Capital Layer
← all notes

2026-09-23 · Lending & DeFi protocols

Kamino Lend — how far can Solana's largest lending protocol be trusted?

Data as of 23 Sep 2026.

Verdict: usable, with limits. Kamino Lend's code hasn't been exploited in three years, and it came through the worst day of the cycle — 10 October 2025 — with no bad debt. But a depositor here is lending into a shared pool, not holding custody. Exits come only out of whatever is sitting idle in that pool. Code and market parameters can be changed by multisigs whose signers aren't disclosed, with 12 to 24 hours between decision and execution.

What it is

Kamino Lend is the largest lending protocol on Solana. Depositors supply into a market reserve, borrowers draw from the same reserve against collateral, and borrower interest flows to depositors. As of 23 Sep 2026 it holds $1.40bn TVL on DefiLlama's methodology (deposits net of borrows), down 59% from a $3.37bn peak on 7 Oct 2025. Two independent counters agree: risk provider Allez Labs reports August 2026 supply of $2.48bn and borrows of $0.98bn (net $1.50bn); DefiLlama shows $1.40bn on 1 Sep 2026.

0 $1bn $2bn $3bn 01.24 01.25 01.26 09.26 peak $3.37bn · 7 Oct 2025 $1.40bn · 23 Sep 2026

Kamino Lend TVL. Source: api.llama.fi/protocol/kamino-lend, read 23 Sep 2026. The 16→21 Apr 2026 dip is the window after the KelpDAO exploit, when around $280m was pulled from Kamino (CVJ, 21 Apr 2026).

Findings

1. A depositor's exit is capped by idle reserve liquidity, not by deposit size

A depositor can withdraw only what is sitting idle in the reserve at that moment. Protocol-wide the picture looks comfortable: Allez Labs' August 2026 figures — $2.48bn supplied, $0.98bn borrowed — put aggregate utilisation near 40%, with about $1.5bn idle. But exits happen per reserve, not across the protocol, and utilisation differs widely between reserves: stablecoin reserves and SOL-family reserves are borrowed for different reasons and at different times.

The arithmetic is simple. At 90% utilisation only 10% of a reserve's supply can leave right now; at 98%, 2%. A reserve that looks liquid on a monthly average can sit near full utilisation for days, and the deposit size makes no difference to the exit — only the reserve's idle balance at that moment does. Utilisation per reserve is public (Kamino API, DefiLlama), and it's the number to read, not protocol TVL.

There's one safety valve: rate curves kink up steeply near full utilisation, into triple-digit APR for some reserves. High rates are supposed to push borrowers out and pull deposits in — a price mechanism, not a guarantee.

The code also has a per-reserve, per-interval withdrawal cap (deposit_withdrawal_cap and debt_withdrawal_cap in the reserve config, Kamino SDK). Live values weren't checked. It's an anti-exploit circuit breaker, but for a depositor it's one more ceiling on exit speed.

2. A depositor with no debt still eats other people's bad debt — via one irreversible call

Per Kamino's docs (22 Sep 2026), the curator or emergency council can call socialize-loss to spread a loss across the affected reserve's depositors, and the docs themselves flag it as irreversible. The conditions — all standard liquidation paths exhausted, plus a recovery plan — are guidance to the curator, not a code-level constraint.

So far the track record is on the protocol's side. On 10 Oct 2025 SOL dropped 14% in under an hour, from $207 to $177. Kamino liquidated $20m of collateral across 8,000+ liquidations on ~1,700 wallets with zero bad debt (Allez Labs, Kamino forum, 11 Oct 2025). An independent write-up on dev.to (K. Brandwijk) cites the same figure from the same report, so it isn't a second source. Allez Labs is Kamino's paid risk provider, not a third-party auditor. The protocol claims more than $20bn in loans originated with zero bad debt (press release, GlobeNewswire, 15 Sep 2026). No independent registry of socialize-loss calls was found.

Allez's August 2026 stress test gives an upper bound: a 30% market drawdown produces $18.2m of potential bad debt protocol-wide — 0.73% of $2.48bn supply. No per-reserve breakdown is provided.

3. Who can change the code and the rules: two multisigs, 12h and 24h

Read on-chain, not from docs. The kLend program's upgrade authority is a Squads v4 vault, 5-of-10, with a 24h timelock (re-verified 23 Sep, slot 449,750,267). The third-party monitor simonvellin/solana-upgrade-watch shows the same address and a last deploy on 20 Aug 2026.

The main-market owner — who sets reserve parameters, oracles and caps, and holds the right to call socialize-loss — is a vault of a different Squads v4 multisig: 4-of-10, 12h timelock, 303 executed transactions (slot 449,749,814). There's no second source for this; it's a direct on-chain read. Who the ten signers are on either multisig is disclosed neither in the docs nor on-chain. Whether a separate emergency council is configured, and at what threshold, wasn't checked.

For context: in 2021, a Compound upgrade bug stayed live for seven days because the fix needed a DAO vote, and ~$68m leaked out in the meantime. At Kamino, neither lever — pause or loss socialisation — needs a vote. Fast for defence, and equally fast for a mistake.

