KETJU Research

← The Register

Other

EtherFi Borrowing Market

Rejected The evidence weighs against it
Issued
2026-08-19
Last confirmed
2026-09-25
Next check due
2027-09-26
Research basis
Individual research
Chains
OP Mainnet · Mixed control

This registry rejects EtherFi’s Borrowing Market because its live status conflicts with its documentation and its borrow side is permissioned. The market is an ether.fi-operated Aave v4 instance that backs ether.fi Cash, the company’s crypto-collateralized Visa card. It has several sound controls, including a price-cap adapter whose owner-reset function is wired so nobody can call it, “for us, for our multisig, for anyone,” according to ether.fi’s own documentation. But every public page that describes this product carries a “coming soon” banner, even though roughly $190M was already supplied and roughly $25M was already borrowed on Optimism at the time of this review. This live conflict between the product’s stated status and its actual on-chain activity is enough for this registry to reject it. Borrowing is restricted to ether.fi Cash account holders. It is not open to third-party lenders as the supply side is. This review also confirmed no separate legal entity name for this specific product.

The research file

Mechanism

Every ether.fi user receives a non-custodial Safe at signup. Assets in that Safe can serve as collateral in an ether.fi-managed Aave v4 instance. Eligible collateral includes stablecoins, weETH, ether.fi’s own Liquid vault receipt tokens, and even tokenized equities, but users can currently borrow only USDC and ETH. The borrow side is permissioned: “only ether.fi Safes can borrow assets, but anyone can supply to Liquidity Hub.” Third parties can therefore supply liquidity without permission, but only ether.fi Cash account holders can draw debt, either directly or automatically through card-purchase “Borrow Mode.” Live on-chain collateral consists mainly of stablecoins and ether.fi’s own Liquid stable vault, not weETH, despite the market’s restaking-adjacent branding.

The documentation-status inconsistency

Every Borrow-related documentation page checked by this review carries a banner stating that the feature is “coming soon.” These pages include the technical documentation, borrowing power and liquidation, lending market parameters, and price feeds. At the same time, live on-chain data shows roughly $190M supplied and roughly $25M borrowed on Optimism. This registry cannot certify a product that its own operator marks as not yet launched while it holds real client funds. That gap alone is enough for rejection, regardless of the technical quality of the underlying mechanism.

Control, a genuine positive finding alongside real gaps

An Owner Safe multisig transaction controls price-feed and asset-listing changes. No automated risk process makes them. The price-cap adapter would let an operator raise the ceiling on how much an asset’s price may grow for collateral purposes. Ether.fi documents it as wired to an access-control interface that can never validate a reset call successfully, which makes the setter “permanently unreachable… for us, for our multisig, for anyone.” That is a real safeguard set in code. But this review found no specific legal entity name for the Borrowing Market itself beyond the general Inc./Ltd. jurisdictional split in ether.fi Cash’s cardholder agreements. DefiLlama’s audit field shows zero, although ether.fi’s own security page discloses a Certora review of the lending gateway (July-August 2026) and a Paladin review of the price-feed contracts (July 2026). DefiLlama understates the real coverage here, but the entity gap remains.

The April 2026 exploit and correlated restaking risk

Ether.fi’s own incident page directly addresses the April 18, 2026 Kelp DAO/LayerZero rsETH bridge exploit. It states that no ether.fi systems were compromised and weETH remained fully backed throughout because weETH’s bridge routes require a 2-of-3 or 3-of-3 quorum of independent verifiers, unlike Kelp’s single-verifier configuration. But ether.fi took precautionary action. It paused all Liquid vaults for roughly a day, disabled cross-chain bridging for five days, and ran active deleveraging workstreams to help borrow-market positions repay debt while borrow rates were elevated. The incident confirms that the Borrowing Market saw real stress-driven deleveraging activity even though weETH itself was not directly compromised. This outcome was materially different and less severe than the direct bad-debt events this registry has documented elsewhere from the same exploit class.

Comparison and decision

Aave and Compound markets that also accept weETH as collateral are fully open on the borrow side and governed by independent DAOs. By contrast, EtherFi’s Borrowing Market is a vertically integrated, first-party product. Ether.fi alone sets its risk parameters without an external governance check, and only the company’s own Cash-account holders may borrow. That concentration might be an acceptable tradeoff for faster and more conservative parameter setting. It cannot outweigh the fact that every one of the product’s own documentation pages still labels it as unreleased while it holds real, live client funds.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.

ChainVerdictControlControl constraint
OP MainnetRejected Mixed control Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit.
The memo is public. Monitoring connects the research to positions clients actually hold and flags evidence changes for advisor review. $49 per advisor per month, first 14 days free. Start the trial.