[ARFC] Onboard mWIN (Midas / Wellington Management) to Aave Horizon

[ARFC] Onboard mWIN (Midas / Wellington Management) to Aave Horizon

Summary

This ARFC proposes onboarding mWIN, a tokenised multi-sector actively managed fixed income portfolio managed by Wellington Management and issued by Midas, as collateral on the Aave Horizon instance.

mWIN provides institutional-grade exposure to an actively managed, fixed income portfolio optimized for yield, liquidity and low volatility. Borrowers on Horizon can utilize mWIN as highly liquid, yield-bearing collateral to execute leveraged carry (looping) strategies, supported by a multi-tiered redemption architecture. mWIN is already live on mainnet with $15M in TVL just a few days after launch, showing strong demand from borrowers and LPs.


Motivation

Horizon exists to give holders of tokenised real-world assets instant, 24/7 liquidity against those holdings while respecting issuer compliance requirements. mWIN extends Horizon’s collateral set into actively managed securitised credit, alongside the existing tokenised treasury and fund exposures.

Why mWIN fits Horizon

  • Institutional Manager: Wellington Management is one of the largest investment management firms in the world. Founded in Boston in 1928, Wellington manages over USD 1.3 trillion in assets across fixed income, equities, multi-asset, and alternative strategies, on behalf of thousands of institutional clients globally, including pension funds, sovereign wealth funds, insurers, and endowments.

  • Liquid & Low Risk Strategy: The portfolio is an investment-grade, diversified credit portfolio designed to balance yield generation, capital preservation, and structural liquidity. With an optimized duration profile to dampen volatility and low spread duration, it offers institutional-grade stability, minimizing mark-to-market drawdown risk in credit sell-off scenarios, while maintaining an average credit rating of A+.

  • Atomic Onchain Liquidity: Midas provides up to $30m of atomic onchain liquidity via MSL, of which $10m are dedicated to mWIN, enabling atomic redemption into USDC across market conditions. This is directly relevant to liquidation feasibility.

  • Institutional Legal Structuring: The strategy is issued through a legally segregated compartment of a Luxembourg securitisation fund. This statutory bankruptcy-remote structure isolates assets and liabilities, providing institutional-grade protection and legal clarity for tokenholders and lending markets.

There is significant demand from onchain funds across multiple parties for the looping use case. Depending on Horizon borrow rates being 150-200 bps lower than the strategy’s YTM, borrowers are targeting double-digit returns when looped 4x. In addition, due to the high organic liquidity provided, this strategy is also suited for unlooped yield optimization for treasury management purposes.

The strategy targets a resilient yield profile adaptable across the cycle, driven by dynamic allocation to asset classes depending on prevailing market conditions. The model portfolio generates a gross market yield of 5.23%, achieving a spread of c107 bps over the equivalent US treasury curve.


About the Manager: Wellington Management

Founded in 1928 and independently owned, Wellington Management is a leading global institutional asset manager with over $1.3 trillion in assets under management. Wellington’s dedicated Financial Reserves Management (FRM Team) manages over $200 billion in AUM, combining experienced portfolio managers, deep credit research, and proprietary risk analytics infrastructure. Wellington has decades of experience with this type of strategy, maintaining a long-standing track record focused on portfolios that appropriately balance risk and return. Notably, the mWIN strategy is run by the same institutional franchise that oversees portfolios for major insurance companies.

About the Issuer: Midas

Midas is a platform for composable onchain investment products and is the issuer behind mWIN, with over $4B in cumulative onchain asset issuance and $600M+ in current TVL, backed by a $50M Series A led by RRE and Creandum.

Midas’ mToken suite is already proven across leading venues, serving as an onchain issuer for institutional-grade strategies from managers such as Wellington Management and Fasanara Capital. Aave Horizon itself is direct proof of this track record: Midas’ mGLOBAL, tracking Fasanara’s alternative credit strategy, launched as collateral on Aave Horizon in June 2026, and its $30M supply cap filled almost immediately, showing strong, real institutional demand for Midas-issued RWA collateral within Aave ecosystem.

mWIN extends that same infrastructure, custody, and compliance framework to Wellington’s actively managed multi-sector fixed income strategy, giving Aave Horizon a natural path to onboard a second Midas-issued institutional credit product with an already-proven distribution and liquidity track record.


Strategy and Portfolio

The strategy is an institutional-grade actively managed fixed income strategy. Managed by Wellington Management’s Financial Reserved Management (FRM) team, the portfolio is designed to balance yield generation, capital preservation, and structural liquidity.

The strategy utilizes an active, multi-sector approach to deliver a resilient portfolio optimized for market conditions. The strategy invests into a diversified portfolio spanning some of the most liquid asset classes within public fixed income. The underlying assets include collateralised loan obligations (CLOs), commercial mortgage-backed securities (CMBS), agency and non-agency residential mortgage-backed securities (RMBS), asset-backed securities (ABS), and investment-grade corporate bonds.

By prioritizing dynamic risk management and broad diversification over static, single-sector concentration, it provides several distinct structural advantages:

  • Active risk management and dynamic sector rotation: Portfolio exposures are adjusted continuously based on macroeconomic data, liquidity constraints, and security fundamentals. During periods of market stress, the management team can tactically reallocate capital from deteriorating sectors into defensive positions.

  • Broad diversification: Drawdowns can originate from a wide spectrum of catalysts, including macro-driven liquidity shocks, structural regulatory shifts, or sector-specific credit events. Allocating across multiple fixed-income sectors mitigates single-asset concentration risk, dampens overall volatility, and ensures independent sources of liquidity during localized stress.

  • Optimized spread duration profile: The actively managed portfolio is structured to maintain a highly optimized spread duration profile. Single-sector portfolios are inherently more sensitive to spread widening events, experiencing meaningfully higher mark-to-market losses. The strategy’s structurally contained spread exposure makes it highly resilient for mandates where drawdown sensitivity is a primary concern.

Wellington Portfolio Parameters & Mandate

Item Detail
Strategy Multi-sector actively managed fixed income
Manager Wellington Management (FRM team)
Largest position / concentration limits Single issuer or issuing trust exposure for structured securities is capped at 5% of portfolio market value (excluding government or government agency guaranteed debt)
Leverage The portfolio does not allow for leverage
Portfolio risk limits Effective Duration: Limited to between 0 and 2 years at the portfolio level. Credit Rating & Quality: Maintained at an investment-grade weighted average credit rating; BBB/Baa capped at 50%, below-investment-grade capped at 10%, unrated capped at 10%. Currency Exposure: Non-USD denominated securities capped at 10% and must be 100% hedged back to USD
Fund size / AUM Current: $25M; expected: >$100M
Track record This custom strategy does not have a realised track record. Backtested annualised return: 5.66% over one year; 6.76% over 3 years; 3.75% from December 2016 to April 2026. The backtested returns assume a static allocation which does not reflect the dynamic portfolio optimisation depending on prevailing market conditions
Fees 40bps per annum management fee. No performance fee

Model Portfolio

Item Detail
Average credit rating A+
Effective duration ~1 year
Spread duration <2 years
Sector allocation CLOs: 40%; IG Corporates: 25%; ABS: 15%; Agency MBS: 10%; Non-Agency RMBS: 5%; CMBS: 5%
Rating distribution AAA: 5%; AA: 26%; A: 47%; BBB: 22%

Stress Behaviour

The drawdown analysis below covers the strategy managed by Wellington and the data is based on a simulated backtest. It excludes the 5% liquidity sleeve, which softens the impact shown in all the tables and metrics below. It should be noted that the analysis rests on a static allocation across asset classes based on the model portfolio and thus is not representative of the dynamic and active portfolio management underpinning the strategy.

The max one-day drawdown is limited to 2.7%. This is relevant given the daily liquidity of the underlying portfolio.

The largest drawdowns over the last 5 years based on the simulated backtest are shown below. This exercise is conservative as it suggests no active management on Wellington’s part to soften the impact of market moves:

Peak Trough Recovery Drawdown Days
2021-09-14 2022-10-20 2023-08-08 -7.79% 693
2025-04-03 2025-04-11 2025-04-28 -1.08% 25
2018-12-10 2018-12-20 2019-01-11 -1.01% 32
2026-02-27 2026-03-20 2026-04-14 -0.84% 46

In addition to the simulated backtest, Wellington has performed a forward-looking scenario analysis to evaluate the model portfolio’s resilience across a range of hypothetical macroeconomic, rate, and volatility shocks.

While severe shock scenarios may induce temporary price drawdowns, the portfolio’s starting carry ensures a projected recovery time of less than six months across all modelled events.

It should be noted that in a credit sell-off scenario, where spreads widen and the flows favour high quality assets, the Wellington portfolio is expected to outperform a pure CLO product.

Liquidity and Redemption

Item Detail
Atomic onchain liquidity 5% of the mWIN TVL sits in onchain tokenised treasuries redeemable atomically for USDC. Additionally, Midas provides instant liquidity redeemable in USDC via MSL (Midas staked liquidity pool), with $10M dedicated to mWIN. As mWIN TVL grows, Midas will also expand instantly redeemable capacity as well as introduce holdbacks, currently set at 0
Standard subscription flow Whitelisted investors can submit a subscription request at any time. The minting process is atomic, meaning investors instantly receive their mWIN tokens upon deposit at the latest available NAV onchain corresponding to the total subscription amount less any holdback. Assets are invested in the underlying portfolio as soon as practicable. If a holdback is applied, the investor receives the remaining tokens after the next NAV update such that the subscription price per token of the total subscription amount averages the token price after the NAV update. Currently the holdback is zero
Standard redemption flow The Fund processes standard redemptions on a daily basis for 100% of the NAV, with settlement of 1 business day if the request is made before the daily cut-off time of 1pm CET, subject to underlying asset liquidations having successfully settled
Redemption assets Redemptions are processed in USDC, PYUSD, RLUSD and other stablecoins if made available on the Midas website
Behaviour under stress The portfolio has been designed to allow for standard redemptions up to 100% of TVL in both normal and stressed market conditions. Similarly, atomic redemptions are expected to be available in both normal and stressed market conditions. However, in case of market disruption events, Midas may pause instant redemptions. Regarding standard redemption in extreme scenarios, Wellington optimizes the sale of assets to balance time, slippage, and costs. Backed by a wide network of counterparties, Wellington is well-positioned to liquidate positions efficiently across various market conditions
Historical redemption performance To date, no redemptions have been rejected or experienced delayed settlements

Technical Specification — Token

Item Detail
Token name / symbol mWIN
Contract address 0x4E72025984424E52838cf8953E2863eFf036B67A
Chain Ethereum mainnet
Decimals 18
Token standard Standard ERC-20 token
Supply mechanics mWIN has an issuer-controlled mint/burn mechanism. There is a minting cap of $20M per day enforced at the Minter vault smart contract level
Transfer restrictions mWIN requires both the sender and recipient of any transfer to be included on the mWIN greenlist. In addition, after the transfer, each party must hold either zero tokens or at least one token. This model is compatible with Horizon’s non-transferable aToken model
Proxy / upgradeability Proxy Type: Standard OpenZeppelin upgradeable proxy pattern. Upgrade Authority: The ProxyAdmin contract (0xbf25b58cB8DfaD688F7BcB2b87D71C23A6600AaC) is owned by the TimelockController (0xE3EEe3e0D2398799C884a47FC40C029C8e241852), which is ultimately governed by the Midas Proxy & ACL Admin Safe (0xB60842E9DaBCd1C52e354ac30E82a97661cB7E89). While the top-level Safe threshold is nominally 1-of-3 for infrastructure redundancy, every signer is an independent, nested quorum-protected system requiring an effective minimum of at least 3 distinct individuals to execute any action. This includes a Fordefi MPC (4-of-7), a Fireblocks MPC (4-of-7), and the Team Signer Safe (0x82B30194bEae06D991Bc71850F949ec8cB7E0CB7, 3-of-7). Safe wallets are being migrated to an elevated 4-signer minimum threshold in Q3 2026, supported by new hardware from diversified vendors. Timelock Delay: A mandatory 48-hour delay is hardcoded and enforced for all contract upgrades
Verified source Token: Address: 0x4E720259...Ff036B67A | Etherscan — Aggregator: Address: 0x1725A66D...71dA19517 | Etherscan — Data Feed: Address: 0xa27c1658...6A0ea4077 | Etherscan — Deposit Vault: Address: 0xF7F1b944...2eB667db4 | Etherscan — Redemption Vault Swapper: Address: 0x605704d7...5523c7924 | Etherscan — Redemption Vault mToken: Address: 0x14fECa41...706709fca | Etherscan

