Aave Labs this week unveiled a comprehensive security framework for Aave V4, describing nearly a year of audits, formal verification, and public testing designed to harden what is widely considered decentralized finance’s largest lending protocol before it goes live.
The organization said in a forum post that the security program spanned roughly 345 cumulative days of review and was backed by a $1.5 million budget approved by the Aave DAO. Rather than treating security as a last-minute hurdle, Aave Labs said the process began at the design stage and continued through code reviews, testing, and final remediation checks.
Audit Timeline: From Design to Public Contest
The effort began in March 2025 when formal verification firm Certora joined developers during an Aave design workshop to shape the protocol’s verification framework. Independent security researchers also reviewed early architectural decisions. From September through November 2025, audit firms including Chainsecurity, Trail of Bits, and Blackthorn conducted manual code reviews and invariant testing, with 15 researchers contributing more than 275 audit days. A public security contest followed between November 2025 and January 2026 on the Sherlock platform, where over 900 verified participants submitted more than 950 findings. No critical or high-severity vulnerabilities were identified, and most submissions were deemed invalid. A second audit round in February 2026 added about 80 review days focused on validating fixes, with published reports from the same firms reporting no high-severity flaws.
Architecture and Future Security Plans
Aave V4’s codebase is smaller than its predecessor due to a redesigned hub-and-spoke architecture, which simplifies review and reduces attack surfaces. The team also tested AI-based auditing tools during development, though human-led analysis remained the primary security layer. Looking ahead, Aave Labs plans to maintain formal verification, continue layered security testing, and introduce a standing bug bounty program to invite hackers to probe for vulnerabilities before malicious actors.
While a governance dispute involving ACI founder Marc Zeller also emerged this week, the security framework itself remains focused on ensuring Aave V4's readiness for launch with the highest safety standards.

