APYBoard
Tiếng Việt
Rate alerts
Risk layer 2 · Platform

Risk profiles of DeFi protocols

You keep your own wallet; the money sits in smart contracts. Rated on protocol age, audits, bug bounty, TVL and loss history. TVL and new incidents update automatically every day from DefiLlama. Sorted by tier, A first.

Profile of each protocol

Aave v3

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

The largest lending protocol in DeFi, audited by multiple firms. Two incidents in 2026 (CAPO oracle, bad debt from Kelp's rsETH) were both covered by the DAO and the DeFi United alliance, and markets returned to normal.

  • ✓Operating since 2022-03 (4 years)
  • ✓Audited by 8 firms: OpenZeppelin, Trail of Bits, PeckShield, Certora, ABDK, Sigma Prime, MixBytes, Cantina
  • ✓Bug bounty programme (Immunefi, up to $1M)
  • ✓Large TVL: $18.3B
  • ✓Users were fully compensated for every known incident
  • iRisk of the asset itself: Pooled lending: depositors bear bad-debt risk from every collateral asset in the same market and from oracle misconfiguration, and may temporarily be unable to withdraw at 100% utilisation.
  • i~USD 71 million recovered from the Kelp attacker is frozen due to a legal dispute in the US; Aave markets are operating normally.
Facts and sources
Operating since
2022-03
Audits
OpenZeppelin, Trail of Bits, PeckShield, Certora, ABDK, Sigma Prime, MixBytes, Cantina[github.com]
Bug bounty
Immunefi · up to $1M[immunefi.com]
TVL
$18.3B (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-04 · Kelp DAO rsETH bridge exploit: the attacker used unbacked rsETH to borrow ~82,650 WETH · ~$195M · users fully compensatedAave contracts were not exploited. WETH withdrawals were locked for a period; the DeFi United alliance (Aave DAO contributed 25,000 ETH) restored the collateral, and markets were normal from ~1/6/2026.[governance.aave.com]
  • 2026-03 · A CAPO oracle misconfiguration caused 34 wstETH positions to be wrongly liquidated · ~$862,000 · users fully compensatedActual loss ~345 ETH in liquidation penalties; Aave recovered part and the DAO covered the rest, with no bad debt.[coindesk.com]
Risk of the asset
Pooled lending: depositors bear bad-debt risk from every collateral asset in the same market and from oracle misconfiguration, and may temporarily be unable to withdraw at 100% utilisation.
Regional notes
  • 2026-06 · ~USD 71 million recovered from the Kelp attacker is frozen due to a legal dispute in the US; Aave markets are operating normally.[cryptotimes.io]

Compound v3

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

Each Compound III market lends only one base asset. It was affected by the collapses of deUSD (11/2025) and rsETH (4/2026); bad positions were liquidated and no depositor losses have been recorded.

  • ✓Operating since 2022-08 (4 years)
  • ✓Audited by 2 firms: OpenZeppelin, ChainSecurity
  • ✓Bug bounty programme (Immunefi, up to $1M)
  • ✓Large TVL: $1.5B
  • ✓Users were fully compensated for every known incident
  • iRisk of the asset itself: Depositors bear bad-debt risk from the market's collateral (e.g. deUSD, rsETH) and cannot withdraw while a market is paused.
Facts and sources
Operating since
2022-08
Audits
OpenZeppelin, ChainSecurity[docs.compound.finance]
Bug bounty
Immunefi · up to $1M[immunefi.com]
TVL
$1.5B (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-04 · Kelp rsETH exploit: ~USD 39 million of WETH/wstETH borrowed against unbacked rsETH · ~$39M · users fully compensatedPositions were fully liquidated by mid-5/2026 with liquidity from DeFi United; markets resumed.[messari.io]
  • 2025-11 · Collapse of Elixir's deUSD: the oracle priced deUSD above market, and the USDC/USDS/USDT markets on Ethereum were paused · users fully compensatedThe shortfall in the USDT market was proposed to be covered from reserves; no depositor losses recorded.[comp.xyz]
Risk of the asset
Depositors bear bad-debt risk from the market's collateral (e.g. deUSD, rsETH) and cannot withdraw while a market is paused.

ether.fi

Last reviewed 27/09/2026

A· Lower risk · meets 5/5 criteria

A major liquid restaking protocol (eETH/weETH) since 3/2023, audited by multiple firms, with upgrades subject to a 10-day timelock. There have been no incidents involving eETH/weETH; the 9/2026 exploit affected only an old ether.fi Liquid contract, with losses of approximately USD 43 thousand.

