You keep your own wallet; the money sits in smart contracts. Rated on protocol age, audits, bug bounty, TVL and loss history. TVL and new incidents update automatically every day from DefiLlama. Sorted by tier, A first.
Profile of each protocol
Aave v3
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
The largest lending protocol in DeFi, audited by multiple firms. Two incidents in 2026 (CAPO oracle, bad debt from Kelp's rsETH) were both covered by the DAO and the DeFi United alliance, and markets returned to normal.
✓Operating since 2022-03 (4 years)
✓Audited by 8 firms: OpenZeppelin, Trail of Bits, PeckShield, Certora, ABDK, Sigma Prime, MixBytes, Cantina
✓Bug bounty programme (Immunefi, up to $1M)
✓Large TVL: $18.3B
✓Users were fully compensated for every known incident
iRisk of the asset itself: Pooled lending: depositors bear bad-debt risk from every collateral asset in the same market and from oracle misconfiguration, and may temporarily be unable to withdraw at 100% utilisation.
i~USD 71 million recovered from the Kelp attacker is frozen due to a legal dispute in the US; Aave markets are operating normally.
2026-04 · Kelp DAO rsETH bridge exploit: the attacker used unbacked rsETH to borrow ~82,650 WETH · ~$195M · users fully compensatedAave contracts were not exploited. WETH withdrawals were locked for a period; the DeFi United alliance (Aave DAO contributed 25,000 ETH) restored the collateral, and markets were normal from ~1/6/2026.[governance.aave.com]
2026-03 · A CAPO oracle misconfiguration caused 34 wstETH positions to be wrongly liquidated · ~$862,000 · users fully compensatedActual loss ~345 ETH in liquidation penalties; Aave recovered part and the DAO covered the rest, with no bad debt.[coindesk.com]
Risk of the asset
Pooled lending: depositors bear bad-debt risk from every collateral asset in the same market and from oracle misconfiguration, and may temporarily be unable to withdraw at 100% utilisation.
Regional notes
2026-06 · ~USD 71 million recovered from the Kelp attacker is frozen due to a legal dispute in the US; Aave markets are operating normally.[cryptotimes.io]
Compound v3
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
Each Compound III market lends only one base asset. It was affected by the collapses of deUSD (11/2025) and rsETH (4/2026); bad positions were liquidated and no depositor losses have been recorded.
✓Operating since 2022-08 (4 years)
✓Audited by 2 firms: OpenZeppelin, ChainSecurity
✓Bug bounty programme (Immunefi, up to $1M)
✓Large TVL: $1.5B
✓Users were fully compensated for every known incident
iRisk of the asset itself: Depositors bear bad-debt risk from the market's collateral (e.g. deUSD, rsETH) and cannot withdraw while a market is paused.
2026-04 · Kelp rsETH exploit: ~USD 39 million of WETH/wstETH borrowed against unbacked rsETH · ~$39M · users fully compensatedPositions were fully liquidated by mid-5/2026 with liquidity from DeFi United; markets resumed.[messari.io]
2025-11 · Collapse of Elixir's deUSD: the oracle priced deUSD above market, and the USDC/USDS/USDT markets on Ethereum were paused · users fully compensatedThe shortfall in the USDT market was proposed to be covered from reserves; no depositor losses recorded.[comp.xyz]
Risk of the asset
Depositors bear bad-debt risk from the market's collateral (e.g. deUSD, rsETH) and cannot withdraw while a market is paused.
ether.fi
Last reviewed 27/09/2026
A· Lower risk · meets 5/5 criteria
A major liquid restaking protocol (eETH/weETH) since 3/2023, audited by multiple firms, with upgrades subject to a 10-day timelock. There have been no incidents involving eETH/weETH; the 9/2026 exploit affected only an old ether.fi Liquid contract, with losses of approximately USD 43 thousand.
✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
iRisk of the asset itself: eETH/weETH are liquid restaking tokens: there are risks of validator and restaking (EigenLayer) slashing, discounts relative to ETH during market stress, waiting for the withdrawal queue, and, for weETH on L2, dependence on the LayerZero bridge.
iContract upgrades must pass through a 10-day timelock (getMinDelay = 864,000 seconds, read on-chain on 27/9/2026).
iFollowing Kelp’s rsETH exploit (which did not affect ether.fi): the weETH bridge verification requirement was raised to 4/4 DVNs, weETH bridging on 8 smaller chains was halted from late 6/2026, and EtherFi Foundation contributed 5,000 ETH to DeFi United.
2026-09 · The old AtomicQueue contract (built by Veda and part of ether.fi Liquid) was exploited through a leftover approval: 15.45 ETH was lost from 11 wallets. · ~$43,260 · users bore losses / compensation not verified · only an isolated market / product was affectedeETH, weETH, and LiquidityPool were not affected. The CEO committed to fully compensate losses, but there is no post-mortem confirming that compensation has been completed.[cryptotimes.io]
Risk of the asset
eETH/weETH are liquid restaking tokens: there are risks of validator and restaking (EigenLayer) slashing, discounts relative to ETH during market stress, waiting for the withdrawal queue, and, for weETH on L2, dependence on the LayerZero bridge.
Regional notes
Contract upgrades must pass through a 10-day timelock (getMinDelay = 864,000 seconds, read on-chain on 27/9/2026).[etherscan.io]
2026-04 · Following Kelp’s rsETH exploit (which did not affect ether.fi): the weETH bridge verification requirement was raised to 4/4 DVNs, weETH bridging on 8 smaller chains was halted from late 6/2026, and EtherFi Foundation contributed 5,000 ETH to DeFi United.[blockonomi.com]
Jito
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
JitoSOL liquid staking token on Solana, live since 11/2022, no incidents recorded.
✓Operating since 2022-11 (3 years)
✓Audited by 3 firms: Neodyme, OtterSec, Halborn
✓Bug bounty programme (Immunefi, up to $250k)
✓Large TVL: $1.3B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: JitoSOL is a liquid staking token: risk of validator penalties and a discount to SOL when market liquidity is thin.
JitoSOL is a liquid staking token: risk of validator penalties and a discount to SOL when market liquidity is thin.
Lido
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
The largest ETH staking protocol (stETH), live since 12/2020, audited by multiple firms. Only a few validator slashing events with very small losses recorded.
✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
iRisk of the asset itself: stETH is a liquid staking token: risk of validator penalties, a discount to ETH under market stress (up to ~8% in 6/2022), and withdrawal wait times.
2023-10 · Validators of Launchnodes (and Chorus One earlier) were slashed · ~$50,000 · users bore losses / compensation not verified~20 ETH in total, very small relative to the protocol's size.[blog.lido.fi]
Risk of the asset
stETH is a liquid staking token: risk of validator penalties, a discount to ETH under market stress (up to ~8% in 6/2022), and withdrawal wait times.
Rocket Pool
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
Decentralised ETH staking (rETH) since 11/2021; node operators must post a bond. No protocol incidents.
✓Operating since 2021-11 (4 years)
✓Audited by 3 firms: Sigma Prime, Consensys Diligence, Trail of Bits
✓Bug bounty programme (Immunefi, up to $150k)
✓Large TVL: $1.4B
✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
iRisk of the asset itself: rETH is a liquid staking token: risk of node operator penalties (reduced by bonds) and a discount to ETH; the Saturn upgrade (2/2026) added new code.
2023-03 · A personal wallet holding a large amount of RPL was phished (~USD 3.8 million) · ~$4M · users bore losses / compensation not verified · only an isolated market / product was affectedNot a protocol bug: an individual signed a malicious transaction.[crypto.news]
Risk of the asset
rETH is a liquid staking token: risk of node operator penalties (reduced by bonds) and a discount to ETH; the Saturn upgrade (2/2026) added new code.
Sky
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
Sky (formerly MakerDAO) has issued DAI/USDS since 2017–2019. The only major incident was "Black Thursday" in 3/2020; DAI holders were not affected.
✓Operating since 2019-11 (6 years)
✓Audited by 4 firms: ChainSecurity, Cantina, Trail of Bits, PeckShield
✓Bug bounty programme (Immunefi, up to $10M)
✓Large TVL: $5.9B
✓No uncovered losses in the last 5 years
iRisk of the asset itself: The solvency of USDS/DAI depends on collateral quality (crypto, real-world assets, USDC) and governance decisions; USDS has a contract-level freeze function.
2020-03 · "Black Thursday": ETH crashed and many collateral auctions were won at 0 DAI · ~$8M · users bore losses / compensation not verifiedThe deficit was covered by MKR debt auctions, so DAI holders were not affected; vault owners lost their excess collateral without compensation.[medium.com]
Risk of the asset
The solvency of USDS/DAI depends on collateral quality (crypto, real-world assets, USDC) and governance decisions; USDS has a contract-level freeze function.
Spark Savings
Last reviewed 24/09/2026
A· Lower risk · meets 5/5 criteria
sUSDS/sDAI savings deposits via Spark, earning the Sky Savings Rate set by Sky governance. No incidents recorded.
✓Operating since 2023-05 (3 years)
✓Audited by 2 firms: ChainSecurity, Cantina
✓Bug bounty programme (Immunefi, up to $5M)
✓Large TVL: $1.3B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: Principal risk is the solvency and depeg of USDS/DAI; Spark Vaults V2 adds risk from allocating idle liquidity.
Pooled lending: bad-debt risk from collateral/oracles and delayed withdrawals at high utilisation.
Ethena
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
USDe is a synthetic dollar (not a cash-backed stablecoin); sUSDe yield comes from perpetual futures funding. No contract incidents; live since 2/2024.
!Operating since 2024-02, under 3 years
✓Audited by 6 firms: Zellic, Spearbit/Cantina, Quantstamp, Pashov, Code4rena, Cyfrin
✓Bug bounty programme (Immunefi, up to $3M)
✓Large TVL: $4.9B
✓Users were fully compensated for every known incident
iRisk of the asset itself: USDe is backed by crypto plus short derivatives positions: counterparty risk from exchanges/custodians, prolonged negative funding, and depegs on secondary markets; sUSDe yield varies with funding.
2025-10 · USDe fell to ~USD 0.65 on the Binance order book during the 10/10 liquidations · users fully compensated · only an isolated market / product was affectedOnly occurred on Binance; on-chain USDe held its peg within ~0.3% and mint/redeem kept working. Binance compensated its users.[cryptobriefing.com]
Risk of the asset
USDe is backed by crypto plus short derivatives positions: counterparty risk from exchanges/custodians, prolonged negative funding, and depegs on secondary markets; sUSDe yield varies with funding.
Jupiter Lend
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
A Solana lending protocol built on the Fluid architecture, launched 8/2025 (over 1 year). No incidents recorded.
High loan-to-value (up to 95%) and shared liquidity; Lend v2 reuses deposits as DEX liquidity, adding depeg risk.
JustLend
Last reviewed 27/09/2026
B· Medium risk · meets 4/5 criteria
The largest lending protocol on TRON (a Compound V2 fork), operating since 12/2020, with no incidents recorded. The lending segment has only 1 public audit (CertiK, 2022), and governance depends on the JST token and is closely tied to the Justin Sun ecosystem.
✓Operating since 2020-12 (5 years)
!Only 1 audit firm: CertiK
✓Bug bounty programme (Immunefi, up to $50k)
✓Large TVL: $3.9B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: Pool-based lending: depositors bear bad-debt risk when collateral falls sharply in value, the oracle (Chainlink) misprices assets, and withdrawals are delayed when utilization is high. Many assets in the pools (USDD, JST, sTRX) belong to the same TRON ecosystem.
iProtocol changes are voted on by JST holders (GovernorBravo) and executed after a 48-hour timelock; 200 million JST is required to submit a proposal, with a quorum of 600 million votes. The CertiK audit in 4/2022 identified multiple centralization risks.
iSlowMist audited only the sTRX staking product (counted separately on DefiLlama), not the lending markets.
iMost of USDD’s collateral (approximately 61%, funds from HTX) is deposited into JustLend and Aave: stablecoin liquidity in JustLend is concentrated among parties related to Justin Sun.
