Counterfactual · 10 Oct 2025

What our engine would have done

On 10 October 2025, Aave liquidated 1,751 accounts across four chains. Every one of them is below, replayed through Membrane’s liquidation engine on the same measured prices, judged against its own liquidation line.

on-chain · 3,111 liquidation events · 2025-10-10T00:00Z to 2025-10-11T23:59Z

Before you look

When Aave liquidated one of these accounts, how much of the loan did it close?

Answered on 2,350 real accounts. Scroll to skip. Every figure stays on the page.

Pick your read

Run your position through Oct 10

Paste an address — the 10-11 Oct 2025 crash replayed minute by minute on its own protocol and on Membrane. Liquidated there, survived here.

→ /simulator

Check a venue's exit

Paste any address — its positions, stressed against recorded capacity and realized flow.

→ /radar

Find the spread

The measured board, exit costs priced in — the yield-hunter's whole picture on one page.

→ /carry

Watch the big books

tracked carry strats, auto-discovered on mainnet and stressed against recorded capacity

→ /strats

carry radar · recorded corpus · 2026-09-28

How much of the loan gets closed

Path-independent, so it holds whichever way the market goes next. This is the one to lead with.

Accounts

748

real, liquidated, priced

Aave closed

$34.7M

entire episode

Membrane would close

$22.2M

8h window, walked minute by minute

Difference

$12.5M

36.02% less debt closed

Same four numbers, unpriced collateral added back

Accounts

1,751

Aave closed

$47.5M

Membrane would close

$54.2M

Difference

$-6.7M (-14.13%)

1,003 of these accounts hold collateral this dataset cannot price, so they take one repay and can never cure — they carry the repay-to-cap upper bound with none of the 8-hour window it is being compared against.

Median share of the account’s debt closed

Aave — whole multi-hit episode

50.8%

Membrane — the 8h window, walked

49.5%

Aave’s side is its entire episode, every repeat liquidation included. Membrane’s is the 8-hour window walked minute by minute against the same oracle rounds, with the sale re-arming after each repay to cap.

Membrane closes less

347

46.4% of accounts — the borrower keeps more of the position

Membrane closes more

401

53.6% of accounts — Aave declined to fully close these; Membrane’s formula would have. Filter the cohort by “Membrane worse” to read them.

By collateral asset

Asset

Accounts

Aave median

Membrane median

Cured

i

WETH

435

64.4%

100.0%

73.56%

OP

353

99.8%

100.0%

n/a

ARB

235

99.9%

100.0%

n/a

LINK

191

57.1%

43.5%

n/a

AAVE

147

65.1%

100.0%

n/a

WBTC

115

50.0%

34.1%

85.22%

cbBTC

60

49.9%

30.8%

96.67%

USDC

52

65.2%

100.0%

0%

wstETH

38

50.0%

38.9%

89.47%

UNI

33

97.1%

61.5%

n/a

USDT

21

54.1%

76.3%

0%

Assets with fewer than 20 accounts are omitted. “Cured” is blank where the Oct 10 oracle series cannot price that collateral.

What this does not show

16

01

Account state is read at block_number-1 (genuine pre-liquidation), then REBASED to the liquidation-minute oracle print — collateral by p(t0)/p(t0-1), and debt too when the debt is not a stable — before any breach is decided. Without that rebase a fresh print landing between block-1 and the liquidating block is invisible, and the account looks healthy at the moment it was liquidated.

02

599 accounts are still not breached after the rebase, and are EXCLUDED from both sides of every total. Aave closed $96.8M on them. Something in the snapshot, the health factor or the minute-resolution price is wrong for those rows; the honest treatment is to drop them from both sides rather than count a $0 Membrane close as a win. They stay in the cohort flagged excluded so the table can still show them.

03

debt_fraction_repaid is per-RESERVE; Aave’s USD figure is valued from debt_to_cover_normalized x price instead.

04

wstETH is priced as (ETH/USD in force) x 1.215989, the MEASURED wstETH<->stETH wrap rate. It is NOT priced through the STETH/ETH market feed, which is what this builder did until this revision. Aave's own per-block prices, recovered from the liquidation CSV and agreed to 1e-6 by >= 2 users, give wstETH/WETH = 1.21598891 to 8 decimal places across blocks over which that market feed moved 0.99960 -> 0.96171: Aave never saw the depeg and no liquidation in this cohort was decided on it. The market-feed version added $32.07M to the priced Membrane total on its own, almost all of it two wstETH accounts it pushed past the band. See meta.sensitivity.wstethMarketFeedMembraneClosedUsd.

05

The pricing chain is CHECKED against Aave's own oracle, and it does not reconcile. 107 per-block prices with a feed are recoverable from the CSV; the median |residual| against the round this builder selects is 0.8009% and 0 of them equal ANY round in the log at ANY block. No block rule (N-2 / N-1 / N / N-with-log-index-filter) changes that, and the round log is internally complete, so the ETH/USD series in this dataset is not the series Aave read. meta.anchor publishes the distribution and meta.sensitivity.aaveAnchored rebuilds the whole cohort off Aave’s own level.

06

78 accounts (debt $11.0M) still hold weETH, rETH, cbETH, ETHx, osETH, cbBTC, tBTC or LBTC, for which this dataset ships no feed at all. The nearest major path (ETH/USD or BTC/USD) carries their ratio. Given the measured 4.4% staked-ETH depeg, that proxy UNDER-states their breach rather than over-stating it. Counts and debt are in meta.collateralMapping.classes.proxied.

07

1003 included accounts (debt $59.7M) have no collateral series of any kind. They cannot be walked: one repay at t0, no band, no cure. They are excluded from doc.debt.priced and added back in doc.debt.allIncluded, never silently blended into one figure.

08

The repay-to-cap is sized from the ORACLE value of the collateral and assumes the sale executes at that price, so on an illiquid leg it is an UPPER BOUND, not a forecast. It is deliberately not capped — a modelled haircut would be a second unmeasured assumption. See meta.cureModel.liquidityBound for the worked counter-example, where real liquidators absorbed a small fraction of what the model closes in one block.

09

A round in the liquidating block counts as in force ONLY if its log_index is below the LiquidationCall's own. Within a block the EVM orders logs by log_index, so a round that printed later in the block cannot be what the liquidation read. The previous rule counted every round in the block regardless of position.

10

111 accounts (debt $50.9M) were liquidated against more than one collateral symbol. The liquidated leg’s path is applied to the whole basket, which is an approximation for those accounts.

11

Cure analysis covers the assets the Oct 10 oracle series prices — ETH-like, BTC-like and stables. A stable leg is a flat 1.0 series, so a stable-collateral / volatile-debt account builds its ratio from the debt leg instead of being dropped.

12

The cure result is PATH-DEPENDENT. Oct 10 was a sharp wick with partial recovery. A window that keeps falling would not cure.

13

Membrane has no mainnet deployment. This models a protocol that is not live, run against real prices.

14

The timer is cleared INSTANTLY on a return under the line here, but both clearing paths (clearRecoveredTimer, saveByDelay) are permissionless calls that somebody has to make. meta.sensitivity.noEarlyClearMembraneClosedUsd is the corner where nobody ever does.

15

The venue recall is credited to no closed-debt total here — recall depends on a deployment that does not exist, so crediting it would be an assumption, not a measurement. Every account also carries membraneOneRepayUsd, so the delay window’s contribution is visible as a subtraction rather than asserted.

16

The cure field on each account remains the earlier BEST-LTV diagnostic over a fixed 8h look-ahead. It is not the walk: it ignores the band, ignores re-arming and is not what any dollar here is computed from. Read outcome / closedAtIndex / minutesToFirstCure / sales for the modelled result.

Method

Each account is judged against its OWN liquidation line, inverted from its measured health factor (LT = hf x debt / coll), after its block-1 state is REBASED to the liquidation-minute oracle print. No modelled per-asset LTV is used anywhere. Aave's side is its ENTIRE multi-hit episode; Membrane's is the delay window walked minute by minute, with the contract's repay-to-cap, its liqDebtMinimum floor, and re-arming after a sale. Accounts that are still not breached after the rebase are excluded from BOTH sides.

Borrow gap 3pp · lib/Constants.sol:30 · repay formula LiquidationEngine.sol:2204-2238 · cure window 28800s · liquidation-engine/src/contract.rs:52

Data compiled by Membrane.