PROPELOO

DEFI / LENDING & BORROWING PROTOCOL

Build peer-to-pool lending markets that protect liquidity under extreme volatility.

PROPELOO engineers production-grade decentralized lending protocols — collateralized debt positions (CDPs), algorithmic dynamic interest rate curves, multi-oracle health feeds, flash loan liquidity vaults, and automated keeper liquidation bots. A lending protocol is an automated solvency engine where risk parameters dictate survival.

A lending protocol is not an ERC-20 contract with a borrow button. It is an algorithmic risk and solvency machine.

Under normal market conditions, almost any lending contract functions. But when asset prices drop 40% in two blocks, protocols fail because of three specific engineering oversights: oracle latency allowing underwater positions to become unliquidatable bad debt, flash loan griefing draining reserve pools, and rigid interest rate models causing liquidity crunches where depositors cannot withdraw. PROPELOO builds institutional lending architecture: isolated lending markets that prevent single-collateral contagion, dual-oracle pricing with fallback circuit breakers, dynamic Dutch auction liquidations, and invariant property testing that formally verifies protocol solvency under extreme liquidation pressure.

The architectural layers of a production DeFi lending protocol.

From interest rate models to automated keeper liquidation engines, every layer is built for mathematical solvency.

System Layers

  • Core Pool & Accounting Layer: Interest-bearing receipt tokens (aTokens/cTokens), debt tracking via normalized indices, reserve pools and collateral balance segregation.
  • Interest Rate & Utilization Engine: Kinked-curve dynamic interest rate models adjusting borrow APY automatically based on pool utilization to incentivize liquidity rebalancing.
  • Oracle & Price Aggregation Layer: Dual Chainlink and Pyth oracle aggregation, time-weighted average price (TWAP) sanity checks, and stale price circuit breakers.
  • Liquidation & Keeper Engine: Dutch auction and fixed-discount liquidation mechanics, flash liquidation callbacks, and automated keeper bot infrastructure.
  • Flash Loan & Liquidity Vaults: Atomic uncollateralized flash loans with premium fee accrual to protocol reserves and reentrancy-guarded execution hooks.

How we engineer decentralized lending protocols.

Protocol solvency is an immutable law. Every line of code must defend collateral adequacy.

  • Bad debt must be isolated, never socialized across markets

    Shared pool designs mean a single volatile or illiquid collateral asset can drain the entire protocol reserves. We build isolated lending pairs and segregated debt pools so high-risk or long-tail assets can never threaten core stablecoin liquidity.

    Axiom: ISOLATED RISK ARCHITECTURE

  • Oracles require redundant verification and staleness guards

    Single-source oracles are the primary attack vector in DeFi lending. We implement dual-oracle aggregation with deviation bounds, heartbeat checks, and circuit breakers that pause liquidations if price feeds disagree.

    Axiom: DEFENSE-IN-DEPTH ORACLES

  • Liquidation speed must exceed market price decline velocity

    If liquidators cannot profitably liquidate an unhealthy loan before collateral value drops below borrowed debt, the protocol absorbs permanent insolvency. We design Dutch auction liquidations and low-gas keeper execution contracts.

    Axiom: RAPID SOLVENCY PRESERVATION

Architectural decisions in DeFi lending engineering.

These choices define protocol solvency, capital efficiency and vulnerability profile.

  • Shared pool-to-peer (Aave v3) vs isolated lending pairs (Morpho/Euler)?

    Impact: Hybrid modular architecture. Core liquid assets (ETH, WBTC, USDC) share a high-efficiency pool, while governance tokens, yield-bearing assets, and RWAs reside in isolated markets with strict risk ceilings.

    • Shared pool — maximum capital efficiency and liquidity depth, shared systemic risk across all accepted collateral
    • Isolated pairs — zero contagion between assets, lower capital efficiency for cross-margin traders
    • Hybrid modular pools — core tier-1 assets in shared pool, long-tail and RWA assets in isolated markets
  • Interest rate curve model: two-slope kinked curve vs PID controller?

