
Credit · Lending · AAVE
Aave is a multichain non-custodial lending protocol for supplying, borrowing, and earning interest. The Aave DAO governs parameters, listings, and emissions; Aave Labs is the primary development company.
Savings for Everyone: open-source non-custodial liquidity protocol.
AAVE price
$122.48
+1.7% 24h
Latest data · 15 min delay
Typed risks scored by severity, likelihood and impact, with the incident record behind them.
45
severity-weighted points across 15 typed risks · 4 critical
assessed Apr 2026Market
14· 4 risks · 2 critical
Technological
9· 3 risks
Counterparty
13· 4 risks · 2 critical
Governance
7· 3 risks
Regulatory
2· 1 risk
Every score is recomputed at render time from the typed risks below; nothing is hand-assigned. Each risk contributes its severity weight (critical 4 · high 3 · medium 2 · low 1) to its category; the headline number is the sum across all categories. Bars scale to this entity's highest category score. Scores are not comparable across tags because a permissionless-market protocol concentrates technological risk while an institutional-credit protocol concentrates counterparty and regulatory risk, and a single league table would misrepresent both.
Market 4 × → 14
Technological 3 × → 9
Counterparty 4 × → 13
Governance 3 × → 7
Regulatory 1 × → 2
Aave's risk profile has shifted decisively from smart contract risk toward collateral issuer and counterparty risk. The core lending logic has held up, but the protocol's willingness to list high-LTV liquid restaking collateral means that a failure anywhere in a partner's minting or bridging stack becomes an Aave solvency event, which is exactly what happened with Kelp and LayerZero in April 2026 (LlamaRisk). The protocol's crisis machinery works: Guardian freezes were executed within hours and roughly 54 percent of the shortfall was recovered (TokenLogic). What is weak is loss absorption. Umbrella was calibrated against historical deficits measured in millionths of a percent of borrows (Aave docs), the treasury is over half AAVE and buybacks are paused (Aave governance), and the residual gap is being closed by a voluntary coalition rather than by protocol capital. Layered on top is a freshly activated V4 hub and spoke architecture with cross-hub credit lines and model-based oracle adapters (Aave governance), which raises technological risk during the hardening period. Net posture: high severity, issuer-driven, with mitigation depending on discretionary emergency powers and external goodwill.
Market4
Technological3
Counterparty4
Governance3
Regulatory1
5 documented incidents · Jun 2022 to 18 Apr 2026 · how the protocol behaved under stress, with sources.
Jun 2022
The Harmony bridge hack impaired bridged collateral held in non-Ethereum Aave deployments.
DetailsThe Harmony bridge hack impaired bridged collateral held in non-Ethereum Aave deployments.
Outcome: Scattered pockets of unrecoverable bad debt remained on affected V2 and V3 deployments.
SourceNov 2022
An actor borrowed roughly 47 million USD of CRV against USDC on Aave V2 Ethereum in an attempted short squeeze.
DetailsAn actor borrowed roughly 47 million USD of CRV against USDC on Aave V2 Ethereum in an attempted short squeeze.
Outcome: The position was liquidated at a loss, leaving about 1.6 million USD of bad debt on V2 Ethereum.
SourceJul 2023
The Multichain bridge collapsed, permanently impairing bridged assets used as Aave collateral.
DetailsThe Multichain bridge collapsed, permanently impairing bridged assets used as Aave collateral.
Outcome: Further stranded bad debt pockets on non-Ethereum deployments, quantified by the DAO in 2026.
SourceApr 2026
The rsETH shortfall of about 163,183 ETH left Aave with a large unbacked collateral position across Ethereum, Arbitrum and Mantle.
DetailsThe rsETH shortfall of about 163,183 ETH left Aave with a large unbacked collateral position across Ethereum, Arbitrum and Mantle.
Outcome: Recoveries of about 87,955 ETH, roughly 54 percent, from Kelp, the Arbitrum Security Council and the attacker's own Aave and Compound positions; residual gap of about 75,081 ETH covered by DeFi United pledges, a Mantle facility and a requested DAO donation.
Source18 Apr 2026
An attacker extracted 152,577 rsETH from the Kelp LayerZero lockbox by poisoning a single verifier node, supplied about 116,500 rsETH into Aave and borrowed WETH against it.
DetailsAn attacker extracted 152,577 rsETH from the Kelp LayerZero lockbox by poisoning a single verifier node, supplied about 116,500 rsETH into Aave and borrowed WETH against it.
Outcome: Guardian froze rsETH and wrsETH across eleven deployments from 18:52 UTC and also froze WETH on six markets; Aave TVL fell from 26.4 billion USD to roughly 18 billion USD.
SourceEvent-type chips are categorised by event type against the risk taxonomy (a documented presentation mapping, not a dataset assessment). Amounts are the dataset's published figures; missing values were never published.