DeFiPunk'd

Mellow Protocol

3 deployments · $146.3M aggregate TVL · Onchain Capital Allocator

Deployments

Each deployment is rated independently. Pick one to see its rating, risk analysis, and stage.

TVL $120.4M
Type Onchain Capital Allocator
Chains Ethereum, RSK, Monad, Mezo
View on DeFiLlama ↗
Control criteria
Upgradeability Mixed Bug bounty Governance forum Docs docs.mellow.finance
About

Mellow Core provides institutional vault smart contract primitives for onchain capital allocation and yield generation. The protocol enables curators to deploy vaults with explicit risk constraints and defined execution surfaces across multiple EVM chains. Users deposit capital to receive vault shares while curators operate strategies across integrated DeFi protocols (Lido, EigenLayer, Symbiotic, AMMs) within pre-defined onchain constraints.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 86 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 10 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Mellow Core has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 86addresses
  • 0verified source
  • 0proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

Ethereumfactory0x0000…dc72discoveryfactory
Ethereumfactory0x0000…639fdiscoveryfactory
Ethereumfactory0x04b3…2c61discoveryfactory
Ethereumfactory0x2e23…2f1ddiscoveryfactory
Ethereumfactory0x41c4…159fdiscoveryfactory
Ethereumfactory0x4e38…dee3discoveryfactory
Ethereumfactory0x75fe…d011discoveryfactory
Ethereumfactory0x77a8…90f8discoveryfactory
Ethereumfactory0x952f…45d8discoveryfactory
Ethereumfactory0xa51e…e5a0discoveryfactory
Ethereumfactory0xaeeb…33c3discoveryfactory
Ethereumfactory0xbb92…9854discoveryfactory
Ethereumfactory0xe357…1659discoveryfactory
Ethereumfactory0xf722…6d45discoveryfactory
Ethereumfactory0xfd23…a5b2discoveryfactory
Ethereumfactory0xfe76…8421discoveryfactory
Ethereumgovernor0x9734…53eadiscoverygovernance
Ethereumgovernor0xb379…c80bdiscoverygovernance
Ethereumgovernor0xdc9c…2153discoverygovernance
Ethereumoracle0x0cdf…aaaddiscoveryoracle
Ethereumoracle0x1a40…cfcfdiscoveryoracle
Ethereumoracle0x624a…5b71discoveryoracle
Ethereumoracle0x7867…c151discoveryoracle
Ethereumoracle0x9d99…b838discoveryoracle
Ethereumvault0x277c…ccc5discoveryvault
Ethereumvault0x5e36…430bdiscoverytoken
Ethereumvault0x63a7…ec5cdiscoveryvault
Ethereumvault0x6ec0…5c7ediscoveryvault
Ethereumvault0x7207…f626discoveryvault
Ethereumvault0x7600…bb84discoveryvault
Ethereumvault0x8463…f93adiscoveryvault
Ethereumvault0x99a0…9d7ediscoveryvault
Ethereumvault0x9c95…46cediscoveryvault
Ethereumvault0xa1ee…dd00discoveryvault
Ethereumvault0xa8a3…3f36discoveryvault
Ethereumvault0xa8d3…4c48discoveryvault
Ethereumvault0xbeef…6abcdiscoveryvault
Ethereumvault0xdbc8…fe8ddiscoveryvault
Ethereumvault0xe12e…2657discoveryvault
Ethereumvault0xfa3c…1336discoveryvault
Mezofactory0x0000…aed1discoveryfactory
Mezofactory0x0000…4386discoveryfactory
Mezofactory0x0d63…67fadiscoveryfactory
Mezofactory0x3b62…a449discoveryfactory
Mezofactory0x4b2b…5172discoveryfactory
Mezofactory0x5310…42d8discoveryfactory
Mezofactory0x664b…a461discoveryfactory
Mezofactory0x6c3b…aa35discoveryfactory
Mezofactory0x7f2f…260ediscoveryfactory
Mezofactory0x9022…07a1discoveryfactory
Mezofactory0xbc14…1178discoveryfactory
Mezofactory0xe4db…13d7discoveryfactory
Mezooracle0xbb7e…4492discoveryoracle
Mezovault0x06ed…dcf8discoveryvault
Mezovault0x07af…131bdiscoveryvault
Mezovault0x807d…e0e0discoveryvault
Monadfactory0x0000…467fdiscoveryfactory
Monadfactory0x0000…2ebfdiscoveryfactory
Monadfactory0x52d5…dda8discoveryfactory
Monadfactory0x711f…58d0discoveryfactory
Monadfactory0x870d…f923discoveryfactory
Monadfactory0x9885…d716discoveryfactory
Monadfactory0x9fba…8ae7discoveryfactory
Monadfactory0xa64e…0a45discoveryfactory
Monadfactory0xafef…5105discoveryfactory
Monadfactory0xbbcd…b3dadiscoveryfactory
Monadfactory0xc5a5…2698discoveryfactory
Monadfactory0xda2a…29f0discoveryfactory
Monadfactory0xe08d…27efdiscoveryfactory
Monadfactory0xf429…e58cdiscoveryfactory
Monadoracle0x727c…0e88discoveryoracle
Monadother0x0000…6351discovery
Polygonfactory0xd3d0…4e1fdiscoveryfactory
Polygongovernor0x6609…6ccediscoverygovernance
Polygongovernor0x8ff3…99c6discoverygovernance
Polygongovernor0xc128…1f37discoverygovernance
Polygonvault0x0b45…315ediscoveryvault
Polygonvault0x13b0…f7ccdiscoveryvault
Polygonvault0x3af5…23aediscoveryvault
Polygonvault0xb376…b516discoveryvault
Polygonvault0xca7e…c66ddiscoveryvault
Rootstockoracle0x4652…bddbdiscoveryoracle
Rootstockother0x3075…4e37discovery
Rootstockother0x7011…7229discovery
Rootstockother0xafb0…48c5discovery
Rootstockvault0x97bb…42ebdiscoveryvault

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@mellowprotocol

Security

[defillama] Source: DeFiLlama
Audits
5 audits
Bug bounty
unknown
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Upgradeability
Mixed (some immutable, some upgradeable)

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC