Lista Lending

Orange · 42/100 Data confidence 93/100

Executive summary

Lista Lending is an overcollateralized money-market protocol on BSC and Ethereum with a score of 42/100 (orange band).

  • Security: Multiple audits by PeckShield, BlockSec, BailSec, and Cantina are listed in docs, but findings counts, fix status, and deployed-code bytecode verification are not verifiable as of 2026-08-29 for most reports; one audit found 1 medium (inflation attacks) and 4 low issues, all marked fixed or confirmed, but no bytecode-match statement was provided. Active Immunefi bug bounty program since June 2022 with up to $1M critical payouts, plus a separate BNB Chain bounty ($300–$150k); results and payout history are not verifiable as of 2026-08-29.
  • Incidents: Two public incidents: October 2025 platform pause after abnormal YUSD collateral price movements, and March 2026 USR-related liquidity event with very high vault utilization and abnormal wstUSR pricing; protocol claims zero user loss and full 1:1 redemption, but independent verification is unavailable. The protocol's stablecoin (USDX) depegged to $0.30–$0.54 in November 2025, a 46–70% drop below peg.
  • Governance & custody: Non-custodial protocol with assets held in smart contracts; governance via LISTA token with token-weighted voting, making it susceptible to concentration; top holder distribution and voting concentration are not verifiable as of 2026-08-29. Admin architecture uses timelock-based controls (Manager and Admin TimeLocks documented), with role-based access for pause, upgrade, and operational functions; exact live contract roster and current owner/admin mappings are not verifiable as of 2026-08-29.
  • Top risks: (1) Extreme recent TVL growth ($1.99B peak) with limited stress testing through major downturns; (2) heavy BNB ecosystem and collateral concentration, exposing the protocol to BNB price cascades and slisBNB/lisUSD stability risk; (3) relatively new isolated-market design with limited battle-testing compared to established lending protocols; (4) liquidator and liquidity shortfall risk during volatile periods, especially in thin markets; (5) residual smart-contract risks including DoS and inflation-attack classes noted in audits, plus oracle downtime/manipulation risk from reliance on Chainlink and other feeds.
  • Strengths: Permissionless market creation; isolated markets that limit contagion between pairs; capital-efficient P2P design for improved utilization and rates; multi-oracle pricing (Chainlink, Binance Oracle, Redstone, API3) for more resilient feeds; security-focused operations including audits, bug bounties, permission controls, and upgradeable contracts.
  • Unverified: Founders and team are not verifiable as of 2026-08-30; protocol presents as Lista DAO with Binance Labs backing but no named individuals or clear corporate structure. Treasury composition, custody arrangement, and reserve policy are not verifiable as of 2026-08-29; only TVL ($625M BSC + $1M Ethereum per DefiLlama) is reported, not protocol-controlled reserves. LISTA token supply, market cap, FDV, and contract addresses show material discrepancies across aggregators and are not verifiable as of 2026-08-29. Legal entity, jurisdiction, ToS, and KYC/AML design are not verifiable as of 2026-08-29; protocol is described as permissionless with no disclosed regulatory license.

Score

Component Weight Raw Points Reason
security 25% 100 25.0 7 audit(s); fresh audit bonus; active bug bounty bonus
incidents 25% 20 5.0 2 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 82 12.3 0 onchain, 20 two-source, 11 one-source of 31 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 20 2.0 timelock in governance +15; legal enforcement/sanction -30
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Lista Lending is a CDP-style lending/borrowing protocol integrated with the lisUSD stablecoin on BSC and Ethereum. Identification

  • Name: Lista (often styled as Lista DAO; lending module usually referred to as Lista Lending).
  • Website: Primary app front-end at app.lista.org (sometimes referenced as lista.finance in aggregators).
  • Docs: Hosted on docs.lista.org, covering lisUSD, LSR staking, and lending markets.
  • Category: Overcollateralized lending / borrowing, CDP stablecoin protocol (similar to Maker/Liquity class).
  • Launch date: Public launch of Lista on BNB Chain reported around mid-2023; rebrand/expansion from Helio Protocol announced 2023–2024. Exact contract deployment block-time is Not verifiable as of 2026-08-29.
  • Chains:
  • BNB Smart Chain (BSC) as primary deployment.
  • Ethereum deployment referenced by aggregators and bridge/stablecoin docs.
  • Native / governance token: LISTA (migrated / rebranded from HELIO), used for governance and incentives.
  • Stablecoin: lisUSD, an overcollateralized stablecoin issued against deposited collateral. Main contract addresses (TVL-relevant) Due to lack of on-chain querying via Dune, all addresses are aggregator or explorer-sourced only and Not verifiable as of 2026-08-29 against raw on-chain data:
  • BSC lisUSD core contracts (stablecoin, staking/lending vaults) cited by DeFiLlama’s Lista entry and BscScan verified-contract pages.
  • Ethereum lisUSD / Lista vaults listed in Ethereum explorers and DeFiLlama chain breakdown. Exact addresses cannot be reproduced here without direct on-chain validation under the current constraints; any single-source address would fail the ≥2-source cross-check requirement. Explorer verification status
  • Key contracts (lisUSD token and major vaults) on BSC are shown as “Contract source code verified” on BscScan.
  • Similar verification is indicated for Ethereum token/vault addresses on Etherscan. These remain explorer-level confirmations, not on-chain analysis. Fork lineage and design
  • Independent analyses and listings describe Lista as an evolution / rebrand of Helio Protocol on BNB Chain, not a straight fork of a single upstream like Maker or Aave.
  • The design is Maker/Liquity-style (CDP, overcollateralized stablecoin with staking), but no reputable source identifies a clean one-to-one code fork.
  • Public audits reference Helio/Lista audits by firms such as PeckShield and SlowMist, covering core stablecoin and staking/lending logic, but specific Lista Lending diffs vs Helio are Not verifiable as of 2026-08-29.
  • No documented history of malicious modifications in forks of Lista or vice versa was found; security incidents specific to Lista lending were Not verifiable as of 2026-08-29. Contradictions
  • Some aggregators still list Lista under “Helio Protocol” or mix HELIO/LISTA tickers, while newer entries show Lista as a separate protocol with lisUSD and LISTA token; without on-chain confirmation, the exact TVL and token mappings are inconsistent across sources.
Evidence (7)

maturity

two sources

Lista Lending appears to be a real, active product portal rather than just a landing page: the docs describe it as Moolah / Lista Lending, with separate developer documentation, smart-contract pages for both BNB Smart Chain and Ethereum, and an explicit lending API section. The public app also appears functional, with user-facing borrow pages and third-party yield pages showing live positions/TVL references. However, exact live deposit/withdrawal execution status and whether every market is currently open is not verifiable as of 2026-08-29 from the available evidence. Maturity signals are solid: the docs are structured like a working product stack (protocol overview, smart contracts, platform services, lending API, and markdown-accessible docs), which is stronger than a marketing-only site. The presence of chain-specific contract documentation for BSC and Ethereum also suggests a maintained multi-chain deployment, not a template shell. I did not find credible evidence of fake metrics or broken-link problems in the retrieved sources, but that also is not fully verifiable as of 2026-08-29. Open API: yes, the docs explicitly describe developer services and a Moolah Lending API with endpoint references for overall, vault, market, and position/liquidation/emission data. That is a documented API surface, though it is not yet verified here whether it is public, unrestricted, or production-grade. Overall: Lista Lending looks like a live, moderately mature DeFi lending product with real docs and developer surfaces, not a simple landing page. The remaining gaps—actual live deposit/withdrawal availability at this moment, broken-link hygiene, and any hidden template signs—are not verifiable as of 2026-08-29.

Evidence (3)

Security

audit

one source

Audit of LISTA Lending. The docs index lists this as the LISTA Lending audit dated 2025-04-10. The audit report title is referenced in the audit-reports page, but the search excerpt does not expose the findings table, fix status, or any explicit bytecode-match/deployed-code coverage statement. Those details are not verifiable as of 2026-08-29 from the provided excerpt.

Auditor
BailSec
Report Date
2025-04-10
Scope
LISTA Lending
Evidence (1)

audit

one source

Audit of LISTA Lending Provider. The docs index lists this report dated 2025-05-22, but the provided excerpt does not include findings counts, severities, remediations, or a bytecode-match statement. Not verifiable as of 2026-08-29.

Auditor
BailSec
Report Date
2025-05-22
Scope
LISTA Lending Provider
Evidence (1)

audit

one source

Audit of SlisBNBMinter for Lista Lending. The docs index lists this report dated 2026-01-05, but the provided excerpt does not include findings counts, severities, remediation status, or bytecode-match/deployed-code coverage. Not verifiable as of 2026-08-29.

Auditor
BailSec
Report Date
2026-01-05
Scope
SlisBNBMinter
Evidence (1)

audit

two sources

Audit of Credit Loan. The docs index lists this report dated 2026-01, and a secondary index-style source mentions the credit-loan reviews by BailSec and Cantina. However, the provided snippets do not expose the full report contents needed to extract exact critical/high/medium counts, fix status, or deployed-code coverage. Not verifiable as of 2026-08-29.

Auditor
BailSec
Report Date
2026-01
Scope
Credit Loan
Evidence (2)

audit

two sources

Audit of Lista Lending code repository. Scope covered smart contracts in the repository's src/ folder, excluding src/moolah/mocks/*, src/moolah-vault/mocks/*, and src/vault-allocator/mocks/*. The report states no critical issues were found. Findings listed: 1 Medium, 4 Low, plus 3 recommendations and 4 notes. Severity/status details: Medium potential inflation attacks — Fixed; Low lack of validation checks in createMarket() — Fixed; Low bypass of the bad debt handling mechanism in liquidate() — Fixed; Low potential replay attacks due to the chain hard fork — Confirmed; Low potential DoS risk in reallocate() — Confirmed. Notes were marked Confirmed or left unclassified. The report does not provide a separate deployed-code bytecode-match statement in the excerpt provided, so bytecode coverage is not verifiable as of 2026-08-29.

Auditor
BlockSec
Report Date
2024-05-17
Scope
Lista Lending smart contracts in src/ with listed exclusions
Evidence (2)

audit

one source

Managed review of Credit Loan. A secondary overview states the review ran 2026-01-15 to 2026-01-29 and found 0 critical, 2 high, 3 medium, 12 low, and 11 info issues, with the listed high/medium items described as fixed or mitigated by compensating controls in the overview. The excerpt does not include the underlying report or any explicit bytecode-match/deployed-code coverage statement, so deployed-code coverage is not verifiable as of 2026-08-29.

Auditor
Cantina
Report Date
2026-01-15
Scope
Credit Loan
Evidence (1)

audit

one source

Audit of Smart Collateral for Lista Lending. The docs index lists this report dated 2025-10-20, but the provided excerpt does not include findings counts, severities, remediation status, or bytecode-match/deployed-code coverage. Not verifiable as of 2026-08-29.

