P11-L08 · P11 · P11-M02
Evaluate a historical protocol claim with unresolved dependencies
Prerequisites: P11-L07
Learning objectives
- Evaluate a historical protocol claim with unresolved dependencies
- Write a claim-specific assessment of an official historical disclosure.
- Preserve unresolved implementation and attribution boundaries.
EN source master · P11-L08 · 30 minutes estimated · needs_review
Offline formative study. No wallet connection, real funds, private keys, signatures, live trade or personal portfolio inputs. Visuals are specifications; this is neither runtime content nor certification.
Why this matters
An official incident statement is strong evidence of what a protocol contributor reported, but cannot by itself prove every underlying security claim.
Explanation
Establish the historical package first
The separately committed package P11-L08-AAVE-DISCLOSURE-20231104-v1 contains two official forum publication records [INC, DEP], retrieved 2026-10-01. It is a selective paraphrase record, not a byte-identical archive. The case is Aave v2/v3's November4,2023 security disclosure, not an invented exploit.
Bound the mechanism claim
R1 records BGD's reported critical bug and stable-rate restriction; R2 records later described stable-debt creation restrictions and an offboarding proposal. The underlying exploit details and exact deployed code are absent from this package. R3 preserves a direction inconsistency in the later specification text; do not resolve it by guessing implemented behavior. The lesson assesses disclosure quality, not a vulnerable-code reproduction.
Separate time lanes
The November report and January31,2024 proposal have different information cutoffs. The currently retrieved thread can include revisions and later updates, so it is not authenticated as the exact November4 screen. Do not use January rationale as evidence available at the earlier decision time. A reported proposal is not an independently verified execution.
Test narrower claims
'Publication R1 contains a non-exploitation assurance' can be assessed from the retained statement. 'No exploit happened anywhere' cannot be authenticated by that assurance alone. Likewise, a protocol's safety language is attributed, not adopted as the Academy's verdict. A native-chain investigation is unnecessary for this publication-assessment objective, but transaction-level claims would require receipts, network and state provenance not collected here. No amount, address, loss or execution-time claim is invented.
Write a bounded conclusion
Pair each claim with record, time lane, evidence state, assumptions and missing material. The teaching inference is that restrictions should be checked against implementation scope before a stronger security conclusion. It is a review priority, not a proven mitigation audit. Preserve accepted P02-L08/P03-L07 boundaries elsewhere unchanged.
Key terms
- Official publication record: dated contributor statement, not automatic underlying-event proof.
- Attribution: keep a report attached to its speaker/source.
- Implementation gap: missing pinned code and state.
- Cutoff lane: claims restricted to what their dated record supplies.
Historical example
HISTORICAL package records R1 (Nov4 disclosure), R2 (Jan31 proposal/rationale) and R3 (later specification inconsistency). See docs/academy-2/datasets/P11-L08-AAVE-DISCLOSURE-20231104-v1.json. No chain transaction record is supplied; the selected source supports a disclosure assessment only.
Visual specifications
Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.
What the evidence proves
What the retained official publication records report, within their rendering and retrieval boundaries.
What the evidence does not prove
Independent non-exploitation, deployed mitigation correctness, actual transaction states, exact exploit arithmetic, losses, human identity or universal safety.
Evidence classifications
- OBSERVED: retained R1 contains the attributed disclosure statement; scope is publication content.
- INFERRED: the reported restriction makes implementation-scope review a useful next evidence question, assuming the report is relevant.
- UNKNOWN: exact vulnerable arithmetic and executed contract state in this package.
- INSUFFICIENT EVIDENCE: the publications independently prove all pools safe or that no exploitation occurred.
Common mistakes
- Upgrading contributor assurance into chain proof.
- Treating a proposal as execution.
- Resolving the inconsistent direction sentence by invention.
- Using later rationale at the earlier cutoff.
Practical exercise
Build four claim rows: report publication, review priority, exact implementation and global non-exploitation. Give state, source/record, time lane and missing evidence. Explain R3 handling and write a two-sentence bounded case conclusion without transactions or loss amounts.
Deliver calculations or annotations, claim/source table and limitations. Suggested allocation: study 12 minutes, exercise 8, correction/quiz 10; estimate subject to calibration.
