KETJU Research

← The Register

Dollar lending

Linx App

Not approved Runs only on a chain that failed review
Issued
2026-08-16
Last confirmed
2026-08-16
Next check due
2026-11-16
Chains
Alephium

Linx App’s surveyed product is isolated overcollateralized lending on Alephium: lenders supply one loan asset, borrowers post a separate collateral asset, and liquidators repay unhealthy debt for collateral. That is lending rather than AMM-LP inventory. The only surveyed deployment is on Alephium, which has not passed Ketju chain review, so the shared version-1 rejected-chain dossier controls before the separate approximately $0.060M size, market, oracle, liquidation, audit and exit questions.

The research file

Mechanism and product perimeter

Linx creates an independent subcontract for each collateral-token and loan-token market. Lenders supply only the loan asset and earn utilization-based interest; borrowers deposit collateral and borrow up to an immutable LLTV; liquidators repay debt and seize discounted collateral after LTV crosses LLTV. The depositor is not supplying a two-asset AMM position, so the prior amm-lp basis was false.

Deployment, authority and measurement

The DefiLlama adapter discovers market-created events from the Linx factory at vQcfta4Mm32L7Xsb7tYF2rrR76JWxjNv3oia8GPK6x71, then counts each market’s collateral plus idle loan tokens and separately reports borrowed loan assets. The 2026-08-16 API read showed approximately $59,968 of TVL and $21,923 borrowed, exclusively on Alephium. Permissionless market creation is bounded by immutable collateral, loan token, LLTV, oracle and protocol-approved IRM parameters, but users still must underwrite each market rather than the aggregate app label.

Oracle, liquidation, audit and exit applicability

Market creators choose an immutable oracle from an oracle-agnostic interface and an approved IRM; the documentation warns users to verify source, staleness, scaling and audit history. Withdrawals require idle loan liquidity, while collateral volatility, interest accrual, oracle failure or failed liquidation can create bad debt. Inference AG published a Linx-on-Alephium assessment, but an audit does not establish every permissionlessly created market, asset, oracle, utilization state or proposed-size exit.

Why the chain dossier decides

All currently investable Linx lending markets and every measured balance settle on Alephium. No approved-chain deployment offers the same surveyed client claim without that settlement dependency. The shared version-1 rejected-chain dossier therefore controls. Reopen only if Alephium passes a versioned Ketju chain review or Linx launches a material independently verified approved-chain deployment; then inspect exact markets, contracts, assets, LLTVs, oracles, IRMs, utilization, bad debt, audit scope and proposed-size withdrawals.

Class rule

The rejected chain class is outside the approved structures, so every protocol in it is not approved until the rule changes. The rule is about the structure, not an adverse finding about this protocol, and it is not a client instruction. The events that would reopen it are listed with the memo.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.

ChainVerdictControlControl constraint
The memo is public. Monitoring connects the research to positions clients actually hold and flags evidence changes for advisor review. $49 per advisor per month, first 14 days free. Start the trial.