Oracle and NAV

Item Detail
NAV source The gross value of the Wellington Strategy is calculated by Northern Trust. When computing a new price for the token, the NAV is calculated by Midas aggregating: the independent NAV as provided by Northern Trust in the daily report (notarised onchain by the Attestation Engine); the onchain verifiable tokenised T-bills; in-flight assets and any idle assets held within the portfolio, such as USDC recently received; and applicable fees
NAV publication frequency Every business day
Onchain feed Chainlink Data Feed delivering LlamaGuard-validated NAV
Feed address Aggregator: Address: 0x1725A66D...71dA19517 | Etherscan — Data Feed: Address: 0xa27c1658...6A0ea4077 | Etherscan — Chainlink oracle currently in development
Heartbeat and deviation threshold healthyDiff: 2,592,000 (30d); maxExpectedAnswer: 150,000; minExpectedAnswer: 129,000
LlamaGuard bounds To be configured by LlamaRisk; Parameter Registry updated via the Horizon operational multisig
Proof of Reserve / attestation The Midas Attestation Engine runs a daily Chainlink CRE workflow to confirm the overcollateralization of mWIN. The attestation is verified independently by Canary. See midas.app/mwin

Privileged Roles

Role Detail
DEFAULT_ADMIN_ROLE 0xB60842E9DaBCd1C52e354ac30E82a97661cB7E89 — Midas Proxy & ACL Admin Safe. The top-level Safe has a nominal 1-of-3 threshold for infrastructure redundancy; however, each of its three signers is itself an independently quorum-protected system, requiring an effective minimum of at least three distinct individuals: Fordefi MPC (4-of-7 quorum), Fireblocks MPC (4-of-7 quorum), Team Signer Safe 0x82B30194bEae06D991Bc71850F949ec8cB7E0CB7 (3-of-7 quorum). Also 0xd4195CF4df289a4748C1A7B6dDBE770e27bA1227 — Access Control Admin, secured by a Fordefi MPC policy requiring a 4-of-7 signer quorum. No timelock currently applied; a new contract iteration introducing timelock functionality is undergoing audit
M_WIN_MINT_OPERATOR_ROLE 0x20D4CeD0EFac28517C1b0a06F98B1180F28f5125 — mWIN Management Vault, 4-of-7 Fordefi MPC policy, used for manual and OTC mints via the backoffice interface; transactions presented as plain-text summaries, cross-checked against independent portfolio spreadsheets, verified via private Slack channels prior to execution. Also 0xF7F1b944FCDe7805F6Ef3088817145d2eB667db4 — mWIN depositVault. No timelock currently applied; new iteration undergoing audit
M_WIN_BURN_OPERATOR_ROLE 0x76e350c5a674db787918e5f728466c7356d4d361 — mWIN Management Vault, 4-of-7 Fordefi MPC policy, used for manual and OTC burn/redemption operations via the backoffice interface, same verification process as above. Also 0x605704d7b36d1677a8d242ded68eD505523c7924 — mWIN redemptionVaultSwapper; 0x14fECa41FB9541Fd8f61a6bA6304c5b706709fca — mWIN redemptionVaultMToken. No timelock currently applied; new iteration undergoing audit
M_WIN_PAUSE_OPERATOR_ROLE 0x20D4CeD0EFac28517C1b0a06F98B1180F28f5125 — mWIN Management Vault. Emergency pause functionality includes a single-signer fast path, accessible through either the backoffice interface or a block explorer, enabling immediate protocol containment when required. Unpausing requires a manual quorum of 3 core signers. No timelock currently applied; new iteration undergoing audit
M_WIN_CUSTOM_AGGREGATOR_FEED_ADMIN_ROLE 0x532FEDcF5837f411646c230CF9b743dFdD0692d3 — mWIN Oracle Admin Vault. Differentiated quorum requirements: setRoundDataSafe requires 2 signers (includes a maximum deviation guardrail and a 1-hour cooldown), while setRoundData requires the standard 4-signer quorum. No timelock currently applied; new iteration undergoing audit
Greenlist/Blacklist Governed by the DEFAULT_ADMIN_ROLE and operationally executed through the Fordefi MPC policy. Greenlisting an address requires a 2-signer quorum; blacklisting requires the standard 4-signer quorum. No timelock currently applied; new iteration undergoing audit

