# Why Ketju rejected Aave v4

- URL: https://riadefi.com/rejections/aave-v4/
- Exposure: stable lending
- Memo version: v1
- Reviewed: 2026-08-16
- Next review: 2026-11-16

## The memo

REJECTED FOR AN IMMATURE PRODUCTION RECORD, not a design flaw. Aave v4 launched on Ethereum in March 2026 with three separate Liquidity Hubs—Core, Prime, and Plus—and ten initial Spokes after roughly 345 cumulative days of security review supported by a $1.5M DAO budget. The code work is serious; the production record is necessarily short. The architectural change is more important than the version number: a Hub owns and prices pooled liquidity, while Spokes define collateral, borrowing, liquidation, and risk-premium rules. Separate Hubs are solvency boundaries, but every Spoke attached to one Hub shares that Hub's assets. Bad debt from one badly parameterized collateral Spoke is realized against the same Hub liquidity, bounded by add/draw caps rather than hard isolation. Inter-Hub credit lines add another controlled contagion path. That is more expressive and potentially more capital-efficient than v3, but it increases the number of contracts, configurations, and governance decisions that determine a supplier's true exposure. Zero allocation until Core, Prime, and Plus each have enough live liquidation and withdrawal history to be assessed separately, and until the v3-to-v4 migration shows that production scale is not outrunning risk operations. This is a reopen-pending rejection, not a postponed judgment: the kill criteria below state exactly what production evidence, per Hub, would flip it.

## What would reopen the file

- Reopen a named Hub and asset only after at least 12 months of production history and one liquidation above 1% of that Hub's TVL without bad debt or withdrawal impairment
- The proposed-size withdrawal must execute from the exact Hub and asset below 50 basis points while trailing-30-day utilization remains below 90%
- Every connected Spoke, per-asset add cap, draw cap, liquidation configuration, pause authority, and inter-Hub credit line must be reproducible from executed governance and live contracts
- Any Spoke draw cap above 10% of its Hub's matching-asset liquidity, or any inter-Hub credit line lacking a published loss boundary, prevents reopening
- Any core exploit, Hub bad debt, failed proposed-size withdrawal, or unaudited Hub, Spoke, oracle, or configurator upgrade keeps allocation at zero
- Re-review migration when v3 liquidity falls below two times v4 liquidity on the same chain and asset; protocol-wide TVL ratios are insufficient

---

Published by Ketju Research (https://ketjuresearch.com). Educational analysis only; not legal, tax, compliance, or investment advice.
Machine-readable index: https://riadefi.com/llms.txt · Content API: https://riadefi.com/content.json
