Save (Solend); Reviewed & Scored | The Block Note
Lending & Borrowing Protocol Review · Updated August 2026

Save (formerly Solend):
Solana's original lender, tested twice, and once by its own governance.

We tore apart Save, the rebranded successor to Solend, Solana's earliest production lending protocol, across the same lending-adapted scorecard we've used throughout this series. From the longest audit history among ranked Solana DeFi protocols, per a detailed source, to a real, well-documented incident history spanning three distinct events, each handled in a way that protected user funds: an August 2021 admin-function exploit attempt that succeeded in altering risk parameters but failed to extract value because the team's own liquidator bot beat the attacker to it; a December 2021 rounding-error bug in the shared underlying lending program, responsibly disclosed by whitehat firm Neodyme before any malicious exploitation across six affected protocols; and a real, executed 2022 exploit that drained $1.26 million via a manipulated USDH oracle price, fully covered by Solend's own treasury with zero user losses. We also found a real, genuinely controversial 2022 governance episode: the SLND1 proposal, where Solend's DAO voted to seize a whale's account to prevent a systemic liquidation cascade, a real, direct decentralization-versus-risk-management conflict that was ultimately never executed. The 2024 rebrand to Save reset the product around simpler core lending, deliberately trading away the structured, leveraged products that Kamino and Jupiter Lend now lead on; and landed on a score the marketing page won't show you.

Type Non-Custodial Lending Protocol (Solana-native) Platforms Web · Solana-native Rates Variable, algorithmically-determined Discount Offer None
save
Lending Protocol
2022 exploit: $1.26M, fully treasury-covered
2022: DAO voted to seize a whale's account

Our take, up front: Save is the 2024 rebrand of Solend, Solana's earliest production lending protocol, and one of the few platforms in this entire series with a track record stretching back to the network's early DeFi days. Real, disclosed genuinely long audit history, described by a detailed source as the longest among ranked Solana DeFi protocols. Real, well-documented incident history spanning three distinct events, and we want to be precise about how each one actually resolved. In August 2021, an attacker exploited an insecure authorization check to alter the protocol's own risk parameters, successfully setting borrow rates to 250% and making nearly all accounts liquidatable, but the team detected the manipulation quickly enough that its own liquidator bot captured the available liquidations before the attacker could, and no user funds were lost. In December 2021, whitehat security firm Neodyme responsibly disclosed a rounding-error bug in the shared underlying lending program before any malicious exploitation, a vulnerability that also affected five other protocols built on the same base code. In 2022, Solend suffered a real, executed exploit: an attacker manipulated the price of USDH, a stablecoin with a thin, single-source oracle feed, to borrow against artificially inflated collateral, draining $1.26 million; Solend's own treasury covered the full loss, and no user funds were affected. What we can't set aside: a real, genuinely controversial 2022 governance episode. Facing a large whale position that risked a systemic liquidation cascade due to thin oracle liquidity, Solend's DAO passed SLND1, a proposal to seize control of the whale's account and liquidate the position over-the-counter to avoid on-chain chaos. The seizure was never actually executed, the whale voluntarily moved $25 million in debt to Mango Markets first, but the precedent that a DAO could vote to seize an individual user's assets drew real, warranted criticism at the time. The 2024 rebrand introduced a native stablecoin (sUSD) and liquid staking token (saveSOL), alongside a redesigned interface, and deliberately reset the product around simpler core lending rather than competing with Kamino and Jupiter Lend's more complex, structured offerings. We weighted all of it below.

Real, disclosed, longest audit history among ranked Solana DeFi protocols, per a detailed source. Real, well-documented three-incident history, each resolved without user losses: Aug 2021, an admin-function exploit succeeded in altering risk parameters, but the team's own liquidator bot beat the attacker to the resulting liquidations; Dec 2021, a shared underlying-program rounding bug was responsibly disclosed by whitehat firm Neodyme before exploitation, affecting five other protocols too; 2022, a real, executed $1.26M exploit via manipulated USDH oracle pricing was fully covered by Solend's own treasury. No confirmed hack or exploit found since 2022, a roughly four-year clean stretch.

