DeFiPunk'd

Stake DAO Yield

Yield

TVL $147.6M
Type Yield
Chains Ethereum, Base, Fraxtal, Arbitrum, Polygon +5
View on DeFiLlama ↗
Control criteria
Upgradeability Mixed Bug bounty docs.stakedao.org Governance forum Docs docs.stakedao.org
About

Stake DAO is a DeFi yield protocol that boosts LP yield by accumulating deep governance power through Liquid Lockers — users deposit governance tokens (CRV, FXN, YB) to receive tradable sdTokens while Stake DAO permanently locks the underlying tokens to accumulate veCRV, veFXN, and veYB. This locked voting power is directed toward gauge weights for Boosted Strategies, allowing LP depositors to earn amplified APY without locking tokens themselves. The protocol also offers vlSDT (vote-locked SDT) for protocol governance and fee sharing, Votemarket for on-chain vote-incentive campaigns, and a Boost Marketplace where vlSDT holders can rent gauge-voting boost to sdToken holders. All protocol-critical parameter changes are subject to a 48-hour ProtocolTimelock, and guardians can immediately pause deposits (but not withdrawals) in emergencies.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 39 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 17 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Stake DAO Yield has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 39addresses
  • 0verified source
  • 0proxies

Arbitrumgovernance (GOVERNANCE)0xb055…c765discoverygovernance
Arbitrumtimelock (PROTOCOL_TIMELOCK)0xb27a…8e6adiscoverytimelock
Arbitrumtreasury (TREASURY on Arbitrum)0x5da0…6c17discoverytreasury
Basegovernance (GOVERNANCE)0xb055…c765discoverygovernance
Basetimelock (PROTOCOL_TIMELOCK)0xb27a…8e6adiscoverytimelock
Basetreasury (TREASURY on Base)0x5da0…6c17discoverytreasury
Ethereumadmin (PROTOCOL_CONTROLLER — governed by PROTOCOL_TIMELOCK)0x2d8b…d4fbdiscovery
Ethereumfactory (Curve LOCKER FACTORY)0xdc97…20aadiscoveryfactory
Ethereumfactory (Curve STRATEGY FACTORY — deploys per-pool strategy vaults)0xef9b…7fe1discoveryfactory
Ethereumfactory (PUBLIC_FACTORY_MONOLITHIC — lending)0xf863…b80fdiscoveryfactory
Ethereumgovernance (GOVERNANCE, Aragon voting app or multisig — actor_class unverified on-chain)0xb055…c765discoverymultisig
Ethereumguardian (ALL_MIGHT — admin bot/operator, present on Ethereum/Arbitrum/Base/Optimism)0x0000…5d05discoveryguardian
Ethereumguardian (ALL_MIGHT_V2 — admin bot/operator, present on Ethereum/Arbitrum/Base/Optimism)0xdbd2…506cdiscoveryguardian
Ethereumguardian (EXECUTOR_GUARD)0xff1c…a87ddiscoveryguardian
Ethereumother (BOOST_MARKETPLACE — on-chain boost order book)0xbc38…b6b8discovery
Ethereumother (DEPLOYER EOA)0x0007…ff62discoveryfactory
Ethereumother (LAPOSTE — cross-chain message relay)0xf000…01c2discovery
Ethereumother (MORPHO_BLUE — Morpho protocol integration)0xbbbb…ffcbdiscovery
Ethereumproxy_admin (PROXY_ADMIN)0xfe61…1b9bdiscovery
Ethereumtimelock (PROTOCOL_TIMELOCK, per-strategy Curve/Balancer/f(x) chains)0xb27a…8e6adiscoverytimelock
Ethereumtimelock (ProtocolTimelock, 48h delay, governs ProtocolController and strategy config)0xd3cf…1616discoverytimelock
Ethereumtoken (SDT governance/utility token)0x7396…db2fdiscoverygovernance
Ethereumtoken (VLSDT — vote-locked SDT governance token)0x9481…80b8discoverygovernance
Ethereumtreasury (L2_SAFE_TREASURY, used as TREASURY on L2 chains)0x5da0…6c17discoverytreasury
Ethereumtreasury (TREASURY, Ethereum main treasury)0x9ebb…f5c1discoverytreasury
Ethereumvault (Curve LOCKER — holds permanently locked veCRV; same address reused on Base/Fraxtal/Sonic/Taiko as LOCKER/GATEWAY)0x52f5…66b6discoverybridge
Ethereumvault (STAKEDAO_VAULT_FRXUSD_V2 — lending vault)0xce13…271ediscoveryvault
Ethereumvault (STAKEDAO_VAULT_USDC_V2 — lending vault)0x8edc…9e6fdiscoveryvault
Fraxtalgovernance (GOVERNANCE)0xb055…c765discoverygovernance
Fraxtaltimelock (PROTOCOL_TIMELOCK)0xb27a…8e6adiscoverytimelock
Fraxtaltreasury (TREASURY on Fraxtal)0x5da0…6c17discoverytreasury
Lineagovernance (GOVERNANCE)0xb055…c765discoverygovernance
Lineatreasury (TREASURY on Linea)0x5da0…6c17discoverytreasury
Optimismgovernance (GOVERNANCE)0xb055…c765discoverygovernance
Optimismtimelock (PROTOCOL_TIMELOCK)0xb27a…8e6adiscoverytimelock
Optimismtreasury (TREASURY on Optimism)0x5da0…6c17discoverytreasury
Sonicgovernance (GOVERNANCE)0xb055…c765discoverygovernance
Sonictimelock (PROTOCOL_TIMELOCK)0xb27a…8e6adiscoverytimelock
Sonictreasury (TREASURY on Sonic)0x5da0…6c17discoverytreasury

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@StakeDAOHQ

Security

[:] Source: DEFI@home quorum
Audits
15 audits
Security contact
https://docs.stakedao.org/bug-bounty

Technical

[:] Source: DEFI@home quorum
Voting token
SDT Ethereum: 0x73968b9a57c6E53d41345FD57a6E6ae27d6CDB2F
Upgradeability
Mixed (some immutable, some upgradeable)

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-09-07 11:30 UTC