JustLend V1

Red · 14/100 Data confidence 93/100

Executive summary

JustLend V1 is a TRON-based Compound V2-style lending protocol with a 32/100 score (red band), reflecting severe centralization, governance opacity, and unverified risk controls despite large reported TVL.

  • Security: Two audits identified 16 issues (6 major/high) including centralization risks, oracle vulnerabilities, and logic flaws in core contracts; bug bounty program active since August 2022 with $50k max payout and $20k total paid to date.
  • Governance & custody: Non-custodial protocol but effectively founder/team-controlled with no credibly decentralized DAO; governance token JST exists but voting power and parameter control remain opaque and tied to Justin Sun/TRON Foundation infrastructure.
  • Top risks: (1) Smart-contract vulnerabilities in lending/upgrade logic; (2) Oracle failure or manipulation risk for liquidations; (3) Collateral depeg/liquidation cascade (USDD depegged 2.18% in Nov 2022); (4) Centralized admin control over upgrades; (5) TRON ecosystem concentration amplifying contagion.
  • Stress scenarios: BTC <$10k would trigger mass liquidations but exposure is unverified; 20% collateral depeg impact cannot be quantified from available data; no documented fraud but governance abuse is a recognized risk class.
  • Strengths: Mature Compound V2 architecture, capital-efficient cross-collateral design, dominant TRON lending position, and broad TRC-20 market support.
  • Unverified: Treasury/reserve size, on-chain governance implementation, token supply/FDV, buyback/burn mechanics, founder track record, and all TVL figures ($3.45B reported) lack independent on-chain verification as of 2026-08-30.

Score

Component Weight Raw Points Reason
security 25% 20 5.0 0 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 70 10.5 0 onchain, 16 two-source, 3 one-source of 25 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 9; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

JustLend V1 is a TRON money-market / supply-and-borrow DeFi protocol (Compound V2-style) with website/app at justlend.org / app.justlend.org and docs at docs.justlend.org. The docs identify the JST token as the governance token; the protocol’s V1 markets include native TRX (jTRX) and TRC20 markets such as jUSDT, and the docs describe the V1 design as a supply-and-borrow market launched in December 2020. Mainnet is on TRON only for V1; the docs also note Nile testnet support, but that is not mainnet exposure. Main V1 contract addresses are documented as Unitroller (proxy) TGjYzgCyPobsNS9n6WcbdLVR9dH7mWqFx7, Comptroller implementation TETm1bMHUm9135d5NmUgfkvqZQ4bk6DgWs, jTRX TE2RzoSV3wFK99w6J9UnnZ4vLfXYoxvRwP, jUSDT TXJgMdjVX5dKiQaUi9QobwNxtSQaFqccvd, and jUSDT delegate TLjn59xNM7VEK6VZ3VQ8Y1ipxsdsFka5wZ. Explorer verification status is only partially verifiable from the gathered material: the docs link these addresses to Tronscan “Contract” pages, but I cannot independently confirm the contract-verified status without live explorer access; therefore: Not verifiable as of 2026-08-30. Fork lineage: JustLend V1 is explicitly Compound V2-derived / “Compound V2’s design” rather than a fresh design. The biggest protocol-level changes visible in the docs are TRON-specific address formats, TRC20 handling, native TRX support through jTRX, and added TRON staking/liquid-staking components; whether each code change was separately audited is only partially verifiable here. The public audit PDF exists, dated Apr 8, 2022, and the docs state the smart-contract code is publicly available for external audits, but I cannot verify the full audit scope or whether all fork-modifications were covered from the gathered material alone. For malicious-modification history in similar forks, Not verifiable as of 2026-08-30.

Evidence (7)

maturity

two sources

JustLend V1 appears to be a real, live product rather than a mere landing page: its documentation exposes public REST endpoints for market state and user positions, and the docs explicitly point to a main app and read-only API base URL. The docs also describe a full set of V1 read and write flows, and the documentation site is current, which supports active product maturity. The available evidence suggests functional lending operations, including supply/borrow-market queries, account summaries, and transaction-history tools for supply, withdraw, borrow, repay, and collateral changes. That said, live deposits/withdrawals cannot be independently verified here, so they are Not verifiable as of 2026-08-30. I did not find reliable evidence of broken links, fake metrics, or obvious template-landing-page signs in the sources reviewed. The strongest indicator of authenticity is the combination of a documented app, a public API, and GitHub-hosted protocol/front-end code. Yes, it does have an open API: the docs state a public REST API with base URL https://openapi.just.network and endpoints such as /lend/jtoken and /lend/account.

Evidence (6)

Security

audit

unverified

Security assessment for JustLend (TRON) covering the supply/borrow financial-model smart contracts. The report lists 16 total issues: 0 critical, 6 major/high, 1 medium, 2 minor, and 7 informational. The finding list includes centralization risks, oracle/feed issues, missing input validation, compiler-version declaration, public/external visibility issues, naming, boolean misuse, return-value handling, checks-effects-interactions violations, and a logic issue in exchangeRateStoredInternal(). The report states the audit was performed with static analysis and manual review, delivered 2022-04-08 UTC.

Auditor
CertiK
Report Date
2022-04-08
Scope
Financial Models / supply & borrow contracts on TRON
Evidence (2)

audit

unverified

Security assessment for STRX Protocol / Staked TRX related code. The report states the audit was completed for version pinned to GitHub commit 38a60d393145a0202814eb870191db56637f6787, with audit period 2023-04-24 to 2023-05-05 and delivery date 2023-05-05 UTC. The vulnerability summary shows 1 medium risk and 10 suggestion-level findings; examples in the report include missing validation of resourceType, and missing zero-address checks for _reserveAdmin and _voteOperator. The report also states the code had been deployed to mainnet.

Auditor
SlowMist
Report Date
2023-05-05
Scope
STRX / Staked TRX protocol code at commit `38a60d393145a0202814eb870191db56637f6787`
Evidence (1)

bug bounty

two sources

Yes — JustLend DAO appears to have an active bug bounty program on Immunefi. Immunefi lists it as Live Since 31 August 2022 and shows it was still updated on 14 August 2026, while JustLend’s own docs describe it as an ongoing bug bounty program and its official site labels it Active. Parameters: the program pays in USDD on TRON, with rewards denominated in USD. The maximum bounty is $50,000. For smart contracts, Immunefi lists Critical up to $50,000, High up to $20,000, and Medium up to $10,000; critical smart-contract reports require a PoC, and high/medium reports require a suggestion for a fix. Immunefi also states that critical smart-contract rewards are capped at 10% of the funds directly affected (up to the $50,000 ceiling). Scope/results: Immunefi lists 43 assets in scope and 7 impacts in scope as of the latest scope page snapshot, including direct theft of user funds, permanent freezing of funds, protocol insolvency, theft of unclaimed yield, permanent freezing of unclaimed yield, block stuffing for profit, and griefing. Immunefi’s bounty page shows Total paid: 20k and Median resolution time: 2 days. BBRadar’s index also records the program as added on 31 Aug 2022 and shows the same $0–$50,000 reward range. One caveat: I could not verify any on-chain payout totals or individual reports from raw chain data in this run, so the only confirmed results are the platform-reported totals above. Not verifiable as of 2026-08-30.

Evidence (5)

counterparty risks

two sources

JustLend V1 on Tron is heavily exposed to centralized governance and proprietary oracle infrastructure, plus collateral concentration in Tron-native stablecoins and LST-like assets. All on-chain verification is Not verifiable as of 2026-08-30. 1. External protocol & asset dependencies

  • Stablecoins (USDD, USDT, USDC): JustLend is a major venue for USDD and other stablecoin deposits on Tron. Failure, under‑collateralization, or regulatory action against these issuers could trigger mass liquidations and insolvency of borrower cohorts.
  • TRON ecosystem concentration: JustLend is described as the largest lending protocol on Tron and dominates Tron DeFi TVL, so stress in JustLend can propagate to the whole ecosystem. 2. Oracle & price‑manipulation risk
  • Docs say JustLend “utilizes decentralized oracles like Chainlink” for price feeds and LST redemption ratios, but this is sourced from protocol docs and therefore an unverified marketing claim.
  • Independent risk research reports that JustLend “now runs its own proprietary internal oracle system (migrated from WINkLink, May 2025)” with only limited decentralized fallback. This creates:
  • Single‑point‑of‑failure for collateral valuation and liquidation integrity.
  • Manipulation risk if governance or insiders can adjust oracle parameters.
  • A security assessment flags GLOBAL‑02: Price oracle feed as a specific risk item, indicating prior concerns around oracle design or validation. 3. Governance / counterparty concentration
  • Governance is reported as heavily centralized under Justin Sun and the TRON Foundation, with no public multisig disclosed. This implies:
  • Single‑person/organization control over parameter changes (collateral factors, oracle sources, listed assets).
  • Elevated governance‑capture and censorship risk for all depositors and borrowers. 4. Stablecoin & collateral failure scenarios
  • USDD has a history of collateralization concerns and near‑depegs; analysis shows material reserves routed into JustLend and lent out, reducing effective backing ratios. Under‑collateralization or a sustained depeg could:
  • Wipe out USDD-denominated collateral and force mass liquidations.
  • Create losses for lenders if bad‑debt accumulates in USDD markets. 5. Bridges, CEX/MM, RWA, restaking
  • No direct dependence on Ethereum bridges, RWAs, or restaking protocols is documented in the available sources.
  • Tron/CEX/MM exposure is indirect: systemic stress in TRON or centralized exchanges affecting TRX, USDD, and stablecoins would feed through prices into JustLend positions via the oracle layer. All specific TVL split by asset, counterparty concentration, and per‑market health are Not verifiable as of 2026-08-30 due to lack of direct on-chain querying in this run.
Evidence (15)

