A verified-participant lending market on Hemi.
BNQ is a non-custodial money market: verified users supply crypto to earn interest and borrow against collateral. The lending engine is unmodified Aave v3; BNQ adds a soulbound access layer and a fail-closed price oracle.
What is BNQ
BNQ is a permissioned lending market — a decentralized, non-custodial protocol where verified users supply assets to earn interest and borrow against their collateral. BNQ never holds user funds; all positions live in smart contracts on-chain.
Built on Aave v3
The lending engine — interest-bearing bnq-Tokens, debt tokens, interest-rate curves, health factors and liquidation mathematics — is Aave v3, one of the most widely used and audited protocols in DeFi. BNQ does not modify the core lending logic. What BNQ adds is an access layer:
- Every protocol action (supply, borrow, liquidate, flash loan) requires the caller to hold a matching access token — a non-transferable, on-chain "soulbound token" (SBT) issued per wallet after verification.
- Access tokens cannot be bought, sold, or moved. They attest that a specific wallet has been verified for a specific market.
- The permission gates can be opened per action class by governance if BNQ later transitions parts of the market to permissionless operation.
Why permissioned?
A verified-participant market enables use cases open pools cannot serve: institutional participation with counterparty assurances, jurisdictional compliance, and curated asset listings — while remaining fully non-custodial.
BNQ launches on Hemi mainnet (chain id 43111), an EVM network that settles to Bitcoin and Ethereum. The BTC-adjacent asset set reflects that focus.
Getting access
Before you can supply or borrow, your wallet must hold the matching access tokens. The app walks you through this the first time you connect — it is a real, ordered sequence:
- Connect your wallet. The app detects you don't yet hold access tokens and shows the Verify your wallet dialog.
- Sign one message. An off-chain signature — free, no gas, and it authorizes no transaction or spending. It only proves you control the wallet. The message lists the grants requested, the chain id, and a timestamp.
- The issuer mints your access tokens. BNQ's issuer verifies the signature (wallet, requested grants, message age, replay guard) and mints your SBTs on-chain in a few seconds. BNQ pays the gas.
- Done. The market loads and you can supply and borrow. You never repeat this unless new assets are listed.
Revocation
An access token for an asset in which you hold an active position cannot be revoked through the standard path — the contract checks your balances first, so routine administration can never strand your funds. A separate emergency revocation power exists for compliance cases, restricted to the protocol admin (a multisig) and logged on-chain. See Risks & FAQ for a frank discussion.
Using the market
BNQ works like Aave v3. If you've used Aave, everything here is familiar.
Supplying
Deposit a listed asset and receive bnq-Tokens (e.g. bnqHemiWETH) 1:1. They grow in balance as interest accrues — paid by borrowers of that asset. Withdraw any time, as long as your remaining collateral still covers your debts and liquidity allows. Only assets flagged as collateral count toward borrowing power.
Borrowing
With collateral supplied, you can borrow any borrow-enabled asset up to your borrowing power = Σ (collateral value × that asset's Max LTV). Every position has a health factor (HF):
- HF > 1 position is safe.
- HF ≤ 1 position can be liquidated.
Borrow interest is variable, driven by each asset's utilization. Stable-rate borrowing is disabled protocol-wide (deprecated upstream by Aave after its 2023 incident).
Liquidations
If your HF falls to 1 or below, a liquidator repays part of your debt and receives collateral worth the repaid amount plus a liquidation penalty. Between HF 0.95 and 1, at most 50% of a position can be closed per liquidation; below 0.95, up to 100%. On BNQ, liquidation is a permissioned role executed by a monitored service that scans positions continuously — not an open bot market.
Avoiding liquidation: keep a buffer — repay debt or add collateral as your HF approaches ~1.1. Price moves on volatile collateral can be fast.
Flash loans
The protocol supports Aave-style flash loans, but they are disabled at launch on every reserve and additionally gated by a FlashLoaner access token. If enabled later, the premium is 0.05%.
Markets & risk parameters
Six reserves are live on Hemi mainnet. Parameters reflect the current on-chain configuration; the authoritative source is the PoolConfigurator state.
| Asset | Collateral | Borrowable | Max LTV | Liq. threshold | Liq. penalty |
|---|---|---|---|---|---|
| hemiBTC | Yes | Yes | 73% | 78% | 10% |
| WBTC | Yes | Yes | 73% | 78% | 10% |
| WETH | Yes | Yes | 75% | 80% | 10% |
| USDT | Yes | Yes | 75% | 78% | 10% |
| USDC.e | Yes | Yes | 75% | 78% | 10% |
| HEMI | Yes | No | 11.11% | 15% | 10% |
HEMI at 9:1. HEMI is accepted as collateral at a deliberately conservative ratio — roughly 9 units of HEMI value per 1 unit borrowed (Max LTV 11.11%) — reflecting its volatility and market depth. It is collateral-only.