4. Dense audit and bounty coverage — but formal verification skips liquidations

Kamino lists 20 external reviews: 15 audits, 4 formal verifications and fuzzing (kamino.com/docs/security/audits, 22 Sep 2026). Dated kLend reports:

DateWhoWhat
3 Jul 2023RX SecuritykLend audit
6 Sep 2023OtterSeckLend audit
6 Feb 2025Sec3kLend audit — latest dated
Oct 2025OtterSecformal verification of deposit, withdraw, borrow and repay; liquidation not included (per dev.to analysis)
Oct 2025 onwardImmunefibounty up to $1.5m for critical bugs; three years of in-house bounty before that (Yahoo Finance, Phemex, Oct 2025)

The Kamino-Finance/audits repo holds Certora, OtterSec and Offside reports covering kLend up to v1.17.0, undated. Which version was deployed on 20 Aug 2026, and whether it's audited, wasn't verified.

kLend exploits in three years: zero across every source found. DefiLlama has no event flags, CertiK's August roundup doesn't mention Kamino, and searching "Kamino exploit" only surfaces other protocols (e.g. the Kame aggregator hack in September 2025).

5. Oracle: flash-move protection sits on borrowing, not on liquidation

Prices come from Kamino's own aggregator, Scope. SOL is covered by Chainlink and Pyth Pro, with staleness checks, TWAP/EWMA smoothing and outlier-feed rejection (docs, 22 Sep 2026). Scope audits: Offside 8 Dec 2023, OtterSec 16 Dec 2023, Sec3 16 Dec 2024.

The dev.to analysis shows where that protection ends. The TWAP-divergence tolerance for SOL is 10%. On 10 Oct 2025 the 14% drop blew through it: new borrows were blocked, while liquidations ran on spot. The author estimates ~$1.08m of premature liquidations. Kamino's response: by design, TWAP protects the platform from bad debt, not users from early liquidation. For a debt-free depositor that's a plus — fast liquidations mean less bad debt. For a borrower it's a minus: the liquidation buffer has to survive an unsmoothed one-hour wick.

What breaks it, and at what number

EventWhat happens to a depositorHow to check
Cream/Euler-style exploit: uncollateralised borrowOnly idle reserve liquidity is withdrawable: at 90% utilisation, about 10% of supply. The rest is frozen until loans are repaid; the reserve's loss is socialised across depositorsDefiLlama incident feed, Kamino forum
Bad debt after a price spike or LST depegLoss pro rata to the depositor's share of the reserve. Protocol-wide upper bound: $18.2m at −30% (Allez, Aug 2026)Allez monthly bad-debt reports
Reserve at 100% utilisation exactly when a depositor needs outNo capital loss, but time: exit waits until the top of the rate curve brings borrowers backdaily idle reserve liquidity on DefiLlama
Malicious code or market-rule changeTail up to 100%. Reaction window: 12h for market rules, 24h for code. A depositor who isn't watching for a week won't use iton-chain read of both multisigs

The call

By 22 Dec 2026, Allez Labs' monthly Kamino Lend reports for September, October and November 2026 will show no non-zero realised bad debt, and there will be no socialize-loss call on the main market. This tests the claim that "zero bad debt in three years" is a property of the liquidation engine, not luck. A miss on either condition pulls the "usable with limits" verdict pending a root-cause review.

Unknowns

Obtainable:

  • Live per-interval withdrawal caps for specific reserves — readable from the reserve struct via the SDK. A low cap is an exit-speed ceiling worth knowing before entry.
  • Whether an emergency council is configured on the main market, and at what threshold. That decides whether an irreversible loss socialisation can happen with fewer than 4 signatures.
  • Which kLend version went live on 20 Aug 2026 and whether it's audited. That decides whether the last audit date, 6 Feb 2025, still describes the live code.
  • The size of Kamino's treasury as a loss backstop — not found in public sources.

Unknowable from outside:

  • Who the signers are on both multisigs and how keys are split.
  • Who the borrowers are in each reserve: how much of the borrowing is shorts against stables versus LST loops. That determines which price move creates bad debt.

Limits, and what pulls the verdict

Exit limit — a sizing method. Cap a deposit in any one reserve at a small fraction (for example 10%) of that reserve's 90-day minimum idle liquidity. Then even on the worst day of the window, the exit is one transaction, not a queue. Idle liquidity differs widely between reserves and moves over time, so the minimum has to be read for each reserve separately and refreshed. The 10% threshold is this analysis's own rule of thumb.

Concentration limit. A common ceiling is no more than 5% of a portfolio in any single protocol; each holder can set their own.

Borrower limit. Liquidations run on unsmoothed spot, so the buffer should survive a 15% one-hour drop — which already happened on 10 Oct 2025.

Pulls the verdict immediately (to "don't use"):

  • any kLend exploit or incident touching depositor funds;
  • any socialize-loss call on any Kamino market;
  • non-zero realised bad debt in an Allez report;
  • upgrade authority moving from the multisig to a single key, threshold below 5-of-10, or timelock under 24h;
  • for the main-market owner — threshold below 4-of-10 or timelock under 12h;
  • a new kLend deploy without a published audit.

Tightens the limit without changing the verdict: a reserve's idle liquidity setting a new 90-day low — the exit limit for that reserve is recomputed from the new minimum. TVL below $700m (half today's level) — time for a fresh review.

Next checkpoint: 22 Dec 2026 — the call resolves and both multisigs get re-read.

Sources: kamino.com/docs — liquidations, security/audits, oracle-pricing (22 Sep 2026) · gov.kamino.finance — "Kamino Lend, Risk Event Analysis: 10th of October 2025" (Allez Labs, 11 Oct 2025), Allez August 2026 report (5 Sep 2026) · dev.to/kbrandwijk · GlobeNewswire 15 Sep 2026 · Yahoo Finance and Phemex on the Immunefi bounty (Oct 2025) · github Kamino-Finance/audits, simonvellin/solana-upgrade-watch · CVJ 21 Apr 2026 · DefiLlama.

Research for information only. Not investment advice.