On-Chain Evidence Review

Aave (AAVE)

COMPLEX - DAO GOVERNED|13/100
Ethereum·0x7Fc665...2DDaE9governance-token
LiveLast scanned 10 July 2026
Run your own scan
Why this example?

Aave is the middle case that most scanners misrepresent. The engine returns 13/100 LOW on contract security - fixed supply, verified source, no honeypot. But the same scan also surfaces proxy upgradeability on the lending protocol, delegate concentration in voting power, and a Guardian emergency veto. None of these are hidden. All are time-locked and partially attributed. A scanner that stops at the score says "safe." One that only looks at governance flags says "risky." XemaS returns both layers and explains what they mean for each audience.

Evidence Summary

What the evidence shows

Ownership

PARTIAL

Aave DAO via governance votes

No single owner address. Effective control is exercised through AaveGovernanceV2. Delegate concentration in the top 10 addresses is meaningful.

Mint Authority

VERIFIED

Fixed supply - no active mint

Maximum supply is capped. The ecosystem reserve holds pre-minted tokens. No active mint authority role in the token contract.

Liquidity

PARTIAL

DEX pool unlocked; deep institutional depth

DEX pool: $2.57M on-chain verified. LP tokens not time-locked (88.4% of LP unlocked per engine). Global institutional depth across T1 exchanges dwarfs the DEX pool - price is not DEX-pool-dependent. LP is DAO-managed, not held by an anonymous EOA. Unlocked is a flag; context determines whether it is a risk.

Governance Power

PARTIAL

Top delegates hold significant concentration

A small number of delegate addresses collectively control a disproportionate share of voting power. Proposal creation requires meeting a minimum threshold.

Protocol Upgradeability

PARTIAL

Token fixed; core protocol is proxy-based

The AAVE ERC-20 token contract is non-upgradeable. Core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by a governance-timelock.

Emergency Controls

PARTIAL

Guardian multisig retains veto power

The Aave Guardian can cancel governance proposals before execution. Multisig composition is partially attributed. This is a circuit-breaker, not routine governance.

Findings

What XemaS found

The engine returns 13/100 LOW on contract security. The AAVE token is a non-upgradeable ERC-20 with fixed maximum supply. Source is verified. No honeypot is detected. No mint authority is active - the ecosystem reserve holds pre-minted tokens; supply cannot be inflated through the token contract. LP is reported UNLOCKED (88.4% of LP tokens unlocked, 0% locked, 0% burned). The on-chain verified DEX liquidity at scan time is $2.57M - institutional depth on centralised exchanges dwarfs the DEX pool, so price is not DEX-pool-dependent. The LP Not Time-Locked condition is factored into the score; it is not flagged as a formal finding because context confirms DAO treasury custody rather than anonymous EOA control.

Protocol governance runs through AaveGovernanceV2. Two executor contracts handle different categories of changes: a Short Executor with a 24-hour timelock for parameter adjustments, and a Long Executor with a longer delay for critical changes such as implementation upgrades. No protocol change can execute immediately. The timelock window is the primary protection for users - it provides a reaction interval between a proposal passing and its effect taking hold. The core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by the governance timelock; the AAVE token contract itself is not upgradeable.

Voting power is concentrated. AAVE holders can delegate to any address, and in practice the top delegate addresses account for a significant share of active voting power. The top holder at scan time holds 14.01% of supply, confirmed as the stkAAVE staking contract (Staked Aave) - a legitimate custody dependency, not a whale accumulator. In total 201,007 holders are recorded. Binance and Robinhood custody addresses (combined 7.85% of supply) are excluded from effective concentration calculations. Governance concentration is an observable on-chain condition, not a hidden threat. It represents an institutional dependency rather than a technical exploit surface.

The Aave Guardian is a multisig with the ability to cancel proposals that have passed a governance vote but not yet executed. It is an emergency veto, not a routine governance actor. Its composition includes partially attributed signers - some addresses correspond to known entities, others are not in the entity registry. The Guardian exists to prevent clearly malicious proposals from executing if governance is temporarily compromised. Governance and control coverage is 2 of 4 dimensions assessed at scan time; upgradeability and vote parameters are partially covered.

Interpretation

Why it matters

The contract security score is 13/100 LOW. The AAVE token itself is structurally sound: fixed supply, no hidden mint, non-upgradeable ERC-20. The DEX pool LP is unlocked but DAO-managed - not an anonymous-deployer risk. The governance exposure is indirect: delegates you do not control make decisions that change protocol parameters affecting the utility of AAVE. The timelock provides a window to exit before critical upgrades take effect. The primary risk scenario is governance capture by a coordinated delegate bloc, not a contract exploit.

Evidence

Evidence table

FactState
Token supply ceilingVERIFIED
LP lock status (DEX pool)PARTIAL
Top holder attributionPARTIAL
Ecosystem reserve addressVERIFIED
Short Executor timelock delayVERIFIED
Long Executor timelock delayVERIFIED
Top-10 delegate voting concentrationPARTIAL
Guardian multisig attributionPARTIAL
Protocol Pool proxy adminVERIFIED
Sanctions match (contract + top holders)VERIFIED
Honest Limits

What was not visible

Governance coverage is 2 of 4 dimensions

The scan assessed upgradeability and governance vote parameters. Owner control and treasury control were not assessed at scan time. Coverage expands as on-chain data is collected. Two dimensions marked PARTIAL; two not yet assessed.

LP controller identity requires verification

The DEX pool LP is unlocked. The entity controlling those LP tokens is attributed to the DAO treasury with high confidence, but the verification is based on on-chain state at scan time. If LP custody changed, the risk profile changes. Verify before large exposure.

Off-chain governance participation

Aave governance discussion and sentiment are largely off-chain. Only the final execution step - timelock queue and on-chain call - is directly verifiable. Proposal intent and delegate reasoning require reading off-chain forums.

Delegate identity is partially unresolved

On-chain delegation addresses do not automatically map to real-world entities. Delegate identity relies on voluntary registration or entity labels in the registry. Some top delegates are not attributed.

Guardian composition is not fully on-chain

The Aave Guardian is a multisig. Its full signer set and required threshold are not fully derivable from on-chain data alone. The scan covers the attributed subset of known signers only.

Investigation series

Same framework, different evidence

CRITICALBNB Chain

Squid Game Token (SQUID)

Anonymous deployer, honeypot transfer logic, no liquidity lock. Risk score 97.

DEPEG - RESTOREDEthereum

USDC / SVB Depeg (2023)

A banking failure priced on-chain in hours: $3.3B reserve exposure, ~$0.88 low, DAI contagion, information-driven recovery.

EXPLOITED - RETURNEDEthereum

Euler Finance Exploit (2023)

A governance upgrade skipped one health check: ~$197M drained via donate-and-self-liquidate, then returned over three weeks.

EXPLOITED - PARTIAL RECOVERYEthereum

Nomad Bridge Hack (2022)

One zeroed initialization parameter made verification a no-op: ~$190M drained permissionlessly by hundreds of copycat addresses.

EXPLOITED - PARTIAL RECOVERYEthereum / Ronin

Ronin Bridge Hack (2022)

Five of nine validator keys compromised: 173,600 ETH and 25.5M USDC drained in two forged withdrawals and undetected for 6 days. Attributed to Lazarus Group by US Treasury.

EXPLOITED - NO RECOVERYEthereum / Harmony

Harmony Horizon Bridge Hack (2022)

Two of five validator keys compromised: ~$100M drained 91 days after Ronin, moved through Tornado Cash within hours. Same attacker group; complete loss. Attributed to Lazarus Group by FBI and OFAC.

EXPLOITED - PARTIAL RECOVERYSolana

Mango Markets Oracle Manipulation (2022)

No code exploit: oracle assumptions failed. MNGO oracle price inflated ~30x; $116M borrowed against manufactured collateral. Conviction: Avraham Eisenberg, SDNY, April 2024.

EXPLOITED - NO RECOVERYEthereum

Beanstalk Farms Governance Exploit (2022)

No code exploit: governance assumptions failed. Flash-borrowed supermajority passed a malicious BIP in one block; $182M drained with no execution delay to stop it. Complete loss.

VERIFIEDEthereum

USD Coin (USDC)

Legitimate administrative controls attributed to a regulated entity. Risk score 14.

Get started

Scan any address with the same evidence engine

EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.

Scan a token or wallet

No account required for a first scan.