    Impact: Two-slope piecewise linear kinked model with governance-configurable kink point (80-85%). Provides transparent predictability for borrowers while providing exponential rate surges to protect withdrawer liquidity during crunches.

    • Two-slope kinked curve — predictable utilization target (e.g. 80%), steep slope beyond kink to penalize full pool exhaustion
    • PID automated rate controller — adapts rates dynamically to market benchmark rates, complex on-chain tuning
  • Liquidation mechanism: fixed bonus vs Dutch auction?

    Impact: Dynamic Dutch auction liquidation with floor cap. Ensures liquidators are incentivized without needlessly stripping borrower equity during temporary liquidity dislocations.

    • Fixed discount bonus (5-10%) — simple to execute, susceptible to MEV gas wars and over-penalization in volatile dumps
    • Dutch auction liquidation — discount starts low and increases over time, captures optimal price for borrower and protocol
  • Oracle architecture: primary oracle with TWAP fallback vs multi-source medianizer?

    Impact: Dual-feed medianizer (Chainlink + Pyth) with 1.5% maximum allowable price deviation threshold and automatic fallback pause if either feed reports stale data.

    • Chainlink primary with Uniswap V3 TWAP secondary fallback — robust for high-cap assets
    • Chainlink + Pyth medianizer with deviation circuit breaker — sub-second updates for multi-chain and L2 deployments

DeFi lending architectures PROPELOO builds.

  • Institutional Overcollateralized Lending

    Enterprise lending markets for compliant institutional participants with whitelisted collateral assets, KYC integration, and automated reporting.

  • RWA & Private Credit Markets

    Lending protocols accepting tokenized real-world assets, private credit notes, and trade finance receivables as loan collateral.

  • Liquid Staking & Restaking Lending

    Leveraged looping protocols supporting LSTs (stETH) and LRTs with automated debt rebalancing and yield-maximization strategies.

  • Flash Loan Protocol Vaults

    Dedicated uncollateralized flash loan reserve contracts earning fee revenue for liquidity providers from arbitrageurs and liquidators.

  • Permissionless Lending Factory

    Factory contract deployment enabling users to spin up isolated lending markets for any arbitrary ERC-20 token pair with custom oracles.

The DeFi lending engineering stack.

Battle-tested Solidity smart contracts and high-frequency keeper infrastructure.

  • Smart Contracts

    Stack: Solidity 0.8.24, Foundry, OpenZeppelin v5, Hardhat, Huff (gas-optimized math)

  • Oracles

    Stack: Chainlink Price Feeds, Pyth Network, Uniswap V3 TWAP, Chronicle Oracles, Chainlink PoR

  • Security & Verification

    Stack: Slither, Echidna Invariant Fuzzing, Certora Prover, Halmos Symbolic Testing

  • Keeper & Liquidation Bots

    Stack: Rust, Go, Flashbots Protect, Tenderly Virtual Testnets, Subgraphs

  • Frontend & Analytics

    Stack: Next.js 14, viem / wagmi, The Graph Subgraphs, Dune Analytics API, PostgreSQL

Solvency and smart contract security in lending protocols.

Lending protocols are the highest-value targets in Web3. Security must be proven mathematically.

  • Reentrancy in token callbacks

    ERC-777, ERC-1155 and certain ERC-20 tokens feature transfer callbacks that can reenter deposit or borrow routines. NonReentrant guards on all external state transitions and CEI pattern enforcement.

  • Oracle manipulation and stale pricing

    Flash loan attacks inflating AMM pool reserves can corrupt spot price oracles. Strict reliance on decentralized off-chain oracles (Chainlink/Pyth) with minimum heartbeat verification and deviation ceilings.

  • Bad debt accumulation

    If collateral drops faster than liquidators can clear positions, the protocol becomes insolvent. Reserve backstop funds and automated protocol debt auctioning mechanics to clear underwater accounts.

  • Rounding errors in interest calculation

    Compounding per-second interest math can accumulate fractional truncation errors. Math library implementations using ray/wad precision (10^27 and 10^18 fixed point) with rounding in favor of protocol solvency.

  • Flash loan callback exploitation

    Malicious flash loan recipients attempting state manipulation. Flash loan logic requires strict validation that repaid principal plus fee is returned before execution completes.

From economic model to mainnet deployment.

  1. 01. Economic Modelling

    Simulation of interest rate curves, LTV thresholds, and liquidation incentives under historical market stress test scenarios.

  2. 02. Contract Architecture

    Core ledger, debt tokens, collateral vaults, interest rate calculators, and oracle adapter development in Foundry.

  3. 03. Invariant Fuzz Testing

    Comprehensive property-based fuzz campaigns with Echidna: verifying protocol total debt equals active borrow balances.

  4. 04. Keeper & Liquidation Bots

    Development of open-source automated liquidator bots and keeper networks to guarantee liquidation execution.

  5. 05. Formal Verification & Audit

    Mathematical verification of core solvency invariants and dual independent third-party smart contract audits.

  6. 06. Testnet & Staged Launch

    Deploy to Sepolia testnet, simulate high-volatility liquidations with simulated whales, and staged capped mainnet rollout.

DeFi Lending Protocol Engagements

Decentralized money markets, isolated CDP protocols and automated keeper liquidation systems.

  • Multi-Asset Decentralized Lending Protocol (M TVL)

    Challenge: DeFi foundation needed high-performance lending protocol supporting cross-margin lending and borrowing across 12 crypto assets on Ethereum L2.

    Architecture: Modular money market protocol with kinked interest rate curves, dual Chainlink/Pyth price oracle adapter, dynamic Dutch auction liquidator, and custom The Graph indexing layer.

    Outcome: Scaled to M peak TVL within 4 months of launch. Successfully liquidated .4M in underwater collateral during a 35% market drop with zero bad debt incurred.

  • Isolated Risk Lending Protocol for Yield-Bearing Collateral

    Challenge: Ecosystem protocol required lending markets allowing users to borrow stablecoins against yield-bearing ERC-4626 vault tokens without risking core pool contagion.

    Architecture: Segregated pair architecture where each collateral asset is paired exclusively against USDC. Isolated borrow caps, custom interest rate curves reflecting vault staking yields, and Flashbots-integrated liquidation bots.

    Outcome: Over M in yield-bearing assets deposited. Property-based fuzz tests confirmed 100% solvency across 5,000 simulated market crash iterations.

  • Zero-Capital Flash Loan Vault & Arbitrage Network

    Challenge: Trading desk needed flash loan routing contract aggregating uncollateralized borrow liquidity across multiple lending pools with minimal gas overhead.

    Architecture: Ultra-gas-optimized assembly (Yul) flash loan callback dispatcher with atomic multi-DEX routing, automatic slippage guards, and gas refund mechanics.

    Outcome: Processed over M in cumulative flash loan arbitrage and liquidation volume. Protocol earned ,000 in fee revenue distributed directly to liquidity providers.

Frequently Asked Questions

How does the lending protocol prevent bad debt during severe price drops?

Multiple defensive mechanisms: (1) Conservative Loan-to-Value (LTV) and liquidation thresholds (typically 75-80% for volatile assets). (2) Dual-oracle price feeds with automated staleness detection that update before on-chain price dislocation occurs. (3) Dutch auction liquidations that provide increasing profit margins to keeper bots, ensuring liquidations execute even during gas price spikes. (4) Protocol reserve insurance fund that automatically absorbs any residual bad debt without haircutting depositor balances.

Can this protocol support custom collateral like RWA tokens or LP tokens?

Yes. The modular architecture supports isolated lending pairs where specialized assets (ERC-3643 RWA tokens, ERC-4626 vault shares, Uniswap V3 LP NFTs) have isolated debt pools. Because these markets are isolated, risks associated with illiquid or long-tail collateral are completely cordoned off from the main liquidity pool.

What tools and methodologies are used for audit and verification?

We employ invariant testing via Foundry and Echidna, running millions of fuzz iterations to prove that total debt assets never exceed backing collateral. In addition, formal verification of the interest rate accrual and liquidation accounting invariants is conducted prior to independent external security audits.