crypto custody

two sources

JustLend V1 is non-custodial: users supply TRX or TRC-20 assets into smart-contract lending markets and receive jTokens that represent their claim on the deposited assets and accrued interest; the protocol’s smart contracts, not a custodian, hold and manage the pooled liquidity. In the V1 design, assets are organized in shared lending pools on TRON’s Compound V2-style architecture, with the Comptroller enforcing collateral requirements, borrow limits, and liquidations across the market. Each jToken is a TRC-20 contract where balances reflect ownership of the market position, and users can mint, redeem, borrow, and repay directly through the protocol contracts.

Evidence (3)

incident

one source

A 2022 security assessment for JustLend reported at least one medium-severity issue, including 'GLOBAL-03: Missing input validation,' but the provided result does not show any exploitation or user loss.

Date
2022-04-08
Cause
smart_contract_exploit
Loss Usd
None
Evidence (1)

key management

unverified

JustLend V1’s key management is organized around on-chain governance plus privileged admin roles, not around a single operational key. The documentation says the protocol uses GovernorBravo + Timelock for governance, and the audit recommends that any privileged roles be moved to multi-signature wallets and protected by a timelock to reduce single-key compromise risk. The GitHub docs also describe a GovernorAlpha (Deprecated) setup and note that proposals are queued into the JustLend timelock before affecting core contracts, which implies that sensitive actions are meant to pass through delayed, governed execution rather than direct hot-key control.

Evidence (3)

smart-contract

two sources

JustLend V1 on Tron uses a Compound V2-style, proxy-based architecture with admin keys controlled by a governance-owned timelock; this creates a material upgrade/rug/freeze risk if governance or timelock are compromised, though users can redeem independently via jToken logic. Core architecture & key contracts (V1 on Tron)

  • Comptroller / Unitroller (proxy): Central risk engine and market controller; entrypoint proxy Unitroller delegates to a separate Comptroller implementation, mirroring Compound V2.
  • jTokens (CErc20 / CEther): Per-asset markets handling mint (supply), redeem (withdraw), borrow, repayBorrow, liquidateBorrow.
  • Interest Rate Models: Separate contracts (e.g. JumpRateModelV2) determining utilization-based rates.
  • Price Oracle: Central oracle contract used by Comptroller for collateral and liquidation logic.
  • All are deployed on Tron mainnet, single-chain exposure. Upgradeability & admin model
  • Unitroller (comptroller proxy), CErc20Delegator (jToken proxy), and related contracts have admin-controlled upgrade functions:
  • _setComptroller() – change Comptroller implementation.
  • _setPendingImplementation() / _acceptImplementation() – change Unitroller implementation.
  • _setImplementation() – change CErc20 implementation.
  • Admin for CEther, Unitroller, CErc20Delegator is a timelock contract, whose admin is a governance contract (JustLend DAO).
  • Timelock and governance are separate contracts; governance can schedule and execute upgrades via timelock delay. Exact delay length on-chain is Not verifiable as of 2026-08-30 (no on-chain tool access). Admin / emergency powers
  • Through upgrades, governance+timelock can:
  • Change Comptroller logic (risk parameters, listing/delisting, liquidity and liquidation rules).
  • Change jToken logic (including mint/redeem/borrow behaviors and fee routing).
  • Change oracle and interest rate model addresses via Comptroller admin functions.
  • The audit explicitly notes that compromise of the admin account may allow a hacker to take over implementations and cause user asset losses.
  • Documentation does not clearly state pause/guardian roles; Not verifiable as of 2026-08-30 whether a dedicated pauseGuardian or emergency shutdown exists beyond upgrades. User exit guarantees vs worst case
  • In normal conditions, users can redeem jTokens to underlying without admin interaction; this is baked into jToken logic.
  • However, if an attacker controls governance/timelock, they could:
  • Upgrade Comptroller/jTokens to block redeem/borrow or siphon reserves via malicious logic.
  • Manipulate oracle and interest rate logic to force liquidations or trap collateral.
  • No evidence of role renunciation or immutable governance: Not verifiable as of 2026-08-30. Risk characterization (institutional view)
  • Key risks: centralized governance+timelock control over all critical logic; single-chain Tron risk; opaque timelock delay and lack of clearly documented pause design.
  • Rug/freeze scenario: governance or timelock compromised → upgrade to hostile implementations → protocol can be frozen or drained at the contract level before users can react. Contradiction box
  • On-chain verification of actual timelock delay, governance token mechanics, and any renounced roles: Not verifiable as of 2026-08-30.
  • Admin-power description relies on audit and protocol docs only → classify as unverified marketing/issuer claim where not backed by independent analysis.
Evidence (8)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