Why this scores above the midpoint: real incidents did occur, but in every case user funds were protected, either by fast detection, responsible whitehat disclosure, or treasury-funded loss absorption, a genuinely consistent pattern of the team absorbing risk rather than passing it to depositors.

Pros

  • Longest audit history among ranked Solana DeFi protocols, per a detailed source
  • No confirmed hack or exploit since 2022
  • Every historical incident was resolved with zero user losses, via fast response or treasury coverage

Cons

  • Aug 2021: an attacker did successfully alter live risk parameters before being contained
  • 2022: a real, executed $1.26M oracle-manipulation exploit occurred

Real, disclosed TVL reaching $400 million-plus in August 2024, though disclosed directly as having "fluctuated since," without a more precise current figure in our sources. Real, disclosed status as one of Solana's established, long-running lending protocols, though now trailing Kamino and Jupiter Lend in scale.

Why this scores at the midpoint: solid, established liquidity for a long-running protocol, tempered by no longer holding category-leading scale and some imprecision in current figures across our sources.

Pros

  • Established, long-running liquidity base reaching $400M+ historically

Cons

  • No longer among Solana's largest lenders by TVL
  • Current, precise TVL figures are less clearly disclosed in our sources than for category leaders

Real, disclosed functioning SLND token governance. What tempers this: a real, genuinely controversial 2022 governance episode. Facing a large whale position that risked a systemic liquidation cascade, Solend's DAO passed SLND1, a proposal to seize control of the whale's account and liquidate the position OTC to avoid on-chain chaos. The seizure was never executed (the whale moved the debt to Mango Markets first), but the precedent that a DAO could vote to seize an individual user's assets drew real, warranted criticism. Real, disclosed governance concentration among early users and the core team, per a detailed source.

Why this scores below the midpoint: a functioning governance token exists, but a real, disclosed precedent for asset seizure by DAO vote, even one never executed, is a genuine, serious concern for a protocol built on the premise of permissionless self-custody.

Pros

  • Functioning SLND governance token exists
  • The DAO ultimately did not need to execute the seizure

Cons

  • A DAO vote to seize an individual user's assets sets a real, disclosed precedent
  • Governance participation is concentrated among early users and the core team, per a detailed source

Real, disclosed support for major assets (SOL, USDC, wrapped BTC) alongside new, disclosed native products introduced with the 2024 rebrand: sUSD, a native stablecoin, and saveSOL, a liquid staking token.

Why this scores well: solid, established asset support extended by real, disclosed new native products introduced with the rebrand.

Pros

  • Native sUSD stablecoin and saveSOL liquid staking token, introduced with the 2024 rebrand

Cons

  • Narrower asset scope than category leaders by deliberate design choice

Real, disclosed "beginner-friendly design" and a redesigned interface introduced with the 2024 rebrand, deliberately positioned as simpler core lending rather than the more complex, structured products Kamino and Jupiter Lend offer.

Why this scores well: a genuinely deliberate, disclosed simplicity-focused design choice that serves a real, distinct user need.

Pros

  • Deliberately simple, beginner-friendly interface following the 2024 redesign

Cons

  • Fewer advanced tools for users who specifically want structured or leveraged products

Real, disclosed algorithmically-determined, standard variable rates based on supply and demand. Our sources disclosed less specific, universally-quoted current rate figures than for some category leaders.

Why this scores at the midpoint: a standard, functional rate model, tempered by less specific disclosed rate data than some competitors in this series.

Pros

  • Standard, algorithmically-determined variable rate model

Cons

  • Less specific, universally-quoted current rate figures disclosed than some competitors

Real, disclosed native stablecoin (sUSD) and liquid staking token (saveSOL), though a detailed source notes the 2024 rebrand deliberately moved away from more complex structured products, meaning fewer advanced features than Kamino or Jupiter Lend by design.