Show worked correction
Publication-content claim: OBSERVED in retained R1 [INC], not independently verified event. Review priority: INFERRED from R2 [DEP], with attributed-report assumptions and Jan31 lane. Exact implementation: UNKNOWN; needs pinned versions, relevant state and verification. Global non-exploitation/safety: INSUFFICIENT EVIDENCE; a broad negative or security conclusion needs defined scope and independent investigation. R3 remains unresolved; no implemented direction is claimed. Conclusion: 'The retained Aave forum records describe a stable-rate security response and later offboarding proposal. This package evaluates those reports and their disclosure gaps; it does not authenticate executed mitigations or protocol safety.'
Formative rubric (5 points): reproducible inputs, correct method, correct result, claim-specific evidence scope, explicit limitations. Invented observation, advisory output or unsupported safety claim requires correction regardless of score.
Checklist
- Use frozen package and dated record.
- Attribute protocol assurances.
- Keep proposal and execution distinct.
- Leave missing code/state and text conflict unresolved.
- Require transaction provenance before adding chain claims.
Summary
The historical gate is satisfied for a bounded official-publication assessment. Underlying event and implementation assurances remain attributed and unverified.
Summary
- Write a claim-specific assessment of an official historical disclosure.
- Preserve unresolved implementation and attribution boundaries.
Next lesson
Program sequence complete. Return to curriculum for Controller-approved progression; no new program is implied.
Tools
NONE in the authoritative catalog. The supplied offline fixture/package is sufficient; no paid feature or unverified Production capability is required. Lab/certification metadata denotes downstream associations, not access gates or live awards.
Sources & claim boundaries
- [INC] BGD Labs on Aave governance — 4 November 2023 disclosure — Attributed bug report, stable-rate mitigation, non-exploitation statement and restricted disclosure; not chain proof. Checked 2026-10-01; locator turn10view0.
- [DEP] BGD Labs on Aave governance — 31 January 2024 follow-up — Attributed stable debt minting restrictions and proposal; source contains a direction inconsistency at specification paragraph. Checked 2026-10-01; locator turn13view1.
Visual specifications
P11-L08-V01
Evaluate a historical protocol claim with unresolved dependencies
Historical source rendering/report; boundaries remain attached.
Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.
Historical evidence panel: R1/R2 dated lanes, R3 unresolved-conflict flag; publication claim versus independent-event-proof columns. No fabricated chain timeline, receipts, loss chart or safety rating.
At 390px stack chart/table, assumptions, correction and source panel; provide complete text equivalent. Rendering pending.
RTL explanatory prose; numeric values, IDs and chronological axes stay LTR; preserve dependency directions.
P11-L08-AAVE-DISCLOSURE-20231104-v1
Sources & claim boundaries
INC · OFFICIAL_PROTOCOL_PUBLICATION
BGD Labs on Aave governance — 4 November 2023 disclosure
- Supported claim
- Attributed bug report, stable-rate mitigation, non-exploitation statement and restricted disclosure; not chain proof.
- Verification boundary
- Documentation supports mechanism only; fixture values are original stipulated inputs. Historical publications remain attributed.
- Checked at
- 2026-10-01
https://governance.aave.com/t/aave-v2-v3-security-incident-04-11-2023/15335
DEP · OFFICIAL_PROTOCOL_PUBLICATION
BGD Labs on Aave governance — 31 January 2024 follow-up
- Supported claim
- Attributed stable debt minting restrictions and proposal; source contains a direction inconsistency at specification paragraph.
- Verification boundary
- Documentation supports mechanism only; fixture values are original stipulated inputs. Historical publications remain attributed.
- Checked at
- 2026-10-01
https://governance.aave.com/t/bgd-full-deprecation-of-stable-rate/16473
Dataset provenance
id: P11-L08-AAVE-DISCLOSURE-20231104-v1
dataStatus: HISTORICAL
observedAt: 2026-10-01
timeBasis: Retrieval date, day precision; event dates are separately recorded.
source: Bounded frozen package in docs/academy-2/datasets; see provenance limitations.
scope: Official protocol-contributor publications only; selective dated paraphrases, no byte-identical archive, pinned code, native receipts, exploit reconstruction, loss reconstruction or independent non-exploitation proof.