Audits and Security

Item Detail
Audits Midas runs constant audits for releases performed by external auditors. Last audit: 6/7/2026. Reports: docs.midas.app/resources/audits
Outstanding findings Neither critical nor high findings were found in the current codebase
Bug bounty Midas maintains dual active bug bounty programs hosted via Cantina and Sherlock with max rewards up to 500,000 USDC
Incident history Due to Midas’s in-depth defence and layered security architecture, no major incidents have happened in the past
Change notification Midas confirms its commitment to pre-notify Aave and LlamaRisk of material contract or structural changes

Dependencies

The only hard external dependencies for mWIN are Wellington Management (Portfolio Manager) and Northern Trust (Custodian). Additionally, the Issuer relies on Midas Software GmbH as the provider of the technical and smart contract infrastructure, vLayer & Chainlink for the onchain oracle infrastructure, as well as off- and on-ramping providers for fiat conversions. A failure in these latter operational layers could temporarily disrupt onchain price feeds, minting, or instant redemptions, but the underlying assets would remain fully insulated within the statutory bankruptcy-remote vehicle. Ernst & Young acts as the external auditor of the Securitisation Fund.

Legal and Structural

Item Detail
Issuing entity and jurisdiction The issuer is the Compartment mWIN of the Aureum Securitisation Fund in Luxembourg
Fund structure The Aureum Securitisation Fund operates through legally segregated compartments, each of which constitutes a separate estate by law. Assets and liabilities of a given compartment are fully ring-fenced from all other compartments, the management company, the originator or sponsor, and any other related parties. Tokenholders therefore have exclusive and limited recourse to the assets of the specific compartment backing their notes, and are insulated from any insolvency or distress elsewhere in the structure. The issuance is therefore statutory bankruptcy-remote
Regulatory status The Aureum Securitisation Fund is an unregulated securitisation fund (fonds de titrisation non réglementé), registered with the Luxembourg companies and business register under number O136, subject to the Luxembourg act dated 22 March 2004 on securitisation, as amended (the Securitisation Act 2004)
Investor eligibility mWIN is a fully permissioned token available to whitelisted institutional and eligible investors. The initial subscription requires a minimum of 1 token bearing an Authorised Denomination and initial value of $130k. Beyond 1 token, fractional holdings are permitted. Investors must complete Midas’s identity verification (KYC/KYB) and compliance checks to have their wallet address whitelisted
Insolvency treatment The statutory bankruptcy-remote structure on which tokenholders have sole claims is supported by a legal opinion from Allen & Overy confirming that investors are protected from the insolvency of the issuer and other Midas entities
Allowlist administration The allowlist (whitelist) is legally administered by the Issuer (the Aureum Securitisation Fund acting on behalf of Compartment mWIN). Operationally, the KYC/KYB and compliance onboarding process is facilitated by Midas Software GmbH. Once an investor is approved by the Issuer, their wallet addresses are added to the onchain whitelist via the Midas Proxy & ACL Admin Safe, utilizing a Fordefi MPC policy

Liquidations

Liquidators must be allowlisted at the token level to receive mWIN collateral. Horizon does not select or whitelist liquidators; eligibility is controlled by the issuer.

Item Detail
Eligible liquidators Eligible onboarded liquidators that Midas can publicly disclose include Keyrock, Dialectic, Vault Street, Metalayer, Fission, and Midas. Midas itself, through MSL, is also a liquidator with $10M of dedicated capacity
Liquidation facility The onboarded liquidators have a capacity of more than $100M per week. Midas liquidity capacity of $10M per day is visible onchain, as it would be cycled using T+1 standard redemptions to process more liquidations if needed
Onboarding path for new liquidators Any party interested in being a liquidator can reach out to Midas through the mWIN page “Get Access” button and will be invited to fill out onboarding forms; onboarding can occur within a few days. Midas is actively engaged with more liquidators and can share that new liquidators are currently being onboarded. Midas is also integrating mWIN into the Symbiotic RFO system for increased onchain liquidity
Expected liquidation route The expected liquidation route is for liquidators to use standard redemptions, as indicated by liquidators themselves. Economically, this is the best route to capture the full upside of a liquidation while taking limited risk due to the low volatility of the asset, its max daily drawdown risk, and high liquidity. Instant redemption is also possible for liquidators wishing to redeem instantaneously following liquidation

Risk Assessment

LlamaRisk is conducting the independent risk review of mWIN, covering the legal structure and the market/portfolio analysis. Their report, including the recommended risk parameters, will be published in this thread ahead of any Snapshot vote.


Specification

Risk parameters for mWIN will be specified by LlamaRisk in their published risk report and reflected here prior to escalation.


Useful Links


Disclaimer

This proposal is presented by Midas Software GmbH (“Midas”), on behalf of Aureum Securitisation Fund, acting in respect of Compartment mWIN. Midas confirms that it has no commercial relationship with Aave Labs.

This proposal, together with any related marketing, technical, or explanatory materials, is provided for informational purposes only. Nothing herein constitutes an offer to sell, or a solicitation of an offer to buy, securities or other financial instruments in any jurisdiction, nor does it constitute investment, legal, tax or financial advice.


Next Steps

  1. Gather community and delegate feedback on this ARFC.

  2. Publication of the LlamaRisk risk report and recommended parameters.

  3. Technical review of the listing payload.

  4. Escalation to Snapshot, and if passed, to AIP for onchain execution.


Copyright

Copyright and related rights waived under CC0.

2 Likes

Posting this before the risk report rather than after it, because the parameters aren’t set yet and these are the questions I’d want answered as a supplier on the other side of them.

Disclosure first: no commercial relationship with Midas, Wellington, Aave Labs or LlamaRisk. I spend my time marking illiquid private positions and I read this proposal as someone who has had to defend an NAV rather than just consume one.

The structure here is genuinely well documented – Luxembourg compartment, ring-fenced, Northern Trust computing the strategy NAV, EY auditing, daily redemption at 100% of NAV, an attestation verified by an independent party. My questions are narrower than the structure: they’re about what the market does on the days the NAV can’t be trusted to be current.

1. Staleness tolerance versus publication frequency. The feed publishes every business day, and the oracle’s healthyDiff is set to 30 days. What is the intended behaviour between day one and day thirty of a missed update – does borrowing and liquidation continue against a NAV that may be up to a month old? And on day thirty-one, when the tolerance is exhausted, what is the intended state of the market? The Technical Asset Listing Framework requires a feed to remain within its expected heartbeat and deviation threshold, or that any deviation from expected parameters be explicitly justified. What is the justification for a thirty-day tolerance on a feed that publishes daily?

2. The bounds, and what happens when one is hit. minExpectedAnswer is 129,000 and maxExpectedAnswer is 150,000, against an Authorised Denomination of $130,000 per token – 0.8% of headroom below the issue value and 15.4% above, asymmetric by a factor of twenty. That is conventional on one side and very tight on the other for a sanity bound, and two consequences follow at different times. On the downside, an NAV print 0.8% below issue value is already at the edge of the band, which is well inside the ordinary variation of a portfolio with roughly one year of effective duration and 22% BBB. On the upside, an income fund compounding at anything near its target reaches 150,000 within a few years, after which every update is outside the band. Is there a review trigger attached to these values, or a rule that moves them as NAV accrues?

The consequence of a breach then depends on which layer catches it, and the two behave in opposite directions. Horizon’s documentation describes bounds configured per RWA feed at the DON level, where a reported NAV outside them means the DON rejects the update and the oracle continues to report the last known valid price, with the emergency multisig preventing new originations. The Midas data feed contract at 0x1D0CB5685791F6E9ABc1B876E3b9017F8aa1807c reverts with “DF: feed is unhealthy”. Rejecting an update leaves the market open against a stale price; reverting closes it. Which governs here, and which is intended?

