Neutral RiskAggregated DeFi Risk Intelligence
← All protocols

Yearn Finance

Yield / VaultAutomated yield vaults (v3).

$168.5M
TVL · DefiLlama
ETH $3,420 ▲1.2%YFI $6,420 ▲0.4%
price · DefiLlama (24h) · preview

AI review

AI

AI assessment

updated 4h ago·Claude (preview)·preview

Yearn Finance is a yield / vault protocol. 6 of 16 risk feeds in the registry report on it. 1 sourced incident on record. No material change has been detected in the current window.

  • Governance: YFI holder DAO; stewardship delegated to 'yChad' multisig (ychad.eth, 0xFEB4…aFF52) governance
  • 6 of 16 feeds report on Yearn Finance. coverage
  • Most recent recorded event: Legacy yUSDT (iearn) vault misconfiguration exploit. incident

AI-generated summary of facts already in this registry — not a Rails assessment, not a risk score, and not a ranking. Per the project charter, the registry never produces its own composite risk judgement. Verify every point against the linked sources below. This is an illustrative preview of a proposed feature; the content is not live.

Feeds

Feed coverage3 covered · 3 partial · 10 not yet covered of 16

How feeds see it

Rating
2 / 2
Dashboard
1 / 0
Monitoring
Research
0 / 1

Seen through 3 of 4 methodology lenses (rating, dashboard, research). A neutral view of who is looking and how — not a risk judgement.

Where feeds differ

The 6 reporting feeds are split on how fully they assess Yearn Finance: 3 assess it fully, 3 only partially, and they use different methodologies and scales. We show every position side by side and do not reconcile them into a single verdict — oracle diversity made visible, not adjudicated.

Philidor Analytics
Rating
Covered

Yearn v3 vaults; e.g. USDC yVault 7.50, Curve sUSD yVault 7.90.

Core (≈7.5–7.9 / 10)verified
View source
Zyfai Risk
Dashboard
Covered

Yearn mainnet USDT/WETH vaults graded live.

Excellent (most vaults)verified
View source
DeFi Safety
Rating
Covered

Process Quality Review of Yearn V2.

93% (PQR)sample
View source
LlamaRisk
Research
Partial

Protocol risk research and parameter recommendations; collateral and governance risk.

View source
DeFiPunk'd
Rating
Partial

Multi-dimension registry: Control, Exit, Autonomy, Open Access, Verifiability via LLM consensus.

View source
Exponential DeFi
Rating
Partial

Yearn appeared in the A-rated tier yet a "Watch out" label also surfaced pre-migration — conflicting; pending re-verification.

View source
DeFiScan
Rating
Not yet covered

Decentralization maturity: who controls keys, upgrades, and admin powers. Stage 0–2 framework.

BlockAnalitica
Dashboard
Not yet covered

Quantitative on-chain risk dashboards for lending markets: liquidations, collateral health, exposure.

CuratorWatch
Dashboard
Not yet covered

Vault-level risk monitoring for Morpho curators: allocation risk and curator behavior.

Credora
Rating
Not yet covered

Institutional-grade credit-risk ratings for DeFi protocols and borrowers. Credora by RedStone; GraphQL API + on-chain attestations (EAS).

Xerberus
Rating
Not yet covered

Independent risk rating for DeFi vaults; 300+ subscores across 85+ mechanisms. Open-source.

pigi.finance
Dashboard
Not yet covered

Vault analytics and risk-adjusted yield across 50+ protocols; exploits, concentration, risk-adjusted APY. Paid structured API.

DeFi Saver
Monitoring
Not yet covered

Position-management tooling: live loan-health / safety-ratio tracking and automated liquidation protection for leveraged positions.

Anticapture
Research
Not yet covered

DAO governance-capture risk: delegate/voting-power concentration, cost-to-attack vs. treasury value, and proposal/power-shift monitoring across major DAOs. Open-source.

Gauntlet
Research
Not yet covered

Agent-based economic simulation: insolvency prevention, parameter optimization, and risk-scenario analysis for lending markets.

Chaos Labs
Dashboard
Not yet covered

Edge risk oracles and economic-risk dashboards: real-time parameter automation and scenario stress for lending markets (active on Aave, GMX, Pendle).

Governance

Governance at a glance

Governance
DAO (YFI)
Multisig
6 / 9
Core contracts
Immutable
Pause capability
Yes

Structural facts, distilled from the sourced control records below — neutral capabilities, not a risk score. Multisig threshold and signer count are fetched live via the Safe API.

Governance
YFI holder DAO; stewardship delegated to 'yChad' multisig (ychad.eth, 0xFEB4…aFF52)verified
Upgradeability
v3 vaults are non-upgradeable — once deployed, vault logic cannot changeverified
Admin control
Per-vault role-based access; role_manager for Yearn vaults = yChad 6/9 Safe (0xFEB4…aFF52)verified
Guardian
yChad 6/9 acts as Guardian (veto only); EMERGENCY_MANAGER role can shut a vault downverified

Incidents

2023-04-13Legacy yUSDT (iearn) vault misconfiguration exploitverified

A deprecated 2020-era iearn yUSDT contract, misconfigured since deployment to reference iUSDC, was exploited to mint vast yUSDT and extract ~$11.6M. Yearn's modern v2 vaults were unaffected; funds were not recovered.

Material risk events, presented verbatim from cited sources — not a Rails assessment.

Audits

AuditorDateScope
ChainSecurity2023Yearn V3 Vaults (ERC-4626 system)Report
yAcademy2023-06Yearn Vaults V3Report
Statemind2023Yearn V3 VaultsReport

Representative public audits, attributed and linked to source — not a Rails assessment, and not a completeness or safety guarantee.