  • ✓Operating since 2023-03 (3 years)
  • ✓Audited by 10 firms: CertiK, Omniscia, Nethermind, Solidified, Hats Finance, Zellic, Decurity, Halborn, Paladin, Certora
  • ✓Bug bounty programme (Immunefi, up to $500k)
  • ✓Large TVL: $5.2B
  • ✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
  • iRisk of the asset itself: eETH/weETH are liquid restaking tokens: there are risks of validator and restaking (EigenLayer) slashing, discounts relative to ETH during market stress, waiting for the withdrawal queue, and, for weETH on L2, dependence on the LayerZero bridge.
  • iContract upgrades must pass through a 10-day timelock (getMinDelay = 864,000 seconds, read on-chain on 27/9/2026).
  • iFollowing Kelp’s rsETH exploit (which did not affect ether.fi): the weETH bridge verification requirement was raised to 4/4 DVNs, weETH bridging on 8 smaller chains was halted from late 6/2026, and EtherFi Foundation contributed 5,000 ETH to DeFi United.
Facts and sources
Operating since
2023-03
Audits
CertiK, Omniscia, Nethermind, Solidified, Hats Finance, Zellic, Decurity, Halborn, Paladin, Certora[github.com]
Bug bounty
Immunefi · up to $500,000[immunefi.com]
TVL
$5.2B (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-09 · The old AtomicQueue contract (built by Veda and part of ether.fi Liquid) was exploited through a leftover approval: 15.45 ETH was lost from 11 wallets. · ~$43,260 · users bore losses / compensation not verified · only an isolated market / product was affectedeETH, weETH, and LiquidityPool were not affected. The CEO committed to fully compensate losses, but there is no post-mortem confirming that compensation has been completed.[cryptotimes.io]
Risk of the asset
eETH/weETH are liquid restaking tokens: there are risks of validator and restaking (EigenLayer) slashing, discounts relative to ETH during market stress, waiting for the withdrawal queue, and, for weETH on L2, dependence on the LayerZero bridge.
Regional notes
  • Contract upgrades must pass through a 10-day timelock (getMinDelay = 864,000 seconds, read on-chain on 27/9/2026).[etherscan.io]
  • 2026-04 · Following Kelp’s rsETH exploit (which did not affect ether.fi): the weETH bridge verification requirement was raised to 4/4 DVNs, weETH bridging on 8 smaller chains was halted from late 6/2026, and EtherFi Foundation contributed 5,000 ETH to DeFi United.[blockonomi.com]

Jito

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

JitoSOL liquid staking token on Solana, live since 11/2022, no incidents recorded.

  • ✓Operating since 2022-11 (3 years)
  • ✓Audited by 3 firms: Neodyme, OtterSec, Halborn
  • ✓Bug bounty programme (Immunefi, up to $250k)
  • ✓Large TVL: $1.3B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: JitoSOL is a liquid staking token: risk of validator penalties and a discount to SOL when market liquidity is thin.
Facts and sources
Operating since
2022-11
Audits
Neodyme, OtterSec, Halborn[jito.network]
Bug bounty
Immunefi · up to $250,000[immunefi.com]
TVL
$1.3B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
JitoSOL is a liquid staking token: risk of validator penalties and a discount to SOL when market liquidity is thin.

Lido

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

The largest ETH staking protocol (stETH), live since 12/2020, audited by multiple firms. Only a few validator slashing events with very small losses recorded.

  • ✓Operating since 2020-12 (5 years)
  • ✓Audited by 9 firms: MixBytes, Certora, Sigma Prime, Quantstamp, ChainSecurity, Statemind, Ackee Blockchain, Consensys Diligence, OpenZeppelin
  • ✓Bug bounty programme (Immunefi, up to $2M)
  • ✓Large TVL: $26.6B
  • ✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
  • iRisk of the asset itself: stETH is a liquid staking token: risk of validator penalties, a discount to ETH under market stress (up to ~8% in 6/2022), and withdrawal wait times.
Facts and sources
Operating since
2020-12
Audits
MixBytes, Certora, Sigma Prime, Quantstamp, ChainSecurity, Statemind, Ackee Blockchain, Consensys Diligence, OpenZeppelin[docs.lido.fi]
Bug bounty
Immunefi · up to $2M[immunefi.com]
TVL
$26.6B (updated 2026-09-27, DefiLlama)
Incidents
  • 2023-10 · Validators of Launchnodes (and Chorus One earlier) were slashed · ~$50,000 · users bore losses / compensation not verified~20 ETH in total, very small relative to the protocol's size.[blog.lido.fi]
Risk of the asset
stETH is a liquid staking token: risk of validator penalties, a discount to ETH under market stress (up to ~8% in 6/2022), and withdrawal wait times.

Rocket Pool

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

Decentralised ETH staking (rETH) since 11/2021; node operators must post a bond. No protocol incidents.

  • ✓Operating since 2021-11 (4 years)
  • ✓Audited by 3 firms: Sigma Prime, Consensys Diligence, Trail of Bits
  • ✓Bug bounty programme (Immunefi, up to $150k)
  • ✓Large TVL: $1.4B
  • ✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
  • iRisk of the asset itself: rETH is a liquid staking token: risk of node operator penalties (reduced by bonds) and a discount to ETH; the Saturn upgrade (2/2026) added new code.
Facts and sources
Operating since
2021-11
Audits
Sigma Prime, Consensys Diligence, Trail of Bits[rocketpool.community]
Bug bounty
Immunefi · up to $150,000[immunefi.com]
TVL
$1.4B (updated 2026-09-27, DefiLlama)
Incidents
  • 2023-03 · A personal wallet holding a large amount of RPL was phished (~USD 3.8 million) · ~$4M · users bore losses / compensation not verified · only an isolated market / product was affectedNot a protocol bug: an individual signed a malicious transaction.[crypto.news]
Risk of the asset
rETH is a liquid staking token: risk of node operator penalties (reduced by bonds) and a discount to ETH; the Saturn upgrade (2/2026) added new code.

Sky

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

Sky (formerly MakerDAO) has issued DAI/USDS since 2017–2019. The only major incident was "Black Thursday" in 3/2020; DAI holders were not affected.

  • ✓Operating since 2019-11 (6 years)
  • ✓Audited by 4 firms: ChainSecurity, Cantina, Trail of Bits, PeckShield
  • ✓Bug bounty programme (Immunefi, up to $10M)
  • ✓Large TVL: $5.9B
  • ✓No uncovered losses in the last 5 years
  • iRisk of the asset itself: The solvency of USDS/DAI depends on collateral quality (crypto, real-world assets, USDC) and governance decisions; USDS has a contract-level freeze function.
Facts and sources
Operating since
2019-11
Audits
ChainSecurity, Cantina, Trail of Bits, PeckShield[developers.skyeco.com]
Bug bounty
Immunefi · up to $10M[immunefi.com]
TVL
$5.9B (updated 2026-09-27, DefiLlama)
Incidents
  • 2020-03 · "Black Thursday": ETH crashed and many collateral auctions were won at 0 DAI · ~$8M · users bore losses / compensation not verifiedThe deficit was covered by MKR debt auctions, so DAI holders were not affected; vault owners lost their excess collateral without compensation.[medium.com]
Risk of the asset
The solvency of USDS/DAI depends on collateral quality (crypto, real-world assets, USDC) and governance decisions; USDS has a contract-level freeze function.

Spark Savings

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

sUSDS/sDAI savings deposits via Spark, earning the Sky Savings Rate set by Sky governance. No incidents recorded.

  • ✓Operating since 2023-05 (3 years)
  • ✓Audited by 2 firms: ChainSecurity, Cantina
  • ✓Bug bounty programme (Immunefi, up to $5M)
  • ✓Large TVL: $1.3B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: Principal risk is the solvency and depeg of USDS/DAI; Spark Vaults V2 adds risk from allocating idle liquidity.
Facts and sources
Operating since
2023-05
Audits
ChainSecurity, Cantina[docs.spark.finance]
Bug bounty
Immunefi · up to $5M[immunefi.com]
TVL
$1.3B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
Principal risk is the solvency and depeg of USDS/DAI; Spark Vaults V2 adds risk from allocating idle liquidity.

SparkLend

Last reviewed 24/09/2026

A· Lower risk · meets 5/5 criteria

A fork of Aave V3 with DAI/USDS liquidity from Sky, live since 5/2023. No incidents recorded; it removed rsETH before the Kelp incident.

  • ✓Operating since 2023-05 (3 years)
  • ✓Audited by 3 firms: ChainSecurity, Cantina, Aave V3 auditors
  • ✓Bug bounty programme (Immunefi, up to $5M)
  • ✓Large TVL: $5.6B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: Pooled lending: bad-debt risk from collateral/oracles and delayed withdrawals at high utilisation.
Facts and sources
Operating since
2023-05
Audits
ChainSecurity, Cantina, Aave V3 auditors[docs.spark.finance]
Bug bounty
Immunefi · up to $5M[immunefi.com]
TVL
$5.6B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
Pooled lending: bad-debt risk from collateral/oracles and delayed withdrawals at high utilisation.

