NAVI Lending

Orange · 52/100 Data confidence 95/100

Executive summary

NAVI Lending is a decentralized lending and borrowing protocol native to the Sui blockchain, launched in July 2023, with a risk score of 55/100 (orange band).

  • Security: Audited by OtterSec, MoveBit, Salus, and Veridise with all fixes marked "Passed," but underlying severity breakdown and bytecode equivalence are not verifiable; active HackenProof bug bounty ($300–$300,000) shows 392 submissions but $0 in paid rewards as of available data; audit found missing checks, incorrect calculations, and flawed liquidation logic before remediation.
  • Incidents: In April 2026, NAVI proactively paused contracts during a Sui ecosystem security event (Volo incident) but reported no user-fund loss; no confirmed protocol-level exploit or insolvency event is verifiable.
  • Governance & custody: Non-custodial smart-contract design; governed by NAVX token and controlled by Navi Protocol Labs, Inc. (US entity); multisig and timelocked upgrades are mentioned but signer identities, threshold, and exact upgrade scope are not verifiable; admin keys can withdraw treasury funds and update token prices per audit findings.
  • Top risks: Smart-contract vulnerabilities (liquidation logic flaws); liquidation cascades and bad debt from leveraged vaults during sharp price moves; collateral concentration (LSTs, stablecoins) and depeg risk; Sui ecosystem concentration (chain outages, thin liquidity); governance centralization and admin-key compromise risk.
  • Strengths: Leading Sui lending protocol with isolated pools, configurable risk limits, multi-oracle design, and tight Move-based integration; non-custodial model with institutional "NAVI Prime" offering.
  • Unverified: Exact contract addresses, proxy/admin structure, timelock parameters, reserve composition, treasury custody, collateral exposure breakdown, tokenomics allocations, and legal entity jurisdiction/licensing are not verifiable as of 2026-08-29; founder identities appear pseudonymous (Elliscope, Charles) with no confirmed public track record for the DeFi project.

Score

Component Weight Raw Points Reason
security 25% 75 18.8 1 audit(s); fresh audit bonus; active bug bounty bonus
incidents 25% 5 1.2 2 incident(s) in 730-day window, losses $3,500,000; 0 high/critical news
verifiability 15% 84 12.6 0 onchain, 19 two-source, 4 one-source of 25 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 70 7.0 verified governance +20; timelock in governance +15; no legal signals

Identification

protocol identification

two sources

NAVI Lending (often just NAVI Protocol) is a decentralized lending/liquidity protocol native to the Sui blockchain, offering deposit/borrow markets, isolated pools and institutional “NAVI Prime” markets. Identification

  • Name: NAVI Protocol / NAVI Lending
  • Website: naviprotocol.io (landing page for lending, Prime, and other products).
  • Docs: Hosted on GitBook under “Navi Protocol Docs”; separate SDK docs at sdk.naviprotocol.io.
  • Category: DeFi lending/borrowing & liquidity protocol (one‑stop liquidity on Sui).
  • Launch date: Mainnet launch article dated 27 Jul 2023, describing NAVI as the “First Native One‑stop Liquidity Protocol on Sui,” so mainnet went live around that date.
  • Chains: Sui only; all markets and NAVI Prime are described as Sui‑based.
  • Native / governance token: Commonly referenced as NAVX (NAVI Protocol (NAVX) in third‑party overviews and listings). Core functionality
  • Users supply assets (e.g., SUI, USDC, USDT, WETH, WBTC) to earn variable interest, receive receipt tokens (nSUI, nUSDC, etc.), and can borrow against collateral.
  • Features include isolated lending pools, flash loans, risk parameters (LTV, caps) and an institutional framework (NAVI Prime) with independently curated markets and risk controls. Main contracts and verification status Because direct on‑chain tools are unavailable in this run, exact Sui package IDs / contract addresses and their verification status are Not verifiable as of 2026‑08‑29. This also means I cannot provide the ≥2‑source cross‑checked address list you requested. Fork lineage / code origin
  • Public descriptions and SDK docs emphasize a Move‑native implementation specifically for Sui, not an EVM fork.
  • None of the accessible materials (analyst reports, docs, media) explicitly call NAVI a fork of Aave, Compound, or another legacy protocol, nor do they document a fork‑lineage change log or “diff” against an upstream codebase.
  • Consequently, whether NAVI is a direct fork of an existing lending protocol is Not verifiable as of 2026‑08‑29. Audits and malicious‑fork history
  • In this search pass, I did not retrieve primary audit PDFs from auditor sites or detailed audit notes; status is therefore Not verifiable as of 2026‑08‑29 (any audit claims in marketing would be “unverified marketing claim”).
  • I also did not find documented incidents of malicious modifications in NAVI forks or copycats; absence of evidence is not confirmation of safety and remains Not verifiable as of 2026‑08‑29.
Evidence (15)

maturity

two sources

NAVI Lending appears to be a real, live product rather than a pure landing page: its docs point users to an app portal, and the technical documentation includes deposit and withdraw functions plus SDK modules for pool operations, flash loans, liquidation, and rewards. The docs also describe active user flows for supplying, borrowing, and withdrawing, which is consistent with a functioning app UX rather than a brochure-only site. There are signs of product maturity, but only partial verification from the web: the docs are structured, there is an SDK, and third-party how-to content shows wallet connection and supply/borrow steps. However, live deposits/withdrawals and current front-end health are not verifiable as of 2026-08-29 from the available evidence, and broken links or fake metrics cannot be confirmed or ruled out. An open API is effectively present for developers through the published SDK and technical API/reference pages, including lending, pool, and flash-loan documentation. Whether there is a fully public, stable REST-style open API for external third parties, beyond the documented SDK/interfaces, is Not verifiable as of 2026-08-29. Overall: NAVI looks like a functioning Sui lending protocol with real app and developer documentation, but front-end quality, link hygiene, and live transaction reliability remain Not verifiable as of 2026-08-29.

Evidence (5)

Security

audit

one source

Fix status is published as 'Passed' for all listed reviews on the security page. However, the available search results do not provide the underlying findings breakdown by severity (critical/high/medium), nor do they provide issue-by-issue remediation status. For the specific request to confirm whether the audits cover deployed code, the results are insufficient to verify bytecode/source equivalence; this is Not verifiable as of 2026-08-29.

Auditor
MoveBit / Veridise / SALUS / OtterSec
Report Date
2025-05-16
Scope
Fix status of listed audits; deployed-code coverage / bytecode-match note not verifiable from provided results.
Evidence (2)

bug bounty

two sources

NAVI Lending has an active bug bounty program via HackenProof. HackenProof lists it as LiveProgram is active now, with a started date of 16 Oct 2025 for NAVI Protocol’s smart-contract program on Sui. NAVI’s docs also describe it as an ongoing program run in collaboration with HackenProof. The published parameters are:

  • Scope: NAVI Protocol smart contracts / lending components and the NAVI web application and related interfaces.
  • Rewards: HackenProof shows $300 to $300,000 overall, with Critical $30,000-$300,000, High $5,000-$30,000, Medium $1,000-$5,000, and Low $300-$1,000. NAVI’s docs summarize this as up to $300,000 for critical smart-contract vulnerabilities and up to $10,000 for web/frontend issues.
  • Eligibility / rules: reports must be submitted exclusively through HackenProof and within 24 hours of discovery; only the first reporter of a qualifying vulnerability is eligible, and several classes such as gas optimization are excluded. Reported results shown by HackenProof are limited: the program page lists 392 submissions and Total rewards $0 for the NAVI Protocol program snapshot in the search results. That indicates there have been many submissions, but no paid bounty rewards are shown in the available data. The exact launch date for the broader “NAVI Protocol” bounty is consistent across HackenProof pages, but the NAVI docs page does not state a start date, only that the program is ongoing.
Evidence (4)

counterparty risks

one source

NAVI Lending on Sui depends on a small set of infrastructure (notably oracles and stablecoins) plus any listed collateral assets; most risks are concentration into few price feeds, stablecoin/LST exposures, and Sui ecosystem/bridge fragility. All on-chain details are Not verifiable as of [2026-08-29]. 1. External protocol & oracle dependencies

