EtherFi Borrowing Market
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON A LIVE DOCUMENTATION-STATUS INCONSISTENCY AND A PERMISSIONED BORROW SIDE. EtherFi’s Borrowing Market is an ether.fi-operated Aave v4 instance backing ether.fi Cash, the company’s crypto-collateralized Visa card — genuinely well-controlled in several respects, including a price-cap adapter whose owner-reset function is wired so it can never be called by anyone, ”for us, for our multisig, for anyone,” per ether.fi’s own documentation. But every public page describing this product carries a ”coming soon” banner despite roughly $190M already supplied and roughly $25M already borrowed on Optimism at the time of this review — a live inconsistency between disclosed product status and actual on-chain activity this registry treats as disqualifying on its own. Borrowing itself is restricted to ether.fi Cash account holders, not open to third-party lenders the way the supply side is, and no separate legal entity name for this specific product was confirmed.
- ether.fi’s own documentation pages are updated to reflect the product’s actual live status, resolving the ”coming soon” inconsistency
- A named legal entity specific to the Borrowing Market is disclosed
- The borrow side opens beyond ether.fi Cash account holders, or the permissioned-borrow design is otherwise justified and disclosed as intentional and permanent
- A primary Certora or Paladin audit report is published and linked, resolving the discrepancy with DefiLlama’s zero-audit field
The research file
Mechanism
Every ether.fi user receives a non-custodial Safe on signup; assets in that Safe can be posted as collateral to an ether.fi-managed Aave v4 instance. Eligible collateral spans stablecoins, weETH, ether.fi’s own Liquid vault receipt tokens, and even tokenized equities, but borrowable assets are currently limited to USDC and ETH only. The market is permissioned on the borrow side — ”only ether.fi Safes can borrow assets, but anyone can supply to Liquidity Hub” — meaning third parties can supply liquidity permissionlessly, but only ether.fi Cash account holders can draw debt, either directly or automatically through card-purchase ”Borrow Mode.” Live on-chain collateral composition is dominated by stablecoins and ether.fi’s own Liquid stable vault, not weETH, despite the market’s restaking-adjacent branding.
The documentation-status inconsistency
Every Borrow-related documentation page this review checked — technical documentation, borrowing power and liquidation, lending market parameters, and price feeds — carries a banner stating the feature is ”coming soon.” At the same time, live on-chain data shows roughly $190M supplied and roughly $25M borrowed on Optimism. A product this registry is asked to certify cannot simultaneously be marked not-yet-launched by its own operator and carry real client funds; that gap alone is disqualifying, independent of the underlying mechanism’s technical quality.
Control — a genuine positive finding alongside real gaps
Price-feed and asset-listing changes route through an Owner Safe multisig transaction, not an automated risk process. The price-cap adapter — which would let an operator raise the ceiling on how much an asset’s price is allowed to grow for collateral purposes — is documented as wired to an access-control interface that can never successfully validate a reset call, meaning the setter is ”permanently unreachable… for us, for our multisig, for anyone.” That is a real, verifiable hard-coded safeguard. Set against it: no specific legal entity name for the Borrowing Market itself was found beyond a general Inc./Ltd. jurisdictional split in ether.fi Cash’s cardholder agreements, and DefiLlama’s audit field shows zero, though ether.fi’s own security page discloses a Certora review of the lending gateway (July-August 2026) and a Paladin review of the price-feed contracts (July 2026) — DefiLlama understates real coverage here, but the entity gap remains.
The April 2026 exploit and correlated restaking risk
ether.fi’s own incident page addresses the April 18, 2026 Kelp DAO/LayerZero rsETH bridge exploit directly, stating no ether.fi systems were compromised and weETH remained fully backed throughout, because weETH’s bridge routes require a 2-of-3 or 3-of-3 independent-verifier quorum rather than Kelp’s single-verifier configuration. But ether.fi did take precautionary action: all Liquid vaults were paused for roughly a day, cross-chain bridging was disabled for five days, and the team ran active deleveraging workstreams to help borrow-market positions repay debt during a window of elevated borrow rates. This confirms the Borrowing Market saw real stress-driven deleveraging activity around the incident even though weETH itself was not directly compromised — a materially different, less severe outcome than the direct bad-debt events this registry has documented elsewhere from the same exploit class.
Comparison and decision
Against Aave and Compound markets that also accept weETH as collateral, both fully permissionless on the borrow side under independent DAO governance, EtherFi’s Borrowing Market is a vertically-integrated, first-party product where ether.fi alone sets risk parameters with no external governance check, and borrowing is restricted to the company’s own Cash-account holders. That concentration might be an acceptable tradeoff for faster, more conservative parameter-setting, but it cannot outweigh a product every one of its own documentation pages still labels as unreleased while carrying real, live client funds.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- ether.fi documentation — Borrow technical documentation · primary · accessed 2026-08-19
Supports: Aave v4 instance description, permissioned borrow side, ”coming soon” status banner - ether.fi documentation — lending market parameters · primary · accessed 2026-08-19
Supports: collateral asset list, borrowable-asset restriction to USDC and ETH - ether.fi documentation — price feeds and admin controls · primary · accessed 2026-08-19
Supports: Owner Safe multisig control, permanently unreachable price-cap setter - ether.fi security — April 18 2026 Kelp rsETH bridge exploit incident report · primary · accessed 2026-08-19
Supports: weETH multi-verifier quorum unaffected, precautionary vault pause and deleveraging - DefiLlama — EtherFi Borrowing Market protocol data · secondary · accessed 2026-08-19
Supports: current TVL and borrow volume, zero audits field
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| OP Mainnet | Rejected | hybrid | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |