KETJU Research

← The Register

stable-lending

Fluid (Instadapp)

Rejected
Max sleeve
Reviewed
2026-08-14 · v1
Next review
2026-09-15
Research basis
Individual research
Chains
Ethereum · sovereign, Arbitrum One · hybrid, Base · hybrid
Symbols
USDC USDT WETH

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED at the 2026-08-15 correction, sleeve at zero. The prior memo approved Fluid on two claims, a clean exploit record and an audit roster of Spearbit, Trail of Bits, and Certora with formal verification, and neither survived checking. By the 2026-08-01 review date Fluid had already absorbed $19.3M to $21M of bad debt from the Resolv collapse: in late March 2026 an attacker compromised Resolv Labs’ off-chain signing keys and minted about 80M unbacked USR, discounted wstUSR entered Fluid markets through stale oracle pricing, and roughly $100M of USR collateral stood against USDC and USDT borrows. The settlement closed 2026-05-11, per the post-mortem: Resolv about $9.7M, Fluid governance treasury $8.2M, the team $1.5M from future revenue. A separate key compromise took about $215k from the Ethereum reward distributor on 2026-06-01. Our published kill criterion reads bad debt in any market we hold, of any size. The Liquidity Layer pools the USDC and USDT borrows the USR markets drew on with the markets this entry approves, so either the criterion fired or the memo’s own shared-liquidity thesis was wrong about what a market is. Either way the file reopens by our own rules. The audit roster fails the same check: no Trail of Bits or Certora report for Fluid exists in either firm’s public index, and the official docs list PeckShield, Statemind, MixBytes, and Cantina. The strongest stated reason for approval could not be confirmed anywhere primary. The mitigations get equal weight. No Fluid contract was itself exploited; the loss came through a listed asset’s oracle. The bad debt was paid in full with a public post-mortem and users were made whole. The architecture description verified accurate: one Liquidity Layer serving lending, vaults, and the DEX, tick-based liquidations with 0.1 to 3% penalties against the 5 to 10% typical elsewhere, and Automated Limits that throttle large movements per block, confirmed by the docs and MixBytes’ engineering write-up. The shared Liquidity Layer prevents the held-reserve loss from being separated with the retained primary accounting, so the existing any-bad-debt trigger fired or cannot be cleared. Reimbursement does not erase that trigger. The remaining facts reinforce rejection: TVL peaked at $2.68B on 2025-10-08 and the stack stood at $802.6M at the 2026-08-14 review with $752.5M borrowed, so free liquidity is thin, and the $500k Immunefi cap is 0.06% of TVL, the same thin shape the StakeWise rejection counted. The review must answer the questions below by 2026-09-15.

The research file

The mechanism

Fluid is not one protocol but a stack. A single Liquidity Layer holds all deposits, and three protocols draw on it: Lending, which takes passive fToken deposits; Vault, which lends against collateral; and the DEX, launched at the end of October 2024. One deposit serves lending borrowers, DEX swappers, and vault strategies at the same time, and the depositor collects both lending interest and swap fees. The docs and MixBytes’ engineering write-up describe the Liquidity Layer as the base contract every module plugs into.

The DEX design adds Smart Collateral and Smart Debt. A borrower can post an LP-style pair, say ETH-USDC, as collateral that stays live as trading liquidity, and can hold debt that itself serves as pool liquidity, so both legs of a leveraged position earn swap fees. Marketing material claims up to $39 of trading liquidity per $1 of TVL. This is the source of both the capital efficiency and the correlated surface the memo priced in: lending deposits and DEX liquidity are the same pool of money.

Automated Limits govern flow. The Liquidity Layer recomputes debt and withdrawal ceilings every block; withdrawals above a base limit expand on a curve, expandPercentage over expandDuration in the contracts, so organic flows pass while a sudden large movement is throttled. This matches the prior memo’s claim of dynamically adjusted per-transaction supply and borrow limits.

The liquidation engine groups positions into ticks by debt-to-collateral ratio, the same data structure a concentrated-liquidity DEX uses. When a tick crosses the threshold, the engine partially liquidates every position in it in one operation: it prices a slice of the aggregate collateral at a small discount and lets any trader repay debt in exchange, including DEX aggregators like CoW Swap and KyberSwap routing through it as a swap. Because liquidation is one aggregated swap rather than per-position keeper races, the penalty can be as low as 0.1%, up to 3%, against the 5 to 10% typical elsewhere, and only the unhealthy slice of a position is sold. Third parties, MixBytes and Mirador, confirm the design; the low penalty is a structural consequence, not a subsidy.

Oracles are where the design failed in practice. Vault liquidation pricing uses multi-source checks, and third parties describe Uniswap TWAP checkpoints combined with Chainlink in the main markets. But the Resolv incident showed that specific markets, wstUSR among them, relied on pricing that went stale against a collapsing secondary market, and Fluid announced an oracle overhaul afterward. The prior memo’s claim that pricing is validated against both Uniswap and Chainlink is true of the flagship markets and was not true of every listed market.

