# Mainnet wstETH Liquidation Assessment: Financing Remains Unverified

**URL:** <https://governance.aave.com/t/mainnet-wsteth-liquidation-assessment-financing-remains-unverified/25643>\
**Category:** Assessments\
**Created:** [September 15, 2026, 11:41am UTC](https://governance.aave.com/t/mainnet-wsteth-liquidation-assessment-financing-remains-unverified/25643 "2026-09-15T11:41:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![GBQuant](https://dub1.discourse-cdn.com/flex013/user_avatar/governance.aave.com/gbquant/32/15392_2.png) [@GBQuant](https://governance.aave.com/u/GBQuant)\
**Post date:** [September 15, 2026, 11:41am UTC](https://governance.aave.com/t/mainnet-wsteth-liquidation-assessment-financing-remains-unverified/25643/1 "2026-09-15T11:41:06Z")

</div>

Three recent discussions kept circling the same question from different sides: if this collateral falls hard, does the market actually get liquidated? The [HINC proposal](https://governance.aave.com/t/arfc-onboard-hinc-neuberger-securitize-high-income-tokenized-fund-to-aave-horizon/25500) asked whether a stated backstop is large enough and whether the oracle could even publish the stress. The [liquidation-bot thread](https://governance.aave.com/t/aave-v3-v4-liquidation-bot/25565) asked whether a bot winning an auction tells you anything about someone who must hold a position for days. My own [stress tests](https://governance.aave.com/t/independent-liquidation-capacity-stress-tests-for-aave/25503) asked whether instant market depth covers the largest borrower.

These discussions lead to four questions that apply to any collateral, answered in order:

1. **Can the oracle show the crash?** If the price Aave reads cannot move that far, nothing else matters.
2. **How much debt has to be repaid at the same moment?** Liquidating $5m and liquidating $500m are different problems.
3. **Is there money to repay it?** Someone has to hand over that cash at the moment of liquidation.
4. **Is the bonus enough to make it worth doing?** Having the money and wanting to use it are not the same thing.

Each test states its criterion before looking at the evidence, and each answer is PASS, FAIL or **INDETERMINATE**. That last outcome matters: it means the evidence cannot decide, and names the missing input and who can supply it. Assuming a number to avoid an INDETERMINATE is how a gap disappears into a result.

## Worked example: mainnet wstETH

Aave V3 Ethereum, at block 25,780,402. The size tested is the 99th percentile of simultaneous repayment under a published two-day stress run: large, but not the worst case in the distribution.

For looped positions, the stress assumes the wstETH/ETH redemption rate itself falls. That is different from wstETH merely trading at a discount on the market.

| Test | Outcome |
| --- | --- |
| 1. Oracle can show the crash | PASS, for the inputs tested |
| 2. Simultaneous repayment | PASS, calculated |
| 3. Money to repay | **INDETERMINATE** |
| 4. Bonus adequate | PASS, at the size and assumptions tested |

**Overall: INDETERMINATE.**

### 1. The oracle

Reading the oracle tells you which price it returns today. The question is whether a crash would get through it, and you cannot wait for one to find out.

So the run swaps the ETH/USD feed for a stand-in for the length of a single read, forces a value into it, and asks the real Aave oracle what price it returns. The deployed contracts do all the work; only the input is ours. Nothing is deployed and nothing changes on chain.

Driving the stand-in down to a fraction of a cent, Aave returned the matching low price every time: neither the adapter nor Aave itself puts a floor under a falling price. A zero or negative value makes the price read fail outright instead of returning something wrong.

Making the timestamp unreadable, and then thirty days old, did not change the price Aave returned. Had anything in the read path checked the timestamp, the first test would have failed and the second would have been rejected as stale. Neither happened, so on the path tested nothing rejects a price for being old.

What this does not cover is the feed itself: the stand-in replaces it, so the real feed’s own rules for accepting a new value never run. One of those rules is readable on chain, a floor of one hundred-millionth of a dollar, far below any crash worth modelling.

### 2. How much, at once

The run sizes every liquidation in every stress scenario, after checking that it reproduces the published stress run. The 99th-percentile requirement is **$7.15m of debt repayment and $7.58m of collateral received**. Across the worst 1% of scenarios, those amounts average $24.14m and $25.59m.

### 3. The money, and why this is undecided

An **atomic liquidator** borrows the cash inside one transaction, so it must sell the collateral in that same transaction. Its ceiling is the depth it can sell into without eating the bonus: about **$1.29m** of repayment under the stated depth assumption, before fees and auction costs.

The remaining **$5.86m** needs capital someone commits and keeps committed while the collateral is sold or redeemed.

This assessment does not establish how much capital is available, or for how long. That is why financing remains INDETERMINATE and not FAIL: the repayment requirement is calculated, the available funding is not verified. Operators in the liquidation-bot thread report the same gap from the other side: positions left unliquidated for days on thinner assets when flash liquidity runs out.

### 4. The bonus

The bonus is fixed at 6%. For a liquidator financing the full $7.15m repayment, the break-even bonus is 5.35% to 5.50% selling into the market, or 4.35% with primary redemption available. So 6% covers it, with about half a percentage point to spare in the worst regime.

With the same assumptions, the bonus stops covering the worst regime at about **$22.85m of repayment** : 3.2 times the tested size and 95% of the worst-1% average. At that average, the required bonus is 6.0414%, just 4.14 basis points above the available 6%. That narrow shortfall depends on costs as well as size. Every exit assumption behind these numbers is a stated sensitivity, not measured capacity.

## This is not specific to wstETH

The four questions transfer to other assets; the evidence does not. A listing proposal should document eligible liquidators, committed capital and redemption terms alongside its risk parameters.

## Reproducing the worked example

To reproduce the worked assessment from the committed inputs, run this after installing the repository. It runs offline, and every verdict cites the evidence it rests on. The linked documents explain the inputs and how to adapt the format to another asset.

```bash
python -m aave_risk_engine.run_four_test_assessment

```

- [Assessment format](https://github.com/BianchiGiacomo/aave-risk-engine/blob/v0.4.0/docs/assessment-template.md)
- [Worked assessment](https://github.com/BianchiGiacomo/aave-risk-engine/blob/v0.4.0/docs/assessments/2026-08-18-aave-v3-ethereum-wsteth.md)
- [Oracle case](https://github.com/BianchiGiacomo/aave-risk-engine/blob/v0.4.0/docs/case_studies/2026-09-aave-wsteth-oracle-reachability.md)

## The ask

I would like one person to run this against a second asset and tell me where the instructions are unclear, which evidence requirements are unreasonable, and which verdicts they disagree with. An asset with a bounded oracle or a permissioned liquidator set would test it harder than wstETH did.

* * *

Independent research, unaffiliated with Aave Labs, the DAO or its service providers. This is not a parameter recommendation or a safety verdict.
