Loopscale
Loopscale lender vaults remain under review. Depositors supply one asset and earn borrower interest; they do not need to borrow or loop their shares. The looping rule does not decide this claim. Lenders bear loan shortfalls through lower vault share value. The April 2025 RateX pricing exploit drained the USDC and SOL Genesis Vaults, although Loopscale reports full recovery and no final deposit loss. Current core audit reports are private, the claimed upgrade threshold lacks an independent account-level check, and sources disagree about whether transactions still need a backend co-sign. No proposed-size exit has been verified. These gaps leave the lender finding unresolved rather than approved or rejected for its name or size.
- Loopscale publishes full core audit reports and a verifiable match between reviewed code and deployed binaries
- Finalized Squads accounts verify the 3-of-5 threshold, members and upgrade delay for both deployed programs
- A verified live withdrawal shows whether backend co-signing still gates exit and reconciles the conflicting audit and security guide
- A proposed-size exit verifies fees, reserves, queue throughput, withdrawal caps and any external idle-fund route
- Any new exploit or oracle failure halts loans or withdrawals, or a vault records realized loan loss
- A withdrawal pause exceeds 24 hours
- Any upgrade authority, oracle configuration, curator, external venue or collateral eligibility changes
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-01.
The research file
Scope and class rules
The fetched DefiLlama yield feed lists 27 Loopscale pools, all on Solana, with single-asset exposure and no reported impermanent loss. Its published adapter reads lender-vault statistics, uses the principal mint as the underlying asset, and reports deposits less deployed loans as TVL. It does not read Loop positions. The loan asset can be USDC, USDG, SOL, JitoSOL, zBTC or another token; a single-asset label does not make every asset a dollar or every vault safe. Loopscale distinguishes these vaults from Loops. Borrowing against a vault share is optional, and that separate debt-funded position can fall under the looping rule. An unborrowed lender deposit has no depositor margin threshold. Borrower liquidation risk remains a lender credit risk, but does not make the lender recursively borrow. Solana has an approved-with-limits chain record, so rejected-chain does not apply. The current below-materiality dossier bars using TVL as a quality verdict or proof of exit capacity. No published class rule rejects all of these lender deposits. Curator allocation within one lending protocol is not by itself proof of changing external venues. However, vaults can route idle funds to outside protocols such as Marginfi. Where a curator can change those venues without a client-enforced allowlist, the delegated-allocation rule can reach that vault. Private-credit or managed fund collateral also needs its own loss and eligibility review. This memo grants no approval to such routes, collateral, deposit assets, Earn Vaults or Loops.
How lenders earn and bear loss
The vault pools one principal asset. Its curator sets eligible collateral, rates, loan sizes and durations, then offers capital through the credit order book. Loans have fixed rates and terms; the vault return changes with utilization, new loan terms, fees and rewards. Deposits mint shares against the strategy net asset value. The interface stakes those shares for rewards; withdrawal burns them to return the principal asset. Borrower interest supplies lending income, while funded reward schedules add a separate return that need not persist. The architecture says a loan shortfall reduces strategy net asset value and falls proportionally on depositors in that vault. Other vaults do not share that loan loss by design, but shared code and upgrade powers can affect several vaults. A stable loan asset does not protect principal when collateral cannot repay the debt. The documents do not establish a standing lender insurance fund or a guarantee that Loopscale will reimburse the next loss. Optional idle-fund lending adds the outside protocol contract and withdrawal risks.
Who controls the vault and its programs
Curators set collateral, loan-to-value limits, liquidation thresholds, rates, durations, buffers, caps and fees. The vault guide states a 24-hour delay for collateral and risk-threshold changes, while rates and origination fees can change at once. The curation guide says outstanding loans keep their initial loan-to-value and liquidation terms until rollover. It also allows rolling withdrawal caps. Curators cannot withdraw deposits directly according to the lender guide, but their settings affect credit losses and available exits. Loopscale selects supported oracle configurations and whitelists liquidators. Its security guide describes automated, backup and manual liquidation services, with outside counterparties sometimes needed for less liquid collateral. These are operating dependencies, not a permissionless exit guarantee.
