AUTOfinance
AUTOfinance remains outside the current firm shelf because its structure falls within the delegated-allocation policy class. This is a firm-policy classification, not an adverse quality rating or a client trade instruction. The factual evidence on its mechanism, control, losses, and exits remains below.
- The Autopool enforces an immutable or client-specific allowlist and per-destination limits covering only currently approved venues
- Position-level holdings, LP inventory, debt, realized losses and executable withdrawal liquidity become continuously independently verifiable
- A separate non-discretionary wrapper fixes its exposure and cannot add or resize destinations after the client deposits
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-15.
The research file
Mechanism and class applicability
An AUTOfinance depositor selects an Autopool, supplies an asset, and receives a yield-bearing ERC-4626-style receipt share. The Autopool monitors a curated set of destinations. It rebalances idle assets into LP positions or swaps one destination LP position for another when its assigned strategy accepts a solver proposal. Rewards are compounded and may be redeployed somewhere other than their source. The v1 delegated-allocation dossier applies directly because venue exposure and weights change after the client deposits, and the holder cannot enforce a client-specific list of approved venues.
Current observation and look-through
The DefiLlama protocol API read on 2026-08-15 reported approximately $34.7M of AUTOfinance TVL across Ethereum, Base, Sonic, Arbitrum, Monad and Plasma. The protocol remains below the size floor, so its individual review will not open until it clears that floor. A more fundamental rule also applies. Current documentation identifies destinations for Balancer LPs, Aura-staked Balancer LPs, Curve LPs staked in Convex and Maverick boosted positions. A share therefore carries the contracts, assets, incentives, staking dependencies and AMM inventory loss of each destination, plus allocator-layer risk.
Control and strategy applicability
Each Autopool has a Strategy that decides whether a proposed rebalance meets configurable tests for return, slippage, and swap cost. A permissioned keeper collects rewards, and debt reporting revalues LP holdings at least daily. System registries list Autopools, destination templates, and vaults. The security design puts roles in an AccessController, allows local or system-wide pauses, and leaves SystemRegistry ownership for multisig and eventual governor control. These limits may constrain execution, but they do not let an advised holder freeze portfolio exposure to Ketju-approved destinations.
Loss and exit applicability
Rebalancing incurs explicit swap cost and slippage, while destination LPs retain their underlying impermanent-loss and integration risks. AUTOfinance says deposits have no ordinary lock or cooldown, and a holder may request withdrawal in a selected asset. The system may, however, need to burn destination LP units and swap the resulting tokens into the base or requested asset. Receipt tokens must first be unstaked. Price impact depends on destination liquidity, and global or local pause powers can suspend operations. “Withdraw anytime” therefore does not guarantee the displayed NAV or low-slippage proceeds under stress.
Why the shared dossier decides
The v1 delegated-allocation rule rejects AUTOfinance because the advisor cannot hold the client to a stable set of individually approved venues and limits while autonomous logic moves capital among destinations. A direct position preserves explicit venue selection and review triggers. A truly non-discretionary wrapper could be reviewed separately. Reopen only if the product enforces an immutable or client-specific allowlist and caps, while position-level holdings, LP inventory, debt, realized losses, and executable withdrawal liquidity remain continuously and independently verifiable.
Class rule
The delegated allocation class is outside the approved structures, so every protocol in it is not approved until the rule changes. The rule is about the structure, not an adverse finding about this protocol, and it is not a client instruction. The events that would reopen it are listed with the memo.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- AUTOfinance Docs — Autopools mechanism · primary · accessed 2026-08-15
Supports: Autopool receipt share, destination set, autonomous rebalance, LP optimization, auto-compounding - AUTOfinance Docs — current auto-rebalancing description · primary · accessed 2026-08-15
Supports: curated destinations, changing allocation, yield signals, rebalance costs - AUTOfinance Docs — Autopool system flow · primary · accessed 2026-08-15
Supports: solver proposal, LP-to-LP rebalance, permissioned keeper, debt reporting, reward redeployment - AUTOfinance Docs — strategy and rebalance controls · primary · accessed 2026-08-15
Supports: assigned strategy, slippage, return metric, swap loss, NAV test - AUTOfinance Docs — destination-vault integrations · primary · accessed 2026-08-15
Supports: Balancer, Aura, Curve, Convex, Maverick, LP withdrawal - AUTOfinance Docs — deposit and withdrawal · primary · accessed 2026-08-15
Supports: receipt tokens, no ordinary lock, unstaking prerequisite, withdrawal swap, slippage tolerance - AUTOfinance Docs — contract roles and pause controls · primary · accessed 2026-08-15
Supports: RBAC, SystemRegistry owner, global pause, local pause, NAV coordination - DefiLlama — AUTOfinance survey record, read 2026-08-15 · secondary · accessed 2026-08-15
Supports: current TVL, chain distribution, yield category, survey perimeter
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |
| Base | Approved with limits | Mixed control | Coinbase, one regulated US company, operates the only sequencer, and admin keys can upgrade bridge contracts within ~7 days. |
| Arbitrum One | Approved with limits | Mixed control | a single sequencer orders >99% of transactions and admin keys can upgrade bridge contracts on a ~7-day timelock. |
| Monad | Approved with limits | Governed, no freeze | the L1 has a public validator path, but its short production record, single initial client lineage, and Foundation-directed delegation keep stake and operations concentrated. |
| Plasma | Rejected | Issuer can freeze | the production validator committee is permissioned and the public docs still describe decentralization as a phased future rollout with no fixed access timeline. |