TokenIntel Research
CROSS-ASSET · LENDING ARCHITECTURE
A TokenIntel Cross-Asset Report

Architecture Determines
Which Crisis
You Survive

Aave and Morpho each absorbed a credit loss five weeks apart. One removed a third of the protocol's capital and has not been repaired four months later. The other did not register.

Drafted August 21, 2026
Protocols AAVE · MORPHO
Lens Loss Containment
tokenintel.org/reports 2026 · Which Failure Is Survivable?
The argument, stated first

The usual way to compare pooled and isolated lending is to argue about which is safer, and that argument mostly generates assertions. Both designs have now been hit. Aave's loss was roughly 60 times larger than Morpho's and produced a deposit response roughly 88 times deeper. The gap is not a measure of how much risk each protocol was carrying. It is a measure of what each architecture does with a loss once one arrives.

Published 2026-08-21 · Authored by Michael Thoma, supported with AI. Deposit series computed from DefiLlama for Aave V3 and Morpho, net TVL plus borrowed, summed across chains, pulled 2026-08-21. Incident details from TI's Aave and Morpho research pages. Analytical lenses: lending architectures and vault credit risk.
Aave bad debt, April
$230M
Scenario 2, LlamaRisk
Aave deposit response
-53.1%
$44.2B to $20.7B over 7 weeks
Aave today vs pre-event
-34.1%
4 months on, not recovered
Morpho bad debt, March
$3.8M
Resolv oracle cascade
Morpho deposit response
-0.6%
recovered inside two weeks
Morpho curator top two
73%
where its real risk now lives

Two protocols, two losses, five weeks apart

In March 2026 a loss landed on Morpho. In April 2026 a larger one landed on Aave. The events are close enough in time to share a market environment and far enough apart in structure to be informative, because Aave and Morpho are the two clearest live examples of the competing designs in TI's lending architectures typology: a monolithic unified pool against modular isolated markets.

On April 18, an attacker exploited a 1-of-1 DVN configuration in Kelp's LayerZero bridge and minted 116,500 unbacked rsETH, roughly $292M of collateral backed by nothing. That collateral was deposited on Aave V3 across seven addresses and borrowed against: 82,650 WETH plus 821 wstETH, about $193M drawn out. LlamaRisk scenarios put the resulting bad debt at $124M or $230M depending on how Kelp allocated losses between mainnet and L2 rsETH holders.

Morpho's event was smaller and different in kind. On March 22, Resolv's 24-hour NAV oracle cadence opened a window in which the oracle read RLP at $1.29 while the market read $0.52, and USR at roughly $1.00 while Curve read $0.025. Borrowers rotated into positions collateralized by the oracle-high, market-low tokens. About $200K of attacker capital triggered an $80M unbacked USR mint and roughly $3.8M of bad debt across Morpho markets.

Different channels failed

Read through the five channels in TI's vault credit risk framework, these are not the same failure wearing different clothes.

Aave V3
Collateral was not what it claimed to be. Unbacked rsETH entered a pool that had approved it at up to 95% e-mode LTV.
Asset coverage
Aave V3
WETH pools sat at 100% utilization, so liquidators received aWETH rather than WETH and the position could not be cleared cleanly.
Execution viability
Morpho
A 24-hour NAV cadence on stress-correlated collateral left a false-solvency window that was derivable in advance from oracle cadence against realized volatility.
Oracle integrity
Morpho
Automated allocators kept routing deposits into stressed markets while the mispricing persisted, sustaining the exposure instead of draining it.
Recovery endogeneity

Neither failure was undetected. BGD Labs warned Aave in February 2025, during the rsETH listing discussion, that a multi-DVN configuration was needed. The warning was not adopted before rsETH was accepted as collateral. The Resolv window was arithmetically foreseeable from the oracle's own update schedule. Detection was never the gap.

The deposit response is where the designs separate

Both protocols absorbed a real loss. What happened to depositor capital afterward differs by about two orders of magnitude. Figures below are total deposits, meaning supplied capital including the portion currently borrowed out, which is the measure relevant to a run because a depositor's claim includes capital that has been lent onward.