Pros

  • Native stablecoin and liquid staking token, both introduced with the rebrand

Cons

  • Deliberately fewer structured or leveraged products than category leaders, by design
Where to get it

Access only through Save's official app, and remember the SLND1 precedent before assuming full self-custody.

Given the real, disclosed 2022 governance vote to seize a whale's account, understand that "permissionless and non-custodial" doesn't necessarily mean immune from a future DAO vote in an extreme scenario, and size any large, concentrated position accordingly.

0/ 100

A genuinely responsible operator, through real incidents, that still has to answer for one uncomfortable precedent.

What stands out most to us about Save's history is how consistently the team absorbed risk rather than passing it to depositors. A fast-detected parameter exploit, a responsibly-disclosed shared-code bug, a real, executed oracle manipulation, three genuinely different kinds of security event, and in every single case, user funds came out whole, either through quick response or the team's own treasury picking up the tab. That's a genuinely strong, consistent pattern, and it's a big part of why this scores as well as it does. But we can't review a lending protocol that markets itself on permissionless self-custody without taking the SLND1 vote seriously. A DAO deciding it can seize an individual account, even with good intentions, even in a genuine emergency, even without ultimately doing it, is a real precedent that sits uneasily next to "your keys, your crypto." We think both things are true: Save has earned real trust through how it's handled money going wrong, and it still owes users a clearer answer about what happens the next time a position gets large enough to threaten the whole pool.

Best forUsers who want a long-established, historically responsible Solana lender with a simpler, less structured product than Kamino or Jupiter Lend
Not forLarge, concentrated position holders who want certainty that governance can never intervene in their individual account
Score Ledger
save · 7 line items
01Security21.0
02Liquidity11.0
03Decentralization7.5
04Assets7.0
05UX7.0
06Rates6.0
07Extras2.75
TOTAL62.25
≈ 62 / 100; Responsible, with one caveat

The scorecard above is deliberately general. Whether Save is right for you depends heavily on which of these you already are.

Best fit

The user who wants a long-established, historically responsible Solana lender with a simpler, beginner-friendly interface

This is exactly where Save's deliberate 2024 repositioning around simplicity delivers real, demonstrated value.

Good fit

The user who values a protocol's demonstrated response to real incidents over one that simply hasn't had any yet

Save's consistent, disclosed pattern of absorbing losses via treasury coverage or fast response is genuine, tested evidence.

Workable fit

The user who avoids concentrating an unusually large position that could draw the kind of governance scrutiny SLND1 set a precedent for

Given the real, disclosed 2022 episode, this specific awareness genuinely matters more here than on protocols without that history.

Poor fit

Large, concentrated position holders who want certainty that governance can never intervene in their individual account

Kamino and SparkLend, both reviewed earlier in this series, don't carry a comparable disclosed DAO-seizure precedent.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; three incidents compared precisely, the SLND1 episode timelined, Solend vs. Save compared directly, and our fifteenth lending-protocol comparison entry.

Three incidents, three different outcomes

DateWhat happenedUser funds lost?
Aug 2021Attacker altered live risk parameters via an admin-function authorization flaw; team's own liquidator bot captured the resulting liquidations firstNo
Dec 2021Whitehat firm Neodyme responsibly disclosed a rounding-error bug in the shared underlying lending program before exploitation (affected 5 other protocols too)No; disclosed pre-exploitation
2022Attacker manipulated USDH's thin, single-source oracle price to borrow against inflated collateral, draining $1.26MNo; Solend's treasury covered the full loss

Three genuinely different kinds of security event, an admin-function flaw, a shared-code bug, and an oracle manipulation, yet the same outcome each time: no user ever lost funds.

The SLND1 episode, timelined

StepWhat happened
1. The riskA large whale position risked a systemic liquidation cascade due to thin oracle liquidity for the collateral involved
2. The proposalSolend's DAO proposes and passes SLND1: seize control of the whale's account and liquidate the position OTC to avoid on-chain chaos
3. The criticismThe proposal draws real, direct criticism over the precedent of a DAO voting to seize an individual user's assets
4. The resolutionThe whale voluntarily moves $25 million in debt to Mango Markets; the seizure is never executed

The emergency resolved itself before the vote had to be acted on, but the vote itself, and what it implies is possible under the right circumstances, remains part of the protocol's real history.

