Aave (AAVE)
Aave is the middle case that most scanners misrepresent. The engine returns 13/100 LOW on contract security - fixed supply, verified source, no honeypot. But the same scan also surfaces proxy upgradeability on the lending protocol, delegate concentration in voting power, and a Guardian emergency veto. None of these are hidden. All are time-locked and partially attributed. A scanner that stops at the score says "safe." One that only looks at governance flags says "risky." XemaS returns both layers and explains what they mean for each audience.
What the evidence shows
Ownership
Aave DAO via governance votes
No single owner address. Effective control is exercised through AaveGovernanceV2. Delegate concentration in the top 10 addresses is meaningful.
Mint Authority
Fixed supply - no active mint
Maximum supply is capped. The ecosystem reserve holds pre-minted tokens. No active mint authority role in the token contract.
Liquidity
DEX pool unlocked; deep institutional depth
DEX pool: $2.57M on-chain verified. LP tokens not time-locked (88.4% of LP unlocked per engine). Global institutional depth across T1 exchanges dwarfs the DEX pool - price is not DEX-pool-dependent. LP is DAO-managed, not held by an anonymous EOA. Unlocked is a flag; context determines whether it is a risk.
Governance Power
Top delegates hold significant concentration
A small number of delegate addresses collectively control a disproportionate share of voting power. Proposal creation requires meeting a minimum threshold.
Protocol Upgradeability
Token fixed; core protocol is proxy-based
The AAVE ERC-20 token contract is non-upgradeable. Core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by a governance-timelock.
Emergency Controls
Guardian multisig retains veto power
The Aave Guardian can cancel governance proposals before execution. Multisig composition is partially attributed. This is a circuit-breaker, not routine governance.
What XemaS found
The engine returns 13/100 LOW on contract security. The AAVE token is a non-upgradeable ERC-20 with fixed maximum supply. Source is verified. No honeypot is detected. No mint authority is active - the ecosystem reserve holds pre-minted tokens; supply cannot be inflated through the token contract. LP is reported UNLOCKED (88.4% of LP tokens unlocked, 0% locked, 0% burned). The on-chain verified DEX liquidity at scan time is $2.57M - institutional depth on centralised exchanges dwarfs the DEX pool, so price is not DEX-pool-dependent. The LP Not Time-Locked condition is factored into the score; it is not flagged as a formal finding because context confirms DAO treasury custody rather than anonymous EOA control.
Protocol governance runs through AaveGovernanceV2. Two executor contracts handle different categories of changes: a Short Executor with a 24-hour timelock for parameter adjustments, and a Long Executor with a longer delay for critical changes such as implementation upgrades. No protocol change can execute immediately. The timelock window is the primary protection for users - it provides a reaction interval between a proposal passing and its effect taking hold. The core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by the governance timelock; the AAVE token contract itself is not upgradeable.
Voting power is concentrated. AAVE holders can delegate to any address, and in practice the top delegate addresses account for a significant share of active voting power. The top holder at scan time holds 14.01% of supply, confirmed as the stkAAVE staking contract (Staked Aave) - a legitimate custody dependency, not a whale accumulator. In total 201,007 holders are recorded. Binance and Robinhood custody addresses (combined 7.85% of supply) are excluded from effective concentration calculations. Governance concentration is an observable on-chain condition, not a hidden threat. It represents an institutional dependency rather than a technical exploit surface.
The Aave Guardian is a multisig with the ability to cancel proposals that have passed a governance vote but not yet executed. It is an emergency veto, not a routine governance actor. Its composition includes partially attributed signers - some addresses correspond to known entities, others are not in the entity registry. The Guardian exists to prevent clearly malicious proposals from executing if governance is temporarily compromised. Governance and control coverage is 2 of 4 dimensions assessed at scan time; upgradeability and vote parameters are partially covered.
Why it matters
The contract security score is 13/100 LOW. The AAVE token itself is structurally sound: fixed supply, no hidden mint, non-upgradeable ERC-20. The DEX pool LP is unlocked but DAO-managed - not an anonymous-deployer risk. The governance exposure is indirect: delegates you do not control make decisions that change protocol parameters affecting the utility of AAVE. The timelock provides a window to exit before critical upgrades take effect. The primary risk scenario is governance capture by a coordinated delegate bloc, not a contract exploit.
Evidence table
| Fact | State |
|---|---|
| Token supply ceiling | VERIFIED |
| LP lock status (DEX pool) | PARTIAL |
| Top holder attribution | PARTIAL |
| Ecosystem reserve address | VERIFIED |
| Short Executor timelock delay | VERIFIED |
| Long Executor timelock delay | VERIFIED |
| Top-10 delegate voting concentration | PARTIAL |
| Guardian multisig attribution | PARTIAL |
| Protocol Pool proxy admin | VERIFIED |
| Sanctions match (contract + top holders) | VERIFIED |
What was not visible
Governance coverage is 2 of 4 dimensions
The scan assessed upgradeability and governance vote parameters. Owner control and treasury control were not assessed at scan time. Coverage expands as on-chain data is collected. Two dimensions marked PARTIAL; two not yet assessed.
LP controller identity requires verification
The DEX pool LP is unlocked. The entity controlling those LP tokens is attributed to the DAO treasury with high confidence, but the verification is based on on-chain state at scan time. If LP custody changed, the risk profile changes. Verify before large exposure.
Off-chain governance participation
Aave governance discussion and sentiment are largely off-chain. Only the final execution step - timelock queue and on-chain call - is directly verifiable. Proposal intent and delegate reasoning require reading off-chain forums.
Delegate identity is partially unresolved
On-chain delegation addresses do not automatically map to real-world entities. Delegate identity relies on voluntary registration or entity labels in the registry. Some top delegates are not attributed.
Guardian composition is not fully on-chain
The Aave Guardian is a multisig. Its full signer set and required threshold are not fully derivable from on-chain data alone. The scan covers the attributed subset of known signers only.
Same framework, different evidence
Squid Game Token (SQUID)
Anonymous deployer, honeypot transfer logic, no liquidity lock. Risk score 97.
USDC / SVB Depeg (2023)
A banking failure priced on-chain in hours: $3.3B reserve exposure, ~$0.88 low, DAI contagion, information-driven recovery.
Euler Finance Exploit (2023)
A governance upgrade skipped one health check: ~$197M drained via donate-and-self-liquidate, then returned over three weeks.
Nomad Bridge Hack (2022)
One zeroed initialization parameter made verification a no-op: ~$190M drained permissionlessly by hundreds of copycat addresses.
Ronin Bridge Hack (2022)
Five of nine validator keys compromised: 173,600 ETH and 25.5M USDC drained in two forged withdrawals and undetected for 6 days. Attributed to Lazarus Group by US Treasury.
Harmony Horizon Bridge Hack (2022)
Two of five validator keys compromised: ~$100M drained 91 days after Ronin, moved through Tornado Cash within hours. Same attacker group; complete loss. Attributed to Lazarus Group by FBI and OFAC.
Mango Markets Oracle Manipulation (2022)
No code exploit: oracle assumptions failed. MNGO oracle price inflated ~30x; $116M borrowed against manufactured collateral. Conviction: Avraham Eisenberg, SDNY, April 2024.
Beanstalk Farms Governance Exploit (2022)
No code exploit: governance assumptions failed. Flash-borrowed supermajority passed a malicious BIP in one block; $182M drained with no execution delay to stop it. Complete loss.
USD Coin (USDC)
Legitimate administrative controls attributed to a regulated entity. Risk score 14.
Scan any address with the same evidence engine
EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.
Scan a token or walletNo account required for a first scan.