Ethena

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

USDe is a synthetic dollar (not a cash-backed stablecoin); sUSDe yield comes from perpetual futures funding. No contract incidents; live since 2/2024.

  • !Operating since 2024-02, under 3 years
  • ✓Audited by 6 firms: Zellic, Spearbit/Cantina, Quantstamp, Pashov, Code4rena, Cyfrin
  • ✓Bug bounty programme (Immunefi, up to $3M)
  • ✓Large TVL: $4.9B
  • ✓Users were fully compensated for every known incident
  • iRisk of the asset itself: USDe is backed by crypto plus short derivatives positions: counterparty risk from exchanges/custodians, prolonged negative funding, and depegs on secondary markets; sUSDe yield varies with funding.
Facts and sources
Operating since
2024-02
Audits
Zellic, Spearbit/Cantina, Quantstamp, Pashov, Code4rena, Cyfrin[docs.ethena.fi]
Bug bounty
Immunefi · up to $3M[immunefi.com]
TVL
$4.9B (updated 2026-09-27, DefiLlama)
Incidents
  • 2025-10 · USDe fell to ~USD 0.65 on the Binance order book during the 10/10 liquidations · users fully compensated · only an isolated market / product was affectedOnly occurred on Binance; on-chain USDe held its peg within ~0.3% and mint/redeem kept working. Binance compensated its users.[cryptobriefing.com]
Risk of the asset
USDe is backed by crypto plus short derivatives positions: counterparty risk from exchanges/custodians, prolonged negative funding, and depegs on secondary markets; sUSDe yield varies with funding.

Jupiter Lend

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

A Solana lending protocol built on the Fluid architecture, launched 8/2025 (over 1 year). No incidents recorded.

  • !Operating since 2025-08, under 3 years
  • ✓Audited by 6 firms: Zenith, Offside Labs, MixBytes, OtterSec, Certora, Code4rena
  • ✓Bug bounty programme (Private programme (OOOSec))
  • ✓Large TVL: $1.2B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: High loan-to-value (up to 95%) and shared liquidity; Lend v2 reuses deposits as DEX liquidity, adding depeg risk.
Facts and sources
Operating since
2025-08
Audits
Zenith, Offside Labs, MixBytes, OtterSec, Certora, Code4rena[developers.jup.ag]
Bug bounty
Private programme (OOOSec)[security.raccoons.dev]
TVL
$1.2B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
High loan-to-value (up to 95%) and shared liquidity; Lend v2 reuses deposits as DEX liquidity, adding depeg risk.

JustLend

Last reviewed 27/09/2026

B· Medium risk · meets 4/5 criteria

The largest lending protocol on TRON (a Compound V2 fork), operating since 12/2020, with no incidents recorded. The lending segment has only 1 public audit (CertiK, 2022), and governance depends on the JST token and is closely tied to the Justin Sun ecosystem.

  • ✓Operating since 2020-12 (5 years)
  • !Only 1 audit firm: CertiK
  • ✓Bug bounty programme (Immunefi, up to $50k)
  • ✓Large TVL: $3.9B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: Pool-based lending: depositors bear bad-debt risk when collateral falls sharply in value, the oracle (Chainlink) misprices assets, and withdrawals are delayed when utilization is high. Many assets in the pools (USDD, JST, sTRX) belong to the same TRON ecosystem.
  • iProtocol changes are voted on by JST holders (GovernorBravo) and executed after a 48-hour timelock; 200 million JST is required to submit a proposal, with a quorum of 600 million votes. The CertiK audit in 4/2022 identified multiple centralization risks.
  • iSlowMist audited only the sTRX staking product (counted separately on DefiLlama), not the lending markets.
  • iMost of USDD’s collateral (approximately 61%, funds from HTX) is deposited into JustLend and Aave: stablecoin liquidity in JustLend is concentrated among parties related to Justin Sun.
Facts and sources
Operating since
2020-12
Bug bounty
Immunefi · up to $50,000[immunefi.com]
TVL
$3.9B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
Pool-based lending: depositors bear bad-debt risk when collateral falls sharply in value, the oracle (Chainlink) misprices assets, and withdrawals are delayed when utilization is high. Many assets in the pools (USDD, JST, sTRX) belong to the same TRON ecosystem.
Regional notes
  • Protocol changes are voted on by JST holders (GovernorBravo) and executed after a 48-hour timelock; 200 million JST is required to submit a proposal, with a quorum of 600 million votes. The CertiK audit in 4/2022 identified multiple centralization risks.[docs.justlend.org]
  • 2023-04 · SlowMist audited only the sTRX staking product (counted separately on DefiLlama), not the lending markets.[justlend.org]
  • 2025-06 · Most of USDD’s collateral (approximately 61%, funds from HTX) is deposited into JustLend and Aave: stablecoin liquidity in JustLend is concentrated among parties related to Justin Sun.[protos.com]

Kamino

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

A large lending protocol on Solana, live since 11/2023, with no incidents or bad debt recorded.

