Aave Officially Launched: AI Can Read Positions and Prepare for Transactions, but the Signing Rights Remain in Users' Wallets
币界网
1h ago
Ai Focus
Aave Labs launched its official MCP Server on September 8th, with the address being mcp.aave.com. The AI assistant, which supports Model Context Protocol, can read real-time data from Aave V3 and V4 through a single connection. It is also capable of handling transactions such as deposits, loans, repayments, withdrawals, mortgage switching, reward claims, settlements, and exchanges. The most crucial restriction is that the transactions returned by the server remain unsigned, the private key is not held by Aave MCP, and the final authorization still lies with the user's wallet.
Helpful
No.Help

Aave Labs launched its official MCP Server on September 8th, with the address being mcp.aave.com. The AI assistant, which supports Model Context Protocol, can read real-time data from Aave V3 and V4 through a single connection. It is also capable of handling transactions such as deposits, loans, repayments, withdrawals, mortgage switches, reward claims, settlements, and exchanges. The most crucial restriction is that the transactions returned by the server remain unsigned; the private key is not held by Aave MCP, and the final authorization still lies with the user's wallet.

These interfaces transform the DeFi operations from web page buttons into natural language. Users can inquire about the health factor of a wallet, the returns on cross-network stablecoins, or request to prepare a deposit of 500 USDC. Instead of relying on training data or third-party encapsulations, the assistant obtains interest rates, limits, risk parameters, and position status directly from official tools. While this improves convenience, expressions that are incorrect also become more in line with real assets; therefore, permission design is even more important than the chat experience.

Official data and transaction construction reduce integration errors, but they do not eliminate market risks.

The reading tool covers chains, markets, reserves, interest rates, supply and borrowing limits, as well as the time series of APY, deposits, and loans. Position queries can return multi-chain supply, liabilities, overall health factors, eligible rewards, and transaction history. V4 also provides single-position health data and liquidity and accounting information at the Liquidity Hub level, allowing assistants to compare V3, V4 or to query both simultaneously.

Trading tools are not sent directly on behalf of the user. The `prepare_` tool returns a transaction request or EIP-712 type data, which is then signed by the user's wallet. The `preview_action` allows for a simulated operation in advance, providing a health factor after execution; the exchange process is also divided into steps such as quoting, preparing, submitting, and checking status. This layered approach helps to conduct checks before irreversible actions are taken, but users still need to be clear about the blockchain, assets, quantities, authorized recipients, and the minimum amount to be credited to their accounts.

Aave states that the server is based on Aave Kit, therefore the mathematical logic is consistent with the official interface, and approximately 17KB of reserve details are compressed into the fields required by a model of about 1KB. A smaller response size saves context and also reduces the chances of errors occurring in the model amidst a large number of irrelevant fields. However, being "of the same origin as the official interface" does not guarantee that market prices will not fluctuate suddenly, that oracles will not experience delays, that transactions will not be preempted, or that users will not misunderstand natural language before signing.

The unified entry point for V3 and V4 also requires a clear version specification. The same "deposit" or "loan" request may yield different results under different networks, market conditions, and risk profiles. When using all for comparison, the assistant should display the selected version and market, rather than just providing the highest APY. A higher yield may result from increased utilization, but it may also come with lower liquidity and higher exit costs.

User-controlled signatures are just the minimum requirement; simulation, limits, and continuous monitoring are also necessary.

Unsigned transactions can prevent the server from transferring assets on its own, but they cannot prevent users from executing incorrect transactions. The wallet interface should translate natural language intentions into readable summaries, highlighting limits on expenditures, unlimited authorizations, asset receipts, and changes in health factors. High-risk actions should require double confirmation, and batch transactions should allow for itemized display to avoid users only seeing a single message like "optimizing positions."

Simulated results also have time boundaries. They are estimated based on the block status, price, and liquidity at that time, and by the time the user confirms, the conditions may have changed. The system should display the simulated blocks, the validity period of the quotes, and the allowed slippage. If necessary, a re-simulation should be performed before signing. If the recalculated health factor or the amount received exceeds the threshold, the process should be terminated instead of continuing to use the old results.

The official example states that the agent can monitor the position when the health factor is below 1.5 and prepare for repayment, then wait for the user to sign off. This indicates that the current design is closer to "automatically detecting risks and semi-automatically generating actions," rather than unattended automatic handling. If the user goes offline, there is network congestion, or the collateral value drops rapidly, waiting for the user to sign off may still be too late. Institutions that require automation should design separate authorization scopes, guardian services, and emergency rules.

Connectors themselves must also be subject to security management. Enterprises should fix the official domain names, check for TLS, limit the tools that assistants can use, and record each read and request preparation. No external text should directly alter the payment address or transaction parameters. If an assistant also browses web pages, prompts on those pages could induce it to perform actions that do not align with the user's intentions; therefore, transaction tools must be isolated from untrusted content.

Governance queries also require a distinction between information and voting. MCP allows for searching proposals, returning the status of the quorum, and listing voting rights, but the model summary may overlook certain conditions or time windows. Users should still open the original proposal and on-chain data for verification before delegating or voting, and in particular, should not authorize indefinite proxy based on automatic summaries. Natural language interfaces are suitable for lowering the reading barrier but should not become a new intermediate layer that obscures the details of the protocol.

Aave MCP Server is already online and has replaced V3 and V4, but the official team also indicates that there are more features still in the works. It reduces the cost for developers to maintain two sets of SDK and to implement protocol accounting repeatedly, yet it does not turn DeFi into a risk-free natural language bank. The most valuable aspect is precisely that the server does not hold the keys: AI can be read, calculated, simulated, and prepared, while it is still up to people to decide whether to sign. Only when this boundary is clearly visible in the interface, logs, and permissions will convenience not come at the cost of losing control.

Tip
$0
Like
0
Save
0
Views 17
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
U.S. wholesale inventories rose to $958.9 billion in July: Sales are also growing; inventory pressure cannot be judged solely by the total amount
The U.S. Census Bureau released wholesale trade data for July on September 10: After adjusting for seasonal and trading day effects, wholesalers' sales amounted to $801.3 billion, a month-on-month increase of 0.8% and a year-on-year increase of 13.0%; inventory at the end of the month was $958.9 billion, a month-on-month increase of 1.3% and a year-on-year increase of 5.7%. Although the growth rate of inventory exceeded that of sales for the month, the inventory-to-sales ratio dropped from 1.28 a year ago to 1.20, indicating that the increase in total inventory did not automatically lead to a general backlog.
币百科
·2026-09-13 09:57:13
19
U.S. corporate applications fell to 531,700 in August: A 7.8% decline from the previous month, but that doesn't mean the startup boom has suddenly ended
The U.S. Census Bureau released statistics on business formation on September 11, showing that in August, after seasonal adjustment, there were 531,728 business applications, which is a decrease of 7.8% compared to the revised figure of 576,512 in July. This decline is quite noticeable, but since it follows a 8.1% month-on-month increase in July, it seems more like a fluctuation at a high level rather than a signal that entrepreneurial activity has entered a recession on its own.
币百科
·2026-09-13 09:56:20
19
Automattic confirms that Mullenweg will return to serve as CEO
Automattic Confirms that Matt Mullenweg will return to serve as CEO. Previously, the board of directors had pushed for his resignation, but subsequently, the company's management made contradictory statements.
TechCrunch
·2026-09-13 07:52:46
37
Altman claims that OpenAI will not go public in 2026
According to Sam Altman, OpenAI will not pursue listing in 2026.
TechCrunch
·2026-09-13 04:33:17
39
View More