3. Discount, or no discount. The feed is described as delivering validated NAV. Is the collateral price the raw NAV, or NAV less a haircut? For context, when another Midas mToken was onboarded elsewhere as collateral, the curator applied a 7.7% discount to the NAV feed and set the liquidation threshold so that NAV could fall about 6% before lenders faced bad debt. If the intended buffer here sits entirely in the LLTV rather than partly in the oracle, it would be useful to see that stated, because the two are not equivalent in a fast move.

4. Liquidation under permissioned exit. Liquidators must be allowlisted at token level by the issuer, and the named set is six parties. Their exit is daily redemption at NAV, 1pm CET cutoff, T+1 settlement, with instant redemption capped at $10m plus roughly 5% of TVL in treasuries – and the proposal states instant redemptions may be paused in market disruption events. So a liquidator is taking overnight NAV risk on a token they cannot freely sell, in exactly the conditions where the pause is most likely to happen. What liquidation bonus is that assumed to compensate, and what is the assumed liquidator capacity when instant redemption is paused?

5. Continuity of the mark. The proposal names Wellington and Northern Trust as the only hard external dependencies. What happens if one of them gives notice? Specifically: is there a notice period, a fallback valuation source, and does the market wind down in an orderly way or simply stop updating? This is the question I’d press hardest, because this year already produced an onchain yield token that lost its peg after its verification provider ended the agreement, leaving a fully drawn market with no exit. The assets being bankruptcy-remote protects the assets; it doesn’t protect a lender whose collateral has stopped having a price.

Two smaller notes, neither of them a question about risk. The proposal cites $15m TVL for mWIN; current Ethereum supply is 195.82 tokens across five holders, which at the Authorised Denomination is roughly $25.5m before any NAV accretion – is the $15m figure a different measure, or has it moved since drafting? And on scope rather than criticism: Midas publishes fourteen audit reports, the closest to this surface being Sherlock’s Growth Oracle review of August 2025 and the vault strategy integration review of March 2026, so the values above are deployment configuration rather than audited code and no published report speaks to them.

None of these are objections to onboarding. These are the five things I would want the risk report to answer explicitly, and the last of them is the lesson this market was taught the hard way earlier this year.

2 Likes

I think the risk case is using the wrong number. The proposal highlights a 2.7% maximum one-day drawdown and scenarios that recover within six months. But its own backtest shows a 7.79% drawdown from 14 September 2021 to 8 August 2023: 693 days to recover. That is the period a 4x looped position would actually have needed to survive.

For me, that points to the supply cap. The dedicated MSL liquidity starts at $10m and may grow with mWIN TVL, but that growth is not guaranteed. Holdbacks are currently zero, and instant redemptions can be paused during market disruption. Aave therefore should not assume redemption capacity beyond the liquidity that is firmly committed.

I would set the initial cap at roughly $10m plus the 5% treasury allocation. Any increase could come in the same AIP as an increase in dedicated MSL liquidity. With only 195.82 tokens currently supplied on mainnet, that would not constrain existing demand.

An automatic cap reduction if holdbacks rise or redemptions are paused could also work. Lowering LLTV enough to discourage 4x looping would address the risk too, but it would also undermine much of the demand case for the asset.

The simplest principle is that Aave’s exposure should grow only when the committed liquidity behind it grows.

4 Likes

Agreed on the number, and I think it reaches further than the cap.

If a 7.79% drawdown over 693 days is the scenario the risk case has to survive, this oracle cannot currently represent it. minExpectedAnswer is 129,000 against an Authorised Denomination of $130,000, so the floor sits 0.8% below issue value, and a fall of that size prints far outside the band. The market does not liquidate into that drawdown; depending on which layer catches it, it either runs on the last valid price or stops. I set out the arithmetic on the hINC thread, where the same question arrived from the other direction: the band can only express its own worst disclosed drawdown once NAV has accrued about 7.6% above issue, and only until it reaches the 150,000 ceiling.

So I would put the two asks together. A supply cap tied to committed liquidity is right. I would add that the oracle band has to be able to represent the drawdown the cap is being sized against, or the cap governs a scenario the feed cannot report.

The 693 days is the part I would carry into the continuity question as well. healthyDiff is 30 days. If the position that has to survive is measured in hundreds of days, the binding question is not just whether the liquidity is committed for that long, but whether the mark is still being published for that long, and what the market does on the thirty-first day if it is not.