  • !Operating since 2023-11, under 3 years
  • ✓Audited by 3 firms: OtterSec, Sec3, RX Security
  • ✓Bug bounty programme (Immunefi, up to $1.5M)
  • ✓Large TVL: $1.5B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: Pooled lending: collateral/oracle risk, and delayed withdrawals at 100% utilisation (the USDC market hit 100% in 4/2026).
Facts and sources
Operating since
2023-11
Audits
OtterSec, Sec3, RX Security[kamino.com]
Bug bounty
Immunefi · up to $2M[immunefi.com]
TVL
$1.5B (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
Pooled lending: collateral/oracle risk, and delayed withdrawals at 100% utilisation (the USDC market hit 100% in 4/2026).

Maple

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

Unsecured/secured lending to institutions (syrupUSDC/USDT). In 2022 borrower Orthogonal Trading defaulted on USD 36 million in an old pool, and lenders recovered only part.

  • ✓Operating since 2021-05 (5 years)
  • ✓Audited by 7 firms: Trail of Bits, Spearbit, Three Sigma, 0xMacro, Sherlock, Dedaub, Sigma Prime
  • ✓Bug bounty programme (Immunefi, up to $500k)
  • ✓Large TVL: $3B
  • !Uncovered losses in the last 5 years: Orthogonal Trading defaulted on USD 36 million after the FTX collapse (2022-12)
  • iRisk of the asset itself: syrupUSDC/USDT carry off-chain credit risk from lending to institutions: loans are overcollateralised but there is no first-loss protection layer; withdrawals go through a queue.
Facts and sources
Operating since
2021-05
Audits
Trail of Bits, Spearbit, Three Sigma, 0xMacro, Sherlock, Dedaub, Sigma Prime[docs.maple.finance]
Bug bounty
Immunefi · up to $500,000[immunefi.com]
TVL
$3.0B (updated 2026-09-27, DefiLlama)
Incidents
  • 2022-12 · Orthogonal Trading defaulted on USD 36 million after the FTX collapse · ~$36M · users bore losses / compensation not verifiedMaple V1 unsecured pool (before syrupUSDC); only partially recovered.[theblock.co]
Risk of the asset
syrupUSDC/USDT carry off-chain credit risk from lending to institutions: loans are overcollateralised but there is no first-loss protection layer; withdrawals go through a queue.

Marinade

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

Liquid SOL staking (mSOL) since 8/2021, no contract incidents. TVL is now about USD 260 million.

  • ✓Operating since 2021-08 (5 years)
  • ✓Audited by 4 firms: Neodyme, Ackee Blockchain, Kudelski Security, Sec3
  • ✓Bug bounty programme (Immunefi, up to $250k)
  • !TVL $287.1M, below $1B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: mSOL is a liquid staking token: validator risk, depegs when liquidity is thin, and dependence on the stake auction mechanism (SAM) for yield.
  • iA third party estimates the stake auction mechanism (SAM) cost stakers ≥37,000 SOL in yield over 126 epochs (forgone yield, not loss of principal); Marinade regards it as a known inefficiency.
Facts and sources
Operating since
2021-08
Audits
Neodyme, Ackee Blockchain, Kudelski Security, Sec3[docs.marinade.finance]
Bug bounty
Immunefi · up to $250,000[immunefi.com]
TVL
$287M (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
mSOL is a liquid staking token: validator risk, depegs when liquidity is thin, and dependence on the stake auction mechanism (SAM) for yield.
Regional notes
  • 2025-05 · A third party estimates the stake auction mechanism (SAM) cost stakers ≥37,000 SOL in yield over 126 epochs (forgone yield, not loss of principal); Marinade regards it as a known inefficiency.[forum.marinade.finance]

Morpho

Last reviewed 24/09/2026

B· Medium risk · meets 4/5 criteria

Morpho's core contracts have not been exploited; all incidents were in isolated markets/vaults managed by curators (Stream/xUSD 11/2025, USR 3/2026, rsETH 4/2026). Actual risk depends on the vault you choose.

