1ч. назад
HypurrFi flags Aave V3 rounding bug as V4 security review and governance rifts collide
On March 6, 2026, HypurrFi, a lending market on Hyperliquid's HyperEVM, disclosed a rounding vulnerability in Aave V3 core code prior to version 3.5 and paused its XAUTO and UBTC markets to protect user funds. The disclosure followed Aave Labs' V4 security report covering March 2025 to February 2026, which cited no critical or high-severity issues after 345 review days and multiple audits, even as $26.5 billion is deposited in the protocol. At the same time, BDG Labs and Aave Chain Initiative are preparing to exit Aave over governance concerns tied to the V4 migration and a $51 million funding proposal for Aave Labs.