JustLend V1 is not a stand-alone, fully transparent company in the way a traditional fintech is; public records instead tie it to the TRON/JUST ecosystem and to Justin Sun as the named founder in third-party project databases. That makes the “team” partly visible but the operating reality less clear: the protocol-facing brand is public, while detailed corporate staffing, governance, and legal-entity structure are not fully verifiable from the available sources. Founder / prior track record: Justin Sun is the only clearly identified founder in the sources provided for JustLend itself. The sources do not, however, give a clean founder bio for JustLend V1, nor do they document his prior projects, exits, or failures in a way that would let me independently assess credibility from this dataset alone. The best-supported claim is simply that JustLend is part of Sun’s broader JUST/TRON product stack. Public vs. anonymous: The protocol is publicly branded, not anonymous, because it is associated with Justin Sun and the broader JUST/TRON ecosystem. But the available material does not verify whether the day-to-day operators of JustLend V1 are a disclosed legal team or a more opaque offshore structure. Reality check: There is a real business signal, not just a web front, because third-party company databases list corporate footprints and named individuals in the wider JustLend/Just Lend orbit, including a UK address and founders/employees in London for a similarly named entity. However, those records appear to mix entities (“JustLend,” “Just Lend Limited,” and “justlend.co”), so they are not sufficient to prove that the Tron protocol itself has that exact office or legal base. The office/onshore-offshore question is therefore Not verifiable as of 2026-08-30. Credibility read: This looks like a real, publicly marketed protocol with an identifiable ecosystem sponsor, but the available sources do not let me confirm a fully transparent operating company, audited team history, or a precise corporate domicile for the Tron deployment.

Evidence (6)

general reputation

two sources

JustLend V1’s reputation is mixed: it is widely described as a major TRON lending protocol with large TVL, but independent risk reviews flag centralized governance and oracle dependence as key concerns. Public sentiment is also lukewarm-to-negative on consumer-review sites: Trustpilot shows a 2.1/5 rating from 19 reviews, and a secondary review site summarizes the same review set as mostly negative. On provenance, the available sources do not provide independently verified founder or investor details in the results set, so those are Not verifiable as of 2026-08-30. The protocol is associated in risk commentary with Justin Sun and the TRON Foundation’s governance influence, but that attribution comes from a risk-analytics source rather than primary governance records. Auditor coverage is also Not verifiable as of 2026-08-30 from the provided results; none of the listed sources identify a specific audit firm or audit scope for JustLend V1. The strongest documented criticisms are governance centralization, concentration on the TRON ecosystem, and reliance on a proprietary/internal oracle path, which Hindenrank describes as a potential single point of failure for liquidations. Fraud/rug allegations were not substantiated in the provided sources. I found no direct fraud or rug-pull finding in the results set, but there is continued reputational drag from poor consumer reviews and risk-platform warnings. Legal/regulatory sentiment is somewhat improved relative to prior overhangs: Hindenrank states that a US regulatory overhang was cleared in March 2026 after an SEC case dismissal, but this is still a secondary-source claim and should be treated cautiously without primary legal documentation. Sanctions concerns were not evidenced in the provided results, so they are Not verifiable as of 2026-08-30. The main unresolved concern is structural: even positive assessments still emphasize that JustLend’s safety depends heavily on TRON-wide concentration and governance arrangements rather than broad decentralization.

Evidence (7)

Economy

TVL: $3.5B

model

unverified

JustLend V1 on Tron is a pooled money-market lending protocol similar to Compound/Aave, offering interest-bearing deposits and collateralized borrowing in TRX and Tron-based tokens. ### Strategy & Assets

  • Core model: Users supply assets to pools and earn variable interest; borrowers post collateral and pay interest. Rates are algorithmic based on utilization (borrowed/supplied).
  • Main assets in/out: TRX, USDT-TRC20, JST, and other Tron ecosystem tokens.
  • Collateral: Overcollateralized; borrowing power depends on each asset’s collateral factor and liquidation threshold. ### Yield Source & Nature
  • Yield source: Interest paid by borrowers; there is no native trading, farming, or external strategy.
  • Organic vs subsidized: Historically, JST incentives were added, but current core yield is primarily organic borrower interest, with occasional subsidized rewards depending on incentive programs.
  • Market-neutral vs directional: Depositors are directionally exposed to the underlying asset’s price; borrowing can create leveraged long/short positions. The protocol itself is market-neutral on credit spread but supports directional and leveraged looping (e.g., supply USDT, borrow USDT, re-supply).
  • External exposure/restaking: No direct restaking or external DeFi integrations are structurally core; exposure is mainly to Tron chain and its asset prices. ### Mechanics: Lock-ups, Withdrawals, Fees
  • Lock-ups: No fixed lock; funds are withdrawable whenever pool liquidity allows. Large withdrawals can be constrained if utilization is high.
  • Withdrawal mechanics: Users redeem interest-bearing tokens for underlying, subject to pool liquidity and any ongoing borrow positions.
  • Fees/gates/limits: Protocol-level fees come from a reserve factor that diverts a share of interest to reserves. There may be per-asset caps, collateral factors, and liquidation penalties for undercollateralized accounts.
  • Protocol revenue: Derived from the reserve factor on interest paid by borrowers. ### TVL, APY, Trends
  • TVL total/by product/by chain: Not verifiable as of [2026-08-30].
  • TVL trend vs DeFiLlama: DeFiLlama lists JustLend on Tron with fluctuating TVL in the low-to-mid single-digit billions (USD) over time, but exact current and historical breakdown by asset and product is aggregator-level only, not on-chain verified.
  • APY history/volatility: Lending APYs are variable, driven by utilization; stablecoins often show lower but steadier rates, volatile assets show higher, more volatile APYs. Sustained high APYs typically coincide with elevated borrowing demand and may not be durable. ### Risk-Relevant Takeaways
  • Economic sustainability rests on continued borrowing demand and healthy collateral parameters.
  • Yield is largely organic, but depends heavily on Tron ecosystem leverage/looping behavior and asset price dynamics.
  • On-chain TVL, detailed product splits, and precise APY history: Not verifiable as of [2026-08-30].
Evidence (2)

reserves

two sources

Not verifiable as of 2026-08-30. The available web results confirm JustLend V1 is a Tron-only lending protocol and provide third-party TVL estimates, but they do not verify treasury/reserve size, reserve addresses, custody structure, control rights, reserve policy, or on-chain reserve balances. DefiLlama shows JustLend V1 TVL on Tron at $2.939B, while other aggregators report higher figures ($3.31B and $3.65B), indicating only that there is a TVL estimate range, not a treasury or reserve disclosure. The protocol site is present but should be treated as unverified marketing for reserve claims unless corroborated elsewhere. No independent attestation, audit statement, or explorer-based reserve address disclosure was available in the provided results.

Evidence (4)

tokenomics

two sources

JustLend V1 on Tron does have a native governance token: JST (TRC-20), contract TCFLL5dx5ZJdKnWuesXxi1VPwjLVmWZZy9. Official docs identify JST as the governance token for JustLend DAO/JUST and say holders can propose, vote on, and execute governance actions through GovernorBravo/timelock contracts. The protocol’s own docs also show jTRX is the TRX market token, but that is a market receipt token, not the native protocol token. Total supply / circulating / market cap / FDV: Not verifiable as of 2026-08-30 without on-chain verification or a current market-data source tied to JST. I did not find a reproducible, independently verified source in the gathered material for these figures. Utility / governance: JST is used for protocol governance; official docs describe it as the core governance token of JUST and JustLend DAO, and GitHub/docs state JST holders can create and vote on proposals that affect JustLend parameters and contracts. Revenue share / buybacks / burns / staking rewards: Official tokenomics text referenced in independent commentary says eligible protocol / ecosystem revenue can be used to buy JST on the open market and burn it, rather than distribute direct revenue share to holders; however, this specific buyback/burn mechanic is not independently verified in the gathered primary material, so treat it as an unverified marketing claim unless confirmed elsewhere. I found no verified evidence of token-holder revenue share or protocol-native staking rewards for JST in the gathered sources. Emissions / unlock schedule / allocations: Not verifiable as of 2026-08-30. I did not find a reliable, independently verifiable emissions table, allocation breakdown (team/investors/treasury/community), or a dated unlock schedule in the gathered sources. Announced unlocks vs. on-chain reality: Not verifiable as of 2026-08-30. Top-holder concentration / insider wallets: Not verifiable as of 2026-08-30. Mint / blacklist / fee-switch controls: JST is documented as a standard TRC-20 with transfer/approve/balanceOf in the docs snippet, but I could not verify whether mint, blacklist, or fee-switch powers exist for JST from the gathered material. Governance control over JustLend protocol contracts is described as being mediated by JST holders via GovernorBravo/timelock, but that is governance of the protocol, not proof of token admin powers. DEX liquidity / main listings: Not verifiable as of 2026-08-30. The gathered sources did not provide independently verified liquidity-depth data or a complete exchange-listing set for JST. Chain exposure: JustLend V1 is a single-chain protocol on Tron.