  • !Operating since 2024-01, under 3 years
  • ✓Audited by 5 firms: Spearbit, OpenZeppelin, Cantina, Blackthorn, Certora
  • ✓Bug bounty programme (Cantina, Immunefi, up to $2.5M)
  • ✓Large TVL: $11.1B
  • ✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
  • iRisk of the asset itself: Isolated markets: vault depositors bear the risk of the curator's market selection, oracle configuration and collateral; bad debt is socialised into the vault's share value.
  • iSome Gauntlet vaults affected by USR only open compensation claims when the vault runs out of liquidity; the Stream/xUSD case is still in litigation.
Facts and sources
Operating since
2024-01
Audits
Spearbit, OpenZeppelin, Cantina, Blackthorn, Certora[docs.morpho.org]
Bug bounty
Cantina, Immunefi · up to $3M[cantina.xyz]
TVL
$11.1B (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-04 · Kelp rsETH exploit: two isolated rsETH markets affected · ~$1M · users bore losses / compensation not verified · only an isolated market / product was affected[bitget.com]
  • 2026-03 · Resolv USR exploit: ~15 vaults with wstUSR markets affected · ~$8M · users bore losses / compensation not verified · only an isolated market / product was affectedThe Gauntlet USDC Core vault lost ~USD 6 million; Gauntlet/Resolv partially compensated (~4.38 million USDC).[bitget.com]
  • 2025-11 · Stream Finance xUSD / Elixir deUSD collapse: bad debt in some isolated vaults · ~$700,000 · users bore losses / compensation not verified · only an isolated market / product was affectedThe MEV Capital vault took ~USD 650–700 thousand in bad debt; Elixir pledged to recover ~80% for lenders.[chorus.one]
  • 2024-10 · PAXG/USDC market oracle misconfiguration · ~$230,000 · users fully compensated · only an isolated market / product was affectedCurator LeadBlock recovered most of the funds.[forum.morpho.org]
Risk of the asset
Isolated markets: vault depositors bear the risk of the curator's market selection, oracle configuration and collateral; bad debt is socialised into the vault's share value.
Regional notes
  • Some Gauntlet vaults affected by USR only open compensation claims when the vault runs out of liquidity; the Stream/xUSD case is still in litigation.[bitget.com]

Euler v2

Last reviewed 27/09/2026

B· Medium risk · meets 3/5 criteria

A modular lending vault platform, launched in 8/2024, audited by many firms and offering a bug bounty of up to USD 7.5 million. Third-party curator vaults incurred bad debt from xUSD (11/2025); Euler v1 was hacked for USD 197 million in 2023, but users were fully reimbursed.

  • !Operating since 2024-08, under 3 years
  • ✓Audited by 10 firms: Spearbit, Cantina, Certora, ChainSecurity, OpenZeppelin, Omniscia, Enigma Dark, yAudit/Electisec, Trail of Bits, Hunter Security
  • ✓Bug bounty programme (Cantina, up to $7.5M)
  • !TVL $355.2M, below $1B
  • ✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
  • iRisk of the asset itself: Vaults are permissionless: depositors bear the risk of each vault curator/governor’s collateral choices, oracle, and parameters; bad debt is allocated to vault share value. Some vaults may be upgradeable.
  • iTVL fell sharply in 2026 (approximately USD 354 million on 27/9/2026), with approximately 74% on Monad.
Facts and sources
Operating since
2024-08
Audits
Spearbit, Cantina, Certora, ChainSecurity, OpenZeppelin, Omniscia, Enigma Dark, yAudit/Electisec, Trail of Bits, Hunter Security[docs.euler.finance]
Bug bounty
Cantina · up to $8M[docs.euler.finance]
TVL
$355M (updated 2026-09-27, DefiLlama)
Incidents
  • 2025-11 · Stream Finance xUSD collapse: third-party curator vaults that accepted xUSD as collateral incurred bad debt. · users bore losses / compensation not verified · only an isolated market / product was affectedThe oracle kept the xUSD price around USD 1, preventing liquidation; Euler froze pools with tens of millions of USD in bad debt. The actual loss amount and whether compensation was provided could not be verified.[pharos.watch]
  • 2023-03 · Euler v1 (the old version, with code different from v2) was exploited through the donateToReserve function, with losses of approximately USD 197 million. · ~$197M · users fully compensatedThe attacker returned all funds before 4/2023; approximately USD 240 million was recovered due to the increase in ETH’s price, and users were fully reimbursed.[euler.finance]
Risk of the asset
Vaults are permissionless: depositors bear the risk of each vault curator/governor’s collateral choices, oracle, and parameters; bad debt is allocated to vault share value. Some vaults may be upgradeable.
Regional notes
  • 2026-09 · TVL fell sharply in 2026 (approximately USD 354 million on 27/9/2026), with approximately 74% on Monad.[defillama.com]

