Kamino (Solana)
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED PROTOCOL-WIDE, WITH A RESERVE-SPECIFIC REOPEN PATH. Kamino Lend is a mature Solana pooled lending system with open code, unusually dense audit and formal-verification coverage, public risk reporting, and no reported lender bad debt since launch. The previous blocker is obsolete: Solana now has a chain verdict, so the decision must be made at the product and reserve level. Direct supply to a named K-Lend reserve is materially different from a Kamino Lending Vault, whose curator can reallocate deposits without depositor approval, and from Multiply, which adds leverage. There is no protocol-wide approval to grant: Kamino is a set of independently parameterized reserves, and no exact client USDC or USDT reserve has been selected. Live liquidity, admin and emergency authorities, collateral and oracle dependencies, borrower concentration, deployment-to-audit mapping and executable exit therefore cannot be certified for any reserve today. Protocol-level evidence cannot substitute for that reserve-level decision, so allocation is zero pending a named reserve that clears the reopen tests below — a standing structural fact, not a postponed judgment.
- No allocation until one exact direct-supply K-Lend market and reserve address is named; a curator vault or Multiply position cannot satisfy this test
- Any exploit or bad debt in the selected K-Lend market; vault or Multiply incidents are reviewed separately unless they share the affected contracts
- Solana liveness failure affecting withdrawal for more than 1 hour
- Selected reserve utilization above 90% for 30 days or a failed proposed-size withdrawal
- Any borrower above 10% of selected-reserve borrows or unapproved collateral above 20% of debt capacity
- Oracle provider, fallback, or staleness configuration changed without a published and audited migration
- Any live K-Lend or Scope deployment that cannot be mapped to a published audit or formal-verification report
- Emergency mode active on the selected reserve for more than 24 hours without a public incident report
The research file
Mechanism and exact claim
A direct lender deposits one token into a reserve within a specific K-Lend market. Borrowers draw that reserve against collateral held in their obligation; interest is utilization-driven and bad debt is ultimately socialized to that reserve’s lenders. Liquidation parameters, supply and borrow caps, debt ceilings, oracle configuration and isolation controls are reserve-specific. A protocol TVL number therefore does not describe the claim or its exit.
Kamino Earn or Lending Vaults are a separate contract and mandate. A curator allocates across eligible K-Lend reserves, may change allocations without a governance vote, and normally retains an unallocated withdrawal buffer. Multiply is a leveraged borrowing workflow. This memo evaluates direct, unlevered supply only; neither a curated vault nor Multiply inherits a future direct-reserve approval.
Control, upgrades, and oracle boundary
K-Lend is upgradeable and each lending market has an owner with broad configuration power. Kamino’s own manager documentation says public markets should be owned by a multisig, but “should” is not evidence of the live owner or signer threshold. Recent releases added an Emergency Council, reserve emergency mode, permissioning, withdraw queues and new term-borrow features. Those releases were paired with named audits, but they materially expand the control and code perimeter.
Prices can be composed through Kamino Scope and external providers including Pyth. Risk contributors monitor staleness and cross-provider deviation. The relevant diligence object is the selected reserve’s live oracle graph and fallback behavior, not the generic claim that Kamino has oracle redundancy. The Risk Council can recommend or execute rapid parameter responses; the exact on-chain powers, owners and thresholds must be recorded before approval.
Security and stress record
Kamino publishes its K-Lend, Scope and vault code and a repository of reviews from OtterSec, Sec3, Offside Labs, Ackee, Certora and others. Its security page reports 20 reviews across the product suite, four formal-verification efforts, a $1.5 million Immunefi bounty and no critical findings in the published tally. Those are protocol-reported counts; the decision should map the current deployed K-Lend and Scope versions to individual reports.
The stress record is substantive. Allez Labs reports $20 million of collateral liquidated on 2025-10-10 with zero bad debt, and $19.36 million across 55,649 liquidations on 2026-02-05 and 06, also with zero bad debt. On 2026-05-22 a network-wide Pyth outage stopped several price feeds for hours; the May report states no adverse liquidation or bad debt and says Scope was upgraded afterward. Kamino has no protocol-wide insurance fund, so the clean history is operational evidence, not a funded guarantee.