Pool-based lending: depositors bear bad-debt risk when collateral falls sharply in value, the oracle (Chainlink) misprices assets, and withdrawals are delayed when utilization is high. Many assets in the pools (USDD, JST, sTRX) belong to the same TRON ecosystem.
Regional notes
Protocol changes are voted on by JST holders (GovernorBravo) and executed after a 48-hour timelock; 200 million JST is required to submit a proposal, with a quorum of 600 million votes. The CertiK audit in 4/2022 identified multiple centralization risks.[docs.justlend.org]
2023-04 · SlowMist audited only the sTRX staking product (counted separately on DefiLlama), not the lending markets.[justlend.org]
2025-06 · Most of USDD’s collateral (approximately 61%, funds from HTX) is deposited into JustLend and Aave: stablecoin liquidity in JustLend is concentrated among parties related to Justin Sun.[protos.com]
Kamino
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
A large lending protocol on Solana, live since 11/2023, with no incidents or bad debt recorded.
!Operating since 2023-11, under 3 years
✓Audited by 3 firms: OtterSec, Sec3, RX Security
✓Bug bounty programme (Immunefi, up to $1.5M)
✓Large TVL: $1.5B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: Pooled lending: collateral/oracle risk, and delayed withdrawals at 100% utilisation (the USDC market hit 100% in 4/2026).
Pooled lending: collateral/oracle risk, and delayed withdrawals at 100% utilisation (the USDC market hit 100% in 4/2026).
Maple
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
Unsecured/secured lending to institutions (syrupUSDC/USDT). In 2022 borrower Orthogonal Trading defaulted on USD 36 million in an old pool, and lenders recovered only part.
✓Operating since 2021-05 (5 years)
✓Audited by 7 firms: Trail of Bits, Spearbit, Three Sigma, 0xMacro, Sherlock, Dedaub, Sigma Prime
✓Bug bounty programme (Immunefi, up to $500k)
✓Large TVL: $3B
!Uncovered losses in the last 5 years: Orthogonal Trading defaulted on USD 36 million after the FTX collapse (2022-12)
iRisk of the asset itself: syrupUSDC/USDT carry off-chain credit risk from lending to institutions: loans are overcollateralised but there is no first-loss protection layer; withdrawals go through a queue.
Facts and sources
Operating since
2021-05
Audits
Trail of Bits, Spearbit, Three Sigma, 0xMacro, Sherlock, Dedaub, Sigma Prime[docs.maple.finance]
2022-12 · Orthogonal Trading defaulted on USD 36 million after the FTX collapse · ~$36M · users bore losses / compensation not verifiedMaple V1 unsecured pool (before syrupUSDC); only partially recovered.[theblock.co]
Risk of the asset
syrupUSDC/USDT carry off-chain credit risk from lending to institutions: loans are overcollateralised but there is no first-loss protection layer; withdrawals go through a queue.
Marinade
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
Liquid SOL staking (mSOL) since 8/2021, no contract incidents. TVL is now about USD 260 million.
✓Operating since 2021-08 (5 years)
✓Audited by 4 firms: Neodyme, Ackee Blockchain, Kudelski Security, Sec3
✓Bug bounty programme (Immunefi, up to $250k)
!TVL $287.1M, below $1B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: mSOL is a liquid staking token: validator risk, depegs when liquidity is thin, and dependence on the stake auction mechanism (SAM) for yield.
iA third party estimates the stake auction mechanism (SAM) cost stakers ≥37,000 SOL in yield over 126 epochs (forgone yield, not loss of principal); Marinade regards it as a known inefficiency.
mSOL is a liquid staking token: validator risk, depegs when liquidity is thin, and dependence on the stake auction mechanism (SAM) for yield.
