YieldNest Max USDC: 0.79/1.00
✅ Why it's strong (the code):
- Clean ERC-4626 mechanics (receipt-token integrity 1.00/1.00)
- BeaconProxy verified
- non-custodial (curator can't touch deposits)
- EVC integration intact
- first-depositor + donation-attack protection
- 90% live utilisation
- LlamaRisk-operated curator.
One of the cleanest vault implementations on @eulerfinance V2.
⚠️ What could still improve (the operating envelope):
• Same multisig governs the supply vault, both collateral vaults, the underlying tokens AND the price oracle.
• Oracle has no fallback, single adapter, governed by the same multisig that sets the 90% LTV
• No pauseGuardian, no hookTarget, no supply or borrow caps → emergency response is fully manual
• Collateral is 365-day Australian private credit with no on-chain redemption until 2026 = liquidators must clear on thin secondary markets
The risk is that one operator holds every key on the loop, and nothing on the risk path fires automatically.
🔁 We corrected our own scorecard this week:
K_oracle_fallback_existence moved YES→NO after we read fallbackOracle() == address(0) on-chain
(dispute approved, confidence 0.92).
That's the standard working.
Full article below.
Full rating → https://t.co/3cT7JX1QzR
Had a amazing day @proofoftalk the quality of conversations and the attendees are all top notch. Privileged to attend with my colleagues from @xerberus
We will be around again for the second day, drop by to say Hi.
Immensely privileged to be representing @xerberus at Proof of Talk next week.
Swing round our booth to chat about how we are changing the game of risk in defi !
If you are a FoF, hedge fund, curator, vault platform or LP- we would love to chat!
Aave v3: 0.82/1.00
✅ Why it's strong (the code):
Governance-gated multi-chain deploys · deep audits + Certora formal verification · snapshot voting · real
supply/borrow caps.
One of the cleanest contract layers in DeFi.
⚠️ What could still improve (the operating envelope):
• Oracle reads raw Chainlink, but no on-chain staleness/deviation guard
• Emergency response is manual, as there are no automated circuit breaker
• Safety Module slashing has never once fired
• 1-token-1-vote, but~33% held by one entity
The risk isn't the code. It's that almost nothing on the risk path fires automatically.
🔁 We corrected our own scorecard this week: 3 findings moved NO→YES (0.79→0.82), a 4th challenge rejected.
That's the standard working.
Full article below.
Full rating → https://t.co/FjHMVRwCT3
@api3dao Core USDC on @Morpho : 0.83/1.00.
( read article for full breakdown )
Vault mechanics: clean.
Non-upgradeable, role-separated, Gnosis Safe Owner, 3-day timelock, forceDeallocate() backstop, Morpho Blue isolation.
Operating envelope: 3 holes.
1. Multisig with no proven signer independence
-->> Harmony Horizon pattern.
2. Fallback oracle drawing from the same Api3 provider set as the primary
-->> Synthetix sKRW pattern.
3. No pause(), no circuit breaker, no public pause-authority key -->> Nomad pattern.
Net APY ~2.07%.
That's the price of off-chain detection latency.
Full breakdown, methodology, and dispute here
→ https://t.co/FjHMVRwCT3
Proof of Talk at the Louvre (June 2–3) brings 2,500 institutional decision makers into one room.
We'll be participating to share how continuous, on-chain risk intelligence is needed for safer DeFi experiences.
If you're attending, drop a comment, and see you there.
xerberus joins Proof of Talk 2026 as a Silver Partner.
@xerberus is the risk rating protocol for DeFi vaults, building the infrastructure that makes onchain finance safer for the builders and capital deploying into it.
Based in London, the team is focused on one of the parts of DeFi most users never think about until something breaks. Independent, real-time risk scoring across vaults, with the kind of transparency institutional capital needs before it can underwrite onchain positions at scale.
The yield opportunity in DeFi is real, the risk surface keeps expanding, and the standardised, audit-ready risk infrastructure underneath has been missing.
At the Louvre, xerberus brings that risk-first lens into the room where the next generation of DeFi vaults, structured products, and onchain credit is being built.
10 days until the Louvre. Pass holders only.
https://t.co/ol4EWRsimW
Solid post from @Mars_DeFi!
One thing id add tho:
Every major DeFi incident this year, Kelp, Drift, the Uniswap V3 oracle issue on MegaETH, Aave’s oracle misconfig.
happened to protocols that had been audited, some multiple times.
—>> Audits are necessary, but not enough..
Continuous risk monitoring is the missing primitive, and it’s why “ratings” deserves its own tier instead of being folded into “security.”
Glad to see the category getting named.