Aave Moves to Pull the Plug on Its Aptos Bug Bounty

Aave is considering ending the public bug bounty for its Aptos deployment. The request is separate from, but connected to, plans for the lending market.
Key Takeaways
- Aave is reviewing the ongoing security setup around its Aptos deployment.
- The Aptos version of Aave V3 uses Move and carries a separate technical scope.
- A different governance proposal covers lending activity and possible limits on new use.
- July’s market snapshot showed sharply lower liquidity and minimal revenue.
- Both measures require governance approval before they affect the protocol.
Aave’s latest ARFC asks the DAO to sunset the bug-bounty program for Aave V3 on Aptos and end Cantina’s role as its provider.
A bug bounty pays independent researchers for valid vulnerability reports. The program provides an ongoing route for security findings after a product goes live.
The request arrives while Aave is separately debating the future of its Aptos lending market. Those discussions cover the market itself and the services that support it.
Two governance requests cover different parts of Aptos
The Aptos discussion involves two Aave proposals.
- The market proposal: A July ARFC on low-adoption markets recommends limiting new use of Aave V3 on Aptos while current positions are reduced over time.
- The bounty proposal: The newer ARFC asks whether Aave should continue funding an Aptos-only bug bounty through Cantina.
The market proposal deals with deposits, borrowing and available liquidity. The bounty proposal covers rewards for researchers who report security issues.
Both requests are awaiting governance approval. The protocol configuration remains unchanged unless a later governance action implements either measure.
Why Aptos had a dedicated bounty
Aave launched on Aptos with a separate version of V3. Aptos uses Move, while Ethereum smart contracts commonly use Solidity.
According to Aave’s launch announcement, the Move-based deployment went through audits, a Cantina mainnet security competition and a bounty offering up to 500,000 GHO, Aave’s stablecoin.
Each measure serves a different purpose:
- Audits examine code before or around a launch.
- Security competitions give researchers a set period to test a project.
- Bug bounties reward valid reports while the program remains open.
Cantina’s published Aptos scope covered Move modules, frontend components, APIs and deployment configuration. The program covered the full Aptos product setup.
Aave outlined this arrangement in its 2026 bounty-program restructuring proposal, which assigned Aave V3 on Aptos to Cantina while other Aave products used different providers.
Aptos market activity had already fallen
The July market proposal described a sharp decline in Aptos activity.
At the time of publication, it estimated about $1.7 million in supplied assets and roughly $719,000 in debt. Available liquidity had fallen from around $18 million to $1 million over the previous six months, while quarterly revenue was below $1,000.
These figures reflect the market conditions reported in July. The proposal recommended freezing Aptos reserves and setting supply and borrow caps to one. Approval would block meaningful new deposits and borrowing while existing suppliers and borrowers reduce their positions.
The document leaves the bounty program’s costs undisclosed, preventing a direct calculation between that expense and the market’s decline. The lower level of activity still provides the backdrop for Aave’s review of a dedicated Aptos security program.
What the proposals mean for users and researchers
For Aave users
The bounty proposal affects the reward program for outside researchers. Lending parameters, withdrawal access and borrowing conditions remain tied to the live protocol configuration and any separately approved market changes.
Users with an Aptos position should follow the market proposal and later governance decisions. Those measures would determine the timetable and limits for activity on Aave V3.
For security researchers
Eligibility follows the active terms published by Aave and Cantina. The ARFC asks to sunset the program, while the published scope and any approved closure terms determine which reports qualify for a reward.
Closing the bounty would close this public reporting and reward route for Aave V3 on Aptos.
The two Aptos plans now move together
Aave Labs recorded the release of Aave V3 on Aptos in its June 2025 development update. The launch introduced Aave’s first deployment outside Ethereum-compatible networks and required its own codebase and security setup.
Approval of both proposals would narrow Aave’s Aptos operations. The market would admit less new lending activity, and the dedicated public bounty through Cantina would close.
The decisions concern Aave’s own Aptos deployment, its activity levels and the operating work required to maintain it.









