Suilend
This registry rejects Suilend because it has no disclosed legal entity and has admitted a past bad-debt event whose size is unknown. Built by the team behind Solana’s Save, formerly Solend, Suilend is a live, growing, Aave-like overcollateralized lending market on Sui with real spending on security. Zellic and OtterSec audited it for its March 2024 launch, and it has an active $250,000 bug bounty. But this review found no legal entity name or incorporation jurisdiction anywhere in Suilend’s documentation or accessible terms. That is a real disclosure gap that this registry does not waive for an otherwise well-regarded product. More important, Suilend’s own documentation says that ”in the past, bad debt in main pool has been filled via top-ups from the Insurance fund.” This is a real, admitted loss event that this review could not date, size, or otherwise verify from any source. The record therefore cannot be treated as clean or the loss as bounded.
- A named legal entity and incorporation jurisdiction are publicly disclosed
- The past bad-debt event referenced in Suilend’s own documentation is dated, sized, and explained in a dedicated disclosure
- The Suilend DAO’s current authority scope over pausing markets and adjusting risk parameters is confirmed
- Twelve consecutive months with no further bad-debt event drawing on the insurance fund
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-19.
The research file
Mechanism
Suilend runs a standard overcollateralized lending market on Sui. Users supply assets to shared pools and borrow against posted collateral up to a loan-to-value threshold. Interest curves respond to use, and the protocol liquidates positions that fall below their collateral limits. Pyth and Switchboard oracles provide prices. The wider Suilend brand has grown beyond lending to include SpringSui, for liquid staking, and STEAMM, an automated market maker in beta since February 2025. The name ”Suilend” now covers several distinct products under one brand. This memo covers the core lending market only.
The undisclosed legal entity
This review found no legal-entity name, jurisdiction of incorporation, or governing-law clause in Suilend’s documentation or on any reachable terms-of-service page. Both attempted paths returned not-found errors. This is a real gap that the registry requires Suilend to close before it can approve a position, despite the product’s otherwise reasonable technical and audit disclosures.
The unquantified bad-debt admission
Suilend’s own documentation states that ”in the past, bad debt in main pool has been filled via top-ups from the Insurance fund.” This confirms that at least one loss event occurred and that a protocol reserve covered it instead of passing it straight to depositors. This review found no date, dollar amount, cause, or dedicated post-mortem for the event in any source it could access. An insurance-fund backstop that the protocol has already used presents a meaningfully different risk from one that has never been tested. This registry cannot approve a position without knowing the size of the event or how close it brought the fund to exhaustion.
Control and redemption
Suilend says governance is moving to a Suilend DAO gated by the SEND token, which launched December 2024. Its documentation lists two DAO-controlled addresses, but available sources did not make their current powers clear. This review could not determine whether they can already pause markets or change risk parameters, or whether they will gain those powers only under a future form of governance. Redemption uses standard Aave-style mechanics. A user can withdraw only the available, unborrowed supply in a given pool.
Track record and comparison
Mainnet launched March 2024; the SEND token in December 2024; STEAMM entered beta in February 2025. Zellic and OtterSec audited the core protocol in March 2024, and Suilend maintains an active $250,000 critical-vulnerability bug bounty. Tracked TVL is consistent with an active, growing market. That is the opposite path from Homora V2, which was researched with this entry and confirmed dead. Against Aave and Compound, Suilend uses the same basic design. Its main differences are its chain, Sui’s Move-based object model rather than the EVM, and its shorter, roughly 2.5-year live history. Those facts must be weighed against the undisclosed entity and the admitted bad-debt event described above.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Suilend documentation — protocol overview · primary · accessed 2026-08-19
Supports: team pedigree from Save/Solend, SpringSui and STEAMM product suite, bad-debt insurance-fund admission, audit and bug-bounty disclosure - DefiLlama — Suilend protocol data · secondary · accessed 2026-08-19
Supports: TVL history confirming live, growing status - Rekt News — hack and exploit leaderboard · secondary · accessed 2026-08-19
Supports: no catalogued major exploit found for Suilend by name - Save (formerly Solend) — team background · secondary · accessed 2026-08-19
Supports: Suilend team pedigree from Solana’s Save/Solend - Suilend — SEND token and DAO governance announcement · primary · accessed 2026-08-19
Supports: December 2024 SEND token launch, transition to Suilend DAO governance
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Sui | Rejected | Issuer can freeze | freeze and seizure are demonstrated: standing validator deny lists began freezing the Cetus exploiter’s ~$162M within about 80 minutes, and a Foundation-organized vote later moved the frozen funds without the owner’s keys. |