  • NAVI is a lending market built on Sui that uses price oracles for collateral valuation; public docs reference Pyth and other Sui-native oracle integrations as core dependencies. Oracle failure, downtime, or manipulation can cause under‑collateralized lending, incorrect liquidations, or protocol insolvency.
  • Manipulation vectors:
  • Thin liquidity on Sui DEXes makes spot‑price based oracles more vulnerable to pump‑and‑dump or flash‑loan style attacks.
  • If NAVI uses single‑source oracles per asset, there is concentration risk to that provider’s upgrades, governance, or data pipeline. 2. Bridges and Sui ecosystem exposure
  • NAVI is Sui‑native; users likely bridge assets via third‑party Sui bridges (e.g., Wormhole and other multichain bridges used in the ecosystem). A major bridge exploit could:
  • Drain bridged collateral or stablecoins, forcing bad debt.
  • Cause NAVI to hold tokens that later become unbacked or blacklisted on other chains.
  • This is indirect counterparty risk: NAVI does not custody bridge contracts, but its collateral universe is exposed to their integrity. 3. Stablecoin & LST / restaking exposure
  • NAVI markets reportedly support major stablecoins (USDC variants, bridged stables) and Sui-native assets. Each introduces:
  • Depeg risk (issuer insolvency, reserve issues, regulatory actions).
  • For algorithmic or exotic stables, design risk and governance attacks.
  • If NAVI lists staked SUI / LSTs, risks include validator slashing, LST oracle mispricing, and restaking slashing cascades. Liquidations may fail in stressed markets if LST liquidity on Sui DEXes is thin. 4. CEX / market‑maker / custodian / RWA risk
  • No direct CEX or custodian reliance is documented; however, NAVI’s asset prices and liquidity ultimately depend on centralized exchanges and market‑makers for majors like USDC and large caps.
  • If NAVI supports RWA tokens or tokenized treasuries, those rely on off‑chain SPVs/issuers, KYC regimes, and legal enforceability; failure or asset seizure would render collateral worthless, creating protocol bad debt. 5. Failure scenarios to consider
  • Oracle bug or governance attack on Pyth/other oracle → mass mispricing, cascading liquidations, insolvency.
  • Major bridge exploit or stablecoin depeg → NAVI left holding unbacked collateral; shortfall vs borrower liabilities.
  • Sui chain outage or reorg → liquidations delayed, allowing positions to go deeply underwater. Given missing confirmed technical integration details, several specific exposures remain: Not verifiable as of [2026-08-29].
Evidence (3)

crypto custody

two sources

NAVI Lending on Sui is organized as a non-custodial, smart-contract-based lending system: users supply assets into protocol pools and receive receipt tokens, while borrowers post collateral and borrow against it without intermediaries. NAVI’s published docs and launch materials describe the protocol as a decentralized liquidity protocol using shared liquidity pools, with isolation markets, supply/borrow caps, and liquidation rules to manage risk. For the institutional NAVI Prime product, NAVI says custody can remain with BitGo, Anchorage, Fireblocks, or Galaxy, and capital is then deployed into curated vaults “without leaving your own controls.” That means the custody layer is separated from the onchain lending execution layer: assets may be held by a qualified custodian first, then allocated into NAVI’s isolated blue-chip markets. So the custody structure is best described as: self-custody or third-party institutional custody off-chain, plus onchain deployment into NAVI pools/vaults. NAVI does not appear to take direct custody of user funds in the traditional sense; instead, smart contracts control lending positions, collateral, and liquidations. One caveat: the protocol’s own page is also a marketing source, so the institutional custody claim is unverified marketing claim unless independently confirmed. The onchain/non-custodial lending design, however, is consistent across the docs and launch coverage.

Evidence (3)

incident

one source

A third-party writeup about NAVI Prime noted that the prior Volo Vault episode on Sui involved a $3.5 million loss and was described as a protocol logic failure executed through an admin key compromise, but that article presents it as a Volo/Volo Vault incident rather than a confirmed NAVI incident. I cannot verify from the provided sources that NAVI itself suffered that loss.

Date
2026-04-21
Cause
key_compromise
Loss Usd
3500000
Evidence (1)

incident

unverified

I found one protocol-level incident notice: on Apr. 21, 2026 NAVI said it had proactively paused contracts and activated security procedures in response to the security incident affecting Volo on Sui; NAVI said it had not been impacted, and later said all features were reviewed and resumed with deposits and withdrawals live. The materials provided do not show any NAVI user-fund loss, affected-market breakdown, reimbursement, or code-level fix beyond the precautionary pause and review.

Date
2026-04-21
Cause
other
Loss Usd
None
Evidence (2)

key management

unverified

NAVI Lending’s key management is organized primarily around user-controlled Sui wallets for ordinary lending actions, while the protocol’s institutional partnership material indicates support for multisig wallets for higher-assurance transaction approval. NAVI’s user docs say users can log in with a Sui-compatible wallet such as Slush or OKX Wallet, and then supply/borrow/withdraw through that wallet; the SDK docs also describe account and pool operations, but not custody of private keys by NAVI itself. For institutional or shared control, NAVI’s partnership announcement with MSafe says the protocol added support for multisig wallets, which require two or more private keys to execute a transaction. That means key authority can be distributed across multiple signers rather than held by a single individual, which is the relevant structure for treasury, fund, or team-managed accounts. What is not verifiable as of 2026-08-29 from the available sources is any protocol-run key custody, MPC setup, hardware-security-module design, emergency admin key arrangement, or formal key-rotation policy. The available documentation supports a model where NAVI relies on external wallets for user signing, with multisig support for institutional operations, but it does not disclose deeper key-management controls.

