Beefy
Beefy is a yield aggregator that auto-compounds deposits across underlying farms, running hundreds of vaults across many chains; DefiLlama recorded about $102.7M on 2026-08-14. The breadth is the problem: deposits route across underlying venues, several on chains the firm shelf excludes, and the mix changes without notice to us. The aggregate brand is therefore not one stable economic claim: each vault requires separate underwriting of its underlying venue, strategy authority, loss path, and executable exit. This is a scope and evidence finding, not a judgment based on Beefy’s yield or aggregate size.
- Publishes allocator mandates, curator accountability, and per-vault disclosure that let the delegation be underwritten
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-15.
The research file
Mechanism
Each Beefy vault accepts a named deposit asset or LP receipt and issues mooTokens. Its strategy stakes that asset in a third-party farm, harvests reward tokens, swaps them and reinvests into more of the deposit asset. The aggregate slug spans money markets, native-token farms, LP farms and concentrated-liquidity managers rather than one economic claim.
Control and operating evidence
Strategists propose and maintain strategies; a developer multisig can schedule strategy changes after a timelock. Beefy documents per-vault testing, risk labels, public timelock monitoring and a panic function that pulls capital from a farm and removes allowances. These controls reduce operational risk but do not make future underlying allocations advisory-approved.
Exit consequences
Burning mooTokens requests the deposited asset from the current strategy. If the farm is liquid, the strategy withdraws it; panic can hold assets locally for exit. LP vaults return LP exposure unless a zap trades it, and any failed underlying, depeg, bridge or rejected chain remains embedded. Fees and swap slippage can reduce a one-asset exit.
Why the class rule decides
Depositors inherit the selected farm, reward routes, strategy authority and chain after deposit. Those changing dependencies prevent the aggregate Beefy brand from being underwritten as one stable claim. A named, static, capped, single-venue vault may be researched individually when its control, loss and exit paths can be evidenced.
Class rule
The delegated allocation class is outside the approved structures, so every protocol in it is not approved until the rule changes. The rule is about the structure, not an adverse finding about this protocol, and it is not a client instruction. The events that would reopen it are listed with the memo.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Beefy Docs — vault receipts, strategies and withdrawals · primary · accessed 2026-08-14
Supports: mooToken receipt, vault types, auto-compounding, withdrawal - Beefy Docs — strategy contract · primary · accessed 2026-08-14
Supports: third-party farm deployment, harvest, reward swaps, panic function - Beefy Docs — SAFU standards and strategy upgrades · primary · accessed 2026-08-14
Supports: vault testing, timelock, risk labels, emergency withdrawal - DefiLlama — Beefy survey record · secondary · accessed 2026-08-14
Supports: survey TVL, chain breadth, yield-aggregator category
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |
| Base | Approved with limits | Mixed control | Coinbase, one regulated US company, operates the only sequencer, and admin keys can upgrade bridge contracts within ~7 days. |
| Monad | Approved with limits | Governed, no freeze | the L1 has a public validator path, but its short production record, single initial client lineage, and Foundation-directed delegation keep stake and operations concentrated. |
| Arbitrum One | Approved with limits | Mixed control | a single sequencer orders >99% of transactions and admin keys can upgrade bridge contracts on a ~7-day timelock. |
| Avalanche | Approved with limits | Governed, no freeze | no party can freeze or seize C-Chain funds, but one vendor writes the only production client and Messari measured over a third of stake hosted on AWS. |
| BNB Smart Chain | Rejected | Issuer can freeze | the validator set concentrates around one company, and the chain has been halted by decision. |
| OP Mainnet | Rejected | Mixed control | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |
| Polygon PoS | Rejected | Mixed control | a public validator set orders transactions, but a 5-of-9 multisig can instantly upgrade staking and canonical bridge contracts, while a 5-of-8 controls custom child tokens. |
| Gnosis Chain | Approved with limits | Governed, no freeze | the chain validator path is permissionless, but its xDAI and canonical bridge exposure adds an 8-of-15 governor multisig outside the base consensus grade. |