KETJU Research

← The Register

stable-lending

Aave v3

Approved · limits

Effective control: crypto-backed. Staked GHO. Same backing as GHO, earning the Aave savings rate.

Max sleeve
30%
Reviewed
2026-08-14 · v1
Next review
2026-09-15
Research basis
Individual research
Protocol TVL, 30d
$17.21B +25%
Protocol revenue, 30d
$4M
Chains
Ethereum · sovereign
Symbols
GHO SGHO

The scheduled date is the outside bound. Kill criteria are checked every day, and a trigger reopens the memo that week.

On 2026-04-18 an attacker forged a LayerZero cross-chain message and minted ~116,500 unbacked rsETH (~$293M, about 18% of supply), deposited 89,567 of it into Aave as collateral, and borrowed about $193M of WETH and wstETH across Ethereum and Arbitrum. BGD Labs modeled loss-allocation scenarios from about $123.7M to $230.1M; those are scenario outputs, not a reconciled final Aave loss. The distinction that keeps this approved: THE AAVE CONTRACTS DID NOT FAIL. They behaved exactly as written; OpenZeppelin’s post-mortem is titled ”Zero Bugs Found.” What failed was risk governance. In January 2026 Aave governance enabled e-mode for rsETH at 93% LTV, explicitly motivated by competitiveness and a target of $1B in new rsETH inflows, and accepted a bridged liquid-restaking token as high-LTV collateral without assessing the bridge. That is a governance-chasing-TVL failure, and it is the failure mode we must now watch for, because unlike a code bug it cannot be audited away. The response was genuinely strong and is why this stays approved: rsETH frozen and LTV cut to zero within 90 minutes per BGD’s incident report. Aave later reported that 95.4% of unbacked rsETH had been restored within thirty days, funded by the DeFi United coalition and Kelp reserves rather than clawed back from the attacker, and interim LTV cuts executed (weETH 93% to 83%, ezETH 93% to 80%, sUSDe 90% to 80%, wrsETH revoked as collateral on nine L2s). Aave Labs announced a new listing framework in May 2026 that assesses cybersecurity, interoperability and technical architecture rather than price volatility alone; the DAO’s wrap-depth tier framework is still a temp check, not yet ratified, and the review holds that open. One clock has started: Aave v4 went live on Ethereum 2026-03-30 after a full governance sequence, holds $0.22B against v3’s $14.07B per DefiLlama, and the DAO plans 24 to 36 months of parallel operation; the 2026-09-15 review tracks the migration. Net: still the most battle-tested lending venue, but the final realized loss remains an estimate rather than a reconciled primary figure. Approval rests on the fast freeze, risk reductions and funded restoration, not on claiming clean absorption of a $200M loss. Approved with limits rather than in full: the sleeve is capped at 30% where the pre-incident record would have supported 40%, and the review cycle is shortened. This approval is only for Ethereum GHO deposited into the Ethereum sGHO vault; it does not approve any other Aave reserve or any Base or Arbitrum market. GHO/sGHO is preferred over USDC: GHO has no blacklist function, so the sleeve stops depending on Circle not freezing the client, a power USDC’s contract gives Circle and Circle has used. sGHO, live since 2026-04-03, adds one ERC-4626 vault on the v3 stack, with no cooldown and no slashing, and GHO held its peg through April.

The research file

The incident

The attack began at 17:35 UTC on 2026-04-18, per the BGD Labs incident report; some coverage cites 18:52 UTC for a later phase. A forged LayerZero V2 packet from Unichain exploited Kelp DAO’s 1-of-1 DVN configuration: the compromised verifier, whose RPC dependencies had been taken over, attested to a fabricated lock that never happened, and the Ethereum-side RSETH_OFTAdapter released 116,500 rsETH (coverage cites 116,500 to 117,132), worth about $292M to $293M. Against a pre-attack supply of roughly 630,000 rsETH that is about 18.5%. The incident report’s socialization scenario uses a different denominator, 112,204 unbacked against 741,893 post-attack supply for a 15.12% depeg; that is a different calculation, not a contradiction.

The attacker deposited 89,567 rsETH ($221.39M) into Aave as collateral, per the BGD incident report, and borrowed 82,650 WETH ($190.86M) plus 821 wstETH ($2.33M) across Ethereum Core and Arbitrum, spread over 7 addresses at health factors of 1.01 to 1.03. Those position values describe attacker borrow exposure, not a final realized protocol loss. BGD’s two modeled allocation scenarios were uniform socialization at about $123.7M and L2-only losses ~$230.1M (Arbitrum $88.4M, Mantle $77.7M, Base $47.5M). Coverage consistently calls it the largest DeFi exploit of 2026. Aave lost roughly $6.6B to $8B of TVL in the panic week of April 18 to 20 and has since recovered to $14.07B.

The contracts and the governance failure

OpenZeppelin’s post-mortem is titled ”$292 Million Lost, Zero Bugs Found.” No Aave smart contract was exploited; every contract behaved as designed. The failure had two parts: Kelp DAO’s bridge infrastructure, a 1-of-1 DVN whose RPC dependencies were compromised, and Aave’s risk governance accepting the asset at high LTV.

The governance path is documented. The proposal originated 2025-11-17 from the Aave Chan Initiative (Marc Zeller) to ”restore WETH utilization and attract an expected $1 billion in rsETH inflows.” E-mode for rsETH activated in January 2026 at 93% LTV, adding WETH as borrowable against rsETH for the first time, with risk parameters vetted by Chaos Labs with LlamaRisk input. Per NYDIG’s research, no bridge risk assessment was conducted on the LayerZero adapter the collateral depended on. The listing process measured price volatility and financial risk on an asset whose real risk was a bridge.

The response

rsETH and wrsETH were frozen and LTV set to zero across all v3 deployments at 19:00 UTC the same day, under 90 minutes after the attack began, per the BGD incident report.

Aave posted on X that 95.4% of the unbacked rsETH was recovered within thirty days, by 2026-05-18. The mechanism matters: staged ETH deposits were converted to rsETH and injected into the bridge lockbox, funded by the DeFi United coalition and Kelp reserves. This was restoration by coalition funding, not the attacker returning funds; attribution points at Lazarus, and no source reviewed reports attacker funds returned. Over 106,000 rsETH was restored in total. DeFi United began as seven protocols, Aave, Lido, EtherFi, Ethena, Mantle, Ink Foundation, and BGD Labs, pooling ~69,534 ETH (~$161M), and later grew past $300M ($320M per AMBCrypto) with dozens of contributors, including personal contributions from Stani Kulechov and Emilio Frangella. Aave restored WETH LTV on six major v3 deployments by 2026-05-18, Kelp completed the rsETH restoration in May, and rsETH functionality reopened. No second bad-debt event has occurred since.

The listing framework

Two distinct things exist and they are at different stages. The first is the Aave Labs framework, announced policy. At Consensus Miami on May 7, Aave Labs CLO Linda Jeng said the existing framework was too narrowly focused on financial risk and volatility; every asset will now face assessment covering cybersecurity, interoperability, and technical architecture. It includes a minimum-standards playbook for issuers, a Level 0 to 5 security classification for privileged wallets and governance, and annual technical reassessments plus immediate review after upgrades, governance changes, bridge modifications, or incidents.

The second is the DAO’s wrap-depth tier framework, a temp check posted 2026-04-24 and not yet ratified: a seven-factor score from 0 to 14 (redemption posture, rehypothecation depth, bridge hops, regulatory status, oracle fragility, volatility, DEX depth) mapping to LTV ceilings, T1 85%/80%, T2 78%/72%, T3 68%/62%, T4 ineligible. No ARFC or AIP advancing it was found through 2026-08-14. The interim cuts did execute: weETH 93% to 83%, ezETH 93% to 80%, sUSDe 90% to 80%, and wrsETH revoked as collateral on nine L2s. The kill criterion on weakening the framework cannot trip before the DAO half of it is ratified; that is a watch item, not a violation.

Governance since the incident

Observable behavior since April is uniformly risk-reducing. The 2026-06-05 ”Aave V3 LTV and E-Mode Update” cut several assets to 0% LTV (PYUSD on Ethereum, AUSD on Avalanche, wstETH on Gnosis, WETH and WMNT on Mantle) and raised nothing above 80%. Deprecation-direction ARFCs continue: Low Adoption Asset Deprecation and Oracle Deprecation for long-tail assets, both posted 2026-08-13. The posture is contraction, not growth-chasing.

The Emergency Guardian signer rotation ARFC of 2026-08-12 rotates the nine signers only: same Safe addresses, same 5-of-9 threshold, no timelock change, and the proposal states it ”does not expand or otherwise modify the authority of the Governance Emergency Guardian.” It does not trip the emergency-powers kill criterion.

All recent listing activity is on chains outside this registry’s scope: PT-AUSD and PT-USDe on the Monad instance, USDC and PT-USDG on X Layer. The PT-USDe Monad proposal (2026-08-05) has no risk parameters yet; LTV will be set by risk providers in the AIP. PT tokens are wrapped yield positions, so an aggressive e-mode LTV there would test the spirit of the bridged-asset kill criterion even off our chains. Watch the parameter AIPs.

Umbrella, the automated slashing backstop on Ethereum for USDC, USDT, WETH, and GHO, shows no structural changes since 2026-07-31. During the incident BGD recommended pausing it to stop capital flight (23,507 WETH staked, ~$54M, with 18,922 aWETH in cooldown at the time). stkGHO is migrating to sGHO, and no August governance thread proposes changing Umbrella’s powers.

The v4 clock

Aave v4 activated on Ethereum mainnet 2026-03-30: the activation ARFC posted 2026-03-13, the Snapshot passed 2026-03-23, and the AIP executed a week later, per the governance record. The architecture is the Liquidity Hub and Spoke design: three hubs (Core, Prime, Plus), dedicated spokes replacing e-mode (Lido, EtherFi, Kelp among them), and conservative launch caps. An Avalanche deployment followed in July 2026, and a Deploy Aave V4 on Base ARFC posted 2026-08-03 and had not reached Snapshot at this review. No migration contract exists; the DAO plans 24 to 36 months of v3 and v4 running in parallel, and the Base proposal defers the v3-position migration approach to its AIP.

Today this touches no v3 kill criterion. v3 holds $14.07B (Ethereum $11.64B, Base $0.41B, Arbitrum $0.41B, summed from per-chain series via api.llama.fi at the 2026-08-14 review) against v4’s $0.22B, a 64x ratio, so the two-times-TVL migration tripwire is far from firing. During the April 2026 rsETH incident v4 was frozen, not hit: the Protocol Security Council disabled rsETH supply and borrow on v4’s Core Hub and Kelp Spoke on 2026-04-18, per LlamaRisk’s live incident thread, and v4’s TVL never dipped more than about 6%. The v4 file itself is under review in this registry with its own time-in-market criteria.

GHO and sGHO

The approved sleeve is narrowly the Ethereum GHO token deposited into sGHO at `0xe1753f2e00940cc31213dd92013cf019dfe4ca1d`. It excludes every USDC, USDT, WETH, wstETH and bridged-GHO reserve, and excludes every Base and Arbitrum market. Consequently, reserve utilization elsewhere cannot silently satisfy or breach this memo; the observable exit test is the named Ethereum ERC-4626 vault.