The official address list names core program 1oopBoJG58DgkUVKkEzKgyG9dvRmpgeEm1AVjoHkF78 and BEAM oracle program beamVVkNmKeXcuZ6zLpC9eM5YgVyAn4Z9xdPrz3gCW2. Finalized Solana RPC reads link the core to program-data account 8KbXd8ATqDQQTozYv2TsCzHUDoiRyWe4DmzHdmJLgdNj and BEAM to HeLvSLkub7mexFKiAfVWR1ERtXZnMYiByRPkdpgAxXKf. Both retain upgrade authority DwBXwJDZ4Av4miT62sEssWJUinkzwkmPPB4Fg3fKEfft. The core authority read used slot 452093335; the BEAM read used slot 452093453. The security guide calls this a Squads 3-of-5 authority. The authority account is system-owned with no account data, which alone proves neither its members nor its threshold. The Squads configuration, signer independence, upgrade delay and emergency powers remain unverified. These upgradeable programs cannot be treated as immutable code merely because the guide calls their logic immutable. No fetched document establishes token-holder control over these powers.
The April 2025 exploit and recovery
Loopscale reports that an April 26, 2025 attacker spoofed the RateX principal-token market program and supplied inflated prices. The integration lacked a program identity check for non-Loop borrowing and had not undergone a formal external audit. Undersecured loans withdrew 5,726,724.97 USDC and 1,211.4 SOL from the USDC and SOL Genesis Vaults. This affected lenders without requiring them to hold a Loop. The team paused protocol functions, then restored repayment and Loop closure on April 26 and Advanced Lending withdrawals on April 30. The post-mortem says recovery completed on April 29, Loopscale was reimbursing a $29,000 conversion discrepancy, and no user deposit incurred a final loss. Vault withdrawals reopened on May 8 with per-user daily limits. Recovery depended on negotiations and incident response; it was not automatic loan repayment or an insurance payout. The patch added RateX program identity checks. The report states that Sec3 and two other auditors reviewed the patch.
The architecture page also says Loopscale has never incurred a bad debt event. That wording does not erase the post-mortem temporary lender losses and paused exits. It may refer to ordinary liquidation shortfalls rather than exploit losses, but the docs do not reconcile the definitions. This review records both statements and does not claim a clean loss history. The fetched materials do not provide a full ledger of later bad debt, pauses or reimbursements, so the final recovery claim remains an issuer report rather than an independent vault-account reconciliation.
Audits and conflicting control evidence
The audit list marks OShield Loopscale V1 dated February 25, 2025 and Sec3 Loopscale V1 dated May 19, 2025 as private. Their full findings and remediation could not be inspected. Public reports cover later integrations and BEAM. The fetched Adevar Labs report dated May 7, 2026 reviews pricing changes for Orca and Raydium positions and replacement of the off-chain signer with an on-chain admin. It records one low-severity issue as fixed and an enhancement as addressed, with no remaining concerns in the reviewed fixes. Its after-fix code commit is 15718a6dd664e816b477794d4d58d7f1c37f398f. This targeted change review does not establish full core audit coverage or that current deployed binaries match the reviewed code. The audit page offers a bug bounty up to $250,000, but excludes curator configuration errors and some third-party integration failures. A bounty is not loss cover.
The security guide still says every program transaction needs the Loopscale AWS Secrets Manager co-sign, and names signer CyNKPfqsSLAejjZtEeNG3pR4SkPhSPHXdGhuNTyudrNs. That conflicts with the May audit description of replacing the off-chain signer. The 2025 post-mortem described co-signing as temporary and said all calls had to pass through the backend. Neither the audit nor the guide proves which instructions require it in the current deployment. This review does not assume either that the signer has been removed or that it still gates every exit. If an exit requires that co-sign, backend failure or refusal can block a wallet even when it holds the shares. The live instruction path remains an open control question.
Exit liquidity and capacity
The lender guide describes instant withdrawal when the buffer has funds, otherwise a paid immediate exit or a queue until funds return. The curation guide also permits hourly and daily caps and refinancing of maturing loans to other lenders when buffers run low. Cash must come from reserves, loan repayment, refinancing or an external idle-fund venue. Fees, exhausted reserves, missing refinancing demand, bad collateral prices, paused withdrawals or signer failure can reduce proceeds or delay exit. A loan maturity is not a firm withdrawal deadline because refinancing itself needs a willing lender.
The fetched Loopscale vault statistics distinguish deposits from deployed principal. The DefiLlama adapter reports their difference, not gross supply, as pool TVL. That accounting value is not proof of cash executable by a client: the statistics omit the full exit route, external reserves, pending queues, caps and transaction permissions. No proposed client or aggregate position size, live withdrawal simulation, queue throughput or stressed secondary sale has been verified. The quoted small immediate-exit fee has no verified amount in this review. The 2025 withdrawal pause shows that recovered principal can still be inaccessible for days.
Comparison and decision
Aave and Kamino provide the relevant lending comparison. Aave v3 adjusts rates with pool utilization and limits withdrawals to available unborrowed liquidity. Loopscale instead offers curator-set fixed-term loans and tailored collateral choices. Fixed loan terms do not give either lender an unconditional exit. That changes rate and credit selection, but also adds specialized collateral pricing, curator settings, loan refinancing and possible outside idle-fund lending. Direct Advanced Lending can remove the pooled curator choice while retaining Loopscale code, oracle, upgrade and exit dependencies; this vault review does not approve that separate product. A higher displayed APY cannot resolve missing control or exit evidence. Full recovery and later audits weigh in Loopscale’s favor. The prior unaudited deployment, private core reports, conflicting signer descriptions, unverified multisig configuration and missing position-size exits prevent a favorable finding today. The lender verdict is under review. Actual debt-funded Loops remain outside the approved structures under the looping rule, independently of this lender finding.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Loopscale: lender vault guide · primary · accessed 2026-09-30
Supports: single principal asset, borrower interest, optional outside idle lending, buffer fee and queue exits, borrowing against shares, curator limits - Loopscale: vault mechanics · primary · accessed 2026-09-30
Supports: fixed loan terms, 24-hour collateral timelock, immediate rate changes, fees, reward schedules - Loopscale: vault architecture · primary · accessed 2026-09-30
Supports: share accounting, proportional lender loss, bad debt claim, optional external idle yield - Loopscale: vault curation · primary · accessed 2026-09-30
Supports: curator authority, withdrawal caps, refinancing, loan parameters until rollover, whitelisted liquidators - Loopscale: security controls · primary · accessed 2026-09-30
Supports: claimed Squads threshold, authority address, backend co-sign, liquidation services, upgrade powers - Loopscale: deployed addresses · primary · accessed 2026-09-30
Supports: core program, BEAM program, Solana mainnet - Solana mainnet RPC: finalized program and authority accounts · primary · accessed 2026-09-30
Supports: getAccountInfo jsonParsed finalized, core program-data 8KbXd8ATqDQQTozYv2TsCzHUDoiRyWe4DmzHdmJLgdNj at slot 452093335, BEAM program-data HeLvSLkub7mexFKiAfVWR1ERtXZnMYiByRPkdpgAxXKf at slot 452093453, shared upgrade authority DwBXwJDZ4Av4miT62sEssWJUinkzwkmPPB4Fg3fKEfft, authority system-owned with zero data at slot 452093338 - Loopscale: April 2025 pricing incident post-mortem · primary · accessed 2026-09-30
Supports: unaudited RateX integration, spoofed program identity, USDC and SOL lender losses, reported recovery and reimbursement, April 29 recovery, May 8 limited vault withdrawals, temporary co-sign - Loopscale: audit list and bug bounty · primary · accessed 2026-09-30
Supports: private OShield and Sec3 core reports, public integration reports, bounty amount and exclusions - Adevar Labs: May 7, 2026 oracle integration audit · primary · accessed 2026-09-30
Supports: pages 4 and 5 targeted scope, off-chain signer replacement, one low issue fixed, reviewed code commit, remediation - DefiLlama: yield feed · primary · accessed 2026-09-30
Supports: 27 loopscale-lending pools, Solana, single-asset exposure, no reported impermanent loss, deposit symbols - DefiLlama: Loopscale lender-vault adapter · primary · accessed 2026-09-30
Supports: lender-vault source, principal mint, TVL is deposits less deployed principal, base and reward APY split - Loopscale: live lender-vault statistics · primary · accessed 2026-09-30
Supports: POST page 0 pageSize 100, vault identities, deposits and deployed principal, base and reward returns - Aave: v3 overview · primary · accessed 2026-09-30
Supports: lending comparison, utilization rate curve, liquidity-limited withdrawal - Kamino: lending product documentation · primary · accessed 2026-09-30
Supports: Solana lending comparison
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Solana | Approved with limits | Governed, no freeze | no admin key can seize funds, but stake concentration and a sub-25 Nakamoto coefficient are the standing watch items. |