Yearn Finance
Yearn V3 vaults are ERC-4626 allocators that assign debt among separately deployed strategies. Role holders can add or revoke strategies, set debt and reorder withdrawals. The infrastructure is capable, but depositors delegate the venue mix and take on every underlying risk. The delegated-allocation rule controls this judgment. It is not a rejection of any individual security.
- Publishes allocator mandates, curator accountability, and per-vault disclosure that let the delegation be underwritten
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-15.
The research file
Mechanism
A V3 vault tracks idle assets and debt assigned to strategies. Authorized roles add strategies, set and update debt, process reports and maintain the withdrawal queue. Each share therefore represents a changing portfolio, not one fixed underlying exposure.
Control and operating evidence
The reference contract defines separate ADD, REVOKE, DEBT, QUEUE, REPORTING, ACCOUNTANT and emergency powers. Yearn governance gives limited operating authority to multisigs, and ChainSecurity reviewed the V3 vault contracts. Those controls reduce implementation risk, but they do not give the client a specific mandate or create a fiduciary duty.
Exit consequences
Withdrawals draw first from idle funds, then from strategies in queue order. Execution can fail or return less than expected if a strategy cannot return funds promptly, bears losses or reaches a set loss limit. Exit quality therefore depends on the live allocation and queue when the holder withdraws.
Why the class rule decides
The advisor cannot enforce protocol-level exclusions if an allocator can add, remove or resize underlying venues. Giving that choice to another party also duplicates the advisor’s core allocation work. Review reopens for a vault with a limited published mandate, an accountable allocator, timely position reports, notice of changes and evidence from a stressed wind-down.
Class rule
The delegated allocation class is outside the approved structures, so every protocol in it is not approved until the rule changes. The rule is about the structure, not an adverse finding about this protocol, and it is not a client instruction. The events that would reopen it are listed with the memo.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Yearn V3 — reference vault contract and roles · primary · accessed 2026-08-14
Supports: reference vault contract, roles - Yearn Governance — YIP-75 V3 launch · primary · accessed 2026-08-14
Supports: YIP-75 V3 launch - Yearn Dev Docs — governance and operations · secondary · accessed 2026-08-14
Supports: governance, operations - ChainSecurity — Yearn V3 Vaults audit · secondary · accessed 2026-08-14
Supports: Yearn V3 Vaults audit
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |
| Base | Approved with limits | Mixed control | Coinbase, one regulated US company, operates the only sequencer, and admin keys can upgrade bridge contracts within ~7 days. |
| OP Mainnet | Rejected | Mixed control | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |
| Arbitrum One | Approved with limits | Mixed control | a single sequencer orders >99% of transactions and admin keys can upgrade bridge contracts on a ~7-day timelock. |