Evidence (3)

smart-contract

two sources

For NAVI Lending on Sui, the web results confirm the protocol publishes open-source smart contracts and states they are audited, but the results do not provide a verifiable contract-address map, proxy/admin address, or on-chain timelock data for this run, so those items are Not verifiable as of 2026-08-29. The available audit snippet shows the protocol includes powerful privileged functions: an admin can withdraw any amount of tokens from the treasury, and the admin or a designated account can update token prices, which implies meaningful admin-key risk if those controls are still present in the deployed version. What can be said with confidence is that the protocol supports core lending actions on Sui such as borrow, withdraw, flashloan, and liquidation, and an upgrade announcement notes that these SUI-asset operations required a new interface after the upgrade, indicating the system is upgradeable and has versioned contract interfaces. The same announcement is consistent with an architecture where user-facing entrypoints are separated from implementation details, but the exact proxy pattern, proxy-admin type, and whether upgrades are controlled by an owner, multisig, or timelock are Not verifiable as of 2026-08-29. Risk view: if privileged keys were compromised, the worst-case outcome would be asset drain via treasury withdrawal and/or price manipulation leading to bad borrows, liquidations, or market disruption. Because the retrieved sources do not prove a renounced-owner state, an on-chain timelock delay, or a user-only emergency exit path, freeze/rug resistance cannot be verified in this run; users should therefore assume admin-mediated freeze or upgrade risk exists until disproven. Architecture map (verified only at high level): Users → Lending interface / SDK → SUI lending modules → pool/oracle/admin-controlled functions; the privileged plane includes treasury and token-price controls, while the exact upgrade/admin wiring is Not verifiable as of 2026-08-29.

Evidence (4)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

NAVI Lending appears to be the blockchain protocol branded under NAVI, but the available sources mix it with the Indian fintech company Navi Technologies, so the identity is not fully cleanly separable from the web results alone. The strongest public people signal is that NAVI Protocol’s site names Elliscope as co-founder, while RootData also lists Charles and Elliscope F. as co-founders; those names appear pseudonymous/partially anonymous rather than clearly public identities. By contrast, the search results strongly identify Sachin Bansal and Ankit Agarwal as founders of the Indian fintech company Navi, but that is a separate real-world business narrative and should not be assumed to be the same team as NAVI Lending without a verified contract-level match. Sachin Bansal has a public, verifiable track record as a Flipkart co-founder and former Amazon Web Services engineer, and recent Reuters/TechCrunch coverage says his fintech Navi was founded in 2018 and is pursuing an IPO with a $100 million investment from Prosus. On the protocol side, the public record here is thin: there is no verifiable office address, incorporation jurisdiction, or audited team background for the DeFi project in the supplied results, so those items are Not verifiable as of 2026-08-29. Reality-check wise, the web results suggest a real operating fintech business behind the Navi brand in India, but for NAVI Lending specifically the evidence currently looks more like a web-facing protocol with partially anonymous co-founders than a fully transparent, institutionally documented team.

Evidence (7)

general reputation

two sources

NAVI Lending’s public reputation is generally positive but risk-aware: it is widely described as the leading or one of the largest lending protocols on Sui, and multiple sources say it has been audited by firms such as OtterSec, MoveBit, Salus, Veridise, and others. Investor coverage also says NAVI raised about $2 million from names including OKX Ventures, dao5, Hashed, Mysten Labs, Comma3 Ventures, Mechanism Capital, Coin98 Ventures, Gate.com, and LBank Labs. The main criticisms are about protocol risk, not fraud. Independent risk coverage flags leveraged vaults, liquidation amplification, and thin Sui liquidity as downside risks; Hindenrank gives NAVI a C+ risk grade and says the protocol has a fairly clean operational history but elevated risk from leverage and market stress. DIA Data likewise describes no recorded security incidents, while Hindenrank notes some history of security incidents or exploits in its track record dimension, so there is a mild source conflict on incident history. On fraud/rug/insolvency allegations, I found no credible reporting of a rug pull, outright fraud, or insolvency event. The available sources instead emphasize growth, audits, and lack of major hacks, though those are not guarantees of future safety. On legal/regulatory/sanctions, I found no specific enforcement action, lawsuit, or sanctions designation tied to NAVI in the provided results. Hindenrank says regulatory exposure is present at a typical DeFi level, but not that any authority has taken action. Unresolved concerns are the usual DeFi ones: leveraged products, liquidation cascades, dependence on Sui liquidity, and the gap between marketing claims and independently verified risk data. Not verifiable as of 2026-08-29: founder identity/background, exact beneficial ownership structure, and whether any of the protocol’s self-reported user/TVL claims are fully accurate from primary-chain data in this run.

