Suilend
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON AN UNDISCLOSED LEGAL ENTITY AND AN UNQUANTIFIED PAST BAD-DEBT EVENT. Suilend, built by the team behind Solana’s Save (formerly Solend), is a live, growing, genuinely Aave-like overcollateralized lending market on Sui with real security investment: Zellic and OtterSec audits from its March 2024 launch and an active $250,000 bug bounty. But no legal entity name or incorporation jurisdiction was found anywhere in Suilend’s documentation or accessible terms — a genuine disclosure gap this registry does not waive for an otherwise well-regarded product. More consequentially, Suilend’s own documentation acknowledges ”in the past, bad debt in main pool has been filled via top-ups from the Insurance fund” — a real, admitted loss event this review could not date, size, or otherwise verify from any source, which is not the same as a confirmed clean or bounded track record.
- A named legal entity and incorporation jurisdiction are publicly disclosed
- The past bad-debt event referenced in Suilend’s own documentation is dated, sized, and explained in a dedicated disclosure
- The Suilend DAO’s current authority scope over pausing markets and adjusting risk parameters is confirmed
- Twelve consecutive months with no further bad-debt event drawing on the insurance fund
The research file
Mechanism
Suilend runs a standard overcollateralized lending market on Sui: users supply assets to shared pools and borrow against posted collateral up to a loan-to-value threshold, with utilization-responsive interest curves and liquidation of undercollateralized positions, priced via Pyth and Switchboard oracles. The broader Suilend brand has expanded beyond lending into SpringSui (liquid staking) and STEAMM (an automated market maker, beta since February 2025), meaning ”Suilend” now spans several distinct products under one brand — this memo covers the core lending market specifically.
The undisclosed legal entity
No legal-entity name, jurisdiction of incorporation, or governing-law clause was found in Suilend’s documentation or in any reachable terms-of-service page — both attempted paths returned not-found errors. This is a real gap this registry requires closed before certifying a position, independent of the product’s otherwise reasonable technical and audit disclosure.
The unquantified bad-debt admission
Suilend’s own documentation states plainly that ”in the past, bad debt in main pool has been filled via top-ups from the Insurance fund” — confirming at least one loss event has occurred and was covered by a protocol reserve rather than falling on depositors directly. No date, dollar amount, cause, or dedicated post-mortem was found for this event in any source this review could access. An insurance-fund backstop that has already been drawn upon is a meaningfully different risk profile than one that has never been tested, and this registry cannot certify a position without knowing how large the event was or how close the fund came to being exhausted.
Control and redemption
Governance is stated to be transitioning to a Suilend DAO gated by the SEND token, launched December 2024, with two DAO-controlled addresses referenced in documentation whose current authority scope — whether they can already pause markets or adjust risk parameters, or only will be able to in a future governance state — was not resolved from available sources. Redemption follows standard Aave-style mechanics: liquidity-dependent withdrawal capped by a given pool’s available, unborrowed supply.
Track record and comparison
Mainnet launched March 2024; the SEND token in December 2024; STEAMM entered beta in February 2025. Zellic and OtterSec audited the core protocol in March 2024, and Suilend runs an active $250,000 critical-vulnerability bug bounty. Tracked TVL is consistent with an actively growing, currently live market — the opposite trajectory from Homora V2, researched alongside this entry and confirmed dead. Against Aave and Compound, Suilend is architecturally a like-for-like peer differentiated mainly by chain (Sui’s Move-based object model rather than the EVM) and by a shorter, roughly 2.5-year live history against which to weigh the undisclosed entity and the admitted bad-debt event above.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Suilend documentation — protocol overview · primary · accessed 2026-08-19
Supports: team pedigree from Save/Solend, SpringSui and STEAMM product suite, bad-debt insurance-fund admission, audit and bug-bounty disclosure - DefiLlama — Suilend protocol data · secondary · accessed 2026-08-19
Supports: TVL history confirming live, growing status - Rekt News — hack and exploit leaderboard · secondary · accessed 2026-08-19
Supports: no catalogued major exploit found for Suilend by name - Save (formerly Solend) — team background · secondary · accessed 2026-08-19
Supports: Suilend team pedigree from Solana’s Save/Solend - Suilend — SEND token and DAO governance announcement · primary · accessed 2026-08-19
Supports: December 2024 SEND token launch, transition to Suilend DAO governance
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Sui | Rejected | freezable | freeze and seizure are demonstrated: standing validator deny lists began freezing the Cetus exploiter’s ~$162M within about 80 minutes, and a Foundation-organized vote later moved the frozen funds without the owner’s keys. |