Evidence (9)

Stress scenarios

stress scenario - bitcoin price falls below $10000

one source

For JustLend V1 on Tron, a BTC move below $10,000 is a severe collateral shock: if BTC is used as collateral in any position, borrower LTV would rise sharply and liquidations would likely accelerate where positions are already near threshold. JustLend’s own risk docs state that sharp declines in collateral value can cause under-collateralization or bad debt, and that the protocol relies on risk parameters and governance to respond to market stress. What can be said with the available sources:

  • JustLend explicitly acknowledges that collateral is subject to market fluctuations and that a sharp decline can create bad debt risk.
  • The BTC market on JustLend V1 uses an interest-rate model with a documented BTC market configuration, but the provided sources do not give the liquidation thresholds, collateral factor, or the current live exposure for BTC on Tron V1.
  • A third-party analytics page reports JustLend V1 BTC TVL around $491M on Tron, but this is not on-chain verified and should be treated as an external estimate only. Implication under the stress scenario:
  • If BTC is the collateral asset, a fall below $10k would materially increase liquidation pressure and the chance of bad debt.
  • If BTC exposure is small or no BTC-backed borrows exist, protocol-wide impact could be limited; however, that exposure is not verifiable as of 2026-08-30 from the available sources.
  • Because Dune/on-chain verification is unavailable in this run, the size of BTC-backed debt, liquidatable accounts, and bad-debt loss under a $10k BTC scenario are not verifiable as of 2026-08-30. The audit material also notes a historical pricing-related weakness in the broader codebase, but it does not quantify current stress losses for this scenario.
Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

JustLend V1 on Tron does not publish, in the provided sources, enough portfolio-level data to compute a numeric system-wide loss from a 20% depeg of the largest collateral asset. The protocol’s liquidation rule is clear: liquidation is triggered when an account’s risk value reaches 100, and the risk value is defined as total borrow divided by borrow limit; the liquidator may repay up to 50% of the debt and receive collateral with an 8% liquidation reward. For a stress scenario, a 20% collateral depeg would reduce each affected position’s borrow limit proportionally to that asset’s collateral factor, pushing accounts with the highest leverage closest to or above liquidation; any position already near the threshold would become liquidatable first. Because the question asks for the largest collateral depeg but the web results do not include on-chain market balances, supplied collateral concentrations, or account-level risk distributions for JustLend V1 on Tron, the impact cannot be quantified from the available evidence. Not verifiable as of 2026-08-30. What can be stated with confidence is the mechanism: if the largest collateral asset falls 20%, the protocol’s risk values for borrowers using that asset rise immediately, and liquidation can cascade account by account as liquidators repay debt and seize collateral at a discount.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For JustLend V1 on Tron, a “top counterparty insolvent” stress is not directly documented as a protocol-level loss-sharing mechanism; the documented insolvency path is borrower default/liquidation, where the borrower’s position is liquidated when risk value reaches 100 and other users can repay part of the debt to seize collateral with a liquidation incentive. The smart-contract impact path is: borrow balance exceeds collateral factor → risk value rises → liquidation is triggered → liquidator repays debt via liquidateBorrow(...) → collateral is transferred to the liquidator. Expected loss path: if a borrower becomes insolvent, the protocol first attempts to offset the debt through collateral seizure; the liquidation reward is quoted as 8% and liquidations can cover up to 50% of a user’s debt at a time, with repeated liquidations until risk value falls below 100. This means the loss path is borrower collateral → liquidator repayment → residual shortfall only if collateral is insufficient; a residual shortfall path is not verifiable as of 2026-08-30 from the provided sources. Who absorbs it: the sources describe liquidators as the immediate actors who repay the debt and receive collateral, while the borrower bears the loss of collateral. If collateral value is insufficient, the protocol’s backstop/insurance-fund treatment is not verifiable as of 2026-08-30 from the provided sources. Compensation: liquidators are compensated by receiving the borrower’s collateral plus the liquidation reward; the support article states liquidators “charge fees equal to 108% of the debt repaid in jTokens,” which is consistent with an 8% liquidation incentive. The borrower is not compensated; their position is reduced and collateral is taken. Impact through contracts: the relevant documented entrypoint is liquidateBorrow(borrower, repayAmount, jTokenCollateral) for jTRC20 positions, and liquidateBorrow(borrower, jTokenCollateral) for jTRX positions. The Comptroller is the risk-management module that determines collateral requirements and liquidation conditions.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

unverified

For the DAO/owner fraud stress scenario, I could not verify any documented incident of JustLend V1 DAO or owners committing fraud from the provided sources. The available materials instead show that the protocol recognizes centralization-related risks, oracle risk, and smart-contract risk, and Immunefi explicitly lists centralization risks and protocol insolvency among scoped impacts, which means governance/owner abuse is a recognized risk class even if no fraud event is documented here. The most defensible answer is: Not verifiable as of 2026-08-30 for a realized DAO/owner fraud event on JustLend V1 on Tron. The protocol docs and audit material describe security and governance risk categories, but they do not evidence that the DAO or owners actually committed fraud. If you need a stress assessment for risk modeling, the relevant failure mode is governance/privileged-access abuse rather than proven fraud: a malicious or compromised controller could change parameters, oracle inputs, or upgrade paths in ways that harm users, and the audit specifically flags centralization-related risks and price-oracle concerns.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

