Rating a decentralised lending protocol starts with the relevant definition of default
A default is a failure to pay. That definition has served credit analysis for centuries, and in decentralised lending it stops working.
In the Aave V3 Ethereum Core Market, the largest lending market in DeFi with more than $16 billion of deposits as of July 2026,1 every loan is over-collateralised and repayment is enforced by code. A borrower who stops servicing a position does not trigger a workout. Once the position's Health Factor falls below 1.0, the protocol allows any third party to repay part of the debt and take the collateral at a pre-set discount.2 There is no covenant to breach and no identifiable borrower to assess. Run the traditional test and you conclude that default cannot occur. The conclusion is misleading.
The consensus view
Ask how risky a lending protocol is and the answer usually arrives as two numbers:
- How much is deposited, and
- How many audits the code has passed
Total value locked (TVL) stands in for strength. Audit history stands in for safety. The position this implies is that over-collateralisation removes credit risk and leaves a residual exposure to smart-contract exploits.
Our position is that over-collateralisation converts credit risk into a dependency on the liquidation mechanism, and that mechanism can fail while every line of code executes exactly as written.
Two ways enforcement fails
The first failure is economic. A liquidator acts only if seizing and selling the collateral is profitable. On-chain records show liquidators typically sell the seized asset inside the same transaction, on a decentralised exchange, taking no period of market exposure. For Wrapped ETH, the discount on offer for doing so is 5%.12 Where a position is large relative to the liquidity available in that market, price impact and slippage can exceed that discount. The liquidator then declines to act, or clears only the profitable slice and leaves the remainder. What is left behind is Bad Debt, a shortfall the protocol has to absorb.
The condition is compound. Bad Debt requires a sharp move against the position and thin liquidity in the collateral at the same time, which is why the exposure is close to invisible in calm markets and concentrated in exactly the ones that matter.
The second failure is the collateral itself. Much of what the protocol accepts as collateral was issued by other DeFi protocols and represents a claim on assets that issuer holds, such as a liquid staking token's claim on staked ETH.1 If the issuer fails, through an exploit or through a governance failure, the collateral loses value regardless of market conditions, and every position secured by it weakens at the same moment. The Ethereum Core Market's loan book is concentrated in leveraged positions backed by exactly this kind of collateral, so a single issuer failure can push a large share of borrowers towards liquidation simultaneously. This is correlation risk arriving through an unfamiliar channel, and it has already been demonstrated: in April 2026, a bridge exploit of the rsETH issuer left Aave markets exposed to unbacked collateral.3 No depositor lost money that time. The exposure was real all the same, and it arrived through exactly the channel described here.
Default as an economic event
If the event that threatens depositors is the failure of enforcement rather than a missed payment, the definition of default has to follow. When liquidation does not recover a debt in full, the shortfall is recorded as a deficit and absorbed through a sequence of protective layers.
The first funded layer is Umbrella, the protocol's staking-based insurance facility, where depositors voluntarily stake for additional yield and are slashed first if a deficit arises.2 That protection is asset-specific, so stake linked to one asset cannot cover a shortfall in another. Behind Umbrella, the layers are discretionary rather than funded. The treasury can be drawn down only by DAO vote. Beyond that, the DAO controls assets outside the protocol's balance sheet, including a substantial position in its own governance token, which it could commit but is under no obligation to do so. Their value is likely to be depressed at precisely the moment support is required.
We define default as the exhaustion of that entire waterfall: a deficit the protocol cannot cover, leaving depositors unable to redeem at par. It is an economic event rather than a legal one, and it is the event a depositor is actually underwriting.
Parsing PD, LGD and EL
Defining the event makes it measurable. We reconstructed every borrower position in the protocol's history from more than six million on-chain events, replayed through a replication of the protocol's own scaled-balance accounting. We modelled liquidator behaviour by tracing historical liquidations to the trades that sold the seized collateral, and measured the slippage paid at each trade size. We then generated 100,000 day-long price paths, assembled them into 10,000 one-year scenarios, applied a replication of the protocol's liquidation logic to the reconstructed positions, and passed the resulting Bad Debt through the waterfall.4
Our rating opinion, as of 1 July 2026, puts the one-year probability of default at 12.23%, loss given default at 2.54% of deposits, and expected loss at 0.31%.4
Read the three numbers together. A 12.23% PD looks alarming beside a rated bank. It is not the same animal. In our view the probability of default is high while the loss borne by depositors in a default is comparatively small, and the LGD reflects the cost of holding or exiting a deposit claim while the waterfall resolves rather than a permanent write-off of principal. That severity is calibrated to how deposit claims have actually been priced in secondary markets during a stress event, not to a theoretical recovery. High probability with low severity is a different risk profile from low probability with total loss, and quoting PD alone conflates the two. For this protocol, expected loss is the more informative measure.
The limitations of our model
The model excludes operating, criminal and legal risk, so smart-contract exploits, oracle manipulation and governance failure sit outside these numbers. Incorporating them is active work. Given the historical rate of major exploits across DeFi and Aave's security record, we do not expect their inclusion to raise the PD materially. A successful exploit is far less likely than the defaults priced here, but it would weigh heavily on severity.
The assumption that the DAO would provide support rests on commercial logic, that the protocol is the DAO's largest source of revenue, rather than on any rule or obligation. We reduce the value attributed to the DAO's holdings under stress to reflect this. Without the assumption, the PD would be materially higher.
We assume losses are shared evenly across depositors. In practice, deficits arise asset by asset and, unless the DAO restricts access after a stress event, withdrawals are met first-come, first-served, so the outcome depends partly on who exits first. Our figure is best read as a fair-value benchmark for an orderly wind-down, not a forecast of how a real default would unfold.
These assumptions lean the same way. Each is defensible on its own terms, and each, at the margin, works towards a lower number rather than a higher one. A reader should weigh them as a set, and treat the result as the considered but not conservative end of the range.
Why it matters
No depositor in the Ethereum Core Market has ever borne Bad Debt.1 The default described here has no precedent, which is exactly why it has to be defined before it can be priced. Over-collateralised lending has not abolished credit risk. It has relocated it, from the borrower's willingness to repay to the market's willingness to clear collateral at a discount. Measure the second and a protocol becomes rateable. Measure the first and you find nothing, then mistake that for safety.