Aave V3, April eventTotal depositsvs pre-event
Apr 18, pre-event$44.16Bbaseline
Apr 22, four days in$29.29B-33.7%
Jun 7, trough$20.72B-53.1%
Aug 21, today$29.11B-34.1%
Morpho, March eventTotal depositsvs pre-event
Mar 20, pre-event$10.60Bbaseline
Mar 25, three days in$10.54B-0.6%
Apr 5, two weeks on$10.73B+1.2%
A $230M credit problem removed $23.4B of deposits. A $3.8M credit problem removed nothing measurable.

The mechanism is the pool itself. In a monolithic design, every WETH depositor lends into one book against many collateral types and earns one blended rate. When part of that book turns out to be backed by nothing, no depositor can determine whether their specific capital is impaired, because no depositor has specific capital. The rational response to unallocatable uncertainty is to withdraw. And because the WETH pools were already at full utilization, withdrawal was precisely what the design could not deliver. A credit problem became a liquidity problem, and the liquidity problem was 100 times larger than the credit problem that started it.

What isolation actually bought

Morpho was not untouched in April. It held rsETH-collateralized markets, and its deposits fell as well. This is where TI's own Morpho page has been slightly too generous, describing the market-level loss as real but the protocol-level run as absent. The data says the run was present. It was simply far smaller, and it reversed.

April eventAave V3Morpho
Apr 18 to Apr 22-33.7%-14.1%
Apr 18 to Jun 7 trough-53.1%-16.9%
Apr 18 to Aug 21-34.1%+18.4%

A 17% drawdown is a real event, and anyone claiming isolated markets confer immunity from contagion should sit with that number. What the isolated design bought was not immunity. It was containment and recovery. Morpho's bad debt stayed in the single market that took it, defined by its own collateral, oracle and liquidation threshold, and could not reach the curator vaults that never opted into rsETH. Depositors elsewhere could establish that they were unaffected, which is exactly what Aave depositors could not do. Four months later Morpho sits 18% above its pre-event level and Aave sits 34% below.

Morpho's risk did not disappear. It moved.

The uncomfortable half of this comparison is that isolation relocates risk rather than removing it. Morpho's core is immutable and takes no view on which collateral is sound, so every underwriting judgment happens one layer up, in the curator vaults that allocate depositor capital across markets. That layer is concentrated. Of $3.91B in vault deposits, Steakhouse Financial holds about $1.67B and Gauntlet about $1.17B, roughly 43% and 30%, or 73% between two firms.

The structural asymmetry A curator allocation failure on Morpho reaches depositors with no protocol-level cushion in between. Aave maintains a treasury and the Umbrella safety module precisely because a pooled protocol has to socialize losses. Morpho maintains neither, by design, because losses are supposed to stay where they land. That works while isolation holds. It offers nothing at all when the entity choosing what to hold is simply wrong.

The March event is the shape of that risk in miniature. It did not come from a bad market design. It came from automated allocators continuing to route capital into markets that a human reading the Curve price would have stopped feeding. The loss was small because the exposure was small, not because the architecture caught it.

What this changes for TI's framework

TI's lending architectures page frames the monolithic and modular designs as a trade between shared liquidity depth and contained risk. Both events support that framing. Both also sharpen it in a way the page does not yet state directly.

Architecture does not set how much risk a protocol carries.
It sets which failure is survivable.

A pooled protocol survives a curator being wrong, because it has no curators and its risk parameters are set once through governance for everyone. It does not survive collateral that is not what it claims to be, because the resulting uncertainty cannot be allocated to anyone and every depositor runs at once. A modular protocol survives bad collateral, because the damage is addressed to a market. It has no defense whatsoever against the judgment of the two firms holding 73% of its vault deposits.

That is a more useful selection question than which design is safer. It asks which failure mode a depositor is better positioned to evaluate. Bridge and collateral integrity is a technical question most depositors cannot assess. Curator quality is a track record most depositors can at least observe.

It also extends the vault credit risk framework in one direction. The five channels score a vault's mechanical risk well. Neither event here was caused by an unmonitored channel; both were foreseeable and both were foreseen. The missing dimension is not detection. It is whether a protocol has a mechanism that acts on a warning once someone has issued one.

What to watch

Limits of this analysis

Read the result with these attached