Aave V3
Lending — Live Aave lending protocol (V3.x). Pooled, cross-collateral markets; stETH/USDC flagship reserves.
AI review
AI assessment
updated 4h ago·Claude (preview)·previewAave V3 is a lending protocol. 15 of 16 risk feeds in the registry report on it. 2 sourced incidents on record. No material change has been detected in the current window.
- Governance: Aave Governance V3 (on-chain, AAVE/stkAAVE voting) governance
- 15 of 16 feeds report on Aave V3. coverage
- Most recent recorded event: Kelp rsETH bridge exploit — collateral exposure. incident
AI-generated summary of facts already in this registry — not a Rails assessment, not a risk score, and not a ranking. Per the project charter, the registry never produces its own composite risk judgement. Verify every point against the linked sources below. This is an illustrative preview of a proposed feature; the content is not live.
Feeds
How feeds see it
Seen through 4 of 4 methodology lenses (rating, dashboard, monitoring, research). A neutral view of who is looking and how — not a risk judgement.
The 15 reporting feeds are split on how fully they assess Aave V3: 10 assess it fully, 5 only partially, and they use different methodologies and scales. We show every position side by side and do not reconcile them into a single verdict — oracle diversity made visible, not adjudicated.
Governance can upgrade pools without a ≥7-day exit window or sufficient Security Council.
Official Aave V3 risk service provider: collateral onboarding, parameter assessments, PT-risk analytics.
Sphere tracks Aave v3 (Core & Prime) rates, liquidations, and risk scores.
5-dimension AI-consensus (page titled Aave V3); spot-check pending.
Aave v3 supply vaults; e.g. WETH 8.76 (Prime), USDT 7.90 (Core).
Vault analytics and risk-adjusted yield across 50+ protocols; exploits, concentration, risk-adjusted APY. Paid structured API.
View sourcePosition-management tooling: live loan-health / safety-ratio tracking and automated liquidation protection for leveraged positions.
View sourceLive per-pool grade; flagship USDC and WETH reserves pass all checks.
A–F pool risk; Aave V3 pools rated around A (top protocol tier). Pre-migration sample — methodology moved into YO Protocol in 2026.
Process Quality Review; ~94% (a 93% figure also appears across sources — confirm on the live PQR). Documentation, testing, audits, admin keys.
Vault-level risk monitoring for Morpho curators: allocation risk and curator behavior.
View sourceIndependent risk rating for DeFi vaults; 300+ subscores across 85+ mechanisms. Open-source.
View sourceListed on the Anticapture governance-security dashboard but no Stage published yet.
Aave's official risk steward 2021–2024 (quarterly risk reviews, parameter recommendations); Gauntlet discontinued the engagement Feb 2024.
Primary Aave risk provider Nov 2022–Apr 2026 (Risk Stewards, Edge Risk Oracles, VaR dashboards); Chaos Labs exited 2026-04-06, LlamaRisk took over continuity.
Institutional-grade credit-risk ratings for DeFi protocols and borrowers. Credora by RedStone; GraphQL API + on-chain attestations (EAS).
Governance
Governance at a glance
- Governance
- DAO (on-chain)
- Core contracts
- Upgradeable
- Pause capability
- Yes
Structural facts, distilled from the sourced control records below — neutral capabilities, not a risk score.
Incidents
After ~$292M of unbacked rsETH was minted via a Kelp DAO bridge exploit, the Aave Guardian froze rsETH and wrsETH markets within the hour. Aave carried the largest exposure (~$196M) and faced an estimated $123M–$230M in potential bad debt; it launched the 'DeFi United' recovery initiative on Apr 23.
A trader borrowed ~92M CRV against USDC on Aave v2 attempting a short squeeze; the liquidation left ~$1.6M of CRV bad debt under thin liquidity. The attempt failed and the Aave DAO subsequently cleared the deficit. Core contracts were not exploited. (Incident predates V3; retained as Aave-lending market-risk history.)
Material risk events, presented verbatim from cited sources — not a Rails assessment.
Audits
| Auditor | Date | Scope | |
|---|---|---|---|
| OpenZeppelin | 2021-11 | Aave V3 core (launch audit) | Report |
| Trail of Bits | 2022-01 | Aave V3 core | Report |
| Certora | 2024-11 | Aave V3.3 (formal verification) | Report |
| Certora | 2025-06 | Aave V3.4 | Report |
Representative public audits, attributed and linked to source — not a Rails assessment, and not a completeness or safety guarantee.