Blend Pools V2
Blend provides lending infrastructure on Stellar. Anyone can use it to create an isolated lending market, and v2 adds pool-specific reserves, a backstop and Dutch auctions for liquidation and bad debt. DefiLlama records about $137.5M supplied and $53.0M borrowed on Stellar at the survey. Those features do not fix the settlement-layer control that led us to reject Stellar. This chain decision does not allege that Blend is insolvent or insecure.
- The Stellar chain verdict changes
- Deploys meaningful liquidity on a chain the registry approves
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-15.
The research file
Reachability, not protocol quality
The rejection concerns the settlement layer, not the application. Every state transition, oracle update, liquidation and withdrawal depends on validator or sequencer operation, finality, bridge security and emergency controls that audited contracts cannot put under the protocol team’s control. Quoted protocol TVL and DEX depth may remain visible on-chain even when users cannot exit because the chain cannot finalize or the bridge route is impaired. The same protocol on an approved deployment would receive its own individual review.
Mechanism
Blend v2 lets pool creators choose reserves and parameters. Suppliers fund isolated lending pools; public Dutch auctions handle borrower liquidations, bad debt and backstop interest. Each pool has its own backstop, which is not a guarantee from Blend.
Control and evidence
Pool creators and backstop participants set market economics, while Stellar ultimately settles every contract and issued asset. Blend publishes v2 contracts, audits and a Certora formal-verification report. Those controls matter at the protocol level, but they cannot override Stellar issuer authorization, clawback or protocol-level freeze powers.
Exit consequences
A supplier may withdraw only the reserve liquidity then available; utilization or bad debt can delay access to the funds. Any Stellar-issued asset received remains subject to its issuer flags, and CAP-77 gives the validator quorum an implemented way to freeze accounts, trustlines and contract data.
Why the class rule decides
The rejected-chain dossier controls the decision before we review any isolated pool because every deposit, auction and withdrawal settles on Stellar. Review reopens only if Blend builds material liquidity on an approved chain or the Stellar verdict changes.
Class rule
The rejected chain class is outside the approved structures, so every protocol in it is not approved until the rule changes. The rule is about the structure, not an adverse finding about this protocol, and it is not a client instruction. The events that would reopen it are listed with the memo.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Blend v2 Docs — protocol and pool-creator overview · primary · accessed 2026-08-15
Supports: protocol, pool-creator overview - Blend v2 Docs — liquidation and bad-debt auctions · primary · accessed 2026-08-15
Supports: liquidation, bad-debt auctions - Blend v2 — official audit repository · primary · accessed 2026-08-15
Supports: official audit repository - Stellar Protocol — CAP-77 asset-control framework · primary · accessed 2026-08-15
Supports: CAP-77 asset-control framework
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Stellar | Rejected | Issuer can freeze | freeze is native at every level: issuers hold revocation and clawback flags on their assets, and since Protocol 26 the validator quorum can vote to freeze specific accounts and trustlines on-chain (CAP-77). |