Aave Seeks to Sunset Its Aptos Bug Bounty and End Cantina's Provider Role
Key Takeaways
- •Aave's new ARFC seeks to sunset the Aptos bug-bounty program for Aave V3 and end Cantina's role as provider.
- •A separate July proposal recommends freezing Aptos reserves and capping supply and borrowing at one to wind down new activity.
- •The Aptos deployment was launched with audits, a Cantina security competition and a bounty of up to 500,000 GHO.
- •The July market proposal reported about $1.7 million in supplied assets, roughly $719,000 in debt, and quarterly revenue below $1,000.
- •Both Aptos-related proposals are still awaiting governance approval and have not changed the live protocol configuration.

Aave's latest ARFC (Aave Request for Comments) asks the DAO to sunset the bug-bounty program covering Aave V3 on Aptos and to end Cantina's role as the program's provider. Aave is a decentralized lending protocol — among DeFi's largest by total value locked — where users supply assets and borrow against them; ARFCs are its forum-based proposal format, and substantive changes generally advance through community discussion and an on-chain vote before taking effect. The request arrives while the DAO is separately debating the future of its Aptos lending market, in discussions that cover both the market itself and the services that support it.
A bug bounty pays independent researchers for valid vulnerability reports. The practice is long-standing in software security and widely used across crypto projects, providing an ongoing route for security findings after a product goes live.
Two governance requests, different scopes
The Aptos discussion involves two separate Aave proposals.
The market proposal: a July ARFC on low-adoption markets recommends limiting new use of Aave V3 on Aptos while current positions are reduced over time.
The bounty proposal: the newer ARFC asks whether Aave should continue funding an Aptos-only bug bounty through Cantina.
The market proposal deals with deposits, borrowing and available liquidity. The bounty proposal covers rewards for researchers who report security issues. Both requests are awaiting governance approval, and the protocol configuration remains unchanged unless a later governance action implements either measure.
Why Aptos had a dedicated bounty
Aave launched on Aptos with a separate version of V3. Aptos is a layer-1 blockchain that uses the Move programming language, while Ethereum smart contracts commonly use Solidity.
According to Aave's launch announcement, the Move-based deployment went through audits, a Cantina mainnet security competition and a bounty offering up to 500,000 GHO, Aave's stablecoin.
Each measure serves a different purpose: audits examine code before or around a launch; security competitions give researchers a set period to test a project; and bug bounties reward valid reports while the program remains open.
Cantina, a security platform that runs audits, competitions and bounties for Web3 projects, published an Aptos scope covering Move modules, frontend components, APIs and deployment configuration, meaning the program covered the full Aptos product setup. Aave outlined this arrangement in its 2026 bounty-program restructuring proposal, which assigned Aave V3 on Aptos to Cantina while other Aave products used different providers.
Aptos market activity had already fallen
The July market proposal described a sharp decline in Aptos activity. At the time of publication, it estimated about $1.7 million in supplied assets and roughly $719,000 in debt. Available liquidity had fallen from around $18 million to $1 million over the previous six months, while quarterly revenue was below $1,000. These figures reflect the market conditions reported in July.
The proposal recommended freezing Aptos reserves and setting supply and borrow caps to one. Approval would block meaningful new deposits and borrowing while existing suppliers and borrowers reduce their positions.
The document leaves the bounty program's costs undisclosed, preventing a direct calculation between that expense and the market's decline. The lower level of activity nonetheless provides the backdrop for Aave's review of a dedicated Aptos security program.
What the proposals mean for users and researchers
For Aave users
The bounty proposal affects the reward program for outside researchers. Lending parameters, withdrawal access and borrowing conditions remain tied to the live protocol configuration and any separately approved market changes.
Users with an Aptos position should follow the market proposal and later governance decisions. Those measures would determine the timetable and limits for activity on Aave V3.
For security researchers
Eligibility follows the active terms published by Aave and Cantina. The ARFC asks to sunset the program, while the published scope and any approved closure terms determine which reports qualify for a reward.
Closing the bounty would close this public reporting and reward route for Aave V3 on Aptos.
The two Aptos plans now move together
Aave Labs recorded the release of Aave V3 on Aptos in its June 2025 development update. The launch introduced Aave's first deployment outside Ethereum-compatible networks and required its own codebase and security setup.
Approval of both proposals would narrow Aave's Aptos operations. The market would admit less new lending activity, and the dedicated public bounty through Cantina would close. The decisions concern Aave's own Aptos deployment, its activity levels and the operating work required to maintain it. The next steps to watch are forum discussion on each ARFC and any votes that follow, together with how the provider split set by the 2026 restructuring holds for Aave's other products.