Who controls it

FLUID token holders, INST until the December 2024 rebrand, govern all products. Third parties report that proposing requires 1% of supply, 1M FLUID; quorum is 4%; voting runs about three days; and execution waits in a roughly two-day timelock. Discussion happens at gov.fluid.io.

Third parties report an elected Guardian multisig that can only pause contracts in emergencies; parameter changes, listings, and emissions go through on-chain votes. The team multisig can reduce protocol ratios, pause withdrawals, and pause rebalancing, but per the Instadapp Lite risk docs it ”does not have access to funds and cannot withdraw or move funds,” and governance can supersede it.

Instadapp was founded in 2018 at the ETHIndia hackathon by brothers Samyak Jain and Sowmay Jain, and the founding team remains central to development. In the Resolv settlement the team took a $1.5M share of the bad debt out of future revenue, which shows the team treasury and protocol treasury are still operationally intertwined.

The exact signer counts and thresholds of the Guardian and team multisigs, whether the timelock covers every upgrade path on every deployed chain, and the founders’ current FLUID holding could not be verified this pass; they are review questions, and on-chain reads are the right tool, as the sAVAX review used.

The record

Fluid lending went live on Ethereum mainnet in early 2024; the DefiLlama TVL series for the lending module starts 2024-02-19 at effectively zero, and The Block covered the January 2024 introduction. The DEX went live at the end of October 2024, and the Instadapp-to-Fluid rebrand came in December 2024. The protocol is about 2.5 years old as a lending venue and under 2 years old as a combined lending-DEX system.

The TVL trajectory, per DefiLlama read 2026-08-14: the lending module grew from roughly zero at launch to $503M by 2024-11-15, $1,403M by 2025-08-12, and a peak zone of $1,934M on 2025-11-10, then fell to $1,372M by 2026-02-08, $789M by 2026-05-09 after the Resolv incident and the April 2026 industry outflows, and $668M on 2026-08-07. The combined parent protocol across all modules peaked at $2.68B on 2025-10-08 and stood at $802.6M on 2026-08-14. The current lending split is Ethereum $461M, Arbitrum $120M, Plasma $65M, Base $19M, Polygon $3M, with $752M borrowed against it. TVL is down roughly two-thirds from peak.

The incident record is not clean. In late March 2026 an attacker compromised Resolv Labs’ off-chain signing infrastructure and minted about 80M unbacked USR; the stablecoin collapsed toward $0.0025. Fluid carried roughly $100M of USR and wstUSR exposure, mostly as collateral against USDC and USDT borrows, and discounted wstUSR entered the markets through stale oracle pricing. The result was $19.3M to $21M of bad debt; the post-mortem says $19.3M absorbed, early coverage said about $21M. It was settled by 2026-05-11: Resolv about $9.7M, the Fluid governance treasury $8.2M, the team $1.5M from future revenue. Users were made whole. The consequences ran further: FLUID buybacks halted, emissions cut, the $250k per month Foundation grant suspended March through June, an oracle overhaul announced, issuer legal agreements for depeg claims, and a DEX v2 delay.

On 2026-05-31 into 06-01, two operational keys for the Ethereum reward distributor were compromised and about $215k was taken, 112,883 FLUID, roughly 47.9k to 51.9k GHO, and some cbBTC, laundered through Tornado Cash. It was not a contract flaw; core lending, vaults, and the DEX were untouched, and keys were rotated within about 10 hours. During the April 2026 KelpDAO and rsETH cascade, Fluid was among the protocols that froze rsETH markets; no Fluid-specific loss was reported from that event. No exploit of Fluid’s own smart contracts has been reported in any source consulted.

The audits, per the official docs page: PeckShield pre-launch; Statemind on the core protocol and Liquidity Layer updates; MixBytes on the Liquidity Layer, the Vault protocol with a report dated 2024-06-25, and the DEX protocol with a report dated 2024-12-04; and Cantina on the DEX. Cantina is Spearbit’s audit platform. The MixBytes VaultT1 audit, run 2024-03-25 to 2024-06-21 with four engineers, found 0 critical, 0 high, 2 medium, and 4 low issues and concluded ”the protocol demonstrates a high degree of security.” Messari additionally reports Statemind and OpenZeppelin as auditors.

The bug bounty is the Immunefi Instadapp program covering Fluid: critical smart contract vulnerabilities pay 10% of directly affected funds with a $25k minimum, capped at $500k; high pays up to $100k; proof of concept is mandatory; no KYC. Against roughly $800M of TVL the cap is 0.06% of funds at risk, the same shape of finding the StakeWise review flagged at $200k against $700M.

The claims checked

The prior memo’s claims were checked one by one against primary sources. The unified Liquidity Layer, collateral doubling as DEX liquidity, debt serving as liquidity, and fees improving both sides: verified, docs and third parties agree. The correlated DEX-lending surface that separated protocols do not have: verified as architecture, with the note that the realized loss came through oracles, not the DEX layer. Dynamically adjusted per-transaction supply and borrow limits with large movements throttled: verified, the Automated Limits exist in docs and contracts.

