defirisk.co
rubric v1.7.0

Empty cToken-style market (zero supply/borrow)

Sky Lending (formerly MakerDAO)'s assessment for RD-F-070 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Sky Lending is a CDP system (Vat-based), NOT a Compound V2 cToken-style lending fork. No cToken markets exist. The empty-market donation exploit precondition does not apply. N/A per taxonomy PD-024 (Compound-fork-only factor).

Detail #

The MCD Vat is an original design (profile §5: 'not forked / original. The dss repository is canonical source'). It tracks debt (art) and collateral (ink) per vault (urn) per collateral type (ilk) — fundamentally different from Compound V2's cToken share accounting. There is no totalSupply()/totalBorrow() per-market split that could be in a zero-supply state susceptible to donation exploit. The factor explicitly applies only to 'Compound V2-fork market' architecture per taxonomy §Cat 4 PD-024: 'Compound-fork-only (subset of lending-only): RD-F-070 — N/A for non-Compound-fork protocols'. The sUSDS ERC-4626 share vault raises first-depositor concerns addressed in RD-F-074 and RD-F-075, but those are not the cToken-style pattern this factor targets.

Sources #

  • Docs
    Sky Lending 00-profile.md §5 Fork lineageProtocol profile §5: original protocol, dss canonical source, not forkedretrieved 2026-04-27
  • Docs
    03-taxonomy.md §Category 4 PD-024 resolutionTaxonomy §Cat 4 PD-024: Compound-fork-only applicability note for RD-F-070retrieved 2026-04-27

Methodology #

Determine whether any listed Compound V2-fork market has `totalSupply == 0` and `totalBorrow == 0`, the precondition for a donation-exploit.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sky-lending factor RD-F-070 score gray collected_at 2026-04-28 00:43:18