Skip to documentation
AnyLend docs
Browse documentation

Docs / Risk and governance

Risk and governance

Isolation narrows the blast radius of a pool. It does not make an asset, oracle, rate model, creator, governance authority, or parameter set safe by itself. Review every layer that can change a user's outcome.

Do not read a curated badge as a safety guarantee. A verified pool is a current configuration and health attestation recorded by the factory. It is not a professional risk assessment, an economic-risk score, or a guarantee that external contracts will not change.

Risk register

LayerQuestions to answerResidual boundary
Token and custodyIs the token canonical, non-rebasing, correctly scaled, and exact-transfer? Does the pool hold the represented balance?Unsupported token behavior or an external upgrade can still invalidate assumptions.
OracleWhich feed prices the assets? What are its staleness, phase, bounds, and owner controls?Feed governance and data quality are external to the pool bytecode.
Rate modelHow does utilization change the borrow rate? Are the parameters within the approved economic policy?A technically valid model can still be economically unsuitable.
ParametersWhat are LTV, liquidation threshold, bonus, supply cap, and borrow cap?Parameters bound exposure but do not promise liquidity or returns.
CreatorWho can pause the pool or recover reserves? Is that address governed and monitored?Creator administration is an operational authority, even when the pool is curated.
Factory governanceWho can approve modules, pause pools, transfer ownership, or curate a pool?The intended production owner is a Safe; signer controls, roles, and monitoring require separate evidence.

Permissionless and curated tiers

Any address can create a pool through PoolFactory, subject to the contract's validation rules. That permissionless tier is useful for experimentation but should not be treated as reviewed.

The curated tier is opt-in. Governance approves the token, oracle, and interest-rate model; the factory and verifier compute a configuration hash; and the pool must pass health checks before isVerifiedPool(pool) becomes true. Ownership handoffs invalidate the curation epoch and require explicit re-curation.

Permissionless
Discover and inspect

No implied endorsement.

Curated
Current config attested

No implied safety rating.

Production
Separate owner gate

Requires external evidence.

Governance responsibilities

Token and oracle boundaries

AnyLend's accounting assumes standard ERC-20 transfer semantics. Fee-on-transfer, rebasing, mutable-decimals, and opaque upgradeable assets need an independent review; the protocol's custody ledgers deliberately fail closed when observed balances no longer support represented values.

Oracle adapters normalize price and enforce sign, round, staleness, lower-bound, upper-bound, aggregator, and phase checks. These checks protect the adapter boundary, not the truth of the underlying market or the governance of the feed provider.

A reviewer’s minimum checklist

  1. Pin the factory, pool, token, oracle, and rate-model addresses to the intended network.
  2. Read the live code hashes and compare them with the reviewed deployment evidence.
  3. Inspect the pool configuration and verify that the parameters fit the risk policy.
  4. Check owner, pending owner, creator, Safe roles, and recent admin events.
  5. Confirm oracle feeds are healthy and current at a finalized block.
  6. Run a small lifecycle on the target network before treating the integration as exercised; use Sepolia for rehearsal and regression testing.