Pre-cautionary measures on three Aave v3 assets

Context

During a security review of the Aave protocol, a technical problem has been detected, affecting a small sub-set of assets under specific circumstances and configurations.

In order to be cautious and reduce any type of risk, as technical service providers of the DAO we have recommended to the Aave Guardian to temporarily halt new supplying and borrowing of WMATIC, MATICx and WAVAX, with all other functionality remaining fully operative.

To be clear, no funds are at risk and all other assets and pools are operating as always.

Next steps

We will keep the investigation, and communicate more details to the community in due time.

9 Likes

Yes, any more information about this will be very appreciated. The market is extremely volatile right now and the timing of this decision couldn’t be worse.

3 Likes

Hi, @JohnPauls !

It’s a purely technical issue, not related with liquidity at all.

@bgdlabs will provide more information about the timeline in a short period of time.


Regards,
Andrei,
BGD Labs

2 Likes

Looking forward to updates …

2 Likes

Recognize you can’t say precisely, but could the team provide any kind of rough order of magnitude on expected timing here? i.e. Are you anticipating more of a 6 hours or 6 days kind of thing?

2 Likes

As an update to the community:

  • We are still working on this, and we can’t still estimate a precise timeline for its resolution. Highly probably will require a governance proposal, which would extend the freezing for some days, given the voting duration limitations.
  • There is no liquidity problem or funds at risk. Withdrawals and repayments on the assets frozen are completely active, together with liquidations. Only “additive” actions like supplying and borrowing them are halted.
  • Given the isolated nature of the protections, it is possible to use any other asset of each pool to refill collateral in any position, including those with similar denomination as sAVAX and stMATIC.

As always, our priority as service providers of the DAO is to look for the security of the protocol, and we will keep informing the community about any following steps.

3 Likes

I appreciate the workaround, but sAVAX only has an LTV of 30%, which makes it pretty useless as collateral.

1 Like

As an update for the community:

We will be creating a governance proposal to apply permanent fix regarding the technical problem detected.

We have asked Certora (security service provider of the Aave DAO) and Avara Labs (development contributor) to review the proposal for extra assurance, and to comment on this threat certifying that no issue has been detected during the review.
Once that review procedure is finished, we will proceed with the proposal creation.

3 Likes

no, the governance process is always 5 days
1 day pending
3 days of voting
1 day timelock

So roughly 5 days before proposal execution.

edit: Sorry first wrote it’s 6, although is 5.

2 Likes

Thanks for the update

2 Likes

Behalf of Aave Labs, confirming that we have reviewed the technical issue and the proposed BGD fix, and we confirm that the fix addresses the issue completely and precisely, while not impacting any other elements of the Protocol.

5 Likes

On behalf of Certora, i can affirm that we reviewed the proposed solution for the issue and that the implementation indeed resolves the problem with no undesired side effects.

Certora will vote YES on the proposal once voting starts

2 Likes

Following the timeline, we have create a governance proposal, with voting starting in approximately 10h.

Participate :ghost:

https://vote.onaave.com/proposal/?proposalId=0&ipfsHash=0xf92585de2ff0761e3d86d0e3253d2f49b2a916ef63784834f5e7230efb1bd194

4 Likes

What happened??? Is this how it works? I didn’t monitor it for 3 days, I don’t follow social media. I left MATICX and MATIC in lending and with a safe margin and I was liquidated, why yes??? Do I always have to be in front of the computer??? Is that what SAFETY is???

2 Likes

You have been liquidated because your HF wasn’t high enough. The freeze didn’t have any impact on your position. Meaning that even without freeze you would have been liquidated. You were still able to supply collateral.

1 Like

I withdraw some of the MATIC that i had in stake and i didn’t receive yet in my wallet. Are we having any issue with withdraws?

1 Like

I even cant switch in ETH mainet ? usdc and eth is it all locked too ?

just work , tks now can move

1 Like

Check the vote, its all written in there. 10th will be the execution day

Hello @JohnPauls .

We will coordinate with the Aave Guardian to execute the unfreeze after the proposal has been executed. The time after that execution is difficult to predict, but in the order of minutes or hours.

1 Like