TL;DR
Aave V3 is over-collateralized lending. You deposit, someone else borrows against collateral, and borrower interest is the yield. The core contracts have never been directly exploited, the audit registry is the deepest in lending and now runs through v3.6, and governance sits behind real timelocks (7 days for core logic, 1 day for risk parameters) with Guardian multisigs that can pause and freeze. That half is intact and was re-verified this run.
The other half is what 2026 did to Aave. There were two separate fund-loss events, not one, and the people who built and watched the system left in between them.
In March, Aave's own oracle broke. A misconfiguration in CAPO, the cap layer the protocol uses to harden Chainlink prices for liquid staking tokens, priced wstETH about 2.85% below market and wrongly liquidated roughly 34 accounts. Damage estimates run from $21.7M to $27M depending on the source. No bad debt hit the protocol and affected users were compensated, but this was not imported risk. It was Aave's own risk pipeline, and the bad parameter reached production one block after it was recommended, with liquidations following within minutes.
In April, an exploit of Kelp's rsETH LayerZero bridge minted unbacked rsETH. An attacker supplied it as collateral on Aave and borrowed roughly $190M of WETH and wstETH, crystallizing an estimated $92M of bad debt on the Ethereum WETH reserve and more across the L2s. Aave's code did exactly what it was built to do and the Guardian froze the affected markets. But WETH depositors were exposed to a loss from collateral they never chose, and the repair came from an external coalition and a federal judge rather than from Aave's own backstop.
Between those two events, Aave lost its bench. BGD Labs, the near-exclusive technical contributor since 2022, ended its engagement on 1 April, seventeen days before the rsETH exploit. Chaos Labs, primary risk manager since November 2022, announced its exit on 6 April. The Aave Chan Initiative wound down by July. Reporting frames all three as symptoms of a single protracted governance power struggle, and the departing governance provider named Aave Labs' control over the governance token supply on the way out.
Read the TVL recovery carefully, because it is easy to misread as confidence returning. Aave v3 TVL is $13.966B, up about 19% from the $11.73B printed in the July report. ETH gained about 19% over the same window. Nearly all of the monthly rise is the price of the collateral, not new deposits. The 90-day view is kinder: USD TVL is roughly flat since early May while ETH fell about 20.5%, which implies the underlying deposit base did grow in unit terms. Both readings sit inside a much larger hole. Today's TVL is about 54% of where it stood the day before the exploit and under a third of the October 2025 peak.
Checklist
Audits & contracts. Re-pulled this run rather than carried forward. The aave-dao/aave-v3-origin audits registry holds 40 reports: OpenZeppelin, Trail of Bits, PeckShield, Certora, ABDK and SigmaPrime on v3.0; PeckShield, SigmaPrime and Certora on v3.0.1 and v3.0.2; Certora, MixBytes and a Cantina competition on v3.1; Certora, Oxorio, Pashov and Enigma on v3.2; StErMi, Certora, Sherlock and Oxorio on v3.3; Enigma, Certora, StErMi and Blackthorn on v3.4; Certora, ABDK, StErMi and MixBytes on v3.5; Blackthorn and Certora on v3.6 in November 2025. Two corrections to the prior report. Blackthorn was missing from the named list, and the registry extends two releases past v3.4. One removal: Code4rena does not appear in this registry, and the Code4rena contests that exist are for Lens Protocol and for PoolTogether's Aave v3 integration, neither of which is an audit of Aave V3 core. The Immunefi bounty is live at up to $1M, launched 18 October 2023 and last updated 17 April 2026. The core lending logic has still never been directly exploited. The honest caveat is forward-looking: the newest audit is nine months old, V4 is in progress, and BGD Labs, which led or heavily contributed to nearly every major technical subsystem, is gone.
Admin control. Downgraded to yellow. The formal machinery is real and was re-verified. Core-logic upgrades go through the Long Executor on a 7-day timelock, risk parameters and listings through the Short Executor on a 1-day timelock, and no single multisig can upgrade the core. The emergency layer is more specific than the prior report said: a Protocol Emergency Guardian holding the EMERGENCY_ADMIN role is a 4-of-7 multisig that can freeze (the lighter mode) and pause (the heavier one), and a separate Governance Emergency Guardian is a 5-of-9 multisig of community-elected signers that can veto a malicious payload.
Two things pull this off green. First, the 1-day figure is not the whole story for risk parameters. A delegated Risk Stewards path, now migrating to automated Risk Agents under an AgentHub, adjusts supply and borrow caps and related parameters within on-chain bounds without a community vote. March 2026 showed what that means in practice: a cap recommendation was executed one block later and cost 34 users real money before any human could intervene. Bounded automation is a reasonable design, but a depositor should know that some risk parameters move in seconds, not a day.
Second, governance is under visible strain. Three service providers exited in 2026: BGD Labs (engagement ended 1 April, citing disagreements over v3 and v4 direction and changes in DAO structure), Chaos Labs (announced 6 April, citing three years of operating losses, contributor attrition, and a risk-methodology disagreement over V4, after a budget gap between a $5M offer and a stated $8M need), and the Aave Chan Initiative (concluding by July with a four-month transition, its lead citing Aave Labs' control over the governance token supply). Proposals still move through the public ARFC path and the Guardian's April freeze proves the pause works under stress, so this is not a broken governance. It is a thinner one than it was a year ago.
Oracle. Downgraded to yellow. Chainlink feeds are wrapped in Aave's CAPO, which caps liquid staking token growth rates and pins stablecoins to a ceiling. The prior report and the draft both treated CAPO purely as a hardening. It is also a realized failure surface. On 10 March 2026 an offchain process tried to update the wstETH snapshot ratio to a rate from seven days earlier, but an onchain constraint limits increases to 3% every three days, so the snapshot ratio and its timestamp desynced. CAPO then reported roughly 1.1939 against a market rate near 1.228, about 2.85% low, and roughly 10,938 wstETH across about 34 accounts was liquidated in E-Mode positions. Liquidators captured around 499 ETH. Aave recovered about 141.5 ETH through BuilderNet rebates plus about 13 ETH in fees and committed up to 345 ETH from the DAO treasury to make users whole. The protocol itself took no bad debt.
That event does not make the oracle layer bad, and it is worth saying that Aave found it, disclosed it and paid for it. But a dimension where users lost money five months ago through the protocol's own configuration is not green. The oracle was correctly not the failure point in April, and no oracle incident has surfaced since. CAPO's live configuration was not re-pulled this run.
Liquidity & exit. Deep in absolute terms at $13.966B, still the top of the lending market. It is also about 54% of the $25.668B sitting there on 17 April, the day before the exploit, and about 31% of the $45.444B October 2025 peak. Exit is utilization-dependent: a fully borrowed reserve means waiting on repayments, and the WETH reserve was frozen for new borrows during the April stress. Note that the freeze power sits with a 4-of-7 multisig and acts immediately. New this month, a 29 July ARFC from LlamaRisk would retire 50 low-adoption reserves plus 21 matured Pendle PTs across eleven V3 deployments ($85.3M supplied, $11.5M debt) and wind down six deployments outright, Sonic, Scroll, zkSync, Metis, Soneium and Aptos, carrying another 25 reserves ($12.8M supplied, $4.1M debt), for $98.1M supplied and $15.6M debt in total. Positions are not force-closed, but if you sit on one of those deployments, plan an exit instead of assuming the market stays.
Yield: real vs emission. Real. Borrower interest paid into the reserve, not token emissions. GHO, the native over-collateralized stablecoin, adds protocol revenue on top.
Holder concentration. Still dark. Etherscan's top-holders endpoint returned the Pro-only error again on 2026-08-05, so the distribution is unverified for another month. What did refresh: AAVE circulating supply is 15,422,150.53 of a 16,000,000 max, up from roughly 15.18M in July, at about $91.35 per token for a market cap near $1.409B. This matters more than usual, because governance sets risk parameters and approves listings, which is exactly the surface that failed in April, and because the departing governance provider raised token-supply control as its stated reason for leaving. A concentrated voter base would be a real concern and we cannot currently see whether there is one.
Track record. No direct contract exploit in several years. Three bad episodes, not the two the prior report listed. The 2022 CRV short squeeze (about $1.6M, later cleared by the DAO via AIP-144). The March 2026 CAPO misconfiguration ($21.7M to $27M of wrongful liquidations across about 34 accounts, no protocol bad debt, users compensated). And the April 2026 rsETH event (an estimated $91.79M crystallized on the Ethereum WETH reserve under the incident report's scenario 1, about 1.54% of that aToken supply, more across the L2s, up to about $230.1M under an L2-isolated model).
The pattern needs correcting too. The July report said the code holds and Aave inherits the risk of whatever collateral governance lists. April fits that. March does not. In March nothing external failed; Aave's own automated risk pipeline pushed a wrong number and the protocol liquidated solvent users. Both failure modes are real and they are different. The April make-whole is complete, with backing fully restored on 26 May. The legal tail is not: a creditor claim over roughly $71M of recovered Arbitrum ETH was still undecided on the merits as of the most recent reporting found, and nothing later surfaced in this run's news or X searches.
Worst case
There are two, and they are unrelated.
The first is collateral contagion. An asset Aave lists loses its backing through a flaw outside Aave (a bridge, a wrapper, a depeg), someone borrows against collateral that is now worthless, and the shortfall lands as bad debt on the reserve you deposited into. This happened in April 2026 on the WETH reserve, and the run that followed pulled about $11.86B out of the protocol in eight days while ETH moved only about 1.4%, which tells you it was depositors leaving rather than marks falling.
The second is that the protocol's own risk automation misprices your collateral and liquidates you while you are solvent. That happened in March 2026. You do not get a warning, and the window between a bad parameter landing and liquidation was one block plus minutes. Compensation came afterward, by governance decision, not by contract.
The designed backstop for the first case is Umbrella. It slashes staked aTokens (aUSDC, aUSDT, aWETH) or GHO once a pool's deficit clears a per-asset offset, routes the proceeds to the Aave Collector, and isolates risk to the specific asset and network staked. Umbrella is progressively replacing the legacy stkAAVE and stkABPT Safety Module, which stay active during the transition with slashing to be disabled once Umbrella reaches sufficient scale. In April, reporting put Umbrella's capacity at roughly $80M to $100M against a modeled deficit of $123.7M to $230.1M. It did not have to carry that alone: an Aave-led coalition called DeFi United (Lido, EtherFi, Ethena, Mantle, Compound, LayerZero and others) committed about $300M, restored the rsETH backing across five tranches ending 26 May, and an emergency court order unlocked the frozen Arbitrum ETH. Whether Umbrella actually slashed anyone, and whether aWETH stakers took a haircut before the coalition arrived, we could not confirm this run.
There is no equivalent backstop for the second case. Oracle-driven wrongful liquidation is repaid, if at all, out of recovered funds and the DAO treasury by vote.
The lesson has not changed and has gotten sharper. In the tail, your protection may depend on an ecosystem rescue that nobody owes you and no contract guarantees. Position sizing, avoiding exotic-collateral markets, and keeping health factors well clear of the liquidation threshold (so a 2.85% oracle error cannot reach you) are the mitigations you actually control.
Bottom line
Caution, held from July, but for more reasons than July gave.
On contract security, audit depth and governance formalism this is still one of the safest venues in DeFi. The registry is genuinely the deepest in lending and now runs through v3.6, the timelocks are real, the core has never been breached, and the yield is real borrower interest. The trajectory since the last report is good: backing fully restored, no new incident in the last month, a binding four-layer risk framework that names bridging risk as its own layer and sets a three-verifier minimum on any bridge carrying Aave exposure, and a first enforcement action clearing out low-adoption reserves and six zero-revenue chains.
It is still not a solid, and the case is stronger than the July report made it. Two separate realized fund-loss events hit in 2026, four and five months ago, on surfaces ordinary depositors use. One was imported collateral risk, the other was Aave's own oracle configuration. The April repair came from outside the protocol and the internal backstop was smaller than the modeled hole. Aave lost its entire V3 technical and risk bench in the same quarter, and the departures are reported as one governance power struggle rather than three coincidences. A roughly $71M creditor claim over the recovered ETH appears to still be open, which means those funds are not unambiguously Aave's. The new framework is two months old and its first big cleanup has not been executed on-chain. And the market has not really come back: strip out ETH's price move and depositors sit roughly where they did in May, far below April.
Prefer Core and Prime with blue-chip collateral, stay out of the long tail, size for collateral contagion, keep buffer against an oracle error rather than sitting near the liquidation line, and re-check the court status, the Umbrella slashing outcome, who now holds V3 incident response after BGD's retainer, and holder concentration next month.
Data appendix
- TVL: $13,965,738,414 (DeFiLlama, aave-v3 slug, 2026-08-05, confirmed twice via MCP get_tvl and api.llama.fi). 30d: $12.890B on 2026-07-06 (+8.3%). 90d: $14.049B on 2026-05-07 (-0.6%). ATH: $45.444B on 2025-10-07, so today is 30.7% of peak. 2026 low $11.345B on 2026-06-07 (confirmed as the year's minimum). Pre-exploit $25.668B on 2026-04-17, down to $13.812B by 2026-04-25.
- Month-over-month basis, stated explicitly: the July report printed ~$11.73B, giving +19.1%. The API's current backfilled value for 2026-07-01 is $11.631B, giving +20.1%. The ~$100M difference is intraday pull timing or a DeFiLlama revision. This report uses ~19% throughout, against the figure the July report actually printed.
- TVL move vs collateral price: ETH went $1,569.83 to $1,868.94 between 2026-07-01 and 2026-08-05 (+19.05%) while TVL rose ~19%, so the monthly gain is essentially all collateral price rather than returning deposits. Over 90 days ETH fell 20.5% while USD TVL was flat at -0.6%, implying the deposit base grew in unit terms. Approximate, because Aave TVL is a mixed basket and not pure ETH. April run: -$11.856B over eight days (17 to 25 April) against an ETH move of only -1.4%.
- AAVE token: circulating 15,422,150.53 of a 16,000,000 max, price $91.35, market cap $1.4086B (CoinGecko, 2026-08-05).
- Audits (re-pulled 2026-08-05, aave-dao/aave-v3-origin/audits, 40 files): OpenZeppelin 2021-11-01, Trail of Bits 2022-01-07, PeckShield 2022-01-14, Certora 2022-01-24, ABDK 2022-01-27, SigmaPrime 2022-01-27 (v3.0); PeckShield, SigmaPrime, Certora (v3.0.1/3.0.2, Dec 2022 to Apr 2023); Certora 2024-04-30, MixBytes 2024-05-02, Cantina contest 2024-06-02 (v3.1); Certora, Oxorio 2024-09-12, Pashov 2024-09-15, Enigma 2024-09-30 (v3.2); StErMi 2024-10-22, Certora 2024-11-07, Sherlock 2025-01-22, Oxorio 2025-01-29 (v3.3); Enigma 2025-05-13, Certora and StErMi 2025-06-11, Blackthorn 2025-06-12 (v3.4); Certora 2025-07-14, ABDK and StErMi 2025-07-17, MixBytes 2025-07-18 (v3.5); Blackthorn 2025-11-16, Certora 2025-11-18 (v3.6). Plus MixBytes on StataToken and Certora on Collector. Immunefi bounty up to $1M, launched 18 Oct 2023, last updated 17 Apr 2026, with a $50k minimum for critical findings.
- Audit corrections vs the July report: Blackthorn added (v3.4 and v3.6, previously omitted). Registry extends through v3.6, not "through v3.4". Code4rena removed: it is absent from the registry, and the Code4rena contests that exist are "Aave Lens" (Feb 2022, Lens Protocol) and "PoolTogether Aave v3" (Apr 2022, PoolTogether's integration), neither an Aave V3 core audit. Cantina confirmed present.
- Admin / governance (re-verified 2026-08-05): Aave Governance V3. Long Executor 7-day timelock (core logic), Short Executor 1-day timelock (risk params, listings). Protocol Emergency Guardian is a 4-of-7 multisig holding EMERGENCY_ADMIN, with Freeze (lighter) and Pause (heavier) modes and a failsafe role for cross-chain messaging in Emergency Mode. Governance Emergency Guardian is a 5-of-9 multisig of community-elected signers (Zapper, Paraswap, Standard Crypto, DeFi Saver, Balancer, Chainlink, Lido, Certora) that can veto a malicious payload. No single multisig can upgrade core.
- Risk Stewards fast path (new to this report): a delegated Risk Stewards mechanism, migrating to Chaos Risk Agents under an AgentHub, adjusts supply and borrow caps and related risk parameters within on-chain bounds without a community vote, with Risk Guardians able to veto during a timelock. On 2026-03-10 this path executed a cap recommendation one block after it was made. The 1-day Short Executor timelock does not cover this route.
- Service-provider exits (new to this report): BGD Labs ceased Aave DAO work when its engagement ended 1 April 2026 after ~4 years of near-exclusive focus, citing disagreements over v3/v4 direction and DAO structure, and proposed a $200k two-month security retainer (1 April to 1 June 2026) covering incident response for v3, governance and Umbrella. Chaos Labs, primary risk manager since Nov 2022, announced its exit 6 April 2026 (2025 budget $3M, Aave Labs offer $5M, stated need $8M, about 5.6% of protocol revenue), citing three years of operating losses, contributor attrition and a V4 risk-methodology disagreement. Aave Chan Initiative announced non-renewal, concluding by July 2026 with a four-month transition, with Marc Zeller citing Aave Labs' control over the governance token supply. Reporting characterizes the three as one protracted power struggle.
- March 2026 oracle incident (new to this report): 10 March 2026, Ethereum Core and Prime instances. An offchain process attempted to set the wstETH snapshot ratio to a rate from seven days earlier, but an onchain constraint limits increases to 3% per 3 days, desyncing the snapshot ratio from its timestamp. CAPO reported ~1.1939 against a market rate of ~1.228, about 2.85% low, wrongly liquidating ~10,938 wstETH across ~34 accounts in E-Mode. Loss estimates: $21.7M (Cryptonomist), ~$26M (The Block, CryptoBriefing), ~$27M (CoinDesk, Cointelegraph). Liquidators captured ~499 ETH; ~141.5 ETH recovered via BuilderNet rebates, ~13 ETH in liquidation fees, up to 345 ETH committed from the DAO treasury. No protocol bad debt. Pipeline: Chaos Labs Edge Risk recommended a cap below market, BGD's AgentHub executed one block later, liquidations followed within minutes. DeFiLlama's hacks registry logs this as 2026-03-12, "CAPO Oracle Misconfiguration", $862,000 with $862,000 returned, classification "Ecosystem"; that net figure is not reconciled with the $21.7M to $27M gross liquidation volume in press reporting.
- Oracle: Chainlink plus CAPO, rate caps on LSTs and fixed caps on stablecoins. DeFiLlama lists Chainlink as the sole primary oracle. Live CAPO config (which assets carry which caps) not re-pulled this run; the July report recorded caps on wstETH, rsETH, weETH, ezETH, osETH and USDC, USDT, EURC, RLUSD.
- Holder concentration: refresh. Etherscan tokenTopHolders on 0x7Fc66500c84A76Ad7e9c93437bFc5Ac33E2DDaE9 returned NOTOK, "API Pro endpoint required", again on 2026-08-05.
- Backstop: Umbrella slashes staked aTokens (aUSDC, aUSDT, aWETH) or GHO past a per-pool offset (documented example: USDT staking carries a 100,000 USDT offset the DAO covers first), sends proceeds to the Aave Collector, and isolates risk per asset and network. It progressively replaces stkAAVE and stkABPT, which remain active during the transition with slashing to be disabled once Umbrella reaches sufficient scale. April 2026 reporting put capacity at about $80M to $100M against the modeled $123.7M to $230.1M deficit. Whether slashing executed, and any haircut to aWETH stakers: refresh. The July report's "$184M stkAAVE Safety Module, up to 30% slashable" was not re-verified and may be superseded by the Umbrella migration.
- April 2026 event, settled items: Kelp rsETH LayerZero bridge exploit on 18 April (confirmed by the DeFiLlama hallmark "KelpDAO hack" dated 2026-04-18), roughly $292M of rsETH minted unbacked. About 89,567 rsETH was supplied as Aave collateral and the attacker borrowed about 82,650 WETH plus 821 wstETH (about $190M). Aave's incident report modeled about $123.7M of total bad debt under uniform socialization (scenario 1), of which about $91.79M on the Ethereum WETH reserve, about 1.54% of that aToken supply at the time, and up to about $230.1M under an L2-isolated model (scenario 2). Those are April-dated modeled figures, not current exposure. Aave contracts were not compromised; OpenZeppelin's post-mortem is titled "Zero Bugs Found". Guardian froze rsETH on 18 April and WETH on 20 April. DeFi United committed about $300M (secondary reporting; CoinDesk reported $160M raised of ~$200M needed as of 26 April) and completed restoration with a final tranche of 20,373.72 rsETH on 26 May, 116,131.72 rsETH across five tranches.
- April 2026 event, open item: 30,765.67 ETH (about $71M) frozen by the Arbitrum Security Council. A restraining notice was served on 1 May by counsel for terrorism judgment creditors holding $877M in unpaid claims against North Korea. On 8 May Judge Margaret Garnett (SDNY) modified but did not vacate that notice, permitting an Arbitrum governance vote to move the ETH to an Aave LLC wallet with Aave LLC bound by the notice as if served directly, and shielding voters from liability. Note that headlines framing this as Aave "winning" describe a procedural motion, not the merits: the court left the underlying dispute between exploit victims and the terrorism judgment holders unresolved. No later decision surfaced in this run's news search or in an X search bounded 2026-06-25 to 2026-08-05, both of which returned nothing. Treat as open on the strength of absent contrary reporting rather than a docket check. refresh with a court docket check next month.
- Recent-news scan (since 2026-07-01): No new exploit, oracle failure or bad-debt event on Aave found, via news search plus an X search over 2026-06-25 to 2026-08-05. Two developments. (1) A four-layer Aave Risk Framework proposed by LlamaRisk in June 2026: Asset Risk (with a $50,000 minimum bug bounty floor for critical findings regardless of TVL), Bridging Risk (mandatory minimum of three independent verifiers on any route carrying Aave exposure), Monitoring and Automated Risk Oracle Systems, and Chain Risk. Binding at four decision points: onboarding, quarterly due-diligence reviews, material parameter changes, and deprecations. Stani Kulechov framed non-compliant assets as subject to offboarding. (2) A 29 July 2026 LlamaRisk ARFC to deprecate 50 low-adoption reserves and 21 matured Pendle PTs across eleven V3 deployments ($85.3M supplied, $11.5M debt) and wind down Sonic, Scroll, zkSync, Metis, Soneium and Aptos, carrying another 25 reserves ($12.8M supplied, $4.1M debt), totalling $98.1M supplied and $15.6M debt. Still at ARFC stage, which precedes a binding on-chain vote.
- Prior incident: 2022 CRV short squeeze, about $1.6M of bad debt, cleared by the DAO via AIP-144.
Maintained monthly. Methodology: DeFi Research Instruction v2.