AssessmentsOn-chainLiquidation
Over-collateralised on-chain lending, assessed from liquidation risk inward
The model that outlasted the last cycle, assessed the way this desk assesses everything: what can go wrong first, and how much of it the published parameters actually tell you.
By Yusuf Karim
Over-collateralised on-chain lending — the model used by protocols such as Aave and Compound — is the structure that came through the last cycle intact. This assessment grades how well the model discloses and manages its risks. It does not grade whether anyone should use it, and it is emphatically not a recommendation to deposit anything.
We start where this desk always starts: with liquidation.
The mechanism
What the model genuinely does well
The risk is enumerable before you act. This is the substantive merit, and it is a real one. Collateral factors, liquidation thresholds and penalties are published per asset. A depositor or borrower can read the exact conditions under which they lose collateral, in advance, without asking anyone’s permission. Almost nothing else in this sector offers that.
Rates are mechanical rather than promised. An algorithmic rate that moves with utilisation is not a yield anyone is committing to pay you. That sounds like a drawback and is the opposite: a firm promising a fixed attractive yield is a firm that has to source it somewhere, and the last cycle demonstrated where.
Liquidation is automated and adversarial. Third parties are paid to enforce the margin, which means enforcement does not depend on the operator’s willingness or solvency.
Positions are inspectable. Total collateral, total borrowed and utilisation are visible on-chain. Whatever else is uncertain, the balance-sheet position is not a matter of trust.
Where it can lose you everything
Smart-contract failure. The mechanism is code. Code in this sector has been exploited repeatedly, and audits reduce that risk without eliminating it. An audit is a report about a point in time, not a guarantee, and treating it as one is the most common error readers make.
Oracle failure or manipulation. Liquidation depends entirely on a price feed. A feed that is wrong, stale, or manipulable liquidates positions that should not be liquidated, or fails to liquidate ones that should be. This is not hypothetical; it is a documented attack category.
Liquidation failure in disorderly markets. The model assumes collateral can be sold near the assumed price. In a sharp, fast decline — precisely the scenario liquidation exists for — that assumption can fail, leaving bad debt in the system. Over-collateralisation is a buffer sized against ordinary volatility, not against every possible move.
Governance risk. Parameters are changeable. A depositor’s risk profile can be altered by a governance decision they did not participate in, and concentration of voting power varies considerably.
Collateral asset risk. The buffer is denominated in an asset that can itself fail, de-peg, or lose liquidity. A well-collateralised position in a collapsing asset is not well-collateralised.
Borrower-side risk is total and fast. For anyone borrowing, liquidation can occur in minutes, with a penalty, without discretion and without notice. That is the design working as intended.
What this assessment is not
It is not a claim that this model, these protocols, or this market is regulated, authorised, licensed, insured or protected by any scheme. We make no such claim, and readers should be sceptical of anyone who does without naming the instrument and what it covers.
Pros and cons
Verdict
Our assessment grades disclosure and mechanism, and on that basis the model earns its score: it publishes its parameters, enforces them mechanically, and does not promise a yield it would have to source from somewhere opaque. Read as a recommendation, that score would be a serious misreading. The failure modes above are not remote — several are documented events in this sector — and anyone deploying assets here should assume that losing all of them is a possible outcome. Nothing here is financial advice.