Fluid

Last reviewed 24/09/2026

B· Medium risk · meets 3/5 criteria

A shared liquidity layer for lending, vaults and DEX. Bad debt from the Resolv USR exploit (3/2026) was absorbed by the treasury, the team and Resolv; the reward distribution key leak (5/2026) was small and covered.

  • !Operating since 2024-02, under 3 years
  • ✓Audited by 4 firms: PeckShield, StateMind, MixBytes, Cantina
  • ✓Bug bounty programme (Immunefi, up to $500k)
  • !TVL $735.4M, below $1B
  • ✓Users were fully compensated for every known incident
  • iRisk of the asset itself: Lenders share one liquidity layer with all Fluid vaults and DEX: bad debt or a bank run in one place can affect the ability to withdraw.
Facts and sources
Operating since
2024-02
Audits
PeckShield, StateMind, MixBytes, Cantina[docs.fluid.instadapp.io]
Bug bounty
Immunefi · up to $500,000[immunefi.com]
TVL
$735M (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-05 · Key leak in the Merkle reward distribution system · ~$215,000 · users fully compensatedOnly affected the rewards contract, not lent funds; the team pledged to compensate.[cryptotimes.io]
  • 2026-03 · Resolv USR exploit: mispriced wstUSR created bad debt in Fluid vaults · ~$21M · users fully compensated~USD 19–21 million of bad debt was absorbed by Resolv, the treasury and the team; using the treasury before a vote drew criticism.[defiprime.com]
Risk of the asset
Lenders share one liquidity layer with all Fluid vaults and DEX: bad debt or a bank run in one place can affect the ability to withdraw.

Lista

Last reviewed 24/09/2026

B· Medium risk · meets 3/5 criteria

Morpho-style isolated lending markets on BNB Chain, launched 4/2025. The Resolv incident (3/2026) was repaid 1:1 with no losses.

  • !Operating since 2025-04, under 3 years
  • ✓Audited by 5 firms: BailSec, BlockSec, PeckShield, CertiK, SlowMist
  • ✓Bug bounty programme (Immunefi, up to $1M)
  • !TVL $952.6M, below $1B
  • ✓Users were fully compensated for every known incident
  • iRisk of the asset itself: Isolated markets: vault depositors bear the risk of the curator's market selection and the collateral (usually slisBNB, lisUSD).
Facts and sources
Operating since
2025-04
Audits
BailSec, BlockSec, PeckShield, CertiK, SlowMist[github.com]
Bug bounty
Immunefi · up to $1M[immunefi.com]
TVL
$953M (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-03 · Impact from the Resolv USR exploit (~USD 8.6 million in related loans) · users fully compensatedRepaid 1:1, no losses to users.[bitget.com]
  • 2022-12 · Helio (Lista's predecessor, a different CDP product): the attacker used near-worthless aBNBc to borrow ~16 million HAY · ~$16M · users fully compensated · only an isolated market / product was affectedAn older product of the parent brand, not Lista Lending; Ankr spent USD 15 million buying back HAY.[cointelegraph.com]
Risk of the asset
Isolated markets: vault depositors bear the risk of the curator's market selection and the collateral (usually slisBNB, lisUSD).

Venus

Last reviewed 24/09/2026

C· Higher risk · meets 4/5 criteria

The oldest lending protocol on BNB Chain, but it has repeatedly incurred bad debt from price manipulation of illiquid assets; it could not be confirmed that the THE incident (3/2026) has been fully covered.

