Aave is under scrutiny following a March incident where about $26 million in user positions were liquidated, not because of a hack or failing code, but due to a misconfigured price oracle. About 34 accounts were affected when the protocol’s Correlated Asset Price Oracle undervalued wrapped staked Ether by about 2.85% compared with the live market. That small gap was enough to push leveraged positions below their thresholds, triggering automated liquidations exactly as the contracts were designed.

Aave governance said the issue came down to a configuration misalignment between the oracle’s snapshot ratio and snapshot timestamp parameters, not a breakdown in the oracle network itself. This exposes a distinct challenge in DeFi: risk is not always about code exploits. Sometimes it is about operational settings and governance oversight. Moonwell saw similar trouble in February, when a Coinbase staked ETH mispricing incident left about $1.78 million in bad debt. Both cases show that even when core contracts function as intended, protocols can still face major losses if configuration errors are not caught quickly enough.