Health Factors and Liquidations in DeFi Lending

Nobody is going to call you.
That is the single most important difference between borrowing against crypto on-chain and borrowing against anything else, and it is the one people underestimate. There is no margin clerk, no courtesy email, no grace period while you arrange a transfer. A contract checks a number, and if the number crosses a line, a bot you have never heard of repays part of your loan and takes a slice of your collateral as its reward. The whole thing takes one block.
The Bank of Canada has published transaction-level work on exactly this, looking at returns, leverage and liquidation dynamics on a major lending protocol. What follows is the arithmetic underneath it.
The position has three numbers, not one
Every collateralised on-chain loan is described by three parameters that the protocol sets per asset, and none of them are the interest rate.
Loan-to-value is the most you can borrow against a given collateral asset at the moment you open the position. Borrow up to it and you are at the ceiling on day one.
Liquidation threshold is the higher ratio at which the position becomes eligible to be liquidated. The gap between LTV and the liquidation threshold is your entire buffer, and it exists because the protocol wants a window in which you can react before it is forced to act.
Liquidation bonus is the discount a liquidator gets on the collateral it seizes. It is the incentive that makes someone bother, and it comes out of your side of the ledger.
Weaker collateral gets a lower LTV, a lower threshold and a larger bonus. All three move against you at once, which is why a position that looks conservative in blue-chip collateral can be aggressive in something illiquid.
The health factor is one division
Protocols express all of this as a single number. In the common formulation:
health factor = sum(collateral value * liquidation threshold) / total debt
Above 1, the position is fine. At or below 1, it is open season.
Work it through. Take collateral worth $100,000 with a liquidation threshold of 0.80, against a $60,000 debt.
(100,000 * 0.80) / 60,000 = 1.33
Now the collateral falls 20%.
(80,000 * 0.80) / 60,000 = 1.07
Another 7% and you are at 1.00. So a position opened at 60% LTV against 80% threshold collateral survives roughly a 25% drawdown, not the 40% the raw gap between 60 and 100 might suggest. That is the calculation people skip.
| Collateral value | Threshold 0.80 | Debt | Health factor | Status |
|---|---|---|---|---|
| $100,000 | $80,000 | $60,000 | 1.33 | Comfortable |
| $90,000 | $72,000 | $60,000 | 1.20 | Watch it |
| $80,000 | $64,000 | $60,000 | 1.07 | One bad hour away |
| $75,000 | $60,000 | $60,000 | 1.00 | Liquidatable |
| $70,000 | $56,000 | $60,000 | 0.93 | Being liquidated |
The figures are arithmetic from the formula above with parameters chosen for illustration. Real thresholds vary by protocol and by asset, and protocols change them by governance vote, sometimes on short notice.
What actually happens at 1.00
A liquidator repays part of your debt and receives collateral worth that repayment plus the bonus. Two design choices decide how much it hurts.
The close factor caps how much of the debt can be repaid in a single liquidation, often a fraction rather than the whole loan, which leaves you with a reduced but still open position. Some protocols allow the entire position to be closed when the health factor falls far enough.
The bonus determines the transfer of value. Repaying $30,000 of debt at a 5% bonus means the liquidator takes $31,500 of collateral. You are not being sold out at market. You are being sold out at a discount, and the discount is the point.
Add the two together and a liquidation is not simply a forced sale at a bad moment. It is a forced sale at a bad moment with a haircut attached, executed by whoever wins the race to your position. That race is the same competition for transaction ordering that shows up as MEV in an ordinary swap, pointed at your collateral instead of at your slippage tolerance.
The oracle is the real trigger
Your position is not liquidated because the price fell. It is liquidated because the price feed the protocol reads says the price fell.
That distinction has been the cause of more than one incident. A thin market, a manipulated feed, a stale update during congestion, and positions liquidate against a price that never existed anywhere you could have traded. The Bank of Canada’s analysis of DeFi oracles sets out the design space and the failure modes better than most protocol documentation does.
When I look at a lending position now, the oracle is the first thing I ask about, not the last. Which feed, how many sources, what happens when they disagree, and is there a circuit breaker. If the answer is a single price source, the collateral parameters are decoration. The design space, and how each version fails, is in oracles: the price feed that decides if you get liquidated.
Where the losses compound
Two mechanisms make a bad day worse.
Correlated collateral. If your collateral and your debt asset move together, you are less exposed than you look. If they move opposite, both sides of the health factor deteriorate simultaneously. Borrowing a stablecoin against a volatile asset is the standard shape and the standard risk.
Cascades. Liquidations sell collateral. Selling collateral moves the price, which is a function of pool depth as I set out in how an automated market maker prices your trade. A lower price liquidates the next position. The Bank of Canada’s work on the fragility of DeFi lending is essentially about this loop. It is why the drawdown that liquidates you is frequently not the one you modelled. The same loop runs on centralised venues, where a liquidation engine and a funding rate do the work the health factor does here.
Deciding what to do as the number falls
Health factor drifting toward 1?
│
├── Above 1.5
│ → Nothing urgent. Note where 1.00 sits in
│ price terms and write it down.
│
├── 1.2 to 1.5
│ → Decide NOW which lever you would pull, and
│ confirm you hold the asset to pull it with.
│ An intention is not a plan.
│
├── 1.05 to 1.2
│ ├── Can you add collateral? → Add it.
│ └── Can you repay debt? → Repay it.
│ Repaying moves the ratio faster per
│ dollar than adding collateral does.
│
└── Below 1.05
→ Assume you will not get a second chance.
Close or materially reduce the position.
Waiting for a bounce is a position, and it
is the one the liquidator is betting against.
Repaying debt is more efficient than topping up collateral, because the debt sits in the denominator undiscounted while collateral enters the numerator multiplied by a threshold below 1. On the numbers above, $10,000 of repayment lifts the health factor further than $10,000 of fresh collateral.
The part that is not mechanical
A liquidation is a disposition, and it happens at a moment you did not choose, frequently in a year you did not plan for. The treatment question is separate from the mechanics and I have dealt with the loss side of it in crypto tax loss harvesting in Canada. The broader picture of borrowing against crypto is in the surge in crypto borrowing, and the protocol-level questions belong in a due diligence checklist for a DeFi protocol.
My honest read: leverage on-chain is not more dangerous than leverage elsewhere because the maths is exotic. It is more dangerous because the enforcement is instant, indifferent and profitable to somebody else. There is no relationship to fall back on.
If you are carrying an on-chain borrowing position and want someone to check the arithmetic, the oracle assumptions and what a liquidation would mean for your return, send me the position details.
