Aave Protocol
Scan basis: 10 July 2026. Run a fresh scan for current data.
Run live scanAave is a non-custodial lending protocol on Ethereum and other EVM chains. The AAVE token is the governance and staking token for the protocol. The contract security score is 13/100 LOW: the token contract is structurally sound (fixed supply, non-upgradeable, no active mint). The governance and protocol layer carries documented complexity - proxy upgradeability on the lending core, delegate concentration in voting power, and an emergency Guardian veto - none of which is hidden and all of which is time-locked. This page explains what that means for each audience.
What the evidence shows
Ownership
Aave DAO via governance votes
No single owner address. Effective control is exercised through AaveGovernanceV2. Delegate concentration in the top 10 addresses is meaningful.
Mint Authority
Fixed supply - no active mint
Maximum supply is capped. The ecosystem reserve holds pre-minted tokens. No active mint authority role in the token contract.
Liquidity
DEX pool unlocked; deep institutional depth
DEX pool: $2.57M on-chain verified. LP tokens not time-locked (88.4% of LP unlocked per engine). Global institutional depth across T1 exchanges dwarfs the DEX pool - price is not DEX-pool-dependent. LP is DAO-managed, not held by an anonymous EOA. Unlocked is a flag; context determines whether it is a risk.
Governance Power
Top delegates hold significant concentration
A small number of delegate addresses collectively control a disproportionate share of voting power. Proposal creation requires meeting a minimum threshold.
Protocol Upgradeability
Token fixed; core protocol is proxy-based
The AAVE ERC-20 token contract is non-upgradeable. Core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by a governance-timelock.
Emergency Controls
Guardian multisig retains veto power
The Aave Guardian can cancel governance proposals before execution. Multisig composition is partially attributed. This is a circuit-breaker, not routine governance.
What XemaS found
The engine returns 13/100 LOW on contract security. The AAVE token is a non-upgradeable ERC-20 with fixed maximum supply. Source is verified. No honeypot is detected. No mint authority is active - the ecosystem reserve holds pre-minted tokens; supply cannot be inflated through the token contract. LP is reported UNLOCKED (88.4% of LP tokens unlocked, 0% locked, 0% burned). The on-chain verified DEX liquidity at scan time is $2.57M - institutional depth on centralised exchanges dwarfs the DEX pool, so price is not DEX-pool-dependent. The LP Not Time-Locked condition is factored into the score; it is not flagged as a formal finding because context confirms DAO treasury custody rather than anonymous EOA control.
Protocol governance runs through AaveGovernanceV2. Two executor contracts handle different categories of changes: a Short Executor with a 24-hour timelock for parameter adjustments, and a Long Executor with a longer delay for critical changes such as implementation upgrades. No protocol change can execute immediately. The timelock window is the primary protection for users - it provides a reaction interval between a proposal passing and its effect taking hold. The core Aave V3 lending contracts use TransparentUpgradeableProxy controlled by the governance timelock; the AAVE token contract itself is not upgradeable.
Voting power is concentrated. AAVE holders can delegate to any address, and in practice the top delegate addresses account for a significant share of active voting power. The top holder at scan time holds 14.01% of supply, confirmed as the stkAAVE staking contract (Staked Aave) - a legitimate custody dependency, not a whale accumulator. In total 201,007 holders are recorded. Binance and Robinhood custody addresses (combined 7.85% of supply) are excluded from effective concentration calculations. Governance concentration is an observable on-chain condition, not a hidden threat. It represents an institutional dependency rather than a technical exploit surface.
The Aave Guardian is a multisig with the ability to cancel proposals that have passed a governance vote but not yet executed. It is an emergency veto, not a routine governance actor. Its composition includes partially attributed signers - some addresses correspond to known entities, others are not in the entity registry. The Guardian exists to prevent clearly malicious proposals from executing if governance is temporarily compromised. Governance and control coverage is 2 of 4 dimensions assessed at scan time; upgradeability and vote parameters are partially covered.
Why it matters
The contract security score is 13/100 LOW. The AAVE token itself is structurally sound: fixed supply, no hidden mint, non-upgradeable ERC-20. The DEX pool LP is unlocked but DAO-managed - not an anonymous-deployer risk. The governance exposure is indirect: delegates you do not control make decisions that change protocol parameters affecting the utility of AAVE. The timelock provides a window to exit before critical upgrades take effect. The primary risk scenario is governance capture by a coordinated delegate bloc, not a contract exploit.
Current state requires a fresh scan
The evidence above reflects a scan from 10 July 2026.
Sign in to run a current deep scan
A deep scan returns current risk scores, live governance proposal status, and updated holder attribution.
Evidence table
| Fact | State |
|---|---|
| Token supply ceiling | VERIFIED |
| LP lock status (DEX pool) | PARTIAL |
| Top holder attribution | PARTIAL |
| Ecosystem reserve address | VERIFIED |
| Short Executor timelock delay | VERIFIED |
| Long Executor timelock delay | VERIFIED |
| Top-10 delegate voting concentration | PARTIAL |
| Guardian multisig attribution | PARTIAL |
| Protocol Pool proxy admin | VERIFIED |
| Sanctions match (contract + top holders) | VERIFIED |
What was not visible
Governance coverage is 2 of 4 dimensions
The scan assessed upgradeability and governance vote parameters. Owner control and treasury control were not assessed at scan time. Coverage expands as on-chain data is collected. Two dimensions marked PARTIAL; two not yet assessed.
LP controller identity requires verification
The DEX pool LP is unlocked. The entity controlling those LP tokens is attributed to the DAO treasury with high confidence, but the verification is based on on-chain state at scan time. If LP custody changed, the risk profile changes. Verify before large exposure.
Off-chain governance participation
Aave governance discussion and sentiment are largely off-chain. Only the final execution step - timelock queue and on-chain call - is directly verifiable. Proposal intent and delegate reasoning require reading off-chain forums.
Delegate identity is partially unresolved
On-chain delegation addresses do not automatically map to real-world entities. Delegate identity relies on voluntary registration or entity labels in the registry. Some top delegates are not attributed.
Guardian composition is not fully on-chain
The Aave Guardian is a multisig. Its full signer set and required threshold are not fully derivable from on-chain data alone. The scan covers the attributed subset of known signers only.
Scan any protocol with the same evidence engine
EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.
Scan a contractNo account required for a first scan.