Case summary
What happened
On 2022-11-22, a large CRV short position on Aave V2 Ethereum was liquidated and left approximately USD 1.7 million of protocol bad debt, later repaid through a DAO treasury process. On 2023-11-04, a vulnerability reported through Aave's security process led the Guardian to pause or freeze affected V2 and V3 pools and assets as a precaution. The affected markets were progressively restored and all V2/V3 pools were operating normally again by 2023-11-16. Aave continued expanding and launched V4 on Ethereum in March 2026 and Avalanche in July 2026.
Customer result
Customer outcome
Unknown
The 2022 CRV reserve deficit was addressed through DAO treasury actions that cleared the protocol's excess debt. That protocol-level recapitalization is not converted into a universal customer recovery percentage. The 2023 security response was precautionary and temporary; reviewed evidence confirms restoration of all affected markets but does not establish a customer compensation process requiring aggregate recovery modeling.
- Estimated recovery
- Unknown
- Repayment started
- —
- Repayment completed
- —
- Confidence
- High
Asset treatment
Terms risk
Customer-owned
Aave is modeled as non-custodial smart-contract lending rather than a platform-owned account balance. The 2022 CRV event demonstrates liquidity and market-concentration risk that can create protocol bad debt, while the 2023 incident demonstrates governance/guardian controls that can temporarily pause or freeze markets to mitigate a reported vulnerability. These controls do not imply centralized custody of supplied assets.
- Affected product
- —
- Confidence
- High
Known unknowns
Uncertainty
The 2022 CRV event created protocol bad debt but is not treated as a universal customer-loss amount. The 2023 security response was precautionary and temporary; no protocol-wide customer loss is inferred from the pause itself.
Chronology
Historical record
Aave V2 CRV liquidation leaves approximately USD 1.7 million bad debt
A large CRV short position on Aave V2 Ethereum was liquidated after CRV price rebounded. The collateral position was fully liquidated, with approximately USD 63 million USDC liquidated and roughly USD 1.7 million of residual CRV-denominated protocol bad debt. The DAO later approved a treasury-funded repayment path that cleared the remaining excess debt.
Liquidation volume and residual protocol bad debt are distinct metrics. Treasury repayment of the reserve deficit is not treated as evidence of a universal customer recovery percentage.
Aave pauses and freezes affected V2 and V3 markets after reported vulnerability
Following a vulnerability reported through Aave's security process, the Aave Guardian paused Aave V2 Ethereum and froze or paused affected assets across several V3 deployments as a precaution. Governance and service providers introduced fixes and a liquidation grace mechanism, then progressively unpaused affected markets. By 2023-11-16 all Aave V2 and V3 pools were reported operating normally again.
This event records precautionary availability restrictions and restoration. It does not infer a protocol-wide exploit loss or permanent shutdown.
Source record
Evidence dossier
Filter by claim, reliability, source type, and whether evidence is linked to a specific event.
customer outcome
2 sourcesRepay excess debt in CRV market for Aave V2 ETH
Aave Governance · 2022-11-23
Governance proposal documenting the approximately USD 1.6M excess debt and proposed DAO treasury repayment path.
Repay Excess CRV Debt on Ethereum v2
Aave Governance
Documents execution of the debt-repayment mechanism and acquisition of CRV to clear the remaining excess debt.
Event
4 sourcesBlameless Post Mortem: Curve - Aug 8, 2023
Aave Governance
Retrospective Aave governance post-mortem documenting the 2022-11-22 CRV position, approximately USD 63M USDC liquidation and approximately USD 1.7M bad debt.
Aave v2/v3 security incident 04/11/2023
Aave Governance · 2023-11-04
Primary governance incident thread documenting precautionary pauses/freezes, fixes and staged restoration through November 2023.
Authorizing Use of Grace Sentinel
Aave Governance · 2023-11-09
Documents the reported security threat, precautionary pool pauses and liquidation-grace mechanism used during restoration.
Aave v2/v3 security incident 04/11/2023 - closure update
Aave Governance · 2023-11-19
Confirms all affected markets and assets had been unpaused/unfrozen and the incident thread was closed.
status
2 sourcesAave V4 is Live on Ethereum
Aave Labs · 2026-03-30
Official Aave Labs announcement confirming Aave V4 live on Ethereum mainnet.
Aave V4 Launches on Avalanche
Aave Labs · 2026-07-15
Official Aave Labs announcement confirming continued multi-chain expansion and active supply/borrow markets in 2026.
No evidence records match the current filters.
Comparative records