Aave’s on-chain governance opened voting on November 5, 2023, on an emergency proposal to disable stable-rate borrowing across the decentralized lending protocol’s affected V2 and V3 deployments. The vote began at Ethereum block 18,508,878, timestamped 22:49 UTC, while temporary restrictions imposed after a critical vulnerability report remained in place.
Proposal 358 called for switching off stable-rate borrowing wherever it was enabled and unfreezing assets that Aave’s emergency stewards had frozen. It did not itself restore every paused market. Separate action by the Aave Guardian would still be required to unpause applicable pools, and the proposal had not been approved or executed when voting opened on November 5.
The development mattered beyond a routine parameter change. Aave was using token-holder governance to replace broad emergency controls with a narrower mitigation, exposing both the defensive capacity and the operational delays built into a decentralized lending system.
A precautionary shutdown preceded the vote
BGD Labs, an Aave DAO service provider, reported that Aave’s bug-bounty program received notice of a vulnerability on November 4. The issue was initially classified as high severity and then raised to critical. Contributors withheld technical details because Aave’s open-source V2 and V3 code had been reused by other protocols, making premature disclosure potentially dangerous.
The contemporaneous incident record said selected assets in Aave V2 on Ethereum and V3 deployments on Optimism, Arbitrum, Avalanche and Polygon could have been exposed to the attack vector. The Aave Guardian responded by pausing or freezing affected operations. BGD Labs said the measures blocked the identified route, that the vulnerability had not been exploited and that no funds were then at risk.
Those statements were representations by Aave contributors based on their investigation as of November 5, not an independent forensic conclusion. The precise flaw remained undisclosed, preventing outside observers from fully testing the claim.
What Proposal 358 would change
The proposal’s published specification instructed V3 pool configurators to turn off stable-rate borrowing for assets where it remained enabled. For Aave V2 on Ethereum, it called the corresponding function for disabling each reserve’s stable-borrow option. It also proposed unfreezing assets covered by the initial emergency measure.
Disabling that borrowing mode was presented as the direct defense because BGD Labs said the reported vector was not exploitable when stable-rate borrowing was unavailable. Existing debt was not described as erased or forgiven. Nor did the proposal guarantee an immediate return to ordinary withdrawals, repayments, collateral additions or liquidations in every affected pool.
The distinction between freezing and pausing was important. Freezing generally prevented new supply or borrowing while leaving some other actions available. A full pause stopped broader interaction with the affected market. Consequently, replacing a freeze with a targeted configuration change could reduce disruption, but paused pools still required a controlled reopening process.
Governance became part of the security perimeter
Aave’s response illustrated a recurring tension in decentralized finance. Public code and on-chain proposals make changes inspectable, but the delay between proposal creation, voting and execution can also expose remediation logic before it takes effect. Emergency guardians can act faster, although those powers introduce reliance on a limited set of authorized participants.
As of the close of November 5, the verified outcome was therefore procedural rather than final: Aave governance had begun considering a specific permanent mitigation, the broad safeguards remained relevant, and no completed repair or unrestricted reopening could yet be claimed. No reliable event-window dataset was identified that would isolate a market-price reaction, so no AAVE token, lending-rate or total-value-locked movement is attributed to the vote.
Later context
Proposal 358 subsequently closed on November 8 with 521,569 AAVE-equivalent voting power in favor and none recorded against, according to Aave’s governance interface. It was executed on November 9. Those later results confirm the proposal’s eventual adoption but were not knowable when voting opened on November 5.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