Hi @aksenovd10, thank you for the detailed feedback and analysis on our proposal. We have gone through each of your points, and wanted to provide clarity and context on our side:

  1. The 30-day healthyDiff is the default tolerance used across Midas feeds. While it is configured in production, it should not be interpreted as an acceptable operating staleness for the NAV. If Midas had any concern around the freshness or validity of the price, minting and redemptions would be paused to prevent investors from entering or exiting at an outdated price.
    For Aave specifically, the market will rely on a Chainlink oracle, with the relevant staleness parameters defined by LlamaRisk as part of the Aave risk configuration. The 30-day healthyDiff on the Midas feed therefore does not represent the effective staleness tolerance of the Aave market.

  2. These are baseline bounds and can be adjusted over time as the NAV evolves. The downside bound is intentionally tighter given the quality and expected volatility of the underlying portfolio, while the upside bound was set with more headroom to avoid having to update it too frequently, with the expectation that it would typically be reviewed roughly every two years.
    The bounds of the Midas data feed can be updated through a function in the smart contract. If the reported price falls outside of the configured bounds, the Midas datafeed reverts and is considered unhealthy. This would temporarily pause the primary market until we readjust the bounds via admin functions.
    For Aave specifically, the behaviour of the Chainlink oracle when these conditions are triggered will depend on the implementation and parameters defined by LlamaRisk.

  3. We believe it will be clarified by Llamarisk in the Risk Report shortly.

  4. The liquidators that we have onboarded understand the overnight NAV risk and are willing to accept it in compensation of the liquidation bonus. The liquidators are therefore assumed to submit a standard redemption request, even if they can theoretically also use the instant redemption path if available.

  5. Both Northern Trust and Wellington are regulated, licensed institutions (Northern Trust as a Luxembourg credit institution, Wellington as an FCA-authorised investment manager). The IMA with Wellington requires 30 days’ prior written notice to terminate, and our custody agreement with Northern Trust requires 90 days’ prior written notice. Beyond the contractual notice period, regulated financial institutions of this size are expected to facilitate an orderly handover for reputational and regulatory reasons. If contrary to expectations, we ever have to replace either counterparty, investors would be notified as soon as practically possible.
    Moreover, the assets in the portfolio are public fixed income securities, meaning that there are public prices for these assets. We currently have two sources of pricing: Wellington and Northern Trust. We use Northern Trust data as the main input for our NAV due to Northern Trust’s independence from the investment manager. However, fallback solutions are there and in particular, we can use Wellington’s data as well.

1 Like

Hey @cedricbrown, it’s a fair point to raise, so wanted to clarify the distinction here:

The 693 days period is the time the actual max drawdown took to materialize, not the recovery period. Given the daily liquidity of the portfolio, we complemented this metric by the highest one-day drawdown of the portfolio from the static backtest. The key caveats of this analysis are that the model portfolio allocation is assumed to remain stagnant over time, meaning we are not taking into account the benefits of active management.

In contrast, the recovery periods refer to a forward-looking shock analysis performed by Wellington using its internal risk engine under several hypothetical market shocks, including scenarios created by the investment team. We believe this type of forward-looking shock analysis is a relevant additional lens for evaluating portfolio risk than historical back-testing, better allowing us to assess how the portfolio may respond to a range of plausible macroeconomic, rate, spread, and volatility scenarios from today’s starting point. From this analysis, we derive that despite periods where the model portfolio could experience negative price returns due to drawdowns, thanks to the portfolio’s starting level of carry, the recovery time from these drawdowns is less than 6 months across all scenarios.

Thank you – that answers most of it, and the continuity detail on notice periods and the Northern Trust / Wellington fallback is exactly what belongs in the final AIP.

Points 1, 3 and 5 are closed for me. 4 makes sense as well. On 2, one thing to carry into the LlamaRisk report rather than back to you: if the bounds are adjustable by contract function, then a print outside the band is resolved by a decision – whose, and on what trigger – rather than by the feed. That is the assurance question in one line, and it matters most on the downside, where the current floor sits 0.8% below issue value against the proposal’s own 7.79% backtest drawdown. The risk report is the right place for both, and I’ll happily read it when it lands.

Appreciate the point-by-point response. :saluting_face: