Save (formerly Solend):
Solana's original lender, tested twice, and once by its own governance.
We tore apart Save, the rebranded successor to Solend, Solana's earliest production lending protocol, across the same lending-adapted scorecard we've used throughout this series. From the longest audit history among ranked Solana DeFi protocols, per a detailed source, to a real, well-documented incident history spanning three distinct events, each handled in a way that protected user funds: an August 2021 admin-function exploit attempt that succeeded in altering risk parameters but failed to extract value because the team's own liquidator bot beat the attacker to it; a December 2021 rounding-error bug in the shared underlying lending program, responsibly disclosed by whitehat firm Neodyme before any malicious exploitation across six affected protocols; and a real, executed 2022 exploit that drained $1.26 million via a manipulated USDH oracle price, fully covered by Solend's own treasury with zero user losses. We also found a real, genuinely controversial 2022 governance episode: the SLND1 proposal, where Solend's DAO voted to seize a whale's account to prevent a systemic liquidation cascade, a real, direct decentralization-versus-risk-management conflict that was ultimately never executed. The 2024 rebrand to Save reset the product around simpler core lending, deliberately trading away the structured, leveraged products that Kamino and Jupiter Lend now lead on; and landed on a score the marketing page won't show you.
Our take, up front: Save is the 2024 rebrand of Solend, Solana's earliest production lending protocol, and one of the few platforms in this entire series with a track record stretching back to the network's early DeFi days. Real, disclosed genuinely long audit history, described by a detailed source as the longest among ranked Solana DeFi protocols. Real, well-documented incident history spanning three distinct events, and we want to be precise about how each one actually resolved. In August 2021, an attacker exploited an insecure authorization check to alter the protocol's own risk parameters, successfully setting borrow rates to 250% and making nearly all accounts liquidatable, but the team detected the manipulation quickly enough that its own liquidator bot captured the available liquidations before the attacker could, and no user funds were lost. In December 2021, whitehat security firm Neodyme responsibly disclosed a rounding-error bug in the shared underlying lending program before any malicious exploitation, a vulnerability that also affected five other protocols built on the same base code. In 2022, Solend suffered a real, executed exploit: an attacker manipulated the price of USDH, a stablecoin with a thin, single-source oracle feed, to borrow against artificially inflated collateral, draining $1.26 million; Solend's own treasury covered the full loss, and no user funds were affected. What we can't set aside: a real, genuinely controversial 2022 governance episode. Facing a large whale position that risked a systemic liquidation cascade due to thin oracle liquidity, Solend's DAO passed SLND1, a proposal to seize control of the whale's account and liquidate the position over-the-counter to avoid on-chain chaos. The seizure was never actually executed, the whale voluntarily moved $25 million in debt to Mango Markets first, but the precedent that a DAO could vote to seize an individual user's assets drew real, warranted criticism at the time. The 2024 rebrand introduced a native stablecoin (sUSD) and liquid staking token (saveSOL), alongside a redesigned interface, and deliberately reset the product around simpler core lending rather than competing with Kamino and Jupiter Lend's more complex, structured offerings. We weighted all of it below.
Real, disclosed, longest audit history among ranked Solana DeFi protocols, per a detailed source. Real, well-documented three-incident history, each resolved without user losses: Aug 2021, an admin-function exploit succeeded in altering risk parameters, but the team's own liquidator bot beat the attacker to the resulting liquidations; Dec 2021, a shared underlying-program rounding bug was responsibly disclosed by whitehat firm Neodyme before exploitation, affecting five other protocols too; 2022, a real, executed $1.26M exploit via manipulated USDH oracle pricing was fully covered by Solend's own treasury. No confirmed hack or exploit found since 2022, a roughly four-year clean stretch.
Pros
- Longest audit history among ranked Solana DeFi protocols, per a detailed source
- No confirmed hack or exploit since 2022
- Every historical incident was resolved with zero user losses, via fast response or treasury coverage
Cons
- Aug 2021: an attacker did successfully alter live risk parameters before being contained
- 2022: a real, executed $1.26M oracle-manipulation exploit occurred
Real, disclosed TVL reaching $400 million-plus in August 2024, though disclosed directly as having "fluctuated since," without a more precise current figure in our sources. Real, disclosed status as one of Solana's established, long-running lending protocols, though now trailing Kamino and Jupiter Lend in scale.
Pros
- Established, long-running liquidity base reaching $400M+ historically
Cons
- No longer among Solana's largest lenders by TVL
- Current, precise TVL figures are less clearly disclosed in our sources than for category leaders
Real, disclosed functioning SLND token governance. What tempers this: a real, genuinely controversial 2022 governance episode. Facing a large whale position that risked a systemic liquidation cascade, Solend's DAO passed SLND1, a proposal to seize control of the whale's account and liquidate the position OTC to avoid on-chain chaos. The seizure was never executed (the whale moved the debt to Mango Markets first), but the precedent that a DAO could vote to seize an individual user's assets drew real, warranted criticism. Real, disclosed governance concentration among early users and the core team, per a detailed source.
Pros
- Functioning SLND governance token exists
- The DAO ultimately did not need to execute the seizure
Cons
- A DAO vote to seize an individual user's assets sets a real, disclosed precedent
- Governance participation is concentrated among early users and the core team, per a detailed source
Real, disclosed support for major assets (SOL, USDC, wrapped BTC) alongside new, disclosed native products introduced with the 2024 rebrand: sUSD, a native stablecoin, and saveSOL, a liquid staking token.
Pros
- Native sUSD stablecoin and saveSOL liquid staking token, introduced with the 2024 rebrand
Cons
- Narrower asset scope than category leaders by deliberate design choice
Real, disclosed "beginner-friendly design" and a redesigned interface introduced with the 2024 rebrand, deliberately positioned as simpler core lending rather than the more complex, structured products Kamino and Jupiter Lend offer.
Pros
- Deliberately simple, beginner-friendly interface following the 2024 redesign
Cons
- Fewer advanced tools for users who specifically want structured or leveraged products
Real, disclosed algorithmically-determined, standard variable rates based on supply and demand. Our sources disclosed less specific, universally-quoted current rate figures than for some category leaders.
Pros
- Standard, algorithmically-determined variable rate model
Cons
- Less specific, universally-quoted current rate figures disclosed than some competitors
Real, disclosed native stablecoin (sUSD) and liquid staking token (saveSOL), though a detailed source notes the 2024 rebrand deliberately moved away from more complex structured products, meaning fewer advanced features than Kamino or Jupiter Lend by design.
Pros
- Native stablecoin and liquid staking token, both introduced with the rebrand
Cons
- Deliberately fewer structured or leveraged products than category leaders, by design
Access only through Save's official app, and remember the SLND1 precedent before assuming full self-custody.
Given the real, disclosed 2022 governance vote to seize a whale's account, understand that "permissionless and non-custodial" doesn't necessarily mean immune from a future DAO vote in an extreme scenario, and size any large, concentrated position accordingly.
A genuinely responsible operator, through real incidents, that still has to answer for one uncomfortable precedent.
What stands out most to us about Save's history is how consistently the team absorbed risk rather than passing it to depositors. A fast-detected parameter exploit, a responsibly-disclosed shared-code bug, a real, executed oracle manipulation, three genuinely different kinds of security event, and in every single case, user funds came out whole, either through quick response or the team's own treasury picking up the tab. That's a genuinely strong, consistent pattern, and it's a big part of why this scores as well as it does. But we can't review a lending protocol that markets itself on permissionless self-custody without taking the SLND1 vote seriously. A DAO deciding it can seize an individual account, even with good intentions, even in a genuine emergency, even without ultimately doing it, is a real precedent that sits uneasily next to "your keys, your crypto." We think both things are true: Save has earned real trust through how it's handled money going wrong, and it still owes users a clearer answer about what happens the next time a position gets large enough to threaten the whole pool.
The scorecard above is deliberately general. Whether Save is right for you depends heavily on which of these you already are.
The user who wants a long-established, historically responsible Solana lender with a simpler, beginner-friendly interface
This is exactly where Save's deliberate 2024 repositioning around simplicity delivers real, demonstrated value.
The user who values a protocol's demonstrated response to real incidents over one that simply hasn't had any yet
Save's consistent, disclosed pattern of absorbing losses via treasury coverage or fast response is genuine, tested evidence.
The user who avoids concentrating an unusually large position that could draw the kind of governance scrutiny SLND1 set a precedent for
Given the real, disclosed 2022 episode, this specific awareness genuinely matters more here than on protocols without that history.
Large, concentrated position holders who want certainty that governance can never intervene in their individual account
Kamino and SparkLend, both reviewed earlier in this series, don't carry a comparable disclosed DAO-seizure precedent.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; three incidents compared precisely, the SLND1 episode timelined, Solend vs. Save compared directly, and our fifteenth lending-protocol comparison entry.
Three incidents, three different outcomes
| Date | What happened | User funds lost? |
|---|---|---|
| Aug 2021 | Attacker altered live risk parameters via an admin-function authorization flaw; team's own liquidator bot captured the resulting liquidations first | No |
| Dec 2021 | Whitehat firm Neodyme responsibly disclosed a rounding-error bug in the shared underlying lending program before exploitation (affected 5 other protocols too) | No; disclosed pre-exploitation |
| 2022 | Attacker manipulated USDH's thin, single-source oracle price to borrow against inflated collateral, draining $1.26M | No; Solend's treasury covered the full loss |
Three genuinely different kinds of security event, an admin-function flaw, a shared-code bug, and an oracle manipulation, yet the same outcome each time: no user ever lost funds.
The SLND1 episode, timelined
| Step | What happened |
|---|---|
| 1. The risk | A large whale position risked a systemic liquidation cascade due to thin oracle liquidity for the collateral involved |
| 2. The proposal | Solend's DAO proposes and passes SLND1: seize control of the whale's account and liquidate the position OTC to avoid on-chain chaos |
| 3. The criticism | The proposal draws real, direct criticism over the precedent of a DAO voting to seize an individual user's assets |
| 4. The resolution | The whale voluntarily moves $25 million in debt to Mango Markets; the seizure is never executed |
The emergency resolved itself before the vote had to be acted on, but the vote itself, and what it implies is possible under the right circumstances, remains part of the protocol's real history.
Solend vs. Save
| Solend (pre-2024) | Save (2024-present) | |
|---|---|---|
| Product scope | Core lending plus some structured features | Simpler core lending, deliberately reset |
| Native token products | None disclosed | sUSD stablecoin, saveSOL liquid staking token |
| Interface | Original design | Redesigned, "beginner-friendly" per a detailed source |
| Competitive position | Among Solana's top lenders | Established but trailing Kamino and Jupiter Lend in scale |
The rebrand was a genuine repositioning toward simplicity rather than a response to any single incident; Save deliberately chose not to chase the structured-product complexity that now defines the category's largest players.
Lending protocols, side by side (series continues)
| Aave | Kamino | Morpho | SparkLend | Euler | Jupiter Lend | Maple | Venus | Fluid | Project 0 | Save | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Most severe disclosed history | $292M bridge exploit | None found | $18M vault loss | None found | $197-240M exploit, recovered | None on contracts | ~$50-54M in 2022 defaults | Known vuln., exploited twice | 3 incidents (~$8.4M), core unaffected | Governance crisis, not a code exploit | $1.26M exploit, treasury-covered; zero user losses across 3 incidents |
| Distinctive model | Multi-network V3/V4 | Curator-managed markets | Immutable core + vaults | Aave fork, blue-chip only | Modular EVK/EVC vaults | Smart Collateral/Debt, superapp | Institutional credit | Compound fork | Shared layer, lending+DEX | Cross-venue prime brokerage | Solana's earliest lender, simplicity-focused |
Save is the only protocol in this series with a real, disclosed history of a DAO voting on whether to seize an individual user's account, a governance question none of the other reviewed protocols have faced this directly.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've treated the Helius and Medium historical-incident writeups as factual references we drew on directly, rather than as independent review scores, since they document history rather than render a verdict.
Our score lands moderately below the aggregated industry average; most general reviews we found emphasize the long audit history and beginner-friendly design favorably without weighting the SLND1 governance precedent as heavily as our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes. Save is the 2024 rebrand of Solend, Solana's earliest production lending protocol. The rebrand introduced a redesigned interface and new native products (sUSD, saveSOL) while deliberately simplifying the product around core lending.
Yes, once with an executed loss: a 2022 exploit manipulated a thin USDH oracle feed to drain $1.26 million, fully covered by Solend's own treasury with zero user losses. A separate 2021 admin-function exploit attempt was thwarted before any funds were extracted, and a 2021 shared-code bug was responsibly disclosed before exploitation. No confirmed hack since 2022.
In 2022, facing a large whale position that risked a systemic liquidation cascade, Solend's DAO passed a proposal (SLND1) to seize control of the whale's account and liquidate it OTC. The seizure was never executed, the whale voluntarily moved the debt to Mango Markets first, but the vote set a real, disclosed precedent that a DAO could seize an individual user's assets.
An attacker exploited an insecure authorization check to alter the protocol's own risk parameters, successfully setting borrow rates to 250% and making nearly all accounts liquidatable. The team detected the manipulation quickly, and its own liquidator bot captured the resulting liquidations before the attacker could profit from them.
Whitehat security firm Neodyme discovered a rounding-error bug in the shared SPL-token-lending program that Solend and five other protocols were built on. Neodyme responsibly disclosed it to the Solana Foundation and affected teams before any malicious exploitation occurred.
Save reached $400 million-plus in TVL in August 2024, though this figure has fluctuated since, per a detailed source. It now trails Kamino and Jupiter Lend in scale.
sUSD is Save's native stablecoin and saveSOL is its liquid staking token, both introduced alongside the 2024 rebrand from Solend.
Save deliberately reset around simpler core lending in its 2024 rebrand, without the structured, leveraged products that Kamino and Jupiter Lend now lead on. It's positioned as a more beginner-friendly option with a longer operating history, rather than competing directly on advanced features.
More Reviews
Ledn – Crypto Lending & Borrowing Review
Score: 75/100. Highest CeFi score in this series: 10 straight PoR attestations, explicit no-re-lending pledge, never lost customer funds.
Read MoreAave – Crypto Lending & Borrowing Review
Score: 69.5/100. Category leader hit hardest by the Apr 2026 KelpDAO crisis: $124-230M bad debt, its largest liquidity event yet.
Read MoreCompound – Crypto Lending & Borrowing Review
Score: 63.25/100. Pioneer whose 2021 self-inflicted $161.7M COMP bug remains its scar, though its caution spared it in Apr 2026.
Read MoreCoinRabbit – Crypto Lending & Borrowing Review
Score: 50.5/100. Fast, no-KYC lending with a great product, but no named founder, no PoR, and vague licensing behind it.
Read More