Auditor
OpenZeppelin
Report Date
2025-10-20
Scope
Smart Collateral
Evidence (1)

bug bounty

two sources

Lista Lending appears to have an active bug bounty program through Immunefi, which is currently marked Live Since 16 June 2022 and was last updated on 29 May 2026. The program scope covers Lista DAO smart contracts, with PoC required and payouts handled in USDT, USDC, and lisUSD on Base. The bounty parameters published by Immunefi are:

  • Critical smart contract bugs: 10% of directly affected funds, capped at $1,000,000, with a $100,000 minimum.
  • High severity: up to $10,000; Medium severity: up to $5,000.
  • Reports are assessed under the Immunefi Vulnerability Severity Classification System v2.2, and only assets listed in the scope table are eligible. On results, the sources reviewed do not provide a full public ledger of submissions, accepted reports, or payouts for this program. The available pages confirm the program exists and is active, but results are not verifiable as of 2026-08-29 from the retrieved sources. There is also a newer Lista/BNB Chain announcement dated 20–23 Aug 2026 stating Lista joined the BNB Chain Bug Bounty Ecosystem Program, with rewards from $300 to $150,000 and scope covering Lista’s smart contracts and protocol. That appears to be a separate or additional bounty arrangement, but the retrieved sources do not clarify whether it supersedes or supplements the Immunefi program.
Evidence (7)

counterparty risks

two sources

Lista Lending is a money market on BSC and Ethereum with material dependencies on stablecoins, LSTs, BNB ecosystem components, and oracle/bridge infrastructure. On-chain verification is not possible in this run: Not verifiable as of 2026-08-29. 1. External protocol & asset dependencies

  • Collateral types (per docs/analytics): on BSC primarily BNB, stables (USDT, USDC, DAI, BUSD) and LSTs such as staked BNB (e.g., Ankr/Liquid Staking); on Ethereum likely ETH/LSTs and major stables. These introduce indirect risk from:
  • BNB chain/layer security and potential reorgs or censorship.
  • Stablecoin issuer credit and regulatory risk (Tether, Circle, Maker, Paxos for historical BUSD).
  • LST protocol slashing, mismanagement, or smart‑contract failure. 2. Oracle & price manipulation risk
  • Lista appears to rely on Chainlink or similar price feeds for collateral valuation and liquidations (common for BSC lending protocols).
  • Risks: oracle downtime, stale prices during sharp moves, or targeted manipulation of thin‑liquidity assets feeding the oracle; under‑ or over‑collateralisation can cause bad debt.
  • Concentrated reliance on a single oracle stack is a systemic vulnerability (oracle upgrade/permission key compromise). 3. Bridges & cross‑chain exposure
  • As a dual‑chain protocol, it is indirectly exposed to bridged stablecoins and wrapped assets (e.g., bridged USDC/USDT to BSC via third‑party bridges).
  • Bridge hacks or depegs can render collateral on one chain worthless while positions remain denominated in allegedly stable units, creating protocol insolvency. 4. CEX / MM & RWA counterparty risk
  • Stablecoins and some LSTs are backed by off‑chain custodians, banks, and money‑market instruments (e.g., Circle’s USDC reserves, Tether’s short‑term credit, RWA vaults in DAI).
  • Failure of these custodians, regulatory freezes, or secondary‑market illiquidity can drive depeg events that directly hit Lista’s collateral base. 5. Stress scenarios
  • Major stablecoin depeg (USDT/USDC/DAI/BUSD): over‑collateralised loans become under‑collateralised; liquidations may not cover debt, leaving protocol bad debt.
  • BNB or LST shock: BNB price collapse or LST slashing event triggers mass liquidations; if oracle/markets are illiquid, positions cannot be unwound efficiently.
  • Oracle failure: incorrect prices enable under‑collateralised borrowing or block liquidations; attackers can drain liquidity by borrowing against inflated collateral.
  • Bridge exploit: bridged tokens on BSC/Ethereum lose value; Lista may accept effectively unbacked collateral. Given the absence of on-chain query data, all protocol-specific dependencies above are based on secondary analytics/docs and should be treated as indicative rather than fully validated. Not verifiable as of 2026-08-29.
Evidence (3)

crypto custody

two sources

Lista Lending is organized as a non-custodial lending protocol: users deposit assets into smart contracts, and the tokens are held and managed by those contracts rather than by Lista or any other person or legal entity. On BNB Smart Chain, Lista Lending (branded as Moolah) is built on Morpho Blue smart contracts, and its documentation describes core contracts such as vaults, liquidator, and provider components that handle lending and collateral flows on-chain. The protocol also uses an isolated market design, where each market has one collateral asset and one loan asset and risk is not shared across markets. In practice, suppliers deposit into vaults, and curators manage those vaults while borrowers post collateral in a market; liquidation occurs on-chain if collateral falls below required thresholds. For Ethereum support, the available sources confirm Lista Lending includes Ethereum in its market interface, but the custody model is described the same way: assets stay under smart-contract control, not protocol custody.

Evidence (5)

incident

two sources

Lista Lending has had at least two publicly reported incidents since launch: an October 8, 2025 platform pause after abnormal $YUSD collateral price movements, and a March 2026 USR-related liquidity/repayment event involving abnormal wstUSR pricing and very high utilization in partnered vaults.

Date
2025-10-08
Cause
oracle_manipulation
Loss Usd
None
Evidence (2)

incident

two sources

A later USR-related event in March 2026 involved abnormal wstUSR collateral pricing and very high utilization in MEV Capital and Re7 Labs vaults, with emergency governance and forced-liquidation discussions; reporting says most USR-related loans were repaid and positions closed at full 1:1 USD redemption, with zero loss claimed for users and the protocol.

Date
2026-03-27
Cause
liquidity_issue
Loss Usd
None
Evidence (2)

key management

one source

Key management in Lista Lending is organized around role-based access control inside the Vault Manager, with distinct roles for Owner, Curator, Guardian, and Allocator. The docs say vault creation requires assigning these roles, and vault settings can later be adjusted through the manager interface, including fee recipient, timelock, and market permissions.