JustLend V1 on Tron does not have a clearly documented *primary yield source* in the provided results that I can verify as separate from the protocol’s own interest-rate markets. The most defensible stress-case answer is therefore: primary yield source negative 30d is not verifiable as of 2026-08-30. The available sources only show that JustLend V1 is a lending protocol with market-based supply/borrow rates and utilization-driven interest, and they do not provide a verified 30-day yield decomposition or a negative-30d stress readout. What can be said from the sources is that JustLend V1’s yields come from lending market utilization and interest-rate models, so a 30-day negative-yield stress would most likely mean utilization-driven supply APY compresses toward zero or below after fees/imperfections, but that inference is *not* directly verified in the provided material. Bathymark and YieldScope both show current positive APY readings for JustLend V1 pools on Tron, which contradicts a negative-30d yield claim in the supplied evidence set; however, those are current-state analytics, not a 30-day stress test. If you need a strict stress-scenario output for risk reporting, the conservative statement is: Not verifiable as of 2026-08-30 for a negative 30-day primary yield source on JustLend V1.

Evidence (4)

Governance & Legal

governance

two sources

JustLend v1 on Tron is effectively company/founder-controlled infrastructure, with only symbolic elements of decentralization visible in public sources. On-chain verification is not possible here: Not verifiable as of 2026-08-30. 1. Contract & protocol control

  • JustLend is the “official lending platform” of the Tron ecosystem and is closely tied to the Tron Foundation/Justin Sun–controlled infrastructure.
  • Core contracts are deployed on Tron; common secondary sources describe protocol parameters (collateral factors, reserves) as upgradable via governance controlled by the Tron/JustLend team, not a broad-based DAO.
  • No independently documented, credibly decentralized governor/timelock architecture (akin to Compound’s Governor Bravo + Timelock) is described in auditor or explorer-linked docs. Not verifiable as of 2026-08-30. 2. Governance process (DAO vs. team)
  • Public documentation and ecosystem overviews describe JustLend as a Tron DeFi component with no robust on-chain proposal/temperature-check/DAO forum process comparable to Ethereum blue-chip DeFi (Aave, Compound).
  • There is no clearly documented governance token with binding on-chain voting power for protocol-level changes; instead, risk-parameter changes are reported as coming from the JustLend/Tron team. This makes any “community governance” mostly symbolic. 3. Voting concentration & top holders
  • Without an identified governance token contract and with Dune unavailable in this run, token-holder-based voting concentration cannot be reliably measured. Not verifiable as of 2026-08-30. 4. Timelock / multisig / signers
  • Independent audit-style detail on:
  • whether upgrades are gated by a timelock,
  • which multisig (if any) controls admin keys,
  • number/identity of signers and thresholds,
  • and signers’ independence is not publicly well-documented by independent sources. Not verifiable as of 2026-08-30. 5. Frontend & operational control
  • The main app frontend is hosted under the Tron/JustLend-controlled web properties; no evidence of a community-managed front-end or ENS/IPFS-style community deployment.
  • This implies operational control over user access, default markets, and UI risk disclosures sits with the Tron/JustLend team. 6. Legal entity, jurisdiction, ToS
  • JustLend is usually described as part of the Tron ecosystem rather than a separately regulated DAO entity.
  • No reliable, independent information on a specific operating company (name, jurisdiction, registration number, directors) or binding Terms of Service governing JustLend v1 usage is available from non-protocol sources. Not verifiable as of 2026-08-30. From an institutional risk perspective, treat JustLend v1 as centralized-admin DeFi with opaque upgrade and key management, heavily reliant on Tron/Justin Sun–linked entities.
Evidence (3)

legal & regulatory

one source

JustLend V1 is a Tron-based lending protocol originally launched as *TRON DeFi* and later renamed; it is tightly associated with the TRON ecosystem and Justin Sun, but detailed corporate structuring and on‑chain verification are Not verifiable as of 2026‑08‑30. 1. Entity, jurisdiction, and legal structure

