DeFiPunk'd

Yearn

3 deployments · $254.2M aggregate TVL · Yield Aggregator

Deployments

Each deployment is rated independently. Pick one to see its rating, risk analysis, and stage.

TVL $170.1M
Type Yield Aggregator
Chains Ethereum, Katana, Base, Optimism, Polygon +2
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty immunefi.com Governance forum gov.yearn.fi Docs docs.yearn.fi
About

<cite index="15-1">Yearn Finance is a suite of products in Decentralized Finance (DeFi) that provides lending aggregation, yield generation, and insurance on the Ethereum blockchain.</cite> <cite index="30-7,30-8">Yearn's V3 system is a decentralized suite of yield-generating products built to fit any need, designed to be un-opinionated and customizable infrastructure for the world to build on, making yield generation as safe, efficient, and easy as possible for all parties.</cite> The protocol operates through ERC4626-compliant vaults that allocate user deposits across strategies, with governance controlled by <cite index="3-10">a 6 of 9 Gnosis Safe multisig.</cite>

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 59 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 7 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Yearn Finance has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 59addresses
  • 0verified source
  • 0proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-14.

Arbitrumaccountant (V3)0x9ab4…f366discovery
Arbitrummultisig (governance, aChad)0xb6bc…56addiscoverymultisig
Arbitrummultisig (strategist)0x6346…5c0ddiscoverymultisig
Arbitrumrole manager (V3)0x3bf7…85b1discovery
Arbitrumtreasury0x1deb…08c1discoverytreasury
Baseaccountant (V3)0x1f39…7c8adiscovery
Basefactory (aerodrome)0x2d12…dff1discoveryfactory
Basehealth check (V2)0x8273…6fa2discovery
Basemultisig (governance, bChad)0xbfaa…b02ediscoverymultisig
Basemultisig (strategist)0x01fe…8e93discoverymultisig
Baseregistry (release, V2)0x697b…ccd3discoveryfactory
Baseregistry (vault, V2)0xf388…8ec5discoveryfactory
Baserole manager (V3)0xea34…d456discovery
Basetoken (YFI)0x9eaf…b239discoverytoken
Basetreasury0x02ff…3480discoverytreasury
Ethereumaccountant (V3)0x5a74…de69discovery
Ethereumcontract (TokenizedStrategy V3.0.4)0xd377…139cdiscovery
Ethereumfactory (curve LP)0x21b1…a17adiscoveryfactory
Ethereumfactory (role manager)0xca12…e5cediscoveryfactory
Ethereumfactory (vault registry)0xaf1f…3319discoveryfactory
Ethereumfactory (VaultFactory V3.0.4)0x770d…812fdiscoveryfactory
Ethereumhealth check0xddce…f012discovery
Ethereummultisig (core dev)0x846e…1cc9discoverymultisig
Ethereummultisig (governance, daddy)0xfeb4…ff52discoverymultisig
Ethereummultisig (strategist)0x1638…0ff7discoverymultisig
Ethereumprotocol address provider (V3)0x775f…653cdiscovery
Ethereumregistry (release, V3)0x0377…7198discoveryfactory
Ethereumregistry (release)0x7cb5…f1e2discoveryfactory
Ethereumregistry (V3 current)0xd40e…b038discoveryfactory
Ethereumrole manager (V3)0xb3bd…9a41discovery
Ethereumtimelock0x88ba…bf73discoverytimelock
Ethereumtimelock executor0xf8f6…779bdiscoverytimelock
Ethereumtoken0x0bc5…d93ediscoverytoken
Ethereumtreasury0x93a6…efdediscoverymultisig
Ethereumvault original (V3.0.4)0xd806…b00ddiscoveryvault
Fantomhealth check (V2)0xf13c…7fe0discovery
Fantommultisig (governance)0xc0e2…6767discoverymultisig
Fantommultisig (strategist)0x72a3…4a16discoverymultisig
Fantomregistry (V2)0x727f…9b04discoveryfactory
Fantomtoken (YFI)0x29b0…ec69discoverytoken
Fantomtreasury0x8971…b12adiscoverytreasury
Katanaaccountant (V3)0x1f39…7c8adiscovery
Katanamultisig (governance, kChad)0xe6ad…7162discoverymultisig
Katanamultisig (strategist)0xbe7c…7ae6discoverymultisig
Katanamultisig (V3)0x3333…97aediscoverymultisig
Katanarole manager (V3)0x4671…7417discovery
Optimismfactory (velodrome)0x8eb5…ff86discoveryfactory
Optimismhealth check (V2)0x3d8f…5296discovery
Optimismmultisig (governance, oChad)0xf5d9…b3a7discoverymultisig
Optimismmultisig (strategist)0xea3a…8b26discoverymultisig
Optimismregistry (release, V2)0x8129…05bfdiscoveryfactory
Optimismregistry (vault, V2)0x7928…c128discoveryfactory
Optimismtoken (YFI)0x9046…107bdiscoverytoken
Optimismtreasury0x8465…f954discoverytreasury
Polygonaccountant (V3)0x5448…4ceediscovery
Polygonmultisig (governance, pChad)0xc4ad…b626discoverymultisig
Polygonmultisig (strategist)0x1638…5bc1discoverymultisig
Polygonrole manager (V3)0x9bcd…61e2discovery
Polygontoken (YFI)0xda53…60b6discoverytoken

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@yearnfi
GitHub
yearn
Governance forum
https://gov.yearn.fi

Security

[:] Source: DEFI@home quorum
Audits
9 audits
Security contact
https://github.com/yearn/yearn-security/blob/master/SECURITY.md

Technical

[:] Source: DEFI@home quorum
Voting token
YFI Ethereum: 0x0bc529c00c6401aef6d220be8c6ea1667f6ad93e
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC

Hallmarks

  1. Jul '20YFI token Launch