Evidence (2)

smart-contract

two sources

Lista Lending’s documented admin architecture is timelock-based, not fully autonomous: the docs list a Manager TimeLock at 0x375fdA2Bf66f4CE85EAB29AB6407dCd4a4C428BA and an Admin TimeLock at 0xa18ae79AEDA3e711E0CD64cfe1Cd06402d400D61. The public docs also split the system into BSC and Ethereum contract sets, but without on-chain verification in this run the exact live contract roster, proxy addresses, and current owner/admin mappings are Not verifiable as of 2026-08-29. What can be stated from the retrieved sources is that Lista’s newer contract patterns use role-based access control with DEFAULT_ADMIN_ROLE, plus operational roles such as MANAGER, BOT, and PAUSER, and some implementations use UUPS-style upgrade authorization via _authorizeUpgrade restricted to the admin role. That implies the system can have separate controls for pause/unpause, emergency actions, and upgrade authority, but the specific Lista Lending contracts and whether each of those functions exists on each chain are Not verifiable as of 2026-08-29. The practical risk picture is therefore: if the controlling keys for the timelock/admin roles are compromised, an attacker could plausibly pause markets, change upgrade logic, or redirect privileged parameters wherever those roles are wired in; the exact blast radius is Not verifiable as of 2026-08-29 because live contract calls were unavailable. Conversely, if user funds sit in non-custodial vaults/markets with normal withdrawal paths, users may be able to exit without admin help, but that user-exit guarantee is also Not verifiable as of 2026-08-29. Architecture map (partial, source-backed): Users -> Lending markets/vaults -> role-gated admin layer -> timelock(s) -> upgrades/pauses/parameter changes. Diagram: [Users] -> [Lending Contracts] -> [Timelock Admins] -> [Upgradeable / Pause / Parameter Controls] No verified evidence was retrieved here for a renounced-owner state, on-chain timelock delay measured from executed transactions, or a confirmed proxy-admin type for the live Lista Lending deployment; those are Not verifiable as of 2026-08-29.

Evidence (3)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

one source

Lista Lending is a lending protocol in the Lista DAO ecosystem, which is closely linked to the BNB Chain / Binance ecosystem and evolved from the Helio Protocol. ### 1. Founders & Team

  • Public individual “founders” of Lista Lending are Not verifiable as of 2026-08-30. The protocol presents itself as Lista DAO, with no clear, consistently documented named founder group across independent sources.
  • Multiple independent sources describe Lista as the successor to Helio Protocol on BNB Chain, backed or strongly supported by Binance Labs / BNB Chain ecosystem, but do not attribute it to a specific founder individual or company in a verifiable way.
  • Helio Protocol’s original team structure and named contributors are partially documented in older ecosystem posts, but direct continuity of the *same* people into Lista Lending is Not verifiable as of 2026-08-30 via independent sources. ### 2. Public vs. Anonymous, Prior Track Record
  • Lista / Helio appears to be ecosystem-backed, with strong integration into BNB Chain and references from Binance Labs and BNB Chain communications.
  • The protocol’s social presence (Twitter, Medium, docs) uses brand-level identities (Lista DAO, Helio) rather than clearly identified, doxxed founders. This is consistent with a semi-anonymous / brand-fronted DeFi structure rather than fully transparent corporate leadership.
  • Independent documentation of prior projects, personal histories, or past hacks tied to named founders is Not verifiable as of 2026-08-30. ### 3. Office, Jurisdiction, Onshore/Offshore
  • No authoritative corporate registry, physical office address, or jurisdictional entity for “Lista Lending” can be confirmed from independent sources. Corporate structure is Not verifiable as of 2026-08-30.
  • Given the strong association with BNB Chain, it is plausible the project operates via an offshore foundation or DAO-like structure, but this remains inference, not verified fact. ### 4. Reality Check: Real Business vs. Web Front
  • Lista Lending is integrated into major ecosystem tooling (BNB Chain, DeFi aggregators, listing platforms) and manages non-trivial TVL according to analytics platforms, indicating real users and capital flows, not just a static web front.
  • However, absence of clearly disclosed founders, legal entity, and office in independent sources means governance and accountability are opaque. Overall: Lista Lending operates as a functioning DeFi protocol with ecosystem backing, but leadership, legal entity, and physical presence remain Not verifiable as of 2026-08-30, which is a material governance/credibility risk for an institutional lender.
Evidence (2)

general reputation

two sources

Lista Lending is generally perceived as a leading, technically sophisticated lending module of Lista DAO on BNB Chain, with no public evidence of fraud, rug pull, or insolvency events as of 2026‑08‑29. Founders / investors / backing

  • Lista DAO positions itself as a BNB‑native DeFi ecosystem (liquid staking, lisUSD, lending, DEX), and Lista Lending is one of its core products.
  • Public materials highlight backing by Yzi Labs and strong integration with BNB Chain’s ecosystem, but named individual founders are not prominently disclosed; this is a transparency gap for institutional due diligence. Audits and security posture
  • Docs and public communications claim smart contracts audited by PeckShield and BlockSec; an audit report for “ListaStakeManager” is referenced in the security section of the docs, and security marketing is repeated on social media.
  • These audits cover parts of the stack (e.g., staking manager, core contracts) rather than an explicitly stated full‑scope audit of every lending market; institutional users should confirm exact coverage and dates directly from auditor sites. Current web data is marketing‑level, not a formal attestation list. Sentiment and reputation in DeFi
  • Third‑party research platforms (e.g., Hindenrank, Exponential, DefiLlama) describe Lista Lending as a major BNB Chain lending protocol with isolated markets, multiple oracles (Chainlink, Binance Oracle, Redstone, API3), and no known historical exploits.
  • Binance‑authored explainers portray Lista Lending as “BNB Chain’s top lending protocol” and “most powerful tool” for DeFi users, which is positive but should be treated as ecosystem‑aligned commentary, not independent risk analysis. Criticisms, risk discussions, and unresolved concerns
  • Independent write‑ups focus on complexity (vaults + isolated markets + Smart Lending using LP collateral) and recommend careful monitoring of oracle behavior, liquidation parameters, and composability risks; they do not allege misconduct but highlight engineering and market‑risk surface.
  • I could not find credible claims of rug pulls, user fund losses due to protocol exploits, sanctions, or formal regulatory enforcement actions specifically targeting Lista Lending or Lista DAO. Not verifiable as of 2026‑08‑29.
  • Key institutional concerns remain: limited public founder identification, unclear legal entity structure, and the need to confirm audit scope, continuous monitoring, and incident response processes beyond high‑level marketing statements. No contradictions between major analytics platforms and protocol claims about being a large BNB Chain lending player were visible, but exact TVL and market share figures are on‑chain metrics and therefore Not verifiable as of 2026‑08‑29 under current constraints.
Evidence (15)

Economy

TVL: $548.0M

model

two sources

Lista Lending is an overcollateralized money market on BSC and Ethereum, similar to Aave/Compound, with a strong link to the Lista LSD/LSDFi stack (e.g., lisBNB, lisETH). Strategy & assets in/out

  • Users supply BNB, stablecoins and major tokens (and Lista LSDs) as collateral, and borrow mainly stablecoins and blue-chip assets.
  • It integrates closely with lisBNB (BNB LST) and lisUSD (CDP/stablecoin), so collateral often originates from Lista’s staking/restaking products. Yield sources & organic vs subsidized
  • Base yield is organic, from borrowers paying variable interest to suppliers; rates set by utilization curves (standard money-market model).
  • Additional LISTA token incentives top up APYs for some markets (liquidity mining), so part of the yield is subsidized and discretionary. Risk posture: neutral vs directional; leverage
  • The lending layer itself is economically market-neutral if users are unlevered; directional risk comes from user positions (e.g., long BNB or ETH with borrowed stablecoins).
  • Users can loop collateral (supply lisBNB → borrow stable → buy more BNB → restake) creating leveraged LST exposure; this increases liquidation and smart-contract risk.
  • There is external exposure to underlying staking/restaking layers and oracles (BNB/ETH prices, LST exchange rates). Lock-ups, withdrawals & mechanics
  • Standard money-market: no fixed lock-up; suppliers withdraw anytime, subject to market liquidity (can be gated if utilization is very high).
  • Liquidations are triggered when health factor < 1, via on-chain liquidators repaying debt for discounted collateral. Fees, protocol revenue & limits
  • Protocol revenue: share of borrow interest spread plus potential reserves/fees on liquidations; parameters governed by Lista governance (LISTA token).
  • Common controls: borrow caps, collateral factors, liquidation thresholds, reserve factors per asset, and potentially per-chain risk parameters. Collateral profile
  • Core collateral: BNB, lisBNB, ETH/lisETH, major stables (USDT/USDC/BUSD equivalents) and blue-chip tokens on BSC/Ethereum.
  • LSD/LRT collateral adds depeg and staking-yield variability risk on top of price risk. TVL and APY (data limits)
  • Exact TVL by chain/product, APY history and volatility are Not verifiable as of 2026-08-29 under current tooling rules.
  • DeFiLlama lists Lista Lending under BSC/Ethereum lending with TVL in the hundreds of millions USD range, but this is aggregator data, not on-chain verified and may diverge from on-chain reality. Key sustainability note
  • Long-term sustainability depends on borrow demand; if token incentives fall faster than organic demand grows, APYs on some markets are likely to compress and become more volatile.
Evidence (3)

reserves

one source

Lista Lending’s reserves / treasury are not verifiable from the provided sources as a clearly defined treasury policy, treasury address set, or independently attested reserve statement. The strongest available web evidence is that the protocol reports TVL, not treasury, and third-party aggregators only expose pooled protocol TVL by chain: BSC $624.33M and Ethereum $1.06M (total $625.39M) as of the DefiLlama snapshot. The protocol’s own pages and annual report describe lending TVL and product metrics, but they do not establish a separately auditable treasury composition, custody arrangement, or reserve-policy framework for a protocol treasury. On the protocol side, Lista’s annual report states that Lista Lending reached an all-time-high TVL of $1.99B and later reported $1.43B TVL, with collateral TVL, earn vault TVL, and active outstanding loans broken out; however, these are operating metrics, not proof of treasury assets under protocol control. The public landing page also shows aggregate lending TVL, but no treasury balance sheet or reserve attestation. For addresses, custody, and on-chain balances via Dune, the only source in the provided set is the Dune landing page itself, which does not supply a queryable treasury result in the snippet; therefore these items are Not verifiable as of 2026-08-29. Likewise, no independent attestation, reserve audit, or treasury custody disclosure appears in the supplied results. There is a clear reporting gap: public sources provide TVL and product-level collateral/borrow statistics, but not a verified treasury/reserve statement. Treat any claim that Lista Lending has a specific treasury size or reserve composition as unverified marketing claim unless supported by a separate audited reserve disclosure or reproducible on-chain query.

Evidence (4)

tokenomics

two sources

Lista Lending does have a native token: LISTA. 1) Basic token data

  • Name / ticker: Lista / LISTA.
  • Main contracts (BEP‑20): Multiple sources reference LISTA as a BSC token, but a canonical contract address consistent across independent sources is Not verifiable as of 2026‑08‑29 (risk: spoofed/duplicate listings).
  • Ethereum token: Several aggregators list bridged/wrapped LISTA on Ethereum, but contract alignment with the BSC original is Not verifiable as of 2026‑08‑29. 2) Supply, market cap, FDV
  • Aggregators show a fixed max supply around 1B LISTA (ranges 1.0–1.1B on different sites). Treat as aggregator estimate, not on‑chain verified.
  • Circulating supply, market cap, FDV: Different platforms report materially different values and sometimes mark LISTA as “untracked” or “self‑reported”. Therefore: Not verifiable as of 2026‑08‑29 at institutional standard. > Contradiction callout: Protocol/marketing claims on total or circulating supply versus third‑party trackers cannot be reconciled without on‑chain data. On‑chain verification is impossible in this run; numbers are not reliable enough for risk limits. 3) Utility and governance Based on docs and listings (all unverified marketing claims absent on‑chain checks):
  • Utility:
  • Incentives for borrowing, supplying collateral and minting the protocol’s stablecoin.
  • Staking/locking LISTA to receive additional rewards and/or boosted yields.
  • Governance:
  • LISTA intended as governance token for risk parameters (collateral types, LTVs, incentives). 4) Revenue share, burns, buybacks
  • Docs and blog posts state that a portion of protocol fees may accrue to LISTA stakers and/or be used for buybacks or burns.
  • Concrete percentages, triggers, and historical buyback/burn volumes are Not verifiable as of 2026‑08‑29. 5) Emissions, unlocks, allocations
  • Public material describes a multi‑year emission schedule with allocations to community incentives, team, investors, and treasury, but key parameters (cliffs, vesting, exact % splits) vary across trackers and articles.
  • Whether announced unlocks happened on‑chain, and the actual team/investor wallet behavior, are Not verifiable as of 2026‑08‑29. 6) Concentration, controls, liquidity
  • Top‑holder concentration, insider wallets, mint/blacklist/fee‑switch roles, and their controllers: Not verifiable as of 2026‑08‑29.
  • DEX liquidity depth and main listings: LISTA is reported on BSC DEXs and some CEXs, but depth and venue share cannot be validated without on‑chain and order‑book data → Not verifiable as of 2026‑08‑29. From an institutional risk lens, treat all LISTA tokenomics as low‑confidence, marketing‑level only until an on‑chain review is possible.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

one source

For Lista Lending, a Bitcoin crash below $10,000 is a stress event for the broader crypto market, but the protocol’s direct exposure appears to be primarily BNB/Ethereum collateral markets, not BTC-specific lending, so the main impact would be indirect liquidation pressure, lower collateral values, and higher bad-debt/liquidity risk rather than an automatic BTC-collateral liquidation cascade. Key mechanics: Lista Lending is described as an isolated-market lending protocol where each market has its own collateral asset, loan asset, LLTV, and liquidity depth, and liquidation is triggered when a borrower’s LTV approaches or exceeds the market’s LLTV. Under a severe BTC drawdown, correlated selloffs in ETH and BNB could reduce collateral values and push leveraged borrowers toward liquidation, especially if market liquidity thins and liquidators cannot fully execute swaps. For the BSC deployment, the most relevant risk is likely BNB price contagion: a BTC collapse can transmit risk-off pressure across altcoins, increasing liquidation frequency in BNB-denominated markets and potentially stressing lisUSD stability if collateral quality weakens. For Ethereum, the same logic applies to ETH-related markets and any cross-asset risk sentiment shock, but the provided sources do not quantify protocol-specific BTC sensitivity or current exposure by chain, so that is Not verifiable as of 2026-08-29. A crucial limitation is that the search results do not provide on-chain position data, market-by-market exposure, or current TVL by chain, so it is Not verifiable as of 2026-08-29 whether BTC-linked collateral exists inside Lista Lending or how much each chain would be affected. The safest risk view is therefore: BTC < $10k would likely trigger elevated liquidation stress indirectly, but the severity for Lista depends on BNB/ETH drawdowns, leverage concentration, and liquidator capacity rather than BTC price alone.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg in the largest collateral would primarily increase liquidation pressure and can create losses if liquidations are delayed, but the exact bad debt / insolvency impact is not verifiable as of 2026-08-29 because no on-chain exposure data for Lista Lending on Ethereum or BSC was provided and on-chain verification is unavailable in this run. General collateral-stress guidance says participants should run extreme-but-plausible stress tests, maintain diversified liquid assets, and calibrate haircuts/collateral arrangements to withstand collateral calls under stress. For Lista specifically, the protocol’s liquidation design is intended to respond when a borrower’s LTV exceeds the market LLTV; liquidators repay debt and receive seized collateral plus a bonus, which means a 20% collateral depeg would be expected to push positions closer to liquidation thresholds and amplify liquidation volume if the depegged asset is widely used as collateral. Independent risk commentary on Lista also notes that lisUSD has experienced prior depegs and that recursive collateral dependencies can worsen liquidation spirals, although that source is an external assessment rather than on-chain verification. What is not verifiable from the available evidence is the protocol’s current largest-collateral composition, chain-by-chain exposure on BSC vs Ethereum, or the dollar amount of positions that would become liquidatable under a 20% depeg. Therefore, the stress result can only be stated qualitatively: higher liquidation rates, possible collateral shortfalls, and increased bad-debt risk if market liquidity is insufficient, with the magnitude dependent on the depegged asset’s share of collateral and the protocol’s liquidation execution quality.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

If a top borrower on Lista Lending becomes insolvent, losses are absorbed primarily via collateral liquidations, then bad debt to the protocol, then socialized across lenders and potentially the protocol treasury. On-chain verification is not possible in this run: Not verifiable as of 2026-08-29. ### 1. Setting: what “top counterparty insolvent” means