Regional notes
2025-05 · A third party estimates the stake auction mechanism (SAM) cost stakers ≥37,000 SOL in yield over 126 epochs (forgone yield, not loss of principal); Marinade regards it as a known inefficiency.[forum.marinade.finance]
Morpho
Last reviewed 24/09/2026
B· Medium risk · meets 4/5 criteria
Morpho's core contracts have not been exploited; all incidents were in isolated markets/vaults managed by curators (Stream/xUSD 11/2025, USR 3/2026, rsETH 4/2026). Actual risk depends on the vault you choose.
!Operating since 2024-01, under 3 years
✓Audited by 5 firms: Spearbit, OpenZeppelin, Cantina, Blackthorn, Certora
✓Bug bounty programme (Cantina, Immunefi, up to $2.5M)
✓Large TVL: $11.1B
✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
iRisk of the asset itself: Isolated markets: vault depositors bear the risk of the curator's market selection, oracle configuration and collateral; bad debt is socialised into the vault's share value.
iSome Gauntlet vaults affected by USR only open compensation claims when the vault runs out of liquidity; the Stream/xUSD case is still in litigation.
2026-04 · Kelp rsETH exploit: two isolated rsETH markets affected · ~$1M · users bore losses / compensation not verified · only an isolated market / product was affected[bitget.com]
2026-03 · Resolv USR exploit: ~15 vaults with wstUSR markets affected · ~$8M · users bore losses / compensation not verified · only an isolated market / product was affectedThe Gauntlet USDC Core vault lost ~USD 6 million; Gauntlet/Resolv partially compensated (~4.38 million USDC).[bitget.com]
2025-11 · Stream Finance xUSD / Elixir deUSD collapse: bad debt in some isolated vaults · ~$700,000 · users bore losses / compensation not verified · only an isolated market / product was affectedThe MEV Capital vault took ~USD 650–700 thousand in bad debt; Elixir pledged to recover ~80% for lenders.[chorus.one]
2024-10 · PAXG/USDC market oracle misconfiguration · ~$230,000 · users fully compensated · only an isolated market / product was affectedCurator LeadBlock recovered most of the funds.[forum.morpho.org]
Risk of the asset
Isolated markets: vault depositors bear the risk of the curator's market selection, oracle configuration and collateral; bad debt is socialised into the vault's share value.
Regional notes
Some Gauntlet vaults affected by USR only open compensation claims when the vault runs out of liquidity; the Stream/xUSD case is still in litigation.[bitget.com]
Euler v2
Last reviewed 27/09/2026
B· Medium risk · meets 3/5 criteria
A modular lending vault platform, launched in 8/2024, audited by many firms and offering a bug bounty of up to USD 7.5 million. Third-party curator vaults incurred bad debt from xUSD (11/2025); Euler v1 was hacked for USD 197 million in 2023, but users were fully reimbursed.
!Operating since 2024-08, under 3 years
✓Audited by 10 firms: Spearbit, Cantina, Certora, ChainSecurity, OpenZeppelin, Omniscia, Enigma Dark, yAudit/Electisec, Trail of Bits, Hunter Security
✓Bug bounty programme (Cantina, up to $7.5M)
!TVL $355.2M, below $1B
✓No material uncovered losses in the core product (incidents in isolated products or under $1M are listed separately)
iRisk of the asset itself: Vaults are permissionless: depositors bear the risk of each vault curator/governor’s collateral choices, oracle, and parameters; bad debt is allocated to vault share value. Some vaults may be upgradeable.
iTVL fell sharply in 2026 (approximately USD 354 million on 27/9/2026), with approximately 74% on Monad.
2025-11 · Stream Finance xUSD collapse: third-party curator vaults that accepted xUSD as collateral incurred bad debt. · users bore losses / compensation not verified · only an isolated market / product was affectedThe oracle kept the xUSD price around USD 1, preventing liquidation; Euler froze pools with tens of millions of USD in bad debt. The actual loss amount and whether compensation was provided could not be verified.[pharos.watch]
2023-03 · Euler v1 (the old version, with code different from v2) was exploited through the donateToReserve function, with losses of approximately USD 197 million. · ~$197M · users fully compensatedThe attacker returned all funds before 4/2023; approximately USD 240 million was recovered due to the increase in ETH’s price, and users were fully reimbursed.[euler.finance]
Risk of the asset
Vaults are permissionless: depositors bear the risk of each vault curator/governor’s collateral choices, oracle, and parameters; bad debt is allocated to vault share value. Some vaults may be upgradeable.
Regional notes
2026-09 · TVL fell sharply in 2026 (approximately USD 354 million on 27/9/2026), with approximately 74% on Monad.[defillama.com]
Fluid
Last reviewed 24/09/2026
B· Medium risk · meets 3/5 criteria
A shared liquidity layer for lending, vaults and DEX. Bad debt from the Resolv USR exploit (3/2026) was absorbed by the treasury, the team and Resolv; the reward distribution key leak (5/2026) was small and covered.
!Operating since 2024-02, under 3 years
✓Audited by 4 firms: PeckShield, StateMind, MixBytes, Cantina
✓Bug bounty programme (Immunefi, up to $500k)
!TVL $735.4M, below $1B
✓Users were fully compensated for every known incident
iRisk of the asset itself: Lenders share one liquidity layer with all Fluid vaults and DEX: bad debt or a bank run in one place can affect the ability to withdraw.
2026-05 · Key leak in the Merkle reward distribution system · ~$215,000 · users fully compensatedOnly affected the rewards contract, not lent funds; the team pledged to compensate.[cryptotimes.io]
2026-03 · Resolv USR exploit: mispriced wstUSR created bad debt in Fluid vaults · ~$21M · users fully compensated~USD 19–21 million of bad debt was absorbed by Resolv, the treasury and the team; using the treasury before a vote drew criticism.[defiprime.com]
Risk of the asset
Lenders share one liquidity layer with all Fluid vaults and DEX: bad debt or a bank run in one place can affect the ability to withdraw.
Lista
Last reviewed 24/09/2026
B· Medium risk · meets 3/5 criteria
Morpho-style isolated lending markets on BNB Chain, launched 4/2025. The Resolv incident (3/2026) was repaid 1:1 with no losses.
!Operating since 2025-04, under 3 years
✓Audited by 5 firms: BailSec, BlockSec, PeckShield, CertiK, SlowMist
✓Bug bounty programme (Immunefi, up to $1M)
!TVL $952.6M, below $1B
✓Users were fully compensated for every known incident
iRisk of the asset itself: Isolated markets: vault depositors bear the risk of the curator's market selection and the collateral (usually slisBNB, lisUSD).
2026-03 · Impact from the Resolv USR exploit (~USD 8.6 million in related loans) · users fully compensatedRepaid 1:1, no losses to users.[bitget.com]
2022-12 · Helio (Lista's predecessor, a different CDP product): the attacker used near-worthless aBNBc to borrow ~16 million HAY · ~$16M · users fully compensated · only an isolated market / product was affectedAn older product of the parent brand, not Lista Lending; Ankr spent USD 15 million buying back HAY.[cointelegraph.com]
Risk of the asset
Isolated markets: vault depositors bear the risk of the curator's market selection and the collateral (usually slisBNB, lisUSD).
Venus
Last reviewed 24/09/2026
C· Higher risk · meets 4/5 criteria
The oldest lending protocol on BNB Chain, but it has repeatedly incurred bad debt from price manipulation of illiquid assets; it could not be confirmed that the THE incident (3/2026) has been fully covered.
✓Bug bounty programme (BNB Chain Bug Bounty, up to $100k)
✓Large TVL: $1.4B
✕Uncovered losses in the last 2 years: Donation attack on the THE market: supply cap exceeded and THE price manipulated (2026-03)
iRisk of the asset itself: Pooled lending that accepts illiquid collateral: depositors bear oracle manipulation and bad-debt risk, covered only by the Risk Fund/treasury.
iAfter the THE incident: the THE/CAKE markets were paused and the collateral factors of many assets (BCH, LTC, UNI, AAVE, POL, FIL, TWT, lisUSD) were set to 0.
2026-03 · Donation attack on the THE market: supply cap exceeded and THE price manipulated · ~$4M · users bore losses / compensation not verified~USD 2.2 million in bad debt; proposals to repay it from the treasury and Risk Fund exist but execution has not been confirmed. The vulnerability had been flagged in a Code4rena audit.[community.venus.io]
2025-09 · A large user was phished (Lazarus), losing a ~USD 13.5 million position · ~$14M · users fully compensated · only an isolated market / product was affectedUser-side error, not a protocol issue; funds were recovered in under 12 hours.[cointelegraph.com]
2025-03 · Donation attack (recorded by DefiLlama on the Core Pool) · ~$902,000 · users bore losses / compensation not verified[defillama.com]
2022-05 · LUNA collapse: the oracle price floor allowed borrowing against near-worthless LUNA · ~$14M · users fully compensatedAccording to secondary sources, covered by protocol funds.[defisafety.com]
2021-05 · XVS price manipulation caused ~USD 100 million in bad debt · ~$100M · users bore losses / compensation not verifiedThere is a plan to cover it with XVS and fee funds, but full repayment has not been confirmed.[medium.com]
Risk of the asset
Pooled lending that accepts illiquid collateral: depositors bear oracle manipulation and bad-debt risk, covered only by the Risk Fund/treasury.
Regional notes
2026-03 · After the THE incident: the THE/CAKE markets were paused and the collateral factors of many assets (BCH, LTC, UNI, AAVE, POL, FIL, TWT, lisUSD) were set to 0.[community.venus.io]
Aave v4
Last reviewed 27/09/2026
C· Higher risk · meets 3/5 criteria
Aave's new version under a Hub-and-Spoke model, running on Ethereum since 30/3/2026 (Avalanche since 7/2026), audited by multiple firms, with no incidents recorded. The new code is under 1 year old, and initial limits remain low.
✕Live only since 2026-03, under 1 year
✓Audited by 5 firms: ChainSecurity, Trail of Bits, Certora, Sherlock, Blackthorn
✓Bug bounty programme (Sherlock, up to $3.5M)
!TVL $637M, below $1B
✓No recorded incident causing user losses in the core product
iRisk of the asset itself: Liquidity is shared within each Hub: depositors bear bad-debt risk from every Spoke borrowing from that Hub, although each Spoke has separate risk parameters and caps. The code is new and has not been through a stressed market cycle.
iLaunched with 3 Hubs (Core, Prime, Plus) and conservative supply/borrow caps; the Aave DAO votes to raise caps, add Spokes, and expand to more networks.
iTwo sources on the bug bounty do not match: Aave’s Immunefi page lists up to USD 1 million, while aave.com/security states “Aave Core ... Up to $5M” on Immunefi. V4 has used a separate program on Sherlock (up to USD 3.5 million) since 18/5/2026.
Facts and sources
Operating since
2026-03
Audits
ChainSecurity, Trail of Bits, Certora, Sherlock, Blackthorn[aave.com]
Liquidity is shared within each Hub: depositors bear bad-debt risk from every Spoke borrowing from that Hub, although each Spoke has separate risk parameters and caps. The code is new and has not been through a stressed market cycle.
Regional notes
2026-03 · Launched with 3 Hubs (Core, Prime, Plus) and conservative supply/borrow caps; the Aave DAO votes to raise caps, add Spokes, and expand to more networks.[aave.com]
2026-05 · Two sources on the bug bounty do not match: Aave’s Immunefi page lists up to USD 1 million, while aave.com/security states “Aave Core ... Up to $5M” on Immunefi. V4 has used a separate program on Sherlock (up to USD 3.5 million) since 18/5/2026.[immunefi.com]