Exit, utilization, and network dependency
Direct withdrawal is atomic only while the selected reserve has unborrowed cash and permits withdrawals. Near-100% utilization can strand lenders until repayment or liquidation; a higher interest rate is an incentive, not an enforceable exit. Emergency or reduce-only states may preserve withdrawals but their exact effects depend on configuration. Solana liveness and the RPC path are additional execution dependencies even when K-Lend itself is solvent.
The pre-trade test is a simulated and then executable withdrawal at proposed size from the exact reserve, together with 30-day utilization, free cash, largest borrowers, liquidation-at-risk, oracle staleness and cap headroom. For a vault, the docs say a 5% to 10% idle buffer is typical, but that does not apply to direct supply and is not enough to certify a client-sized redemption.
Comparison and decision frame
Against Jupiter Lend, Kamino has a longer public record and richer published stress reporting, while Jupiter’s newer architecture may isolate risks differently. Against Aave or Spark on Ethereum, K-Lend adds Solana runtime and oracle-operational risk but has demonstrated large-scale micro-liquidation throughput. Against a Kamino curator vault, direct supply removes discretionary allocation risk and makes the borrower, collateral and exit perimeter observable.
Reject protocol-wide; the evidence supports a reserve-specific reopen pathway. Reopen for a named USDC or USDT reserve only after its live owner and emergency roles are identified, every oracle dependency is approved, the proposed-size exit works, and utilization and borrower concentration stay within written limits. SOL supply is a staking/market-risk decision and must not be blended with a stable lending sleeve.
Open questions and observable triggers
Unresolved this pass: the exact production market address intended for clients; market owner, Emergency Council and program upgrade authorities and thresholds; current deployment hashes; selected-reserve free liquidity and utilization; top borrower and collateral concentrations; oracle providers and fallback order; reserve factor; and whether any unrecognized insolvency is visible on-chain despite the published zero-bad-debt claim.
Observable reopen tests: proposed-size withdrawal succeeds; 30-day utilization stays below 90%; no borrower represents more than 10% of reserve borrows; no one collateral represents more than 20% of debt capacity without an exception; every live binary maps to a published review; and the authority snapshot is reproducible. Any stale primary oracle beyond its configured bound, bad debt, unexplained emergency mode, or network outage blocking withdrawals for more than one hour forces immediate review.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Kamino risk framework and track record · primary · accessed 2026-08-15
Supports: reserve-specific risk parameters, liquidation and bad-debt boundary, risk monitoring - Kamino security program, audits, formal verification and bounty · primary · accessed 2026-08-15
Supports: reported review counts, formal verification, bug bounty, reported incident history - Kamino K-Lend source and mainnet program ID · primary · accessed 2026-08-15
Supports: K-Lend code, mainnet program identity, deployment verification - Kamino audit-report repository · primary · accessed 2026-08-15
Supports: published audit reports, review scope, K-Lend and Scope coverage - Kamino K-Lend releases and audited feature history · primary · accessed 2026-08-15
Supports: release history, emergency and permission features, audit references - Kamino Lending Vault risks and curator discretion · primary · accessed 2026-08-15
Supports: vault curator discretion, allocation risk, withdrawal buffer distinction - Kamino forum, October 2025 stress-event analysis · primary · accessed 2026-08-15
Supports: October 2025 liquidations, reported zero bad debt, stress performance - Kamino forum, February 2026 stress-event analysis · primary · accessed 2026-08-15
Supports: February 2026 liquidation count and value, reported zero bad debt - Kamino forum, May 2026 risk report and Pyth outage · primary · accessed 2026-08-15
Supports: Pyth outage, reported liquidation outcome, Scope response
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Solana | Approved · limits | crypto-backed | no admin key can seize funds, but stake concentration and a sub-25 Nakamoto coefficient are the standing watch items. |
| Asset | Grade | Who can freeze it |
|---|---|---|
| USDC | freezable | Issued by Circle, backed by bank deposits and T-bills. Circle can and does freeze addresses on request from law enforcement. |
| USDT | freezable | Issued by Tether. Has frozen addresses on request. Reserve composition is less transparently attested than USDC. |
| SOL | sovereign | Solana native asset. No issuer, no freeze — but chain-level liveness history differs materially from Ethereum. |