RD-F-089 red Insurance coverage active No confirmed active insurance coverage found for Solend/Save on Nexus Mutual, Sherlock, or Unslashed. Nexus Mutual product ID 187 (found via search) redirects to homepage without Solend/Save listed. Sherlock public protocol coverage list does not include Save/Solend. Unslashed dashboard not confirmed. At $79.77M TVL, absence of confirmed active coverage scores red (no active coverage). RD-F-077 yellow Prior exploit count Two confirmed distinct smart-contract incidents: (1) 2021-08-19 — insecure admin-check in process_update_reserve_config; $0 direct loss, $16K user compensation paid by team, full remediation within 98 min. (2) 2022-11-02 — oracle price manipulation via thin-liquidity Saber USDH pool; $1.26M bad debt; ~$900K recovered from attacker; DAO proposals SLND5/SLND6 made users whole. Scored yellow: users suffered no final loss (DAO fully compensated), but two distinct incidents occurred and one involved unrecovered bad debt absorbed by the protocol. The 2022 SLND1/SLND2 governance controversy is excluded per U20 (no contract exploited, $0 loss). Nirvana Finance Solend-as-venue entry is excluded per U4/U22. RD-F-081 yellow Post-exploit response score Incident 1 (Aug 2021): Strong response — detect 41 min, mitigate 70 min, fix 98 min, $16K user refund paid by team, SLND-INCDT-01 report published, Neodyme post-mortem Dec 2021 with detailed root cause. Score ~4/5. Incident 2 (Nov 2022): Pools paused after detection; DAO passed SLND5/SLND6 covering bad debt; users made whole; blog post-mortem published at blog.solend.fi; oracle root cause described by Ackee Blockchain. Score ~3/5. No confirmed external re-audit post-Nov-2022 oracle incident. Overall ~3.5 → yellow (green ≥4). RD-F-083 yellow Auditor re-engaged after last exploit After Aug 2021: Neodyme published a detailed post-mortem / security analysis (Dec 2021) — constitutes an external security firm incident review. After Nov 2022 oracle incident: no confirmed external re-audit found in public sources. The oracle manipulation was a configuration/parametric issue (single-source thin-liquidity feed in isolated pools), not a code logic bug, but absence of documented re-audit engagement post-Nov-2022 is a gap. Scoring yellow (external security review for one incident; no confirmed re-audit for most recent). RD-F-076 green Protocol age (days) Mainnet deployed 2021-08-12; age as of 2026-05-17 ≈ 1,739 days (~57 months). Well above the 365-day green threshold. Protocol has operated continuously through multiple market cycles without full shutdown.
RD-F-078 green Chronic-exploit flag (≥3 incidents) Incident count = 2 (Aug 2021 + Nov 2022). Does not reach the ≥3 threshold for the chronic flag. No CHRONIC designation.
RD-F-079 green Same-root-cause repeat exploit Two confirmed incidents have distinct root-cause clusters: (1) Aug 2021 — Solana program account ownership validation failure (access-control / insecure authentication check class); (2) Nov 2022 — single-source oracle price manipulation via thin-liquidity DEX pool (oracle manipulation class). No same-root-cause repeat.
RD-F-080 green Days since last exploit Last confirmed exploit: 2022-11-02. Days elapsed to 2026-05-17 ≈ 927 days. Green threshold: >365 days or no incidents.
RD-F-082 green Post-mortem published within 30 days Nov 2022 (most recent incident): post-mortem published at blog.solend.fi in November 2022, within 30 days of the Nov 2 incident. Aug 2021: SLND-INCDT-01 public report published shortly after incident; Neodyme post-mortem published Dec 2021 (~4 months later, but initial report was prompt). Most recent incident post-mortem meets the 30-day threshold.
RD-F-084 green TVL stability (CoV over 90d) TVL CoV (90-day trailing) = 0.055. Green threshold: CoV < 0.15. Mean TVL $77.7M, std $4.3M. Window 2026-02-18 to 2026-05-17, 90 samples. Well within green.
RD-F-085 green Incident response time (minutes) Aug 2021 incident (best-documented): team detection at 41 minutes, mitigation at 70 minutes. Green threshold: ≤60 minutes for first on-chain response. Detection at 41 min meets green. Nov 2022 incident: pools paused after detection but precise minute-level timestamp not found in public sources. Primary scoring on Aug 2021 incident; Nov 2022 response time partial gap flagged in issues.
RD-F-086 green Pause activations (trailing 12 months) No pause activations in the trailing 12 months (May 2025–May 2026) found in public sources or data cache. Last known pause was in Nov 2022 following the oracle attack (isolated pools paused). No pause events documented in cache or public reporting for the trailing 12-month window. Scoring green (0 pauses).
RD-F-087 green Pause > 7 consecutive days No pause exceeding 7 consecutive days found in the trailing 12 months. Last known extended pause was the Nov 2022 oracle incident pool freeze (Stable, Coin98, Kamino isolated pools); that is now more than 29 months ago, outside the 12-month window. No pause events found in cache or current public sources for May 2025–May 2026.
RD-F-088 green Re-deployed to new addresses in last year The 2024-07-24 Solend→Save rebrand involved no redeployment to new contract addresses. Main lending program So1endDq2YkqhipRh3WViPa8hdiSpxWy6z3Z6tMCpAo remains the live program both before and after rebrand. No migration of user funds to new address set in trailing 12 months. Rebrand was a UI/brand/product-suite change only, per profile §1 note.
RD-F-166 green Deprecated contracts still holding value No deprecated contracts identified. The 2024-07-24 Solend→Save rebrand did not involve a contract deprecation or migration; the main lending program So1endDq2YkqhipRh3WViPa8hdiSpxWy6z3Z6tMCpAo continues as the live program. No protocol-announced deprecated contracts holding >$100K in assets found in public documentation or on-chain data. Solana substrate note: ERC-20 stale-approval mechanics do not apply on Solana; Solana programs use a different account-authorization model.