White-label Aave deployment: the risk function an operator cannot rebuild alone
On 4 May 2026, Tydro suspended every market it operated. Chaos Labs, then its sole price data provider, had disclosed an attack on its infrastructure and recommended a halt.
On 4 May 2026, Tydro suspended every market it operated. Chaos Labs, then its sole price data provider, had disclosed an attack on its infrastructure and recommended a halt. No incorrect price reached the markets, and no user positions were impacted. About 48 hours later, Chaos Labs approved a restart, but the markets remained closed as the operator migrated the feeds.
The incident exposed something structural. Tydro runs Aave v3, and a white-label Aave deployment does not inherit the system that would normally have handled a moment like that. Three functions go missing. Tydro bought two of them back within a week, and the third is why its v2 release will carry an independent Credora rating.
What a white-label Aave deployment inherits
Tydro is a non-custodial lending protocol on Ink, Kraken's Ethereum L2, carrying $56.15M in TVL and $48.67M in active loans across 11 pools per DefiLlama, roughly half of the chain's DeFi TVL.
The ARFC responsible for approving the deployment establishes the terms: Aave DAO will license the code and will take 'a share of all the revenue generated by the platform'. This share should be equal to or greater than the equivalent of a Reserve Factor of 5% calculated on the borrow volume in all pools.
That is where the relationship ends. Since the same ARFC states "the instance will initially be centrally governed by the Ink Foundation without a governance token", Aave DAO has no voting power over listings or parameters. BGD Labs, Aave's core development team, put it plainly: "the decision to include/not to assess in the listings set is of the friendly fork manager, not ours.” Bad debt is not covered by the backstop since "this instance will not be protected by the DAO-run Umbrella". The provision allowing trusted parties to modify the guardrails without a governance vote does not apply here.
This is the general form of the fork risk in Aave v3. The contracts are the same, and there is no oversight, leaving the operator with three functions they can replace: parameter stewardship, a loss backstop, and an external viewpoint on whether the markets are correctly priced from the start.
Of the 17 recorded security incidents across Aave forks tracked by DefiLlama, not including the Tydro incident, nine (just over half) were oracle-manipulation attacks, accounting for $52.0M of the $119.8M lost.
Aave's own governed instances have lost $918K in two incidents within the same dataset. One notable incident was a March 2026 oracle-parameter misconfiguration, which caused about $27M in liquidations. Aave DAO then voted to reimburse affected users, recovering $862K of the loss. No fork in the dataset has had an equivalent safety measure.
What an operator can buy
Two of the three are procurable. Feed redundancy is a vendor decision, and Tydro made it in May: Chainlink Data Feeds as primary, RedStone as the redundancy layer, migrated under a 48-hour timelock, with markets reopening around 10 May behind a grace period that halted liquidations while borrowers repaid or topped up.
That decision isn't the norm: across all DefiLlama-tracked protocols with an oracle on record, only 190 of 1,116 (17%) run two or more concurrent price feeds; most operators, forked or not, rely on a single source.
Transaction screening is software, and Hypernative's Transaction Guard now checks multisig transactions across Ethereum, Optimism, and Ink against policy before execution.
Both closures were the result of budget constraints and the use of engineering time; any operator possessing either of them could carry out the same action.
The part that has to come from outside
The third function does not work that way.
The reason that Aave's listing votes and Risk Stewards were useful had nothing to do with the mechanism itself; it was because the mechanism was situated outside the entity that held the position. A deployment that evaluates its own markets and then releases the grade is engaging in marketing. The value of a risk assessment lies in the fact that the assessor has no interest in the outcome, a property which no operator can create internally regardless of how much money they spend.
The gap remained open into May, and the v2 release is what closes it.
Adding a DeFi risk rating layer
Assets and markets with exposure to kBTC and USDC will carry a Credora rating on an A+ to D scale, shown in the Tydro interface, under the same methodology applied to every protocol on that scale.
The two metrics behind the letters differ by object. Markets are scored on a Probability of Significant Loss: the annualized probability that a market will lose more than 1% of its principal over a one-year horizon. That threshold suits a lending market, where the realistic failure mode is a partial loss which lenders absorb rather than a binary default. The estimate comes from 100,000 Monte Carlo simulations of price movements, liquidity conditions, and correlated shocks affecting the market's collateral, the probability being determined by the proportion of simulation paths that exceed the threshold. The five factors involving smart contract risk, liquidity risk, oracle risk, counterparty risk, and collateral quality risk are each modeled separately and thus affect the final rating.
Assets are scored on a Probability of Default, built by asset type: direct ratings where reserves are themselves rated tokens, published cumulative default rates for instruments such as T-Bills, and simulation for crypto-native reserves.
Both resolve onto one letter scale. For example, an ‘A’ corresponds to a PSL of roughly 0.1% to 0.4% annually, in the range of an investment-grade BBB/BBB- in traditional credit. Because the same scale covers markets on other protocols, a position here can be set against one on a protocol with entirely different mechanics, on a single axis, against a methodology published in full.
The scope is limited. A rating measures the downside associated with a particular market or asset that has been rated. It does not constitute an audit of the underlying protocol or chain, it does not claim that any position is free of risk, and it is not a replacement for a backstop. It is an assessment, and assessments do not cover losses.
The takeaway
A white-label Aave deployment inherits the code but not the oversight, and the three functions it leaves behind are not all equally replaceable. The feed and screening functions are acquired as external services. An independent assessment of the risk involves a party that does not report to the operator. It is the one function of the three that cannot, in principle, be set up in-house.
On Tydro v2, that party is Credora, rating every market and asset in scope.