Yearn Finance
DAMASCUSYield Aggregator · Multi-chain · $400M+ TVL · 20 contracts
Official site: yearn.fi ↗
838
3004756508251000
Confidence65%
Z-Factor0.91
Updated 2026-05-27Public scoreSecurity Profile
Access Control
80
80
Economic Soundness
82
82
Oracle Integrity
82
82
Compositional Risk
58
58
Governance
78
78
Maturity
90
90
Resilience
68
68
Supply Chain
80
80
Op Security
55
55
Cascade Exposure
100
100
Access Ctrl
80
80
Economic
82
82
Oracle
82
82
Compos.
58
58
Govern.
78
78
Maturity
90
90
Resilience
68
68
Supply Ch.
80
80
OpSec
55
55
Cascade
100
100
Min
55
Avg
77
Max
100
Audit History
Trail of Bits
2021-03
MixBytes
2022-06
ChainSecurity
2022-01
Bug Bounty Program
$200,000
Max payout on Immunefi
Assessment
Pioneer of yield aggregation, 75+ months live with zero core vault exploits. Strategy-level dependencies create composition risk but core vault architecture is proven. veYFI governance and community-driven strategy approval provide oversight.
Dimension Breakdown
MethodologyAccess Control
80Weight 18% · 78% confidence
+20Vault management permissions
+20Strategy approval process
+20Guardian for emergency
+20Multisig operations
Provenance
Economic Soundness
82Weight 13% · 80% confidence
+20Yield aggregation model proven
+20Performance fees transparent
+20Multiple strategy diversification
+20Withdrawal queue management
Provenance
Oracle Integrity
82Weight 13% · 80% confidence
+20Strategy-dependent oracle usage
+20Share price calculation from underlying
+20No direct oracle dependency in vault core
+20Strategy-level oracle risks
Provenance
Battle-Tested Maturity
90Weight 12% · 88% confidence
+22Live since February 2020 (75+ months)
+22Pioneer of yield aggregation
+22Survived multiple market events
+22Zero core vault exploits
Provenance
Governance & Upgradeability
78Weight 10% · 75% confidence
+20YFI governance proven
+20veYFI staking model
+20Community-driven strategy approval
+20Reasonably decentralized
Provenance
Adversarial Resilienceredacted
68Weight 10% · 72% confidence
- Strategy-level exploits historically
- Core vaults clean
- Active bounty program
- Multiple auditors across versions
Provenance
Operational Security
55Weight 10% · 60% confidence
-22No branch protection detected
-22CI/CD present but unstable (20% success)
+14Commit signing: 100% verified
+14SECURITY.md present (detailed)
Provenance
Compositional Risk
58Weight 5% · 65% confidence
+19Deep DeFi strategy dependencies
+19Strategies interact with many protocols
+19yVault composability across DeFi
-42Strategy failure cascades to vault
Provenance
Cascade Exposure
100Weight 5% · 55% confidence
+50Appears in 1 cross-protocol cascade chain(s)
+50Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
80Weight 4% · 78% confidence
+20Standard Solidity
+20Vyper for V2 vaults
+20Verified contracts
+20Strategy dependencies vary
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Operational Security
55+33.1 potential
No branch protection detected
Access Control
80+22 potential
Vault management permissions
Adversarial Resilience
68+21.1 potential
Compositional Risk
58+14.8 potential
Strategy failure cascades to vault
Economic Soundness
82+14.1 potential
Yield aggregation model proven
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.0weights v1.0evidence sha256:sha256:5...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "yearn"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("yearn")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/yearn?variant=card&theme=dark"
title="BlackHart Risk Index: Yearn Finance"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>