Evidence (8)

Economy

TVL: $125.6M

model

two sources

NAVI Lending is a money market on Sui: users supply assets to earn yield and borrow against collateral. Not verifiable on-chain as of 2026-08-29. Strategy & assets in/out

  • Core activity: overcollateralized lending/borrowing on Sui, similar to Aave/Compound.
  • Supported assets (from docs/app): SUI and major Sui ecosystem tokens; exact list: Not verifiable as of 2026-08-29.
  • Users deposit assets into pools (earning supply APY) and can borrow other assets subject to collateral factors. Yield source: organic vs subsidized
  • Base yield: interest paid by borrowers to suppliers, set by utilization-based interest rate curves (higher utilization ⇒ higher borrow APY).
  • Additional incentives: NAVI has used token incentives / points campaigns (e.g., airdrop-related activity on Sui) – these are subsidized yield, not organic.
  • Overall yield is mixed: organic (interest spread) + subsidized (rewards). Risk profile: market-neutral vs directional; leverage/looping
  • Supplying only and not borrowing is directional exposure to token price (e.g., SUI).
  • Users can loop (supply, borrow same asset, resupply) to lever up yield; this increases liquidation risk and is not market‑neutral.
  • No native restaking or external exposure products identified; Not verifiable as of 2026-08-29. Lock-ups & withdrawal mechanics
  • Standard money‑market design: no fixed lock‑up, withdrawals allowed as long as pool liquidity is available and user health factor remains above liquidation threshold.
  • Large withdrawals may be constrained by utilization (if most assets are borrowed). Fees, protocol revenue, gates/limits
  • Typical model (per docs/analytics): a portion of borrow interest spread is allocated to protocol reserves/treasury; Not verifiable precisely as of 2026-08-29.
  • Possible liquidation bonuses/fees to liquidators; protocol may take a cut.
  • Risk parameters (LTVs, caps) are set per asset; current numbers: Not verifiable as of 2026-08-29. Collateral model
  • Assets are designated collateral or non‑collateral with individual LTV / liquidation thresholds; similar to Aave-style. TVL & APY (level, composition, trend)
  • DeFiLlama shows NAVI Lending as a Sui‑only lending protocol with TVL in the low-to-mid hundreds of millions USD at peak, declining with Sui market conditions; exact current TVL and by‑asset breakdown: Not verifiable as of 2026-08-29.
  • APYs are variable, utilization- and incentive-driven, historically spiking during campaigns and dropping post‑incentives, implying high volatility and limited sustainability of top-line yields. Contradiction box
  • On-chain Dune verification: Not verifiable as of 2026-08-29.
  • Any TVL/APY numbers from NAVI’s own site or marketing are unverified marketing claims unless cross-checked with independent analytics like DeFiLlama.
Evidence (4)

reserves

two sources

Not verifiable as of 2026-08-29: the available sources do not provide a verifiable NAVI Lending treasury/reserve statement with addresses, custody model, composition, or on-chain balances. The protocol docs confirm that NAVI uses asset-specific liquidity pools and receipt tokens, and that users supply assets directly to pools, but they do not identify a separate treasury wallet or reserve fund for the lending protocol. The parameter docs list supported assets and risk settings, which helps characterize reserve composition at the market level, but they do not evidence treasury custody or reserve control. Public third-party coverage only gives high-level TVL figures for the protocol or Sui lending portfolio and does not break out reserves, treasury ownership, or attestations in an auditable way. No on-chain Dune balance verification is possible in this run because Dune MCP is unavailable, so on-chain balances remain unverified.

Evidence (5)

tokenomics

two sources

NAVI Lending on Sui does have a native token: NAVX. 1) Basic token info

  • Name / ticker: Navi Token / NAVX.
  • Chain: Sui.
  • Type: Sui native coin; no EVM-style contract address. Public object ID shown in explorers is 0x99b2bc…3e29 (cannot be treated as an ERC‑20 address).
  • Main listings: Centralized: Bybit, KuCoin, Gate, OKX, Bitget. DEX: Cetus (Sui), Kriya. 2) Supply, market cap, FDV
  • Multiple aggregators (CoinGecko, CoinMarketCap) give conflicting circulating supply and market cap figures as of 2026‑08‑29.
  • Total / max supply and FDV are likewise inconsistent between platforms.
  • On-chain verification: Not verifiable as of 2026‑08‑29. 3) Token utility & governance According to Navi’s docs and third‑party summaries:
  • Protocol token for Navi Lending: used for governance voting, protocol parameter changes, and possibly future DAO operations.
  • Incentive token: distributed as liquidity mining rewards for lending/borrowing on Navi.
  • Some portion allocated to ecosystem incentives and community programs. All of the above are unverified marketing claims unless corroborated by independent sources. 4) Emissions & unlocks / allocations
  • Public tokenomics charts show a standard split across community incentives, team, investors, treasury, liquidity with a multi‑year vesting schedule; exact percentages differ across sites.
  • No independent, chain‑level vesting or unlock tracker exists for NAVX on Sui.
  • Whether announced unlocks actually occurred on‑chain is Not verifiable as of 2026‑08‑29. 5) Control features (mint / admin / blacklist / fee‑switch)
  • Documentation and explorers do not clearly expose mint authority, pause/blacklist functions, or admin control for NAVX on Sui.
  • Not verifiable as of 2026‑08‑29 who can mint, freeze, or otherwise administratively intervene in NAVX. 6) Holder concentration & insider risk
  • No reliable public holder‑distribution analytics for NAVX on Sui.
  • Top‑holder concentration, insider wallets, and treasury holdings: Not verifiable as of 2026‑08‑29. 7) DEX liquidity depth
  • Main on‑chain liquidity appears on Cetus and Kriya pools paired with SUI and stablecoins.
  • Independent volume / depth data across these pools is inconsistent and cannot be reliably quantified from public dashboards; Not verifiable as of 2026‑08‑29.
Evidence (9)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For NAVI Lending on Sui, a BTC drop below $10,000 would be a severe collateral shock for any positions using BTC or wrapped BTC as collateral, because liquidations are triggered when borrower health falls below the protocol’s liquidation thresholds. NAVI’s docs state that assets can be collateral/borrowable and that liquidation thresholds are enforced through its lending markets, but the exact threshold for BTC collateral is not verifiable as of 2026-08-29 from the provided sources. What can be said with confidence is that NAVI supports Bitcoin-related lending activity on Sui and uses standard overcollateralized lending mechanics, so a move to sub-$10k BTC would almost certainly push many BTC-backed accounts into undercollateralization, increasing liquidation volume and bad-debt risk if market liquidity is thin. The protocol-level impact would likely be:

  • Higher liquidation frequency as health factors deteriorate faster.
  • Potential slippage during liquidations if BTC market depth is weak.
  • Strain on reserve liquidity if borrowers rush to repay or withdraw collateral, especially in correlated risk-off conditions.
  • Knock-on effects on any BTC-adjacent pools or isolated markets exposed to BTC price correlation. A key limitation is that the provided sources do not give NAVI’s live BTC collateral share, current utilization, or liquidation buffers, so the size of losses under this scenario is not verifiable as of 2026-08-29. The only directly supported conclusion is that a BTC move below $10,000 would be an extreme stress event for NAVI’s BTC-backed lending book and would likely trigger broad liquidations.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-08-29. The provided sources do not identify NAVI Lending’s largest collateral asset on Sui, nor do they provide protocol-specific collateral weights, liquidation thresholds, or a live exposure map needed to model a 20% depeg stress. NAVI’s docs do state that liquidation occurs when a borrower’s health factor falls below 1, and that a position’s liquidation threshold is a value-weighted average across supplied collateral assets, so a 20% depeg would reduce health factors for accounts using that collateral and could trigger liquidations if positions were near threshold. The remaining search results are not sufficient for a protocol-specific answer: Hindenburg-style risk pages are third-party opinions and do not provide auditable on-chain exposure data, while general stress-test articles from the Federal Reserve, Brookings, and other non-crypto sources are not directly applicable to NAVI Lending’s Sui markets. To answer quantitatively, the missing inputs are: the largest collateral type on Sui, its share of supplied collateral, current liquidation thresholds, and the distribution of borrower health factors. Without those, the impact of a 20% depeg cannot be calculated reliably.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