The preference for GHO over USDC rests on a contract-level fact. GHO has no blacklist or freeze function; only its contract code and Aave governance control it. USDC’s contract carries a notBlacklisted modifier on transfer and transferFrom that lets Circle unilaterally freeze addresses, a power Circle has exercised repeatedly: the Tornado Cash sanctions, and the 2025 Zama freeze of $12.6M. Holding GHO removes Circle from the sleeve’s dependency list.

One refinement on ”same contract risk”: GHO minted against Aave collateral shares the v3 contract stack, but sGHO, launched 2026-04-03, is a separate ERC-4626 savings vault, so it adds one additional audited, simple vault contract on top of the v3 stack. It pays a fixed APR (launched at 4.25%, in a 5% to 7% range since) with no cooldown, no slashing, and no rehypothecation per Aave’s docs. That is materially less risk than stkGHO, which it replaces; stkGHO carried Safety Module slashing risk. GHO held its peg through and after the April incident, and as of May 2026 sat within a basis point of $1.00 at ~$584M circulating.

Two items for the next review: the stkGHO to sGHO migration is active and requires users to exit the legacy contract and re-deposit, and an Arbitrum RemoteGSM pairing GHO with USDC.e was posted 2026-08-08. That stability-module link should be read before extending the no-Circle-dependency argument to L2 GHO liquidity paths.

Comparison and cap rationale

Compared with Morpho, Aave v3 concentrates more upgrade and multi-asset risk in governed pools, but has a longer operating record, named risk providers, an emergency response process, and a protocol-level backstop. Morpho’s immutable base removes upgrade risk while pushing asset selection and liquidity risk to curators. Compared with Compound v3, Aave offers broader collateral and chain coverage, improving capacity while multiplying listing and bridge dependencies. Within Aave, GHO/sGHO avoids Circle’s address-freeze power that remains in USDC, although sGHO adds its ERC-4626 contract. The 30% cap, below the 40% a clean pre-incident record could have supported, prices the demonstrated governance failure and unresolved final-loss reconciliation while retaining the venue’s response and liquidity advantages.

Open questions

The v4 question from the original memo is settled: BGD’s bad-debt scenarios span eleven v3 deployments only, and v4 was frozen preemptively on 2026-04-18 rather than exploited, per LlamaRisk’s incident thread. The old claim that the attack repeated on v4 was wrong and has been removed.

The DAO wrap-depth framework’s ratification status is open. It had not advanced past temperature check as of mid-May per ArkenYield, and no ARFC or AIP was found through 2026-08-14. The Labs assessment overhaul is announced policy; the wrap-depth limits are a pending DAO proposal. The next review must check whether it advanced, stalled, or quietly died.

The 95.4% recovery figure is Aave’s own number, and the mechanism was coalition-funded re-collateralization plus Kelp reserves, not clawback from the attacker. No reviewed primary source supplies a reconciled final Aave loss. BGD’s $123.7M and $230.1M figures are modeled allocation scenarios; the roughly $193M borrowed is position exposure, while later restoration-plan headlines measure a different backing shortfall. This memo therefore does not quote a definitive $195M-$196M realized bad-debt figure.

PT listing parameters on Monad and X Layer are not yet published; re-check when the AIPs land. And the $14.07B v3 and $0.22B v4 totals were summed from per-chain series via api.llama.fi on 2026-08-14; the DefiLlama site UI may show slightly different headline numbers depending on borrowed and staking splits.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
AssetGradeWho can freeze it
GHO crypto-backed GHO is backed by on-chain collateral. Aave governance can change its parameters, but it cannot freeze an address.
SGHO crypto-backed Staked GHO. Same backing as GHO, earning the Aave savings rate.

Live positions

MarketYieldAvailable nowControl
SGHO · Ethereum 4.25% $152M crypto-backed · asset
GHO · Ethereum · Aave Horizon Market 1.17% $34M crypto-backed · asset
GHO · Ethereum · Prime Instance 2.07% $13M crypto-backed · asset
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.