  • On Lista, users borrow against overcollateralized positions; liquid staking tokens and stablecoins are key collateral.
  • A “top counterparty” = largest borrower (by debt) per asset and chain (BSC vs Ethereum). ### 2. Stress path: borrower insolvency 1. Trigger event
  • Price drop in collateral or protocol-specific hack on borrower’s collateral tokens causes health factor < 1 (under-collateralized). 2. Smart-contract reactions
  • Lending contracts mark the position as liquidatable and allow liquidators to repay debt and seize collateral at a discount.
  • If price oracles fail or are delayed, liquidations may be mispriced or stuck, increasing bad debt risk. 3. If liquidations succeed
  • Debt is repaid by liquidators; collateral is transferred to them.
  • Lenders are made whole, aside from temporary liquidity or rate effects. 4. If liquidations fail / are insufficient (true insolvency)
  • Part of the borrower’s debt cannot be covered → bad debt in the market.
  • Smart contracts now show an accounting shortfall: total assets < total liabilities for that asset pool. ### 3. Who absorbs the loss?
  • Liquidity providers (depositors): suffer through:
  • Reduced pool assets → lower effective claim; in extremis, some depositors may not be able to withdraw at par.
  • Protocol treasury / insurance funds (if any on Lista): can cover bad debt via governance-approved transfers; this shifts loss from users to token holders.
  • LISTA / governance token holders: value dilution if treasury is used; possibly future fee hikes. ### 4. Compensation & impact path
  • Direct compensation only exists if there is an explicit insurance/coverage program; otherwise, depositors bear economic loss.
  • Governance may pass ex-post compensation measures, but these are political, not contractual.
  • Smart-contract impact chain: 1. Oracle update → health factor breach. 2. Liquidation calls → collateral transfer, debt repayment. 3. If deficit remains: pool accounting shows bad debt; interest rate models may react (higher borrow rates). 4. Potential governance actions: parameter changes, recapitalization from treasury, pausing markets. Per-chain exposure (BSC vs Ethereum), actual top borrowers, and any insurance reserves: Not verifiable as of 2026-08-29.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For the specific stress scenario of committed fraud by the DAO or owners, I did not find verifiable evidence that Lista Lending’s DAO, founders, or owners have been accused or found to have committed fraud. As of 2026-08-29, this is Not verifiable as of 2026-08-29 based on the available sources. What can be verified is that Lista DAO describes a governance-controlled risk fund and emergency powers for self-operated vaults, including suspension/closure rights in extreme cases, which indicates centralized emergency discretion rather than proof of fraud. Immunefi shows an active bug bounty program, which is consistent with a protocol that expects technical risk, not with any confirmed fraud finding. The only incident-like material in the results concerns unusual YUSD price fluctuations and a temporary pause of operations; the available writeups frame this as a risk-management / market-stress event, not as proven fraudulent conduct by DAO participants or owners. No source in the provided set establishes misappropriation, intentional deception, or a regulatory finding of fraud. If you want, I can next assess the most plausible loss path from governance abuse or insider abuse for Lista Lending, which is a different and more analyzable scenario than proven fraud.

Evidence (5)

stress scenario - primary yield source negative 30d,

one source

For Lista Lending, the primary yield source is described as swap fees from trading activity generated by assets deployed into Lista’s internal DEX pools when users supply collateral to Smart Lending markets. In a stress scenario where that primary yield source is negative over 30 days, the protocol’s own description does not provide any downside mechanics, reserve backstop, or loss-allocation framework, so the impact is Not verifiable as of 2026-08-29. What can be stated is that this yield source is activity-dependent rather than rate-dependent: if trading activity and therefore swap-fee generation fall materially, the yield available to Smart Lending depositors would also fall. However, whether that would merely reduce APY, produce a net negative return after costs, or impair peg/collateral mechanics is not disclosed in the available source. No on-chain verification was possible in this run, and no independent source in the provided results documents BSC- or Ethereum-specific yield attribution for Lista Lending, so the chain split and loss magnitude are also Not verifiable as of 2026-08-29.

Evidence (2)

Governance & Legal

governance

one source

Lista Lending governance is structured around a token-based DAO (LISTA) with strong ongoing influence from the founding team and associated entities. On‑chain verification is not possible in this run: Not verifiable as of 2026‑08‑30. 1. Who controls what

  • Smart contracts & protocol parameters: Controlled via governance using the LISTA token; proposals can modify key parameters such as collateral factors and supported markets.
  • Frontend & brand: Operated by the Lista/Team finance entity (exact legal wrapper not independently identifiable). Not verifiable as of 2026‑08‑30.
  • Treasury/funds: Governance controls protocol reserves and DAO treasury, with spending subject to proposals and votes. 2. Governance mechanics (symbolic vs real)
  • Lista Lending positions itself as a DAO governed protocol where token holders can submit and vote on proposals regarding protocol upgrades, parameter changes and treasury usage.
  • Governance is token‑weighted: voting power scales with LISTA holdings, making it susceptible to concentration.
  • There is no independent evidence of regulatory filings or legally binding DAO wrapper; governance appears de facto on‑chain corporate control, not a regulated entity. Not verifiable as of 2026‑08‑30. 3. Voting concentration & top holders
  • Detailed holder distribution, voting concentration, and top voter profiles would normally be retrieved from Dune or explorers; this is Not verifiable as of 2026‑08‑30 in this environment. 4. Timelock & multisig
  • Lista Lending documentation and third‑party analytics mention a multisig / timelock structure for protocol admin keys and treasury operations, but specific contract addresses, signer list, threshold (e.g., 3/5, 4/7), and independence of signers cannot be confirmed from primary sources here. Not verifiable as of 2026‑08‑30. 5. Powers of governance vs team
  • Governance can: adjust risk parameters (LTVs, liquidations), add/remove supported assets, and allocate treasury for incentives or partnerships.
  • The core team / multisig typically retains emergency powers (pause functions, parameter caps), implying shared control rather than fully decentralized governance. Not verifiable as of 2026‑08‑30. 6. Legal entity, jurisdiction, ToS
  • Publicly accessible Terms of Service and company registration (if any) for Lista Lending or any associated foundation are Not verifiable as of 2026‑08‑30. No independent regulatory or corporate registry records were identified. Key risk takeaway: governance is token‑weighted and team‑influenced, with unverified but likely multisig/timelock admin, and no demonstrably independent legal wrapper, which raises centralization and key‑person risks for institutional exposure.
Evidence (2)

legal & regulatory

two sources

Lista Lending is presented as a decentralized, permissionless P2P lending protocol operated by Lista DAO on BNB Chain and Ethereum, with no clear central corporate operator or explicit jurisdiction disclosed in public docs. As of 2026‑08‑29, most legal points are not verifiable on-chain, and several core aspects remain undocumented. ### Legal entity / jurisdiction

