DeFiPunk'd

Beefy

Yield Aggregator

TVL $121.4M
Type Yield Aggregator
Chains Ethereum, Base, Arbitrum, Binance, Fraxtal +35
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty immunefi.com Governance forum vote.beefy.finance Docs docs.beefy.finance
About

Beefy is a decentralized, multichain yield optimizer that automates yield farming across 40 blockchains. The protocol allows users to deposit crypto assets into vaults that execute yield-generating strategies through automated reinvestment (autocompounding), earning compound interest with minimal effort. The BIFI token (80,000 fixed supply) serves as the governance and revenue-sharing token, allowing holders to vote on protocol decisions via Snapshot and earn a share of protocol revenues through staking in BIFI Vault or BIFI Pool. The protocol operates across 37+ chains with treasury multisigs managing protocol assets and revenue distribution.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 32 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 14 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Beefy has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 36addresses
  • 4verified source
  • 0proxies
  • 0of 1 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-14.

alltreasury0x0374…78f3discoverytreasury
alltreasury0x03e7…3fd3discoverytreasury
alltreasury0x428b…b9cddiscoverytreasury
alltreasury0x6fce…df3fdiscoverytreasury
alltreasury0xa289…8c27discoverytreasury
alltreasury0xd38d…9358discoverytreasury
alltreasury0xdae7…f6c4discoverytreasury
alltreasury0xf24f…d30ediscoverytreasury
arbitrumBeefyVaultV70x0c08…b409TVL0x9a94…bdad
Arbitrumtreasury0x3f5e…7862discoverytreasury
Auroratreasury0x088c…8d83discoverytreasury
Avalanchetreasury0x26de…ceeddiscoverytreasury
avaxBeefyVaultV70x79a8…5732TVL
avaxBeefyVaultV70x7e74…0eeaTVL
avaxBeefyVaultV70xd1fe…bcb2TVL
Basetreasury0x1a07…c3cbdiscoverytreasury
Binancetreasury0x7c78…2141discoverytreasury
Cantotreasury0xf09d…ff75discoverytreasury
Celotreasury0xca80…a2fddiscoverytreasury
Cronostreasury0xa972…920fdiscoverytreasury
Emeraldtreasury0x8fd0…aedfdiscoverytreasury
Ethereumgovernor0x4697…5446discoverygovernance
Ethereumtoken0xb1f1…b1f1discoverygovernance
Ethereumtreasury0xc9c6…6041discoverytreasury
Fantomtreasury0xdff2…d2d2discoverytreasury
Fusetreasury0x1c12…599fdiscoverytreasury
Harmonytreasury0x5231…0389discoverytreasury
HECOtreasury0xdbb7…c9badiscoverytreasury
Kavatreasury0x07f2…ea6fdiscoverytreasury
Metistreasury0x0f96…d095discoverytreasury
Moonbeamtreasury0x3e7f…e81adiscoverytreasury
Moonrivertreasury0x617f…6551discoverytreasury
Optimismtreasury0x4aba…f4aediscoverytreasury
Polygontreasury0xe37d…218ddiscoverytreasury
zkEVMtreasury0x6fdf…3b29discoverytreasury
zkSynctreasury0x9f9f…2560discoverytreasury

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@beefyfinance
Governance forum
https://vote.beefy.finance

Security

[curated] Source: curated human overlay [:] Source: DEFI@home quorum
Audits
2 audits
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Voting token
BIFI Ethereum: 0xb1f1ee126e9c96231cc3d3fad7c08b4cf873b1f1
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC