Aave has published a new V4 security audit, with the latest review focused on the Tokenization Spoke. The component uses the ERC-4626 vault standard to turn Liquidity Hub deposits into fungible ERC-20 share tokens, a structure intended to make tokenized liquidity easier to integrate across Aave V4.
The latest review examined the ERC-4626 vault interface
According to Aave, the audit was conducted by ChainSecurity and looked at an ERC-4626-compliant vault. The design wraps deposits from the Liquidity Hub into ERC-20 share tokens, giving liquidity providers claims on the underlying liquidity. Aave founder and CEO Stani Kulechov also highlighted the release on social media, saying the vault interface is especially important for teams seeking integration access to Aave V4.
The Tokenization Spoke is one part of Aave V4’s broader architecture. It links liquidity deposits with fungible tokenized strategies inside the ecosystem. In plain terms, it converts a core liquidity position into a standardized on-chain interface that outside developers and protocols can work with more easily.
A broader V4 security effort ran for 345 days
The new report sits inside a much larger review process. Aave said its V4 security program lasted 345 days and included multiple audit rounds, formal verification, and public security testing, all centered on validating the protocol’s new Hub and Spoke architecture. Certora handled continuous formal verification during development, while ChainSecurity, Trail of Bits, and Blackthorn performed manual reviews across several stages.
Aave added that Blackthorn’s final audit cleared the submitted codebase without reporting any findings. That does not mean no issues ever appeared. During the review process, auditors flagged several minor and low-level issues, and the teams said those were addressed before the final reports were published.
More than 900 bug bounty participants joined the public review
Outside the private audit process, Aave also opened V4 to public testing through a six-week bug bounty program on Sherlock. The protocol said more than 900 participants joined the contest and reviewed the code. According to Aave, the program produced no critical or high-severity findings, and the broader audit process also ended with zero high-severity vulnerabilities after the code was finalized.
The newly published ChainSecurity report adds one more review layer to that process. Its focus is narrow but central: how the ERC-4626 vault interface connects Liquidity Hub deposits with fungible tokenized strategies inside Aave V4. The release shows that Aave is still putting core V4 components through detailed security checks, with standardized liquidity access standing out as a major point of attention.

