clearly to Suilend are visible in public search.
  • Practically, users face typical DeFi legal risks: uncertain regulatory classification of protocol tokens and lending activity, limited recourse, and potential retroactive scrutiny of unregulated lending markets, especially if the team is later deemed to be offering financial services without licenses. Data protection
  • As a non-custodial protocol with wallet-based access, it likely holds minimal personal data directly, but without a published privacy policy this is Not verifiable as of 2026-09-03.
Sanctioned
No
Evidence (4)

Stability

stability

one source

Suilend does not appear to issue its own stablecoin; the protocol docs and independent coverage instead describe Suilend as supporting third-party stable assets such as USDC and USDT, while SEND is the protocol token and is not a stablecoin. A stablecoin depeg for the assets used on Suilend is not verifiable from the available sources, so the depeg history cannot be confirmed here as of 2026-09-05.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDT
  • walUSDC
Evidence (4)

Risks & Strengths

risks

one source

Suilend’s principal risks are lending-market solvency, oracle accuracy, smart-contract failure, liquidity stress, and dependence on liquid-staking assets. Dune MCP was unavailable for this review; therefore, current on-chain exposure, reserve composition, utilization, and loss-absorption capacity are Not verifiable as of September 5, 2026. The assessments below rely on documented controls and independent cross-checks, not protocol TVL marketing.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract exploitA logic, access-control, or integration flaw could drain or permanently freeze deposits and collateral; Move safety does not eliminate application-level bugs.HighMediumZellic and OtterSec audits, a stated bounty of up to $250,000, isolated markets, and staged risk controls.Medium
Oracle failureIncorrect, stale, or manipulated Pyth or Switchboard prices could trigger wrongful liquidations or leave undercollateralized loans insufficiently marked.HighMediumTwo named oracle providers, asset-specific collateral parameters, liquidation thresholds, and isolated markets for weaker assets.Medium
Bad debt cascadeRapid price gaps or liquidation congestion can make collateral proceeds insufficient, creating losses for insurers, pool depositors, or isolated-market participants.HighMediumOvercollateralization, liquidation incentives, deposit/borrow limits, isolated pools, insurance-fund top-ups, and loss socialization.Medium-High
Liquidity lock-upAt 100% utilization, withdrawals and new borrows can fail; stressed markets may also make liquidations or exits economically unavailable.HighMediumUtilization-based rates, liquidity management, pool limits, and market segmentation; actual current utilization is Not verifiable as of September 5, 2026.Medium
LST depeg dependencysSUI or another liquid-staking asset could trade below underlying SUI or become difficult to redeem, impairing collateral values and liquidation recoveries.MediumMediumInstant-unstaking design, LST-specific controls, conservative collateral parameters, and isolated-market treatment for higher-risk assets.Medium
Evidence (4)

strengths

two sources

Suilend’s top strengths are: market leadership on Sui, broad product breadth, risk controls, Sui-native performance advantages, and team/audit credibility. It is described as the largest lending protocol on Sui and a leading DeFi suite rather than a single-purpose money market.

  • Largest lending presence on Sui: multiple sources describe Suilend as the largest or dominant lending protocol on Sui, which is a strong indicator of network position and user adoption.
  • Broad DeFi suite: beyond lending and borrowing, Suilend also offers leverage, liquid staking, swap, bridge, and points features, giving it a more complete product stack than a narrow lender.
  • Risk management design: sources highlight multi-asset collateral support, dynamic interest rates, isolated/risk-separated lending pools, and oracle-fed liquidations, all of which strengthen capital efficiency while limiting contagion risk.
  • Sui-native execution advantage: Suilend is built on Sui, whose parallel execution and fast finality are repeatedly cited as structural advantages for low-latency DeFi applications.
  • Credibility and security posture: third-party coverage reports audits by Zellic and Ottersec and a $1 million bug bounty, while also noting the protocol was launched by the team behind Solend, which adds operating experience. A useful caveat: several sources are secondary media or aggregator pieces, so the strength claims are directionally consistent but not all are independently verified from primary on-chain data in this run.
Evidence (10)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 13 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-28.