Aave Horizon
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON GOVERNANCE AMBIGUITY AND A DEMONSTRATED SYSTEM-WIDE VULNERABILITY, NOT ON HORIZON-SPECIFIC BAD DEBT. Horizon is a permissioned instance of the audited Aave V3.3 codebase letting institutions borrow stablecoins (USDC, RLUSD, GHO) against allowlisted tokenized RWA collateral (Superstate USTB and USCC, Centrifuge JTRSY and JAAA, Circle USYC, VanEck VBILL, and others). No Horizon-specific bad debt or exploit was found, and risk parameters are managed by LlamaRisk with Chainlink NAVLink pricing — real institutional infrastructure. But Aave’s own public statements are in direct tension on who actually controls it: Aave’s blog states ”Aave Labs does not control or operate any version of the Aave Protocol,” while the governance forum describes Aave Labs holding an ”Executive role” over Horizon’s risk parameters, oracle configuration, and asset listings — an unresolved accountability question a delegate has separately disputed in a funding-vote controversy. Horizon shares its codebase, oracle infrastructure, and DAO governance with Aave’s core markets, which suffered a roughly $177-200M bad-debt event in April 2026 after a LayerZero-bridge exploit let attackers mint unbacked rsETH used as collateral — a vulnerability class this registry has already used to reject LayerZero V2 itself. Horizon TVL has also declined 28% month-over-month as of a July 2026 snapshot. Together, these are standing facts, not a temporary gap in a otherwise-clean file.
- Aave Labs’ authority over Horizon is stated consistently across Aave’s own public materials, resolving the ”does not control the Protocol” versus ”Executive role” tension
- Horizon demonstrates no correlated exposure through a subsequent Aave-ecosystem-wide exploit or bad-debt event
- TVL and active-loan volume recover and stabilize, ending the multi-month decline documented through July 2026
- A primary Certora (or equivalent) audit report specific to the Horizon deployment is published and reviewed
The research file
Mechanism
Horizon runs the same audited Aave V3.3 smart contracts as core Aave markets, in a separate deployment with its own risk parameters, splitting access by side: the RWA collateral side is permissioned, gated by each issuer’s own KYC and on-chain allowlist (Superstate, Centrifuge, Circle, VanEck, and others each run their own onboarding); the stablecoin supply side (USDC, RLUSD, and Aave’s native GHO) is permissionless, open to any wallet. Only wallets holding allowlisted RWA collateral can borrow against it, and liquidation execution is reported as restricted to ”qualified market makers” rather than fully open, permissionless liquidators.
The governance accountability gap
Aave governance forum language describes Horizon as ”a white label instance based on the existing Aave DAO framework,” with the Aave DAO retaining smart-contract upgrade (”superadmin”) authority via on-chain governance while Aave Labs holds an ”Executive role” over risk-parameter configuration, oracle management, and asset listing — exercised alongside LlamaRisk as an independent risk provider. Aave’s own public blog states elsewhere that ”Aave Labs does not control or operate any version of the Aave Protocol on any blockchain network,” a statement in direct tension with the governance-forum description of its Executive role over Horizon specifically. This is not resolved in any public source, and a delegate (ACI) has separately published a disputed audit of Aave Labs’ accountability and wallet transparency around a Horizon-adjacent funding vote that reportedly passed on 57% ”FOR” votes from a single delegation.
The shared vulnerability surface
On 2026-04-18, a compromise of LayerZero Labs’ own operational infrastructure — already the basis for this registry’s rejection of LayerZero V2 — let attackers forge attestations and mint roughly $292M of unbacked rsETH, which was then used as collateral on Aave’s core Ethereum and Arbitrum markets, producing roughly $177-200M of bad debt concentrated in the WETH reserve and a $6.6B, 44-46% drop in Aave’s broader TVL within days. No source found confirms Horizon assets were directly affected, but Horizon runs the same underlying V3.3 codebase, shares Aave DAO governance, and depends on oracle infrastructure from the same ecosystem — the vulnerability class that produced this loss is not isolated from Horizon by design, only by which specific collateral asset happened to be exploited that day.
Track record and current trajectory
Horizon launched 2025-08-27, crossed $50M in deposits within days, grew to roughly $540M by November 2025 and roughly $600M net deposits with GHO utilization peaking near 97% in early 2026 — a utilization level this registry treats elsewhere as a liquidity-stress warning sign, not a health signal. Token Terminal’s July 2026 report showed Horizon TVL averaging $350M that month, down 28% month-over-month after five consecutive months of decline, with active loans down 30% month-over-month over the same period, though showing early signs of recovery. A Certora audit of the Horizon-specific V3.3-based infrastructure is referenced in secondary sources citing a GitHub repository, but the primary audit report itself could not be independently retrieved to confirm scope and findings.
Comparison and decision
Against core Aave V3 markets, which are fully permissionless on both supply and borrow, Horizon adds issuer-enforced collateral permissioning and RWA-specific risk parameters but inherits the same contract, oracle, and governance vulnerability surface that produced Aave’s largest 2026 loss event. Against Maple Finance and Centrifuge-style undercollateralized credit structures, Horizon’s overcollateralized-RWA-as-collateral design is structurally more conservative, but that comparison does not resolve the governance-accountability and disclosure gaps found here. Reopen only once Aave Labs’ actual authority over Horizon is stated consistently and once Horizon demonstrates it can withstand a system-wide Aave exploit without correlated exposure.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Aave — how Horizon is built for institutions · primary · accessed 2026-08-17
Supports: permissioned collateral / permissionless supply structure, risk management partners - Aave governance forum — ARFC: Horizon’s RWA instance · primary · accessed 2026-08-17
Supports: Aave Labs Executive role, Aave DAO superadmin authority, governance framework - CoinDesk — Aave Labs debuts Horizon to let institutions borrow stablecoins against tokenized assets · secondary · accessed 2026-08-17
Supports: launch date, product description - Forbes — inside Aave’s sudden $200M bad-debt crisis · secondary · accessed 2026-08-17
Supports: April 2026 LayerZero-linked exploit, bad debt figures, TVL drop - CoinDesk — Aave records $6 billion TVL drop as Kelp hack exposes structural risk · secondary · accessed 2026-08-17
Supports: systemic TVL impact, shared vulnerability surface - The Defiant — Aave’s Horizon RWA market nears $540 million, adds VanEck treasury fund · secondary · accessed 2026-08-17
Supports: growth trajectory, GHO utilization, collateral asset list
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |