Aave
RISK: LOW
Aave is a long-established decentralised non-custodial liquidity protocol (DeFi) launched in 2020, operated by Aave Labs. It is one of the most prominent protocols in DeFi with over six years of uninterrupted operation, trillions in lifetime deposits, extensive independent security auditing, and a well-documented governance framework. The main risk factors identified are the upgradeable proxy contract architecture, top-10 holder concentration at 43%, and the Cayman Islands legal domicile which carries its own regulatory considerations.
This report is published free of charge and stays published. It was produced because
somebody paid for the investigation to happen — we never disclose who requested a
report, and paying for one does not influence what it says.
What we could not check. These are gaps in our collection, not findings about
the project. The affected sub-signals were excluded from the score and from the maximum —
the project is not penalised for them.
- The /tokenomics and /token pages returned 404 — no tokenomics breakdown, total supply figure, or vesting schedule was available from the website. These may exist in external documentation (e.g., governance forum, Aave DAO documentation) that was not retrieved.
- The /whitepaper page returned 404; any supply or emission schedule that may have been published there was not assessed.
- The docs.aave.com subdomain was not fetched; detailed technical documentation including AAVE token supply parameters may reside there and was not assessed.
- The full text of the Terms of Service was truncated in the retrieval log at the IPFS hosting section; arbitration seat, governing law clause, and any restricted jurisdiction list were not fully assessed.
- Individual audit report PDFs linked from the security page were not fetched; the existence of links was confirmed but the content and findings of individual audits were not reviewed.
- No GitHub repository URL was surfaced in the retrieved pages; repository activity was inferred from the audit cadence and product release announcements rather than directly observed commit history.
- The Aave Governance forum and Snapshot space referenced on the security page were not retrieved; on-chain governance activity was not directly assessed.
On-chain contract data
AAVE · Ethereum ·
0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9
- Upgradeable proxy — logic can be replaced
- Top-10 holders control 43% of supply
- Contract source is verified on the explorer
- Liquidity is NOT locked
These facts are read from the contract and override anything the project's
own material claims. See the live on-chain check →
Scores by category
Team & Transparency
15/20
identities verifiable 7 · track record 5 · public presence 3
- Stani Kulechov is named as CEO of Aave Labs on the About page (https://aave.com/about), and is independently verifiable across numerous external sources including conference appearances, media coverage, and a documented history of founding ETHLend (later rebranded to Aave) — this constitutes strong independent verifiability.
- The About page documents Aave's origin from ETHLend and its debut in 2020, which is consistent with independently verifiable blockchain and media records, providing a traceable institutional history.
- A dedicated /team page returned 404, and no broader team roster with individual verifiable profiles is surfaced on the retrieved pages; only the CEO is named, leaving the broader team unverifiable from website content alone.
- The About page references open positions and values but does not link individual team members to external verifiable profiles (LinkedIn, GitHub, social media); public presence is partially inferred from the CEO's known public activity rather than from site content.
- Aave Labs is described as the 'original author and contributor' to the protocol, consistent with on-chain and GitHub history, but no individual contributor profiles or GitHub handles are surfaced in the retrieved content.
Tokenomics
13/20
supply documented 3 · holder concentration 4 · unlocks disclosed 2 · token function 4
- The homepage and FAQ describe the AAVE token's function clearly: governance voting on Aave Improvement Proposals (AIPs), staking in the Safety Module as a backstop for shortfall events, and earning staking incentives — this constitutes a documented, substantive token utility beyond speculation.
- No total supply figure, emission schedule, or tokenomics breakdown page was found across all retrieved pages; the /tokenomics and /token URLs returned 404. Supply documentation is absent from the website content retrieved.
- On-chain verified facts show 202,991 holders, which is a meaningful distribution for a DeFi governance token; however, top-10 holders control 43% of supply, representing meaningful concentration risk even for a mature protocol — this is a moderate concern.
- No vesting or unlock schedule for team, investor, or treasury allocations was found in any retrieved page. The /whitepaper URL returned 404. Unlock disclosures are absent from the website as retrieved.
- The docs page (https://aave.com/docs) references an 'Ecosystem — AAVE' section and GHO stablecoin integration, suggesting broader documented token context in technical documentation, but the specific tokenomics content was not rendered in the retrieval log.
Technology
19/20
source verified 4 · audit published 5 · repo activity 5 · stage matches claims 5
- Contract source is verified on-chain (confirmed by verified on-chain facts for 0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9 on Ethereum), satisfying the source_verified criterion fully.
- The security page (https://aave.com/security) lists an extensive, timestamped audit record across 65 audits and AI-assisted reviews, from multiple independent firms including Trail of Bits, OpenZeppelin, Certora, Sigma Prime, PeckShield, ChainSecurity, Sherlock, Spearbit, MixBytes, Quantstamp, Ackee, and others — spanning V3 through V4 — with firm names and dates published. Links to 'View Contracts' and downloadable PDF security assessment are cited.
- SOC 2 Type II certification is listed as of March 2026, with the attestation letter available on demand, representing a significant institutional-grade security validation beyond smart contract audits.
- Development activity is consistent with the claims: V4 launched on Avalanche per the About page news, Aave V3.7/3.6/3.5/3.4 audit records show continued iterative development through 2025–2026, and the documentation page references active SDK versions and multi-chain deployments — consistent with a live, actively developed protocol.
- The product stage matches claims: six years of claimed uninterrupted operation is consistent with independently verifiable on-chain history; $3.46T lifetime deposits and live multi-chain deployments are consistent with publicly verifiable on-chain data from Aave's smart contracts.
