Ethereum co-founder Vitalik Buterin published a research proposal on June 1, 2026, calling for a structural overhaul of decentralized lending. The proposal, posted to the Ethereum Research forum, argues that the collateralized debt position (CDP) model underpinning Aave, MakerDAO, and virtually a...
Ethereum co-founder Vitalik Buterin published a research proposal on June 1, 2026, calling for a structural overhaul of decentralized lending. The proposal, posted to the Ethereum Research forum, argues that the collateralized debt position (CDP) model underpinning Aave, MakerDAO, and virtually all DeFi lending protocols should be replaced with an options-based architecture that eliminates forced liquidations entirely.
The timing is not incidental. DeFi lending protocols have processed $4.65 billion in liquidations since Aave's 2020 launch. In 2026 alone, a February selloff triggered $429 million in Aave liquidations across 12,500 transactions — a single-protocol record. A March oracle glitch wrongly liquidated $26 million in wstETH positions across 34 accounts. In April, the $292 million Kelp DAO exploit left Aave holding $196 million in bad debt and wiped $6.6 billion from its total value locked. The cumulative damage to user trust and protocol solvency is quantifiable and growing.
Buterin's proposal reframes the problem. Rather than iterating on liquidation thresholds, collateral ratios, or oracle speed, it removes the liquidation mechanism altogether. Deposited ETH splits into two complementary tokens — P and N — that always sum to one ETH regardless of price movement. An oracle reports a single price at maturity, not in real time. No position can go bankrupt by construction, so there is no liquidation trigger.
DeFi lending has grown to an estimated $75–80 billion in total value locked as of April 2026, according to DeFi Llama. Aave alone holds over $40 billion in TVL across 14+ networks and has originated more than $1 trillion in cumulative loans since inception. The protocol commands approximately 60–62% of the DeFi lending market.
The scale of this lending activity produces correspondingly large liquidation events during market stress. The data from 2026 alone illustrates the pattern:
January 31 – February 5, 2026: A selloff driven by Federal Reserve nomination concerns and forced selling pushed BTC from $85,000 to $60,000 and ETH from $2,900 to $1,750 over seven days. Aave processed $429 million in liquidations across 12,500 transactions, surpassing the May 2021 record. The average liquidation size was $68,000 — higher than during the 2021 China crypto crackdown.
March 10, 2026: A configuration error in Aave's CAPO risk oracle undervalued wstETH by 2.85%, producing an exchange rate of 1.1939 versus the actual market rate of 1.228. The error triggered $26 million in wrongful liquidations across 34 accounts. Third-party liquidators extracted approximately 499 ETH in profit. Aave's governance approved reimbursement using 141.5 ETH recovered from the incident plus up to 345 ETH from the DAO treasury.
April 19, 2026: The Kelp DAO bridge exploit drained $292 million in rsETH through a LayerZero verification weakness. The attacker deposited 89,567 rsETH into Aave as collateral and borrowed approximately $190 million in ETH across Ethereum and Arbitrum. Aave absorbed $196 million in bad debt, its TVL dropped $6.6 billion, and its token fell 16%.
The pattern is consistent. Liquidation mechanisms — designed to protect lenders — amplify volatility rather than absorb it. Cascading liquidations force asset sales at depressed prices, widening losses. Oracle dependencies create additional failure modes, as the March wstETH incident demonstrated.
Across the broader DeFi ecosystem, oracle manipulation accounts for 13% of all DeFi exploits in 2025, according to OWASP's Smart Contract Top 10, with 31% of early 2025 DeFi losses attributed to oracle-based attacks. In 2026, total DeFi hack losses topped $750 million through mid-April, with the Kelp DAO and Drift Protocol ($285 million) exploits leading the toll.
The core of Buterin's proposal, published on ethresear.ch on June 1, replaces the CDP model with a two-token split structure derived from options theory.
How it works: One unit of ETH deposited into the system is split into two tokens: P (positive exposure) and N (negative exposure). P and N always sum to exactly one ETH in value, regardless of market price. At maturity, an oracle determines the final price of the tracked index (USD, CPI, or a custom basket), and payouts are distributed accordingly.
The structure mirrors a prediction market. P holders bet one direction on a price index; N holders take the opposite side. Because P + N = 1 ETH by construction, neither position can ever go to zero. There is no collateral ratio to breach and no liquidation threshold to trigger.
This differs from the CDP model in several respects:
| Feature | CDP Model (Aave, Maker) | Options Model (Proposed) | |---|---|---| | Liquidation risk | Yes — forced sale at threshold | None — positions drift gradually | | Oracle requirement | Real-time, continuous | Single price at maturity | | Position bankruptcy | Possible | Impossible by construction | | Price tracking | Enforced via liquidation | Maintained via rebalancing | | User experience during crash | Abrupt position closure | Gradual deviation from target |
Buterin frames this as part of what he has called "low-risk DeFi." In a September 2025 blog post, he argued that low-risk financial primitives are "crucial for the sustainable economic backbone of Ethereum's ecosystem." The June 2026 proposal operationalizes that argument.
The oracle redesign may be the proposal's most consequential element for protocol security.
Current DeFi lending protocols require near-instantaneous price feeds to enforce collateral ratios. This creates a race condition: oracles must report accurate prices faster than attackers can exploit stale or manipulated data. The March 2026 wstETH incident — where a 2.85% oracle error triggered $26 million in wrongful liquidations — demonstrates the fragility.
Buterin's model uses what he describes as "slow oracles," similar to the resolution mechanisms in prediction markets like Polymarket. The oracle reports a single price at contract maturity rather than streaming continuous updates. This design has several implications:
Reduced attack surface. Flash loan attacks and millisecond price manipulations become irrelevant when the oracle does not respond in real time. The protocol does not act on instantaneous price data.
Lower infrastructure costs. Continuous price feeds across multiple chains require significant infrastructure. Chainlink's SVR mechanism, for example, processed $675 million in liquidations across 3,900 events in its first nine months, reclaiming approximately $16 million — 65% directed to Aave DAO and 35% to Chainlink. A maturity-only oracle would reduce these operational costs substantially.
Trade-off: delayed price discovery. Positions can drift from their target index between rebalancing events. Buterin suggests this drift — estimated at 1–4% annually — is an acceptable cost for eliminating liquidation cascades and oracle manipulation vectors.
Buterin explicitly addresses algorithmic stablecoins, a category that has not recovered credibly since the May 2022 Terra/UST collapse, which erased $80 billion in market value.
The proposal positions options-based stablecoins as structurally superior to CDPs for maintaining dollar pegs. Buterin stated he would feel "much safer" holding algorithmic stablecoins built on an options-based structure than those dependent on real-time oracle feeds.
The reasoning centers on failure modes. CDP-based stablecoins like the original DAI (and its successor USDS under Sky/MakerDAO) depend on continuous price monitoring and rapid liquidation execution to maintain collateral adequacy. When those mechanisms fail — due to network congestion, oracle delays, or sudden market moves — the stablecoin's peg can break.
An options-based stablecoin would instead allow gradual drift from the $1 peg during market stress, with rebalancing trades restoring the peg over time. The absence of a liquidation trigger means there is no mechanism to produce cascading failures.
The practical question is whether the market would accept a stablecoin that drifts 1–4% annually from its target. For comparison, the stablecoin market currently stands at approximately $323 billion, dominated by fully collateralized assets (USDT, USDC) with near-zero peg deviation under normal conditions.
Beyond single-currency pegs, Buterin envisions "personalized baskets of value" — stablecoins tracking custom asset mixes rather than the U.S. dollar alone. This would allow users to maintain purchasing power against individualized inflation baskets, though the practical demand for such products remains unproven.
The proposal does not arrive in a vacuum. Several DeFi protocols already facilitate on-chain options trading, though none currently use options as the foundation for lending or stablecoins.
Derive (formerly Lyra Finance) has transitioned from an AMM-based options protocol to a gasless central limit order book with on-chain settlement, targeting institutional-grade derivatives infrastructure.
Opyn developed one of the earliest DeFi options protocols and introduced Squeeth, the first perpetual option product, which provides continuous exposure to ETH squared returns.
Hegic operates as an Arbitrum-based AMM for options trading, using a stake-and-cover liquidity pool model.
These protocols demonstrate that on-chain options infrastructure exists at a functional level. However, none have attempted to use options as a replacement for lending primitives. The gap between trading options and building an entire lending/stablecoin system on options contracts is significant — particularly regarding the rebalancing mechanics Buterin acknowledges as unsolved.
Buterin explicitly flags several unresolved challenges:
Rebalancing costs. Maintaining index tracking requires periodic portfolio adjustments. These trades incur slippage, gas costs, and potential front-running. During volatile conditions — precisely when the system's advantages should be most apparent — rebalancing costs may spike. Buterin acknowledged it "remains unclear whether those adjustments can be made cheaply and efficiently enough to avoid excessive trading costs or slippage."
Counterparty matching. Every P token requires a matching N token. If demand is imbalanced — for example, if everyone wants dollar exposure (P) and no one wants to hold the inverse (N) — pricing adjusts rather than liquidation occurs. But severe imbalances could make the product uneconomical for one side, limiting adoption.
Maturity management. The system requires defined maturity dates for option contracts. This introduces rollover mechanics — users must migrate positions to new contracts at maturity, adding complexity and cost. Prediction markets handle this for discrete events, but continuous financial products like stablecoins require perpetual exposure, creating a structural mismatch.
1–4% annual drift. Buterin suggests this deviation range is acceptable. For stablecoin applications competing against USDT and USDC, which routinely maintain sub-0.1% deviations, this tolerance may not satisfy institutional users or payment applications requiring price certainty.
No live implementation. The proposal remains a research concept posted to a forum. No protocol has announced plans to implement it. The distance between a theoretically sound mechanism and a production system capable of handling billions in TVL is substantial.
The proposal is best understood as a diagnostic document. Buterin identifies a real and well-documented failure mode — liquidation cascades amplifying market stress rather than containing it — and proposes a mechanism that eliminates liquidations by construction. The data supports the diagnosis: $4.65 billion in lifetime Aave liquidations, three major incidents in 2026 alone, and growing oracle-related losses across the ecosystem.
Whether the cure is practical is a separate question. The rebalancing cost problem is non-trivial. The 1–4% drift tolerance may be acceptable for speculative products but is likely insufficient for stablecoin applications competing against fiat-backed alternatives. And the leap from research proposal to production protocol — particularly one that must handle tens of billions in deposits during market stress — requires engineering work that has not begun.
The proposal's value may lie less in its specific mechanism than in the direction it establishes. Buterin is arguing, with increasing specificity, that the current DeFi lending architecture has a design flaw at its foundation, not merely at its margins. The February, March, and April 2026 incidents provide the evidence. Whether the replacement is options-based or takes some other form, the pressure to move beyond incremental CDP improvements is now coming from Ethereum's most influential technical voice.