Solend vs. Save

Solend (pre-2024)Save (2024-present)
Product scopeCore lending plus some structured featuresSimpler core lending, deliberately reset
Native token productsNone disclosedsUSD stablecoin, saveSOL liquid staking token
InterfaceOriginal designRedesigned, "beginner-friendly" per a detailed source
Competitive positionAmong Solana's top lendersEstablished but trailing Kamino and Jupiter Lend in scale

The rebrand was a genuine repositioning toward simplicity rather than a response to any single incident; Save deliberately chose not to chase the structured-product complexity that now defines the category's largest players.

Lending protocols, side by side (series continues)

AaveKaminoMorphoSparkLendEulerJupiter LendMapleVenusFluidProject 0Save
Most severe disclosed history$292M bridge exploitNone found$18M vault lossNone found$197-240M exploit, recoveredNone on contracts~$50-54M in 2022 defaultsKnown vuln., exploited twice3 incidents (~$8.4M), core unaffectedGovernance crisis, not a code exploit$1.26M exploit, treasury-covered; zero user losses across 3 incidents
Distinctive modelMulti-network V3/V4Curator-managed marketsImmutable core + vaultsAave fork, blue-chip onlyModular EVK/EVC vaultsSmart Collateral/Debt, superappInstitutional creditCompound forkShared layer, lending+DEXCross-venue prime brokerageSolana's earliest lender, simplicity-focused

Save is the only protocol in this series with a real, disclosed history of a DAO voting on whether to seize an individual user's account, a governance question none of the other reviewed protocols have faced this directly.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've treated the Helius and Medium historical-incident writeups as factual references we drew on directly, rather than as independent review scores, since they document history rather than render a verdict.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands moderately below the aggregated industry average; most general reviews we found emphasize the long audit history and beginner-friendly design favorably without weighting the SLND1 governance precedent as heavily as our methodology does.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes. Save is the 2024 rebrand of Solend, Solana's earliest production lending protocol. The rebrand introduced a redesigned interface and new native products (sUSD, saveSOL) while deliberately simplifying the product around core lending.

Yes, once with an executed loss: a 2022 exploit manipulated a thin USDH oracle feed to drain $1.26 million, fully covered by Solend's own treasury with zero user losses. A separate 2021 admin-function exploit attempt was thwarted before any funds were extracted, and a 2021 shared-code bug was responsibly disclosed before exploitation. No confirmed hack since 2022.

In 2022, facing a large whale position that risked a systemic liquidation cascade, Solend's DAO passed a proposal (SLND1) to seize control of the whale's account and liquidate it OTC. The seizure was never executed, the whale voluntarily moved the debt to Mango Markets first, but the vote set a real, disclosed precedent that a DAO could seize an individual user's assets.

An attacker exploited an insecure authorization check to alter the protocol's own risk parameters, successfully setting borrow rates to 250% and making nearly all accounts liquidatable. The team detected the manipulation quickly, and its own liquidator bot captured the resulting liquidations before the attacker could profit from them.

Whitehat security firm Neodyme discovered a rounding-error bug in the shared SPL-token-lending program that Solend and five other protocols were built on. Neodyme responsibly disclosed it to the Solana Foundation and affected teams before any malicious exploitation occurred.

Save reached $400 million-plus in TVL in August 2024, though this figure has fluctuated since, per a detailed source. It now trails Kamino and Jupiter Lend in scale.

sUSD is Save's native stablecoin and saveSOL is its liquid staking token, both introduced alongside the 2024 rebrand from Solend.

Save deliberately reset around simpler core lending in its 2024 rebrand, without the structured, leveraged products that Kamino and Jupiter Lend now lead on. It's positioned as a more beginner-friendly option with a longer operating history, rather than competing directly on advanced features.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Save.

More Reviews