Red Flags
18/20
contract mechanics 7 · copied content 4 · impossible claims 3 · manufactured activity 4
- The AAVE token contract (0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9) is confirmed non-mintable, non-pausable, with no blacklist function and 0% buy/sell tax — these are favourable mechanics. However, the contract is deployed as an upgradeable proxy, which means the contract logic can be modified by the controlling address or governance multisig. This is a material structural capability that users should be aware of, even in a governance-controlled context.
- No evidence of copied or plagiarised documentation or site content was identified across the retrieved pages; the content is consistent with Aave's own long-standing public documentation style and references original research and audits.
- The homepage presents a chart comparing Aave USDC supply APY against T-Bills and savings accounts showing Aave outperforming. While labelled as 'based on historical rates' and not stated as a guarantee, the presentation of growth of a hypothetical $10,000 investment could be read as performance promotion. This is not an impossible claim, but warrants user attention as rates are variable and past performance is not indicative of future results.
- The claim of '$3.46T Lifetime deposits' and '6+ years of uninterrupted operation' are consistent with independently verifiable on-chain data and are not assessed as impossible; they are specific and checkable.
- No evidence of manufactured social media activity, purchased followers, or fabricated engagement was identified from the retrieved website content. Partner integrations cited (Kinexys by J.P. Morgan, MetaMask, Kraken, Ethena) are independently verifiable public relationships.
Legal
15/20
entity disclosed 5 · jurisdiction 3 · terms and privacy 4 · regulatory posture 3
- The operating entity 'Aave Labs' is named throughout the website, Terms of Service, and Privacy Policy as the entity responsible for the Services. The Terms of Service (https://aave.com/terms-of-service, updated January 6, 2026) explicitly identifies 'Aave Labs' as 'we,' 'us,' or 'our.' However, no company registration number, full legal name, or registered address is provided in the retrieved content.
- The Privacy Policy (https://aave.com/privacy-policy, updated July 15, 2026) references compliance with 'the Data Protection Act (as amended) of the Cayman Islands,' identifying the Cayman Islands as the governing jurisdiction for data protection purposes. This is the only jurisdictional identifier found in the retrieved content; no registered office address or company number is provided.
- Terms of Service and Privacy Policy are project-specific, detailed, and recently updated (January 6, 2026 and July 15, 2026 respectively). The Legal Hub page (https://aave.com/legal) lists separate ToS and Privacy Policies for Aave.com, Aave App, and Aave Pro, indicating deliberate legal structuring rather than generic boilerplate.
- The regulatory posture adopted in the Terms of Service — stating that Aave Labs 'does not control or operate any version of the Aave Protocol,' is not an intermediary, agent, advisor, or custodian, and has no fiduciary relationship with users — is a common legal positioning for DeFi protocol front-ends. This positioning carries regulatory uncertainty, particularly in jurisdictions that may characterise the Interface's role differently from how the Terms characterise it.
- The Terms include a mandatory binding arbitration clause and class-action waiver, which is a substantive legal term users should review. No specific arbitration seat or governing law clause was visible in the retrieved portion of the Terms.
Key risks
- Upgradeable proxy architecture on the AAVE token contract (0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9): the contract logic can be modified through the controlling governance or multisig mechanism. While Aave's on-chain governance includes timelocks and a Guardian veto, the structural capability for contract modification exists and depends on governance integrity.
- Top-10 holder concentration at 43% of total supply: a relatively small number of addresses hold significant governance and economic weight. If protocol-controlled addresses (Safety Module, treasury) are excluded and this concentration reflects external holders, it creates governance centralisation risk.
- Regulatory uncertainty: Aave Labs' legal positioning as a non-controlling, non-custodial entity may not align with how regulators in major jurisdictions (EU, US, UK) characterise the front-end interface operator. The Cayman Islands domicile provides limited regulatory clarity for users in regulated markets.
- Absence of tokenomics disclosure on the website: no total supply, emission schedule, or vesting information was found across all retrieved pages, making it impossible to assess dilution risk or insider unlock schedules from the official website alone. Users must consult external sources for this information.
- Variable yield presentation: the homepage displays a historical yield comparison chart in a manner that, while labelled as historical, may be interpreted as indicative of future returns; DeFi yields are variable and subject to market conditions, protocol risk parameters, and governance changes.
Questions to ask before investing
- What is the full legal name, company registration number, and registered address of Aave Labs, and in which jurisdiction is it formally incorporated (the Privacy Policy references the Cayman Islands Data Protection Act, but the corporate domicile is not confirmed in retrieved content)?
- Who are the keyholders of the upgradeable proxy contract for the AAVE token, and what governance process governs any upgrade — specifically, can the 5-of-9 Guardian multisig or Aave Labs unilaterally initiate an upgrade, or does an upgrade require full on-chain governance approval with timelock?
- What is the current total supply of AAVE, the full allocation breakdown (team, investors, ecosystem, treasury), and the remaining vesting or unlock schedule for any non-circulating supply?
- Which entities or wallets constitute the top-10 holders (43% of supply) — are these protocol-controlled addresses (Safety Module, treasury, liquidity mining contracts) or externally held addresses, and what is the governance voting weight distribution?
- What is the governing law and arbitration seat specified in the Terms of Service (the retrieved text was truncated before these provisions), and what jurisdictions are restricted from using the Interface?
- Has Aave Labs received any regulatory inquiries, enforcement actions, or formal legal proceedings from any jurisdiction, and if so, what is their current status?
- What is the process and threshold for a protocol upgrade that would affect the AAVE token contract's upgradeable proxy — specifically, what timelock applies and which Guardian or governance body can veto such an upgrade?
Scored by the published
ChainSift methodology: five categories
of 20 points each. Sub-signal scores are summed by code, not chosen by a language model.
This is risk assessment, not investment advice, and it describes what was observable on
the date shown. Projects change.