Liquidation pricing validated against both Uniswap and Chainlink: partly verified. It is true of the main markets per third parties, but the wstUSR market’s pricing went stale in March 2026, so it was not true everywhere.

Audited by Spearbit, Trail of Bits, and Certora with formal verification of core invariants: could not be verified, and the official docs contradict the list. Trail of Bits’ public reports index shows no Fluid audit; Certora’s public SecurityReports repository, 212 entries, contains no Fluid or Instadapp report. The claim of formal verification of core invariants is unsourced anywhere primary. Of the five-firm assurance-stack claim, Statemind is verified by the docs, OpenZeppelin rests on a third party only, Messari, and the documented roster is PeckShield, Statemind, MixBytes, and Cantina.

The claim that the exploit record remained clean as of 2026-08-01: false at the time of writing. The $19.3M to $21M of bad debt was settled 2026-05-11 with a published post-mortem, and the $215k key compromise happened 2026-06-01; both were public months before that review.

The survey’s reading of roughly $1.1B TVL: stale or module-mixed. The lending module was about $670M and the whole stack about $800M in early August 2026, so $1.1B matches neither series on 2026-08-01. The discarded $77B figure was directionally right to discard as TVL; the likely explanation is cumulative DEX volume, though which figure the source garbled could not be confirmed.

The youth question

Fluid’s lending history is about 2.5 years, against Aave’s six-plus and Compound’s eight. The young record has now shown three things. First, one full bad-debt cycle, absorbed without user loss, with a published post-mortem and a funded settlement; that is the best available evidence of how the team behaves when the design fails, and it is better behavior than most young protocols manage. Second, the failure came through a listed asset’s oracle, not through the novel DEX-lending coupling the sleeve cap was built for; the correlated surface has not yet produced a loss, while the ordinary listing-and-oracle surface has. Third, operational key management failed once, in the $215k incident, a category audits do not cover.

Observable events that would argue for loosening a cap at a future review: the promised oracle overhaul shipped and documented, issuer legal agreements in place, two-plus years of clean record after May 2026, the bug bounty raised to scale with TVL, and the multisig composition published. Events that argue for tightening or exit beyond the existing criteria: a second oracle-sourced loss, buyback or emission resumption before the treasury is rebuilt, and TVL continuing to fall while the borrowed share stays high.

The exit

Withdrawals pass through the same Automated Limits as everything else: above a base limit, per-block expansion meters out a large exit over time. That is orderly for the protocol, but it means a large client exit in a stressed hour is throttled by design, and everyone else’s rush shares the same expanding ceiling.

As in any lending pool, withdrawable liquidity is TVL minus borrows. The current reading is $802.6M of TVL against $752.5M borrowed across the stack, so free liquidity is thin at the aggregate level. Per-market utilization is what matters and should be read at each survey; the entry’s $10M minLiquidityUsd floor does this per market.

During April 2026 Fluid froze rsETH markets. Freezes are a real state this protocol enters under stress.

Open questions

No Trail of Bits or Certora audit of Fluid could be located: Trail of Bits’ public reports index shows none, and Certora’s public SecurityReports repository of 212 entries contains no Fluid or Instadapp report. The formal-verification claim is unsourced anywhere primary. The OpenZeppelin audit is reported by third parties but no report was located.

The Guardian and team multisig signer counts, thresholds, and addresses are unpublished, and whether the roughly two-day timelock covers every upgrade path on every deployed chain, Ethereum, Arbitrum, Base, Polygon, and Plasma, is unverified. The founders’ current FLUID stake and the largest delegate concentrations are unknown.

The exact composition of the roughly $1.1B figure the 2026-08-01 survey recorded could not be established. Whether the specific markets this entry would hold, the USDC, USDT, and WETH main markets on Ethereum, Arbitrum, and Base, were themselves the bad-debt markets, or only adjacent USR-collateral markets that borrow from the shared Liquidity Layer, needs on-chain and post-mortem market-level detail; the distinction decides whether the kill criterion tripped. The post-Resolv oracle overhaul was announced, but no published spec or completion evidence was located.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
Arbitrum OneApproved · limits hybrid a single sequencer orders >99% of transactions and admin keys can upgrade bridge contracts on a ~7-day timelock.
BaseApproved · limits hybrid Coinbase — one regulated US company — operates the only sequencer, and admin keys can upgrade bridge contracts within ~7 days.
AssetGradeWho can freeze it
USDC freezable Issued by Circle, backed by bank deposits and T-bills. Circle can and does freeze addresses on request from law enforcement.
USDT freezable Issued by Tether. Has frozen addresses on request. Reserve composition is less transparently attested than USDC.
WETH sovereign Wrapped ETH. Immutable contract, no admin key, no blocklist.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.