  • JustLend is described as the “official lending platform” of TRON, but no clear, public corporate entity (e.g. specific company, registration number, jurisdiction) is disclosed in standard documentation or analytics sources.
  • TRON itself has historically been linked to entities in multiple jurisdictions (e.g., Singapore, Grenada), but tying a specific legal entity to JustLend V1 is Not verifiable as of 2026‑08‑30. 2. Terms of service, user restrictions
  • Publicly accessible JustLend documentation focuses on technical and economic aspects; a conventional, lawyer‑written Terms of Service (user eligibility, governing law, dispute resolution) tied specifically to JustLend V1 is Not verifiable as of 2026‑08‑30.
  • No clearly documented geographic blocking or age restrictions for JustLend V1 were identified; any such controls would need to be confirmed via the front‑end and TRON ecosystem disclosures, which are Not verifiable as of 2026‑08‑30. 3. KYC/AML and user onboarding
  • JustLend operates as a non‑custodial smart‑contract protocol on Tron and appears accessible via Web3 wallets without identity checks.
  • There is no evidence of integrated KYC/AML, customer due diligence, or sanctions screening at the protocol level; any compliance would be at the level of centralized gateways (exchanges, fiat on‑ramps) rather than the protocol itself. 4. Regulatory classification and guidance
  • No specific regulatory classification (e.g. as a collective investment scheme, lending institution, or VASP) by named regulators for JustLend V1 was identified.
  • More general regulatory scrutiny exists around TRON and Sun (e.g., SEC actions), but explicit inclusion or treatment of JustLend as a subject of enforcement is Not verifiable as of 2026‑08‑30. 5. Warnings, enforcement, court cases, sanctions
  • No public, regulator-issued warning, enforcement action, or sanctions listing specifically naming “JustLend” or “JustLend V1” was identified in major enforcement databases or media within the last 7 days; historical coverage also appears sparse and indirect. 6. Data protection and user data risk
  • As a smart‑contract protocol, JustLend mainly processes on‑chain addresses and transaction data; standard web privacy policy or data‑protection statements for the JustLend front‑end specifically are Not verifiable as of 2026‑08‑30. Risk takeaway (legal vs actual risk)
  • Formal legal structure and compliance framework for JustLend V1 are opaque, increasing regulatory and enforcement uncertainty.
  • User exposure is primarily on‑chain and pseudonymous, but interaction may conflict with local securities/derivatives/credit laws depending on jurisdiction.
  • For institutional use, lack of clearly documented governance, licensing, KYC/AML, and ToS should be treated as a material non‑compliance/legal risk.
Evidence (1)

Stability

stability

unverified

JustLend V1 on Tron used USDD as a stablecoin market, and the available web evidence shows that USDD did depeg. A Binance report says USDD depegged on November 9, 2022 and was trading at $0.978161, which is a depeg of about 2.18% below $1.00 at that point. For your specific questions: the depeg did happen, the last documented time in the retrieved results is November 9, 2022, and the size of that depeg was approximately 2.18%. However, the search results do not provide a complete incident count for all USDD depegs on JustLend V1, so the total number of times is Not verifiable as of 2026-08-30.

Evidence (2)

Risks & Strengths

risks

two sources

Top 5 risks for JustLend V1 on TRON are: 1) Smart-contract risk — bugs or vulnerabilities in lending, reserve, or upgrade contracts could be exploited and cause losses. 2) Oracle risk — JustLend depends on third-party price and redemption feeds, so faulty or compromised oracle data could trigger incorrect liquidations or bad loan valuations. 3) Collateral/liquidation risk — sharp declines in collateral value or liquidity can cause under-collateralization, bad debt, or liquidations that fail to fully cover loans. 4) Governance/centralization risk — the audit flags centralized admin control over key upgrade paths; compromise of privileged accounts could let an attacker change core contract implementations. 5) Protocol concentration / ecosystem dependency risk — independent analysis highlights JustLend’s heavy dominance on TRON DeFi, which can amplify contagion if TRON, governance, or regulatory conditions deteriorate.

Evidence (4)

strengths

two sources

Top 5 strengths of JustLend V1 on TRON are:

  • Capital efficiency: it uses a cross-collateral money-market design, letting users borrow while their supplied assets continue earning yield.
  • Strong TRON-native fit: it is built specifically for TRON assets and TRC20 usage, which aligns it with the network’s low-fee, high-throughput environment.
  • Mature lending architecture: the protocol is based on the Compound V2 model / Jump Curve-style lending design, which is a well-known and battle-tested framework for money markets.
  • Broad market utility: it supports standard supply/borrow workflows, collateralized lending, and algorithmic interest-rate adjustment, making it useful for both passive lenders and active borrowers.
  • Established market position: independent sources describe JustLend as the leading or dominant lending protocol on TRON, which suggests liquidity depth and user adoption relative to peers. A cautious reading is important: several quantitative claims in the search results come from the protocol itself or secondary marketing pages, so they should be treated as *unverified marketing claims* unless separately validated.
Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 16 two independent sources, 3 one source, 6 unverified.
  • Oldest fact verification date: 2026-08-30.