For NAVI Lending on Sui, the documented stress path for a top counterparty insolvency is borrower undercollateralization rather than a lender-run insolvency waterfall: when a position’s Health Factor falls below 1, anyone can call execute_liquidation on the LendingPool contract, which repays part of the debt and transfers discounted collateral to the liquidator. The documented close factor is 35%, so the immediate loss path is limited to liquidating up to 35% of the debt per valid liquidation call, with the remaining position still subject to further liquidations if health stays below 1. Expected loss path: the insolvent borrower’s collateral is sold at a discount; if collateral value is insufficient or keeps falling, the protocol can be left with residual bad debt on that position. NAVI’s docs do not specify a lender socialization waterfall or an explicit insurance fund payout in the materials reviewed, so compensation for any unrecovered loss is Not verifiable as of 2026-08-29. Who absorbs it: first, the borrower loses collateral through liquidation; second, the liquidator receives the discount incentive and repaid debt; any shortfall after liquidation would be borne by the protocol’s risk framework, but the exact backstop mechanism is Not verifiable as of 2026-08-29. Impact path through smart contracts: an undercollateralized account is detected via the protocol’s Health Factor check, then execute_liquidation is invoked on LendingPool, repaying debt and moving collateral to the liquidator; the borrower’s Health Factor should rise above 1 after successful liquidation. The docs also describe a liquidation threshold and a liquidation incentive/bonus, but do not provide a separate insolvency-resolution contract path beyond liquidation execution.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For NAVI Lending on Sui, there is no verifiable evidence in the provided sources that the DAO or owners committed fraud. The only directly relevant material is a community post alleging the NAVI founder spread FUD against a competitor, but it is an unverified accusation and not proof of fraud by the protocol’s DAO or owners. The other results do not establish DAO-owner fraud for NAVI Lending. One result is a general discussion of DAO fraud risks, not an allegation about NAVI. Several results instead describe external fraud against Navi Technologies or generic loan-fraud/impersonation scams, which are not evidence of protocol-level fraud by NAVI Lending’s governance or owners. Given the evidence available here, the appropriate stress-scenario assessment is: Not verifiable as of 2026-08-29. If you want, I can next assess adjacent risks that are more supportable from the available material, such as governance concentration, admin-key risk, or market-manipulation exposure on Sui.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For NAVI Lending on Sui, I could not verify a protocol-specific 30-day negative primary-yield stress result from the provided web sources. The available results are generic NAV-lending or macro stress-test materials, not evidence about this protocol’s on-chain yield composition or 30-day performance, so the correct status is: Not verifiable as of 2026-08-29. If you want a usable risk read despite the verification gap, the relevant stress interpretation is that a NAV-lending or yield protocol with a negative 30-day primary yield source would typically be under pressure if the yield leg depends on market carry, incentives, or asset performance; but that inference is generic and not protocol-verified here. The only protocol-adjacent source in the set is a credit-rating document for Navi Limited, which is not sufficient to establish the DeFi protocol’s yield mechanics or stress resilience.

Evidence (5)

Governance & Legal

governance

two sources

NAVI Lending on Sui is governed via the NAVX token and a governance-layer that is still heavily team-controlled, with upgrades guarded by multisig and timelocks, and a US-based corporate entity behind the frontend and terms. Controlling entities & legal wrapper

  • The Terms of Service define the counterparty as Navi Protocol Labs, Inc., which is the legal entity responsible for the website/frontends and user-facing “services”.
  • The ToS explicitly state that on-chain lending, staking, bridging, and swapping are “services made available via the Protocol”, distancing the company legally from the smart contracts while still signaling operational control over the interfaces.
  • Jurisdiction, registration number, and board/directors are not disclosed in the ToS page available online. Not verifiable as of 2026-08-29. Smart contract & upgrade control
  • The institutional/“Prime” page highlights multisig governance and timelocked upgrades, plus “continuous monitoring”, aimed at institutional comfort.
  • Exact multisig details (chain addresses, signers’ identities, threshold, relationship to team/investors, and which contracts they can upgrade) are not publicly broken out in independent sources. Not verifiable as of 2026-08-29.
  • No independent confirmation of an additional emergency pause/guardian role beyond what the team has informally exercised during past incidents (e.g., pausing borrowing). Governance token & DAO structure
  • NAVX is the governance token for the protocol.
  • NAVX holders can vote on interest rate parameters, supported assets, collateralization ratios, liquidation parameters, and other protocol updates.
  • Governance weight can be boosted through dLP (locked LP) tokens: users provide liquidity into NAVX/SUI or NAVX/vSUI pools, receive LP tokens, and lock them as dLP to gain:
  • higher NAVX emissions,
  • a share of borrowing fees,
  • increased voting power relative to plain NAVX balances.
  • This structure effectively ties governance power to liquidity provision and long-term lockups (dLP), giving large LPs disproportionate influence. DAO reality vs. symbolism
  • Docs and third‑party descriptions consistently frame NAVX governance as a DAO-style process where token holders decide on protocol changes.
  • However, no independent data on:
  • on-chain proposal contracts on Sui,
  • quorum/threshold rules,
  • historical proposal count, participation, or
  • top NAVX holders/voting concentration. This is Not verifiable as of 2026-08-29 without on-chain analytics.
  • Given the presence of a centralized US corporate entity, multisig-controlled upgrades, and lack of transparent voting data, governance should be treated as partially decentralized with material team/multisig override power, rather than fully autonomous DAO control. Timelock & powers
  • The Prime page claims “timelocked upgrades”, implying a delay between governance/multisig decision and contract change; duration and exact scope (which contracts, exceptions for emergencies) are not disclosed in independent documentation. Frontend & funds control
  • Frontend domains and institutional marketing are run by Navi Protocol Labs, Inc., implying they can geofence or restrict access via ToS enforcement.
  • Actual custody of user funds remains smart-contract based; however, without on-chain verification of admin roles, the extent of upgrade, reconfiguration, or pause powers over user positions is Not verifiable as of 2026-08-29.
Evidence (9)

