Aave Horizon
We reject Horizon because its governance remains unclear and it shares a system that has suffered a serious failure, not because Horizon itself has recorded bad debt. Horizon is a permissioned instance of the audited Aave V3.3 codebase. It lets institutions borrow stablecoins, including USDC, RLUSD, and GHO, against allowlisted tokenized RWA collateral from Superstate USTB and USCC, Centrifuge JTRSY and JAAA, Circle USYC, VanEck VBILL, and others. This review found no Horizon-specific bad debt or exploit. LlamaRisk manages risk parameters, and Chainlink NAVLink supplies prices. These are real institutional safeguards. But Aave’s own public statements conflict over who controls Horizon. Aave’s blog says, ”Aave Labs does not control or operate any version of the Aave Protocol,” while its governance forum says Aave Labs holds an ”Executive role” over Horizon’s risk parameters, oracle configuration, and asset listings. That leaves accountability unresolved, and a delegate has separately disputed it in a funding-vote controversy. Horizon shares its codebase, oracle infrastructure, and DAO governance with Aave’s core markets. Those markets suffered roughly $177-200M of bad debt in April 2026 after a LayerZero-bridge exploit let attackers mint unbacked rsETH and use it as collateral. This registry has already cited that type of failure in rejecting LayerZero V2 itself. Horizon TVL had also fallen 28% month-over-month in a July 2026 snapshot. These are lasting facts, not a short-lived gap in an otherwise clean file.
- Aave Labs’ authority over Horizon is stated consistently across Aave’s own public materials, resolving the ”does not control the Protocol” versus ”Executive role” tension
- Horizon demonstrates no correlated exposure through a subsequent Aave-ecosystem-wide exploit or bad-debt event
- TVL and active-loan volume recover and stabilize, ending the multi-month decline documented through July 2026
- A primary Certora (or equivalent) audit report specific to the Horizon deployment is published and reviewed
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
Horizon uses the same audited Aave V3.3 smart contracts as Aave’s core markets, but runs as a separate deployment with its own risk parameters. Access differs on each side. The RWA collateral side requires permission from each issuer through its own KYC process and on-chain allowlist. Superstate, Centrifuge, Circle, VanEck, and the other issuers each handle their own onboarding. The stablecoin supply side, which supports USDC, RLUSD, and Aave’s native GHO, is permissionless and open to any wallet. Only wallets that hold allowlisted RWA collateral may borrow against it. Reports also say that only ”qualified market makers” may carry out liquidations, rather than any permissionless liquidator.
The governance accountability gap
The Aave governance forum calls Horizon ”a white label instance based on the existing Aave DAO framework.” The Aave DAO keeps smart-contract upgrade, or ”superadmin,” authority through on-chain governance. Aave Labs holds an ”Executive role” over risk-parameter settings, oracle management, and asset listings, working with LlamaRisk as an independent risk provider. Elsewhere, Aave’s own public blog says that ”Aave Labs does not control or operate any version of the Aave Protocol on any blockchain network.” That claim conflicts directly with the governance forum’s account of Aave Labs’ Executive role over Horizon. No public source resolves the conflict. A delegate, ACI, has also published a disputed audit of Aave Labs’ accountability and wallet transparency around a Horizon-adjacent funding vote. The audit says that one delegation supplied 57% of the ”FOR” votes that passed the measure.
The shared vulnerability surface
On 2026-04-18, attackers compromised LayerZero Labs’ own operational infrastructure. This registry has already used that incident to reject LayerZero V2. The attackers forged attestations and minted roughly $292M of unbacked rsETH. They then used it as collateral in Aave’s core Ethereum and Arbitrum markets, causing roughly $177-200M of bad debt, concentrated in the WETH reserve, and a $6.6B, 44-46% fall in Aave’s wider TVL within days. No source found by this review confirms that Horizon assets were directly affected. Still, Horizon uses the same underlying V3.3 codebase, shares Aave DAO governance, and relies on oracle infrastructure from the same system. Horizon’s design does not isolate it from the type of failure that caused this loss. Only the choice of collateral meant that a Horizon asset was not the one exploited that day.
Track record and current trajectory
Horizon launched 2025-08-27 and passed $50M in deposits within days. It grew to roughly $540M by November 2025 and roughly $600M in net deposits, while GHO utilization peaked near 97% in early 2026. Elsewhere, this registry treats that level of utilization as a warning of liquidity stress, not as a sign of health. Token Terminal’s July 2026 report said Horizon TVL averaged $350M that month, down 28% month-over-month after five straight months of decline. Active loans fell 30% month-over-month during the same period, though they showed early signs of recovery. Secondary sources refer to a Certora audit of Horizon’s V3.3-based infrastructure and cite a GitHub repository. This review could not retrieve the primary audit report itself to confirm its scope or findings.
Comparison and decision
Core Aave V3 markets allow permissionless supply and borrowing. Horizon adds issuer-enforced permission for collateral and risk parameters built for RWAs, but it keeps the same contracts, oracles, and governance links involved in Aave’s largest loss event of 2026. Compared with the undercollateralized credit structures used by Maple Finance and Centrifuge, Horizon’s design, which uses overcollateralized RWAs as collateral, is more conservative. That comparison does not answer the questions about governance, accountability, and disclosure found here. Reopen the review only after Aave Labs states its actual authority over Horizon consistently and Horizon shows that it can withstand a system-wide Aave exploit without suffering linked exposure.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Aave — how Horizon is built for institutions · primary · accessed 2026-08-17
Supports: permissioned collateral / permissionless supply structure, risk management partners - Aave governance forum — ARFC: Horizon’s RWA instance · primary · accessed 2026-08-17
Supports: Aave Labs Executive role, Aave DAO superadmin authority, governance framework - CoinDesk — Aave Labs debuts Horizon to let institutions borrow stablecoins against tokenized assets · secondary · accessed 2026-08-17
Supports: launch date, product description - Forbes — inside Aave’s sudden $200M bad-debt crisis · secondary · accessed 2026-08-17
Supports: April 2026 LayerZero-linked exploit, bad debt figures, TVL drop - CoinDesk — Aave records $6 billion TVL drop as Kelp hack exposes structural risk · secondary · accessed 2026-08-17
Supports: systemic TVL impact, shared vulnerability surface - The Defiant — Aave’s Horizon RWA market nears $540 million, adds VanEck treasury fund · secondary · accessed 2026-08-17
Supports: growth trajectory, GHO utilization, collateral asset list
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |