Back

DeFi evidence assessment

P11-L08 · P11 · P11-M02

Evaluate a historical protocol claim with unresolved dependencies

HISTORICAL · needs_review

Prerequisites: P11-L07

Learning objectives

  • Evaluate a historical protocol claim with unresolved dependencies
  • Write a claim-specific assessment of an official historical disclosure.
  • Preserve unresolved implementation and attribution boundaries.

EN source master · P11-L08 · 30 minutes estimated · needs_review

Offline formative study. No wallet connection, real funds, private keys, signatures, live trade or personal portfolio inputs. Visuals are specifications; this is neither runtime content nor certification.

Why this matters

An official incident statement is strong evidence of what a protocol contributor reported, but cannot by itself prove every underlying security claim.

Explanation

Establish the historical package first

The separately committed package P11-L08-AAVE-DISCLOSURE-20231104-v1 contains two official forum publication records [INC, DEP], retrieved 2026-10-01. It is a selective paraphrase record, not a byte-identical archive. The case is Aave v2/v3's November4,2023 security disclosure, not an invented exploit.

Bound the mechanism claim

R1 records BGD's reported critical bug and stable-rate restriction; R2 records later described stable-debt creation restrictions and an offboarding proposal. The underlying exploit details and exact deployed code are absent from this package. R3 preserves a direction inconsistency in the later specification text; do not resolve it by guessing implemented behavior. The lesson assesses disclosure quality, not a vulnerable-code reproduction.

Separate time lanes

The November report and January31,2024 proposal have different information cutoffs. The currently retrieved thread can include revisions and later updates, so it is not authenticated as the exact November4 screen. Do not use January rationale as evidence available at the earlier decision time. A reported proposal is not an independently verified execution.

Test narrower claims

'Publication R1 contains a non-exploitation assurance' can be assessed from the retained statement. 'No exploit happened anywhere' cannot be authenticated by that assurance alone. Likewise, a protocol's safety language is attributed, not adopted as the Academy's verdict. A native-chain investigation is unnecessary for this publication-assessment objective, but transaction-level claims would require receipts, network and state provenance not collected here. No amount, address, loss or execution-time claim is invented.

Write a bounded conclusion

Pair each claim with record, time lane, evidence state, assumptions and missing material. The teaching inference is that restrictions should be checked against implementation scope before a stronger security conclusion. It is a review priority, not a proven mitigation audit. Preserve accepted P02-L08/P03-L07 boundaries elsewhere unchanged.

Key terms

  • Official publication record: dated contributor statement, not automatic underlying-event proof.
  • Attribution: keep a report attached to its speaker/source.
  • Implementation gap: missing pinned code and state.
  • Cutoff lane: claims restricted to what their dated record supplies.

Historical example

HISTORICAL package records R1 (Nov4 disclosure), R2 (Jan31 proposal/rationale) and R3 (later specification inconsistency). See docs/academy-2/datasets/P11-L08-AAVE-DISCLOSURE-20231104-v1.json. No chain transaction record is supplied; the selected source supports a disclosure assessment only.

Visual specifications

Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.

What the evidence proves

What the retained official publication records report, within their rendering and retrieval boundaries.

What the evidence does not prove

Independent non-exploitation, deployed mitigation correctness, actual transaction states, exact exploit arithmetic, losses, human identity or universal safety.

Evidence classifications

  • OBSERVED: retained R1 contains the attributed disclosure statement; scope is publication content.
  • INFERRED: the reported restriction makes implementation-scope review a useful next evidence question, assuming the report is relevant.
  • UNKNOWN: exact vulnerable arithmetic and executed contract state in this package.
  • INSUFFICIENT EVIDENCE: the publications independently prove all pools safe or that no exploitation occurred.

Common mistakes

  • Upgrading contributor assurance into chain proof.
  • Treating a proposal as execution.
  • Resolving the inconsistent direction sentence by invention.
  • Using later rationale at the earlier cutoff.

Practical exercise

Build four claim rows: report publication, review priority, exact implementation and global non-exploitation. Give state, source/record, time lane and missing evidence. Explain R3 handling and write a two-sentence bounded case conclusion without transactions or loss amounts.

Deliver calculations or annotations, claim/source table and limitations. Suggested allocation: study 12 minutes, exercise 8, correction/quiz 10; estimate subject to calibration.

Show worked correction

Publication-content claim: OBSERVED in retained R1 [INC], not independently verified event. Review priority: INFERRED from R2 [DEP], with attributed-report assumptions and Jan31 lane. Exact implementation: UNKNOWN; needs pinned versions, relevant state and verification. Global non-exploitation/safety: INSUFFICIENT EVIDENCE; a broad negative or security conclusion needs defined scope and independent investigation. R3 remains unresolved; no implemented direction is claimed. Conclusion: 'The retained Aave forum records describe a stable-rate security response and later offboarding proposal. This package evaluates those reports and their disclosure gaps; it does not authenticate executed mitigations or protocol safety.'

Formative rubric (5 points): reproducible inputs, correct method, correct result, claim-specific evidence scope, explicit limitations. Invented observation, advisory output or unsupported safety claim requires correction regardless of score.

Checklist

  • Use frozen package and dated record.
  • Attribute protocol assurances.
  • Keep proposal and execution distinct.
  • Leave missing code/state and text conflict unresolved.
  • Require transaction provenance before adding chain claims.

Summary

The historical gate is satisfied for a bounded official-publication assessment. Underlying event and implementation assurances remain attributed and unverified.

Summary

  • Write a claim-specific assessment of an official historical disclosure.
  • Preserve unresolved implementation and attribution boundaries.

Next lesson

Program sequence complete. Return to curriculum for Controller-approved progression; no new program is implied.

Tools

NONE in the authoritative catalog. The supplied offline fixture/package is sufficient; no paid feature or unverified Production capability is required. Lab/certification metadata denotes downstream associations, not access gates or live awards.

Sources & claim boundaries

Visual specifications

P11-L08-V01

SPECIFICATION_ONLY · HISTORICAL

Evaluate a historical protocol claim with unresolved dependencies

Historical source rendering/report; boundaries remain attached.

Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.

Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.

At 390px stack chart/table, assumptions, correction and source panel; provide complete text equivalent. Rendering pending.

RTL explanatory prose; numeric values, IDs and chronological axes stay LTR; preserve dependency directions.

P11-L08-AAVE-DISCLOSURE-20231104-v1

Sources & claim boundaries

INC · OFFICIAL_PROTOCOL_PUBLICATION

BGD Labs on Aave governance — 4 November 2023 disclosure

Supported claim
Attributed bug report, stable-rate mitigation, non-exploitation statement and restricted disclosure; not chain proof.
Verification boundary
Documentation supports mechanism only; fixture values are original stipulated inputs. Historical publications remain attributed.
Checked at
2026-10-01
Open primary source
https://governance.aave.com/t/aave-v2-v3-security-incident-04-11-2023/15335

DEP · OFFICIAL_PROTOCOL_PUBLICATION

BGD Labs on Aave governance — 31 January 2024 follow-up

Supported claim
Attributed stable debt minting restrictions and proposal; source contains a direction inconsistency at specification paragraph.
Verification boundary
Documentation supports mechanism only; fixture values are original stipulated inputs. Historical publications remain attributed.
Checked at
2026-10-01
Open primary source
https://governance.aave.com/t/bgd-full-deprecation-of-stable-rate/16473

Dataset provenance

id: P11-L08-AAVE-DISCLOSURE-20231104-v1

dataStatus: HISTORICAL

observedAt: 2026-10-01

timeBasis: Retrieval date, day precision; event dates are separately recorded.

source: Bounded frozen package in docs/academy-2/datasets; see provenance limitations.

scope: Official protocol-contributor publications only; selective dated paraphrases, no byte-identical archive, pinned code, native receipts, exploit reconstruction, loss reconstruction or independent non-exploitation proof.

Test your reasoning

P11-L08-Q1 · What is OBSERVED in R1?
P11-L08-Q2 · Can R2 prove a November execution?
P11-L08-Q3 · How should R3's direction inconsistency be handled?
P11-L08-Q4 · What is exact vulnerable arithmetic status here?
P11-L08-Q5 · What would a transaction-level claim require?