# \[ARFC\] Deploy Aave v3 on X Layer

**URL:** <https://governance.aave.com/t/arfc-deploy-aave-v3-on-x-layer/23175>\
**Category:** Governance\
**Created:** [September 26, 2025, 5:33am UTC](https://governance.aave.com/t/arfc-deploy-aave-v3-on-x-layer/23175 "2025-09-26T05:33:05Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![LlamaRisk](https://dub1.discourse-cdn.com/flex013/user_avatar/governance.aave.com/llamarisk/32/12865_2.png) [@LlamaRisk](https://governance.aave.com/u/LlamaRisk)\
**Post date:** [February 17, 2026, 10:29pm UTC](https://governance.aave.com/t/arfc-deploy-aave-v3-on-x-layer/23175/11 "2026-02-17T22:29:33Z")

</div>

## xSOL Asset Review

### **Summary**

LlamaRisk supports onboarding xSOL to the Aave V3 X Layer instance. The SOL wrapper is managed centrally by OKX, with underlying SOL custodied in a locked reserve address. Key access control roles are assigned to MPCs managed by the X Layer team. Withdrawals are facilitated by OKX, introducing permissioned barriers for redemptions.

Onchain supply is currently worth $1.5M, with 2 pools supplying the only sources of DEX liquidity. As with other xAssets, liquidity will be bootstrapped to support the onboarding, with modest initial supply caps intended to introduce the Solana-native asset.

The asset’s recent deployment offers little insight into its volatility or growth, and lacks a Chainlink price feed. The X Layer team has informed us that a Chainlink SOL/USD price feed is still under development. We therefore recommend onboarding contingent on the price feed being deployed to support efficient pricing.

> **Full Asset Evaluation**
>
> ## **1. Asset Fundamental Characteristics**
> 
> ### **1.1 Asset**
> 
> **[xSOL](https://web3.okx.com/explorer/x-layer/token/0x505000008de8748dbd4422ff4687a4fc9beba15b)** is a cross-chain wrapped SOL representation, backed 1:1 by native SOL, custodied by OKX. xSOL is minted when users send SOL to the designated xSOL reserve address or when a user withdraws SOL from their OKX account to a supported network address (currently only deployed on X Layer). Underlying SOL is redeemed back into user accounts when xSOL is deposited on the OKX Exchange.
> 
> ### **1.2 Architecture**
> 
> xSOL minting, burning, and transferring are controlled through OKX’s MPC system. SOL deposits are held in OKX’s SOL reserve address, which consists of SOL secured for xSOL. The reserve holding underlying SOL can be viewed through Solana explorers, like [Solscan](https://solscan.io/account/9LpZPYWtMu6bm8cir7VmDwnv53s492VGdSQDcfrpdeSs), and via a [public dashboard](https://www.okx.com/xassets). The reserve is a locked address that is controlled, which strictly stores segregated SOL.
> 
> The core components of xSOL include:
> 
> - xSOL: an ERC-20 contract for X Layer wrapped SOL. Inherits from `xToken` contract.
> - **[Reserve Address](https://solscan.io/account/9LpZPYWtMu6bm8cir7VmDwnv53s492VGdSQDcfrpdeSs)**: Solana-based address that stores underlying xSOL.
> - **[Mint & Burn Controller](https://web3.okx.com/explorer/x-layer/address/0x65e392dda704bb2ccfee7fa62d0945094dd2037a)**: MPC that controls xSOL minting and burning operations.
> - **[TimelockController](https://web3.okx.com/explorer/x-layer/address/0x9fe97748c1f357350492214c7ecdd5cb7452f00a/contract)**: Manages sensitive admin functions.
> - **[Authorized Receiver](https://web3.okx.com/explorer/x-layer/address/0x5075ff68a0efb54db13423ad924bd680327d305e)**: Dedicated address that receives newly minted xSOL
> - **[Admin](https://web3.okx.com/explorer/x-layer/address/0xa07ae4bdfa7ba8bc0e8a8525bcc768300a8970bb)**: MPC that manages updates and controls transfer restrictions/blacklisting.
> - **[ProxyAdmin](https://web3.okx.com/explorer/x-layer/address/0xe07020a77abbd24aeaae6709e9f03044d97d1c54)**: Can modify contract parameters or implement xSOL upgrade.
> 
> An internal verification engine monitors and enforces the minting and burning of 1:1 SOL from OKX exchange addresses.
> 
> A Chainlink PoR is planned to support reserve attestations, which will reference the public reserve address linked above. The X Layer team indicated that this initial setup is planned to be updated in the future to incorporate a 3rd party auditor.
> 
> ### **1.3 Tokenomics**
> 
> A mint and burn mechanism is used on X Layer for xSOL with a corresponding deposit and withdrawal messaging system on Solana for SOL. No supply cap is in place for xSOL on X Layer. Given that minting is facilitated by OKX, liquidity and supply for xSOL are dependent on SOL availability on OKX or user deposits into the controlled reserve.
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/1/153d8ef21f6aed0c9c88ea1c7f559084f291a31e.png)  
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/f/fa2c8b84cd573d505556c36f00812c262ae3e216.png)  
> Source: X Layer Internal Documentation, February 13th, 2026
> 
> xSOL follows established wrapper patterns, with permissioned minting and burning.
> 
> #### **1.3.1 Token Holder Concentration**
> 
> Current supply is 18,843 ($1.5M) with 547 holders. Supply is concentrated on 3 accounts, which hold over 96% of xSOL on X Layer:
> 
> - [OKX. Deposit\_1 EOA](https://www.oklink.com/x-layer/address/0x5075ff68a0efb54db13423ad924bd680327d305e): 48.89%
> - [Uniswap xSOL/USDT0](https://www.oklink.com/x-layer/address/0x4651300221f345a4c6f566079bd1ddc291049c7d): 29.28%
> - [Uniswap xSOL/xOKSOL](https://www.oklink.com/x-layer/address/0x97bb2a4ea57b1a20d3b237b2325f56efe25e4ce0): 18.57%
> 
> ## **2. Market Risk**
> 
> ### **2.1 Liquidity**
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/2/245644445df73e54c8669454012455ce41a86127.png)  
> _Source: xSOL swap USDT0, [Uniswap](https://app.uniswap.org/swap), February 13th, 2026_
> 
> Meaningful liquidity is currently lacking. Additional liquidity has been committed to support onboarding, with $1M and $2M allocated to the xOKSOL/xSOL and xSOL/USDT0 pools, respectively.
> 
> #### **2.1.1 Liquidity Venue Concentration**
> 
> As shown in section 1.3.1, Uniswap represents the sole venue for xSOL liquidity. As of February 13th, liquidity in each pool amounted to $789K in the [xSOL/USDT0](https://www.oklink.com/x-layer/address/0x4651300221f345a4c6f566079bd1ddc291049c7d) pool and $551K in the [xSOL/xOKSOL](https://www.oklink.com/x-layer/address/0x97bb2a4ea57b1a20d3b237b2325f56efe25e4ce0) pool.
> 
> #### **2.1.2 DEX LP Concentration**
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/1/1795f54371f9d035742a2d7d4880cb56c8a4cc6b.png)  
> _Source: xSOL/USDT0 LPs, [Debank](https://debank.com/protocols/pool/0x4651300221f345a4c6f566079bd1ddc291049c7d/xlayer/holders), February 13th, 2026_
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/f/f0934145cdeccf27843a8470f1c8bfea19a417d6.png)  
> _Source: xSOL/xOKSOL LPs, [Debank](https://debank.com/protocols/pool/0x97bb2a4ea57b1a20d3b237b2325f56efe25e4ce0/xlayer/holders), February 13th, 2026_
> 
> Given the asset’s recent deployment, liquidity is primarily supplied by the X Layer team, resulting in a single LP source for both pools.
> 
> ### **2.2 Volatility**
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/9/92062a56cd87c6b731ef1d7f1168226dfa882ddd.png)  
> _Source: xSOL/USD, [Geckoterminal](https://www.geckoterminal.com/x-layer/pools/0x4651300221f345a4c6f566079bd1ddc291049c7d), February 13th, 2026_
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/b/bd89711cfc045ce12ae6dac9a0daecdd3d7645e2.png)  
> _Source: SOL/USD price feed (Base), [Chainlink](https://data.chain.link/feeds/base/mainnet/sol-usd), February 16th, 2026_
> 
> xSOL price data is limited, with data only available from January 21st. Since then, secondary market price action in the USD pool has remained closely correlated with a SOL/USD Chainlink price feed.
> 
> ### **2.3 Exchanges**
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/7/77d12602ec3a364c35ec5b1ca571e3afe26c02cd.png)  
> _Source: SOL spot markets, [OKX](https://www.okx.com/markets/spot/usdt-all), February 16th, 2026_
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/a/ab82d75d78b7a454c255f09c35dff5a7c12fee8f.png)  
> _Source: SOL/USDT, [OKX](https://www.okx.com/trade-spot/sol-usdt#workspaceId=1771258327449), February 16th, 2026_
> 
> The spot market on OKX experiences considerable volume, as shown above, the SOL/USDT market is the largest, with 24-hour volume exceeding $90M. Money flows from these pairs show predominant net outflows within these pairs; however, it should be noted that this coincides with the recent market volatility seen recently.
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/5/58ea41661a99375f7a127c7a921901ea76545c45.png)  
> _Source: SOL perp markets, [OKX](https://www.okx.com/trade-swap/sol-usdt-swap#workspaceId=1771258327449), February 16th, 2026_
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/8/8a1b4070b1ed9f0d13b69eb7e434b34d17d6bc14.png)  
> _Source: SOLUSDT perp market, [OKX](https://www.okx.com/trade-swap/sol-usdt-swap#workspaceId=1771258327449), February 16th, 2026_
> 
> The perpetual market for SOL is similarly active in terms of volume, across 3 separate markets. Open interest, as shown above, has fluctuated between 3.97M contracts and 2.67M in the largest SOLUSDT perpetual market over the 30 days observed.
> 
> ### **2.4 Growth**
> 
> ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/3/3a3c12551641df6b0501edbdb6bf76849b0aa3a4.png)  
> _Source: xSOL Market Cap, [Coingecko](https://www.coingecko.com/en/coins/okx-wrapped-sol), February 13th, 2026_
> 
> Limited growth was observed at the time of writing as measured by onchain TVL, given the token’s recent deployment. As shown in section 2.3, OKX exchange represents a large base for potential growth for xSOL on X Layer, given that xSOL is minted when users withdraw SOL from OKX.
> 
> ## **3. Technological Risk**
> 
> ### **3.1 Smart Contract Risk**
> 
> A Zellic audit was completed on xSOL and other assets on December 23, 2025. 1 medium severity, 2 low severity issues, and 1 informational issue were found. The team acknowledged the issues and implemented fixes to the medium and low-severity issues. The medium issue was related to potential addresses on the denylist being able to transfer funds from accounts that granted them allowances. The final report is yet to be shared publicly.
> 
> ### **3.2 Bug Bounty Program**
> 
> xSOL smart contracts are covered under a live OKG bug bounty program hosted on **[HackerOne](https://hackerone.com/okg)** with a max bounty of $1M.
> 
> ### **3.3 Price Feed Risk**
> 
> No Chainlink price feed has been deployed, with the team indicating that it is still in development.
> 
> ### **3.4 Dependency Risk**
> 
> xSOL relies on OKX to effectively maintain a 1:1 custody of the underlying SOL custodied on OKX and on Solana. The Solana reserve creates an additional foreign network dependency, one that Aave has yet to deploy on. xSOL does not call external unverified functions, calling only internal system functions.
> 
> ## **4. Counterparty Risk**
> 
> ### **4.1 Governance and Regulatory Risk**
> 
> To the extent other X Layer assets are governed by the same dedicated [wrapped-token user agreement](https://www.okx.com/en-sg/help/wrapped-token-user-agreement) that applies across all wrapped 1:1 assets, they should be treated as operating within the same core legal architecture as xETH. On that premise, the [legal analysis](https://outline.llamarisk.com/doc/arfc-x-layer-xeth-B9FevirHtt#h-41-governance-and-regulatory-risk) prepared for xETH is directionally applicable to such X Layer assets, particularly the findings regarding (i) the assets’ legal construct, (ii) the eligibility and access model, and (iii) the authorisation and regulatory perimeter status of the operating entity.
> 
> ### **4.2 Access Control Risk**
> 
> xSOL is deployed behind a Transparent Upgradeable Proxy, with the current implementation **[contract](https://web3.okx.com/explorer/x-layer/address/0xb7b0673e87bb18877e75dcfc84c3ca4f656782d0)**.
> 
> #### **4.2.1 Contract Modification Options**
> 
> A Role-Based Access Control system is utilized. The roles and their associated capabilities are outlined below:
> 
> MINTER\_ROLE: Can mint and burn tokens, assigned to **[MPC 1.](https://web3.okx.com/explorer/x-layer/address/0x65e392dda704bb2ccfee7fa62d0945094dd2037a)**
> 
> DENY\_LISTER\_ROLE: Can pause/unpause transfers and manage the deny list, assigned to **[MPC 2](https://web3.okx.com/explorer/x-layer/address/0xa07ae4bdfa7ba8bc0e8a8525bcc768300a8970bb)**.
> 
> DEFAULT\_ADMIN\_ROLE: Has admin privileges over Timelock, ProxyAdmin, and xSOL, assigned to **[MPC 2](https://web3.okx.com/explorer/x-layer/address/0xa07ae4bdfa7ba8bc0e8a8525bcc768300a8970bb)**.
> 
> TimelockController Roles manage sensitive admin functions through a timelock delay mechanism. assigned to **[MPC 2](https://web3.okx.com/explorer/x-layer/address/0xa07ae4bdfa7ba8bc0e8a8525bcc768300a8970bb)**:
> 
> - PROPOSER\_ROLE: initiates transactions to the queue.
> - EXECUTOR\_ROLE: executes transactions after a delay.
> - CANCELLER\_ROLE: can cancel pending operations.
> 
> Sensitive functions exposed by each role include
> 
> MINTER\_ROLE:
> 
> - mint & burn xSOL
> - `transferMinter` relinquishes the role to a new account
> 
> DENY\_LISTER\_ROLE:
> 
> - `pause` and unpause all token transfers
> - `setReceiver` determines where the newly minted are sent
> - `addToDenyList` & `removeFromDenyList` controls a permissioned Deny list that blocks addresses from sending/receiving tokens
> - `transferDenyLister` relinquishes the role to a new account
> 
> DEFAULT\_ADMIN\_ROLE:
> 
> - All Deny List Role functions
> - `grantRole` assigns roles to addresses
> - `revokeRole` removes roles assigned to addresses
> 
> PROPOSER\_ROLE:
> 
> - `schedule` schedules a single transaction (target address, value, and data).
> - `scheduleBatch` schedules multiple transactions to be executed in sequence.
> 
> EXECUTOR\_ROLE:
> 
> - `execute` triggers the actual call to the target contract once the delay has ended.
> - executeBatch triggers a group of function calls.
> 
> CANCELLER\_ROLE:
> 
> - `cancel` deletes a pending operation before it is executed.
> 
> These roles highlight the highly centralized controls that roles have key contract functions, i.e, minting, transferring, pausing, and determining where newly minted xSOL are sent (and indirectly, access to the underlying SOL redemption right).
> 
> #### **4.2.2 Timelock Duration and Function**
> 
> TimelockController enforces a 3-day delay for upgrades and role changes.
> 
> #### **4.2.3 Multisig Threshold / Signer identity**
> 
> MPCs are controlled internally by OKX; no external parties are involved in the management of control systems. Admin actions require internal review and senior management approval.
> 
> **Note** : This assessment follows the LLR-Aave Framework, a comprehensive methodology for asset onboarding and parameterization in Aave V3. This framework is continuously updated and [available here](https://github.com/llama-risk/aave-research/blob/main/frameworks/aave_v3_framework.md).

### Disclaimer

This review was independently prepared by LlamaRisk, a DeFi risk service provider funded in part by the Aave DAO. LlamaRisk is not directly affiliated with the protocol(s) reviewed in this assessment and did not receive any compensation from the protocol(s) or their affiliated entities for this work.

The information provided should not be construed as legal, financial, tax, or professional advice.

---

_[View the full topic](https://governance.aave.com/t/arfc-deploy-aave-v3-on-x-layer/23175)._