  • ✓Operating since 2020-11 (5 years)
  • ✓Audited by 7 firms: CertiK, PeckShield, OpenZeppelin, Quantstamp, Fairyproof, Hacken, Code4rena
  • ✓Bug bounty programme (BNB Chain Bug Bounty, up to $100k)
  • ✓Large TVL: $1.4B
  • ✕Uncovered losses in the last 2 years: Donation attack on the THE market: supply cap exceeded and THE price manipulated (2026-03)
  • iRisk of the asset itself: Pooled lending that accepts illiquid collateral: depositors bear oracle manipulation and bad-debt risk, covered only by the Risk Fund/treasury.
  • iAfter the THE incident: the THE/CAKE markets were paused and the collateral factors of many assets (BCH, LTC, UNI, AAVE, POL, FIL, TWT, lisUSD) were set to 0.
Facts and sources
Operating since
2020-11
Audits
CertiK, PeckShield, OpenZeppelin, Quantstamp, Fairyproof, Hacken, Code4rena[docs-v4.venus.io]
Bug bounty
BNB Chain Bug Bounty · up to $100,000[community.venus.io]
TVL
$1.4B (updated 2026-09-27, DefiLlama)
Incidents
  • 2026-03 · Donation attack on the THE market: supply cap exceeded and THE price manipulated · ~$4M · users bore losses / compensation not verified~USD 2.2 million in bad debt; proposals to repay it from the treasury and Risk Fund exist but execution has not been confirmed. The vulnerability had been flagged in a Code4rena audit.[community.venus.io]
  • 2025-09 · A large user was phished (Lazarus), losing a ~USD 13.5 million position · ~$14M · users fully compensated · only an isolated market / product was affectedUser-side error, not a protocol issue; funds were recovered in under 12 hours.[cointelegraph.com]
  • 2025-03 · Donation attack (recorded by DefiLlama on the Core Pool) · ~$902,000 · users bore losses / compensation not verified[defillama.com]
  • 2022-05 · LUNA collapse: the oracle price floor allowed borrowing against near-worthless LUNA · ~$14M · users fully compensatedAccording to secondary sources, covered by protocol funds.[defisafety.com]
  • 2021-05 · XVS price manipulation caused ~USD 100 million in bad debt · ~$100M · users bore losses / compensation not verifiedThere is a plan to cover it with XVS and fee funds, but full repayment has not been confirmed.[medium.com]
Risk of the asset
Pooled lending that accepts illiquid collateral: depositors bear oracle manipulation and bad-debt risk, covered only by the Risk Fund/treasury.
Regional notes
  • 2026-03 · After the THE incident: the THE/CAKE markets were paused and the collateral factors of many assets (BCH, LTC, UNI, AAVE, POL, FIL, TWT, lisUSD) were set to 0.[community.venus.io]

Aave v4

Last reviewed 27/09/2026

C· Higher risk · meets 3/5 criteria

Aave's new version under a Hub-and-Spoke model, running on Ethereum since 30/3/2026 (Avalanche since 7/2026), audited by multiple firms, with no incidents recorded. The new code is under 1 year old, and initial limits remain low.

  • ✕Live only since 2026-03, under 1 year
  • ✓Audited by 5 firms: ChainSecurity, Trail of Bits, Certora, Sherlock, Blackthorn
  • ✓Bug bounty programme (Sherlock, up to $3.5M)
  • !TVL $637M, below $1B
  • ✓No recorded incident causing user losses in the core product
  • iRisk of the asset itself: Liquidity is shared within each Hub: depositors bear bad-debt risk from every Spoke borrowing from that Hub, although each Spoke has separate risk parameters and caps. The code is new and has not been through a stressed market cycle.
  • iLaunched with 3 Hubs (Core, Prime, Plus) and conservative supply/borrow caps; the Aave DAO votes to raise caps, add Spokes, and expand to more networks.
  • iTwo sources on the bug bounty do not match: Aave’s Immunefi page lists up to USD 1 million, while aave.com/security states “Aave Core ... Up to $5M” on Immunefi. V4 has used a separate program on Sherlock (up to USD 3.5 million) since 18/5/2026.
Facts and sources
Operating since
2026-03
Audits
ChainSecurity, Trail of Bits, Certora, Sherlock, Blackthorn[aave.com]
Bug bounty
Sherlock · up to $4M[aave.com]
TVL
$637M (updated 2026-09-27, DefiLlama)
Incidents
None recorded
Risk of the asset
Liquidity is shared within each Hub: depositors bear bad-debt risk from every Spoke borrowing from that Hub, although each Spoke has separate risk parameters and caps. The code is new and has not been through a stressed market cycle.
Regional notes
  • 2026-03 · Launched with 3 Hubs (Core, Prime, Plus) and conservative supply/borrow caps; the Aave DAO votes to raise caps, add Spokes, and expand to more networks.[aave.com]
  • 2026-05 · Two sources on the bug bounty do not match: Aave’s Immunefi page lists up to USD 1 million, while aave.com/security states “Aave Core ... Up to $5M” on Immunefi. V4 has used a separate program on Sherlock (up to USD 3.5 million) since 18/5/2026.[immunefi.com]