legal & regulatory

two sources

NAVI Lending appears to be a Sui-based DeFi protocol, but its own website/docs should be treated as *unverified marketing claims* unless independently corroborated. On the regulatory side, I could not verify a dedicated legal entity, jurisdiction, licensing status, KYC/AML policy, sanctions-screening regime, or formal data-protection disclosure for the protocol itself, so those items are Not verifiable as of 2026-08-29. The strongest independently sourced legal fact in the gathered material is that Sui’s own Terms of Service are governed by Cayman Islands law, but that governs the Sui platform terms, not necessarily NAVI Lending itself. What can be said with confidence is limited. Independent coverage describes NAVI as a DeFi lending protocol on Sui and, in recent reporting, a framework aimed at institutional lending on Sui, but those sources do not establish a regulated legal wrapper, KYC/AML obligations, or a formal entity behind the protocol. No court cases, sanctions actions, or regulator warnings specific to NAVI Lending were identified in the gathered material; those are Not verifiable as of 2026-08-29. From a risk perspective, the legal structure likely differs from the actual exposure profile: even if the frontend, team, or related companies sit in a normal corporate/jurisdictional structure, users still face on-chain smart-contract, governance, oracle, and liquidity risks that are not resolved by corporate paperwork. Because the protocol-level disclosures were not independently verified, any claim about consumer protections, KYC/AML controls, or liability allocation should be treated as unsupported until confirmed in a primary legal document or regulator filing. Callout: contradiction / gap - The gathered web material contains general Sui platform terms and unrelated or low-confidence third-party commentary, but no protocol-specific legal filing. The gap between a DeFi protocol’s implied operating status and a documented legal entity/jurisdiction is the key finding here.

Evidence (3)

Stability

stability

two sources

NAVI Lending on Sui is not verifiable as of 2026-08-29 for the specific question “did the stablecoin used ever depeg, how many times, when was the last time, and by how much?” because the provided web results do not identify which stablecoin NAVI Lending used, and they do not provide protocol-specific, chain-specific price history for that asset. The search results only show general stablecoin depeg history for tokens such as USDC, USDT, DAI, and FDUSD, including major events like USDC’s March 2023 depeg to about $0.87 (roughly 13% below peg), but they do not confirm that NAVI Lending used any of those assets or that any of those depegs affected NAVI’s collateral or liabilities. If you want, I can next identify NAVI’s stablecoin assets from public materials and then check whether any of them had known depeg events.

Evidence (3)

Risks & Strengths

risks

two sources

Top 5 risks for NAVI Lending on Sui, based on the available sources, are: 1. Smart contract / code risk — OtterSec’s core audit found issues including missing checks, incorrect calculations, flawed validations, and outdated collateral-state checks in liquidation logic, any of which could lead to fund loss or incorrect liquidations. 2. Liquidation and bad-debt risk from leverage — NAVI’s leveraged vaults and borrowing markets can amplify losses during sharp SUI or collateral price moves, increasing liquidation cascades and bad-debt risk. 3. Collateral concentration / depeg risk — NAVI uses assets such as liquid staking tokens and stablecoins as collateral; if a major collateral asset depegs or weakens, correlated liquidations can hit multiple positions at once. 4. Sui ecosystem concentration risk — NAVI is tightly tied to the Sui chain, so chain outages, limited DeFi market depth, or weaker ecosystem growth would directly affect user activity and liquidation quality. 5. Governance / centralization / admin-key risk — Early-stage DeFi protocols often retain upgrade or emergency controls, and third-party analysis flags governance-capture or compromised-admin-key scenarios as a material risk for NAVI. A key contradiction to note: NAVI’s own site emphasizes that audits were completed by multiple firms, but the audit itself still documented several medium-to-high severity issues before remediation, so “audited” should not be read as “risk-free.”

Evidence (6)

strengths

two sources

NAVI Lending’s top strengths are its position as a core liquidity protocol on Sui, its non-custodial lending/borrowing model, its risk segmentation via isolated pools and configurable limits, its multi-oracle / price-feed and risk-control design, and its tight integration with Sui’s Move-based, parallel-execution environment. These strengths are the most consistently supported by the available sources, while more specific claims like exact TVL, user counts, or audit coverage are not independently verifiable from the provided results.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 4 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-29.