  • Docs and website consistently refer to Lista DAO, not a registered company, and do not specify incorporation jurisdiction or regulatory license.
  • Backing by Binance’s YZi Labs and listing on Binance are mentioned, but these are unverified marketing claims regarding regulatory comfort rather than formal authorization. ### Terms of Service, user restrictions
  • Public-facing docs (Lista Docs, app pages) focus on technical design (vaults, markets, oracles) and do not expose a detailed ToS for Lista Lending (no age, residency or prohibited jurisdiction rules found).
  • A separate "Lista Card" ToS is tied to a Philippines financial app with KYC and loan brokering obligations, but this appears to be a different product/entity, not the BNB/Ethereum DeFi protocol; it must not be conflated with Lista Lending. ### KYC / AML
  • Lista Lending is repeatedly described as permissionless, implying no protocol-level KYC for on-chain lending and borrowing.
  • No evidence of integrated KYC/AML, blocklist logic, or travel‑rule compliance in public docs; therefore KYC/AML design is Not verifiable as of 2026‑08‑29. ### Regulatory classification and licensing
  • Protocol is marketed as DeFi lending, liquid staking, and stablecoin (lisUSD) CDP infrastructure, which regulators may treat as lending/borrowing and potentially as collective investment or stablecoin issuance, but no formal regulatory classifications or licenses are disclosed.
  • There is no public indication of registration as a VASP, lending institution, or broker‑dealer in any major jurisdiction; Not verifiable as of 2026‑08‑29. ### Warnings, enforcement, court cases, sanctions
  • No public records of regulatory warnings, enforcement actions, court cases, or sanctions against Lista DAO / Lista Lending were identified; Not verifiable as of 2026‑08‑29. ### Data protection / privacy
  • On-chain protocol by design holds no off-chain personal data, but web/app layers may collect analytics; there is no dedicated privacy policy specific to Lista Lending in the available docs. ### Legal structure vs actual risk (institutional angle)
  • DAO structure + permissionless smart contracts suggests:
  • Users interact directly with smart contracts, likely without formal client status or investor protection.
  • Cross‑border use without geographical controls increases regulatory perimeter risk (unlicensed lending, staking, stablecoin activity).
  • Lack of disclosed legal entity and ToS complicates contract law, dispute resolution, and enforceability for institutional participants.
  • For institutional use, Lista Lending currently looks like a pure on-chain, non‑KYC protocol with opaque legal entity and licensing, which materially raises counterparty and regulatory risk despite strong ecosystem positioning.
Evidence (11)

Stability

stability

two sources

Yes. Based on the available web results, the stablecoin used by Lista Lending (USDX) did depeg in November 2025: one source reports it briefly fell to $0.54 on Nov. 7, 2025, and another reports a low of $0.30 on Nov. 6, 2025. That implies a depeg of roughly 46% to 70% below the $1 peg, depending on which reported low is used. The last clearly reported depeg in the search results is this Nov. 2025 event. How many times it happened is not verifiable as of 2026-08-29 from the provided sources, because the results document this major depeg but do not provide a complete historical count for Lista’s stablecoin on BSC and Ethereum.

Evidence (5)

Risks & Strengths

risks

two sources

The top 5 risks for Lista Lending on BSC/Ethereum are: (1) extreme recent growth with limited stress testing, (2) heavy BNB ecosystem/collateral concentration, (3) relatively new isolated-market design with limited battle-testing, (4) liquidator/liquidity shortfall risk in volatile periods, and (5) smart-contract/security residual risk, including DoS and inflation-attack classes noted in audits. Hindenrank highlights that the protocol’s rapid TVL expansion means its lending markets have not been tested through a major downturn, while BNB price declines can cascade into slisBNB collateral and lisUSD stability. It also flags that isolated markets may have too few liquidators during stress, and that the Morpho-inspired design is newer than established lending systems. Third-party vault docs warn of oracle limitations, thin liquidity, delayed updates, and extreme volatility in curated assets. Blocksec’s audit found potential inflation attacks, a reallocate() DoS risk, and other residual issues, while DefiCare summarizes additional acknowledged risks including liquidations, Morpho-level attack vectors, and privileged governance powers.

Evidence (5)

strengths

two sources

Top 5 strengths of Lista Lending, based on the available sources, are: permissionless market creation; isolated markets that limit contagion between pairs; capital-efficient P2P design that aims to improve utilization and rates; multi-oracle pricing for more resilient price feeds; and security-focused operations including audits, bug bounties, permission controls, and upgradeable contracts. Lista’s docs and related coverage describe it as a fully decentralized, permissionless P2P lending protocol on BNB Chain with vault-based liquidity allocation and first-party as well as third-party vault creation. The protocol is also described as using isolated markets so a failure in one market does not automatically spread to others, which is a major structural risk-control advantage. Multiple sources emphasize that its P2P architecture is designed to maximize capital efficiency and support lower borrowing costs versus more rigid pooled models. The protocol’s multi-oracle design is repeatedly highlighted as a strength because it reduces reliance on a single price source and lowers manipulation risk. Finally, Lista states that security is reinforced by top-tier audits and an active bug bounty program, while other coverage points to granular permissions and upgradeable contracts as additional resilience features.

Evidence (7)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 11 one source.
  • Oldest fact verification date: 2026-08-29.