RIADeFi
Refusal file · stable lending

Why Ketju rejected Fluid (Instadapp)

Memo v1Published by Ketju Research

A registry memo, published verbatim and versioned. Superseded versions are recorded, never edited away. A rejection is a judgment for Ketju's client base and thesis, not a universal safety claim. Not investment, legal, tax, or compliance advice.

The memo

REJECTED at the 2026-08-15 correction, sleeve at zero. The prior memo approved Fluid on two claims, a clean exploit record and an audit roster of Spearbit, Trail of Bits, and Certora with formal verification, and neither survived checking. By the 2026-08-01 review date Fluid had already absorbed $19.3M to $21M of bad debt from the Resolv collapse: in late March 2026 an attacker compromised Resolv Labs' off-chain signing keys and minted about 80M unbacked USR, discounted wstUSR entered Fluid markets through stale oracle pricing, and roughly $100M of USR collateral stood against USDC and USDT borrows. The settlement closed 2026-05-11, per the post-mortem: Resolv about $9.7M, Fluid governance treasury $8.2M, the team $1.5M from future revenue. A separate key compromise took about $215k from the Ethereum reward distributor on 2026-06-01. Our published kill criterion reads bad debt in any market we hold, of any size. The Liquidity Layer pools the USDC and USDT borrows the USR markets drew on with the markets this entry approves, so either the criterion fired or the memo's own shared-liquidity thesis was wrong about what a market is. Either way the file reopens by our own rules. The audit roster fails the same check: no Trail of Bits or Certora report for Fluid exists in either firm's public index, and the official docs list PeckShield, Statemind, MixBytes, and Cantina. The strongest stated reason for approval could not be confirmed anywhere primary. The mitigations get equal weight. No Fluid contract was itself exploited; the loss came through a listed asset's oracle. The bad debt was paid in full with a public post-mortem and users were made whole. The architecture description verified accurate: one Liquidity Layer serving lending, vaults, and the DEX, tick-based liquidations with 0.1 to 3% penalties against the 5 to 10% typical elsewhere, and Automated Limits that throttle large movements per block, confirmed by the docs and MixBytes' engineering write-up. The shared Liquidity Layer prevents the held-reserve loss from being separated with the retained primary accounting, so the existing any-bad-debt trigger fired or cannot be cleared. Reimbursement does not erase that trigger. The remaining facts reinforce rejection: TVL peaked at $2.68B on 2025-10-08 and the stack stood at $802.6M at the 2026-08-14 review with $752.5M borrowed, so free liquidity is thin, and the $500k Immunefi cap is 0.06% of TVL, the same thin shape the StakeWise rejection counted. The review must answer the questions below by 2026-09-15.

What would reopen the file

  • Reopen only after primary market-level accounting proves no held USDC, USDT, or WETH supplier balance absorbed Resolv bad debt through the shared Liquidity Layer
  • Reopen only after every live held-market binary maps to a published PeckShield, Statemind, MixBytes, or Cantina review and any claimed formal verification is linked
  • Reopen only after Guardian, team multisig, signer thresholds, upgrade paths, and timelock delays are reproduced on-chain for every approved chain
  • Reopen only after proposed-size withdrawals from each named reserve succeed while free liquidity exceeds $10M and trailing-30-day utilization stays below 90%
  • Reopen only after the post-Resolv oracle overhaul is deployed and mapped to a published specification and audit; any new bad debt or key compromise keeps the protocol rejected

Facts on file

Verdict
Rejected
Exposure
stable lending
Chains examined
Ethereum, Arbitrum, Base
Instruments
USDC, USDT, WETH
Memo version
v1
Reviewed
Next review

← All published refusals