KETJU Research

← The Register

other

Aave Horizon

Rejected
Max sleeve
Reviewed
2026-08-17 · v1
Next review
2026-11-17
Research basis
Individual research
Chains
Ethereum · sovereign

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED ON GOVERNANCE AMBIGUITY AND A DEMONSTRATED SYSTEM-WIDE VULNERABILITY, NOT ON HORIZON-SPECIFIC BAD DEBT. Horizon is a permissioned instance of the audited Aave V3.3 codebase letting institutions borrow stablecoins (USDC, RLUSD, GHO) against allowlisted tokenized RWA collateral (Superstate USTB and USCC, Centrifuge JTRSY and JAAA, Circle USYC, VanEck VBILL, and others). No Horizon-specific bad debt or exploit was found, and risk parameters are managed by LlamaRisk with Chainlink NAVLink pricing — real institutional infrastructure. But Aave’s own public statements are in direct tension on who actually controls it: Aave’s blog states ”Aave Labs does not control or operate any version of the Aave Protocol,” while the governance forum describes Aave Labs holding an ”Executive role” over Horizon’s risk parameters, oracle configuration, and asset listings — an unresolved accountability question a delegate has separately disputed in a funding-vote controversy. Horizon shares its codebase, oracle infrastructure, and DAO governance with Aave’s core markets, which suffered a roughly $177-200M bad-debt event in April 2026 after a LayerZero-bridge exploit let attackers mint unbacked rsETH used as collateral — a vulnerability class this registry has already used to reject LayerZero V2 itself. Horizon TVL has also declined 28% month-over-month as of a July 2026 snapshot. Together, these are standing facts, not a temporary gap in a otherwise-clean file.

The research file

Mechanism

Horizon runs the same audited Aave V3.3 smart contracts as core Aave markets, in a separate deployment with its own risk parameters, splitting access by side: the RWA collateral side is permissioned, gated by each issuer’s own KYC and on-chain allowlist (Superstate, Centrifuge, Circle, VanEck, and others each run their own onboarding); the stablecoin supply side (USDC, RLUSD, and Aave’s native GHO) is permissionless, open to any wallet. Only wallets holding allowlisted RWA collateral can borrow against it, and liquidation execution is reported as restricted to ”qualified market makers” rather than fully open, permissionless liquidators.

The governance accountability gap

Aave governance forum language describes Horizon as ”a white label instance based on the existing Aave DAO framework,” with the Aave DAO retaining smart-contract upgrade (”superadmin”) authority via on-chain governance while Aave Labs holds an ”Executive role” over risk-parameter configuration, oracle management, and asset listing — exercised alongside LlamaRisk as an independent risk provider. Aave’s own public blog states elsewhere that ”Aave Labs does not control or operate any version of the Aave Protocol on any blockchain network,” a statement in direct tension with the governance-forum description of its Executive role over Horizon specifically. This is not resolved in any public source, and a delegate (ACI) has separately published a disputed audit of Aave Labs’ accountability and wallet transparency around a Horizon-adjacent funding vote that reportedly passed on 57% ”FOR” votes from a single delegation.

The shared vulnerability surface

On 2026-04-18, a compromise of LayerZero Labs’ own operational infrastructure — already the basis for this registry’s rejection of LayerZero V2 — let attackers forge attestations and mint roughly $292M of unbacked rsETH, which was then used as collateral on Aave’s core Ethereum and Arbitrum markets, producing roughly $177-200M of bad debt concentrated in the WETH reserve and a $6.6B, 44-46% drop in Aave’s broader TVL within days. No source found confirms Horizon assets were directly affected, but Horizon runs the same underlying V3.3 codebase, shares Aave DAO governance, and depends on oracle infrastructure from the same ecosystem — the vulnerability class that produced this loss is not isolated from Horizon by design, only by which specific collateral asset happened to be exploited that day.

Track record and current trajectory

Horizon launched 2025-08-27, crossed $50M in deposits within days, grew to roughly $540M by November 2025 and roughly $600M net deposits with GHO utilization peaking near 97% in early 2026 — a utilization level this registry treats elsewhere as a liquidity-stress warning sign, not a health signal. Token Terminal’s July 2026 report showed Horizon TVL averaging $350M that month, down 28% month-over-month after five consecutive months of decline, with active loans down 30% month-over-month over the same period, though showing early signs of recovery. A Certora audit of the Horizon-specific V3.3-based infrastructure is referenced in secondary sources citing a GitHub repository, but the primary audit report itself could not be independently retrieved to confirm scope and findings.

Comparison and decision

Against core Aave V3 markets, which are fully permissionless on both supply and borrow, Horizon adds issuer-enforced collateral permissioning and RWA-specific risk parameters but inherits the same contract, oracle, and governance vulnerability surface that produced Aave’s largest 2026 loss event. Against Maple Finance and Centrifuge-style undercollateralized credit structures, Horizon’s overcollateralized-RWA-as-collateral design is structurally more conservative, but that comparison does not resolve the governance-accountability and disclosure gaps found here. Reopen only once Aave Labs’ actual authority over Horizon is stated consistently and once Horizon demonstrates it can withstand a system-wide Aave exploit without correlated exposure.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.