Yearn Finance
Yield / Vault — Automated yield vaults (v3).
AI review
AI assessment
updated 4h ago·Claude (preview)·previewYearn Finance is a yield / vault protocol. 6 of 16 risk feeds in the registry report on it. 1 sourced incident on record. No material change has been detected in the current window.
- Governance: YFI holder DAO; stewardship delegated to 'yChad' multisig (ychad.eth, 0xFEB4…aFF52) governance
- 6 of 16 feeds report on Yearn Finance. coverage
- Most recent recorded event: Legacy yUSDT (iearn) vault misconfiguration exploit. incident
AI-generated summary of facts already in this registry — not a Rails assessment, not a risk score, and not a ranking. Per the project charter, the registry never produces its own composite risk judgement. Verify every point against the linked sources below. This is an illustrative preview of a proposed feature; the content is not live.
Feeds
How feeds see it
Seen through 3 of 4 methodology lenses (rating, dashboard, research). A neutral view of who is looking and how — not a risk judgement.
The 6 reporting feeds are split on how fully they assess Yearn Finance: 3 assess it fully, 3 only partially, and they use different methodologies and scales. We show every position side by side and do not reconcile them into a single verdict — oracle diversity made visible, not adjudicated.
Yearn v3 vaults; e.g. USDC yVault 7.50, Curve sUSD yVault 7.90.
Yearn mainnet USDT/WETH vaults graded live.
Protocol risk research and parameter recommendations; collateral and governance risk.
View sourceMulti-dimension registry: Control, Exit, Autonomy, Open Access, Verifiability via LLM consensus.
View sourceYearn appeared in the A-rated tier yet a "Watch out" label also surfaced pre-migration — conflicting; pending re-verification.
View sourceDecentralization maturity: who controls keys, upgrades, and admin powers. Stage 0–2 framework.
Quantitative on-chain risk dashboards for lending markets: liquidations, collateral health, exposure.
Vault-level risk monitoring for Morpho curators: allocation risk and curator behavior.
Institutional-grade credit-risk ratings for DeFi protocols and borrowers. Credora by RedStone; GraphQL API + on-chain attestations (EAS).
Independent risk rating for DeFi vaults; 300+ subscores across 85+ mechanisms. Open-source.
Vault analytics and risk-adjusted yield across 50+ protocols; exploits, concentration, risk-adjusted APY. Paid structured API.
Position-management tooling: live loan-health / safety-ratio tracking and automated liquidation protection for leveraged positions.
DAO governance-capture risk: delegate/voting-power concentration, cost-to-attack vs. treasury value, and proposal/power-shift monitoring across major DAOs. Open-source.
Agent-based economic simulation: insolvency prevention, parameter optimization, and risk-scenario analysis for lending markets.
Edge risk oracles and economic-risk dashboards: real-time parameter automation and scenario stress for lending markets (active on Aave, GMX, Pendle).
Governance
Governance at a glance
- Governance
- DAO (YFI)
- Core contracts
- Immutable
- Pause capability
- Yes
Structural facts, distilled from the sourced control records below — neutral capabilities, not a risk score. Multisig threshold and signer count are fetched live via the Safe API.
| Governance | |
| Upgradeability | |
| Admin control | |
| Guardian |
Incidents
A deprecated 2020-era iearn yUSDT contract, misconfigured since deployment to reference iUSDC, was exploited to mint vast yUSDT and extract ~$11.6M. Yearn's modern v2 vaults were unaffected; funds were not recovered.
Material risk events, presented verbatim from cited sources — not a Rails assessment.
Audits
| Auditor | Date | Scope | |
|---|---|---|---|
| ChainSecurity | 2023 | Yearn V3 Vaults (ERC-4626 system) | Report |
| yAcademy | 2023-06 | Yearn Vaults V3 | Report |
| Statemind | 2023 | Yearn V3 Vaults | Report |
Representative public audits, attributed and linked to source — not a Rails assessment, and not a completeness or safety guarantee.