Interest rate model
Borrow rates are variable and rise with utilization. Below the optimal point they climb gently; above it, steeply, to attract liquidity back.
| Curve | Assets | Optimal utilization | Rate at optimal |
|---|---|---|---|
| Stablecoin | USDC.e, USDT | 75% | 4.5% |
| Volatile | hemiBTC, WBTC, WETH | 75% | 2.5% |
Supply & borrow caps
Every reserve launches capped, and caps are raised as liquidity forms. Current on-chain values: BTC assets 25 supply; WETH 500 / 150; USDC.e 2,000,000 / 1,500,000; USDT 1,000,000 / 750,000; HEMI 20,000,000 supply.
Planned assets, not yet listed: msUSD, VUSD, sVUSD, svetBTC and Beefy VUSD/crvUSD are configured but remain unlisted until each has an independently verified price feed on Hemi. They will appear only once their feed is live and has a demonstrated track record.
Oracles
BNQ's price infrastructure is designed to halt rather than misprice: if no sufficiently fresh price is available for an asset, reads revert and that asset's market pauses until a fresh price returns.
Price resolution order
- RedStone push feeds — primary. On-chain Chainlink-compatible feeds updated on a 0.5% deviation or at least every 6 hours.
- Pyth Network — backstop. If the primary is missing or stale, the oracle falls back to the asset's Pyth feed under the same freshness bound.
- Staleness halt — any price older than 8 hours is rejected. If no tier can serve a fresh price, pricing-dependent actions for that asset revert until feeds recover.
Feed assignment (live reserves)
| Asset | Primary source |
|---|---|
| hemiBTC, WBTC | RedStone BTC/USD |
| WETH | RedStone ETH/USD |
| USDC.e | RedStone USDC/USD |
| USDT | RedStone USDT/USD |
| HEMI | RedStone HEMI/USD |
Disclosure: hemiBTC and WBTC share the BTC/USD feed. A de-peg of one wrapper relative to native BTC would not be reflected in its price. Supply caps on these assets are sized with this in mind.
BNQ-operated feeds
For assets that will list once third-party feeds arrive on Hemi, BNQ operates its own on-chain feed contracts with safety enforced by the contract itself, not by trust in the updater: hard owner-set min/max price bounds, a per-update deviation cap (5%, or 10% for BTC-denominated assets), and fail-closed staleness. Re-anchoring after a large legitimate move requires the protocol admin (multisig) after human review.
Fees
BNQ charges no deposit, withdrawal, or account fees. Protocol revenue comes from three standard Aave v3 mechanics.
Reserve factor
A share of borrower interest goes to the protocol treasury; the rest goes to suppliers.
| Assets | Reserve factor |
|---|---|
| Stablecoins (USDC.e, USDT) | 10% |
| BTC (hemiBTC, WBTC) | 20% |
| WETH | 15% |
| HEMI (collateral-only) | 10% |
Liquidation protocol fee
When a position is liquidated, the liquidator receives the liquidation penalty; 10% of that penalty goes to the protocol treasury.
Flash loan premium
Flash loans are disabled at launch. If enabled, the premium is 0.05% of the loaned amount (0.04% to the protocol, 0.01% to suppliers).
Security & audits
BNQ's security posture rests on three pillars: an extensively audited foundation, a small and fully disclosed modification surface, and fail-closed operational design.
Audited foundation
The Aave v3 lending engine, secured by eleven third-party audit and formal-verification reports.
Disclosed surface
~1,550 lines of BNQ-specific Solidity, fully documented — no hidden changes to lending math.
Fail-closed design
No fresh price ⇒ the asset halts. Caps bound exposure. Reserves stay frozen until feeds prove out.
Inherited audits — the Aave v3 lending engine
BNQ's lending engine is Aave v3, unmodified in its core logic. aTokens, debt tokens, interest-rate strategies, and health-factor/liquidation mathematics are exactly the audited upstream code, which has secured tens of billions of dollars under these reports:
| Date | Auditor | Scope | Report |
|---|---|---|---|
| Nov 2021 | OpenZeppelin | Aave v3 core | Published |
| Jan 2022 | Trail of Bits | Aave v3 core | Published |
| Jan 2022 | ABDK | Aave v3 core | Published |
| Jan 2022 | PeckShield | Aave v3 core | Published |
| Jan 2022 | Sigma Prime | Aave v3 core | Published |
| Dec 2022 | PeckShield | Aave v3.0.1 | Published |
| Dec 2022 | Sigma Prime | Aave v3.0.1 | Published |
| Apr 2023 | Sigma Prime | Aave v3.0.2 | Published |
| Jan 2022 | Certora | Formal verification | Published |
| Dec 2022 | Certora | Formal verification v3.0.1 | Published |
| Mar 2023 | Certora | Formal verification v3.0.2 | Published |
Full report PDFs are distributed with the BNQ documentation package and are available from each auditor and the Aave protocol's published audit set. Stable-rate borrowing — the subject of Aave's 2023 incident and later removed upstream — is disabled on every BNQ reserve.
BNQ modifications — what we changed, exactly
The audits above do not cover BNQ's additions. In the interest of full transparency, this is the complete modification surface:
SoulBoundToken
Non-transferable ERC-721-based access token. Roles: Member (supply+borrow), Liquidator, FlashLoaner. Revoking a token with an open position is blocked on-chain; an emergency admin path is multisig-gated. UUPS-upgradeable by the admin.
PermissionedLendingPool
Extends the Aave v3 Pool: every user action checks the caller's access token. Four per-action-class gates can open the market to permissionless operation by governance. No lending math is modified.
AaveOracle (modified)
Adds RedStone (Chainlink-compatible) sources as the primary tier with a staleness threshold, Pyth as a bounded backstop, and fail-closed behavior: no fresh price ⇒ the asset halts.
BNQPriceFeed
BNQ-operated AggregatorV3-compatible feed for assets without third-party coverage on Hemi. Hard min/max bounds, per-update deviation cap (5–10%), owner-only re-anchoring, two-step ownership.
Independent audit — scheduled. BNQ's additions to the audited Aave v3 engine (~1,550 lines — the access token, permissioned pool, and oracle adaptations) have completed internal review and are covered by an automated test suite. An independent third-party audit of this layer is scheduled ahead of scaling, and its report will be published here.
Status & roadmap
- Internal review: completed July 2026, including live-chain state verification and a passing test suite over the SBT and price-feed guards.
- Third-party audit of the BNQ layer: planned before caps are raised for scale. Given the small scope, this is a focused engagement.
- Operational hardening before scale: admin/issuer/updater keys move to a multisig; per-asset caps enforced; new reserves stay frozen until their feeds have a track record.
Responsible disclosure
If you believe you've found a vulnerability, please contact the BNQ security team at the address published on the official BNQ site — do not open a public issue. Good-faith reports are appreciated and will be acknowledged.
Contract addresses
Hemi mainnet (chain id 43111). Verified against the live deployment. Explorer: explorer.hemi.xyz.
Core protocol
| Contract | Address |
|---|---|
| PoolAddressesProvider | 0x381D905bA4bc8378E09A910b4EDbC763A0F2dc92 |
| Pool | 0x5af1BaC695d38D6769EC4A6d031776C8A6AB0e1d |
| PoolConfigurator | 0xb7E0408DB9963b4Cddeb9680C1d6b7C6299b7d18 |
| Protocol oracle (AaveOracle) | 0xE3A477A8488dd5e4AB1b8624eBE7024A0257946E |
| Access token (SoulBoundToken) | 0xF2AD206F2e30EA84DB48FA318effbf01609DC594 |
| PoolDataProvider | 0xB3D711832d1cf0F03D34D74d8a560071d52319a3 |
| ACLManager | 0xACA0D936909Bf7fFD6eBC581b9e1E0b60156d5a5 |
Listed assets
| Asset | Underlying token |
|---|---|
| hemiBTC | 0xAA40c0c7644e0b2B224509571e10ad20d9C4ef28 |
| WBTC | 0x03C7054BCB39f7b2e5B2c7AcB37583e32D70Cfa3 |
| WETH | 0x4200000000000000000000000000000000000006 |
| USDT | 0xbB0D083fb1be0A9f6157ec484b6C79E0A4e31C2e |
| USDC.e | 0xad11a8BEb98bbf61dbb1aa0F6d6F2ECD87b35afA |
| HEMI | 0x99e3dE3817F6081B2568208337ef83295b7f591D |
bnq-Token and debt-token addresses per reserve are shown in the app on each asset's detail page.
Risks & FAQ
No lending protocol is risk-free. BNQ's material risks, plainly stated:
- Smart-contract risk. The engine is unmodified Aave v3 (eleven reports). BNQ's access layer and oracle adaptations are BNQ-specific and carry unaudited-code risk until the planned third-party review.
- Oracle risk. The system fails closed, but a wrong fresh price within the deviation bounds is a theoretical risk. hemiBTC and WBTC share one BTC/USD feed.
- Liquidation-coverage risk. Liquidations are permissioned and run by BNQ's monitored service; an outage during a sharp move could let bad debt accrue. Mitigations: continuous scanning, conservative caps, and the ability to open liquidation to the public.
- Liquidity risk. Withdrawals depend on unborrowed liquidity; high utilization raises rates sharply to restore it, but temporary delays are possible.
- Permission risk. The admin multisig controls listings, parameters, gates, and an emergency access-revocation power. Routine revocation is blocked on-chain while you hold a position; emergency use is logged on-chain.
- Network risk. BNQ runs on Hemi; a network outage or sequencer halt pauses the market.
FAQ
Why do I sign a message when connecting?
It proves you control your wallet so BNQ can issue your access tokens. It's free and authorizes nothing.
Are my funds custodied by BNQ?
No. Funds sit in the protocol's smart contracts; only your wallet can move your positions (liquidation excepted, as in every collateralized market).
Why can't I borrow HEMI?
HEMI is collateral-only by design; its volatility and pricing model don't support a borrow market at launch.
What's the difference between Max LTV and liquidation threshold?
Max LTV limits what you can open (73–75% of value, depending on the asset); the liquidation threshold (78–80%) is where the position fails. The gap is your safety buffer.
Is there a token or points program?
No protocol token exists. Anyone claiming to sell one is a scammer.