CoinYQ Dossier

Yearn: the vault that kept changing its keyholders

Yearn promised to automate the exhausting hunt for yield. Its real history is a succession of control maps—controller, strategist, guardian, allocator, role manager and multisig—drawn around code that can never automate away loss.

The first machine moved stablecoins

In 2020, Yearn began as a practical answer to moving stablecoins between lending markets. A v1 vault held deposits, a controller routed capital and a strategy pursued yield.

The design compressed user work but concentrated policy in replaceable controller and strategy addresses. Even the old documentation warned that each vault differed and components could change.

A fair launch acquired a minting constitution

YFI launched with 30,000 distributed through liquidity mining and no founder, investor or sale allocation. Days later, mint authority moved from Andre Cronje toward a 6-of-9 community Safe with a three-day governance handover.

The scarcity story changed in February 2021. YIP-57 minted 6,666 for retention and treasury: roughly 2,222 vested for contributors and 4,444 for operations.

That was not a contract migration. The original token still has governance-controlled minters and no numerical cap, making future dilution a governance question.

v2 made one vault a portfolio

v2 removed the single controller pattern. A vault could lend debt to several strategies, aggregate their profit and loss, and unwind them according to a withdrawal queue.

Governance, management and guardian remained powerful. They could add strategies, tune debt, change fees and activate emergency shutdown. Keepers automated calls, but authorized humans set the envelope.

The share price became the truth

Depositors receive vault shares, not a fixed debt claim. Price per share rises with reported profit and can fall when a strategy realizes loss; external protocol failure, slippage and illiquidity pass through to recovery.

Emergency shutdown blocks deposits and asks strategies to return debt as quickly as practical. “Emergency” describes a control path, not a guarantee that a locked or insolvent external position exits immediately.

This boundary became concrete when the v1 yDAI vault lost about 11 million DAI in 2021. Treasury made users whole once and explicitly warned against treating that choice as insurance.

v3 divided authority into roles

v3 adopted ERC-4626-style accounting and separated vaults from tokenized strategies. ADD_STRATEGY, DEBT_MANAGER, REPORTING_MANAGER, emergency and fee roles can be assigned to different EOAs, Safes or contracts.

Debt allocators calculate targets and keepers submit transactions. The vault factory governs protocol fee settings and can stop new deployments; cloned vault logic avoids a general proxy-upgrade switch in each vault.

Permanent shutdown and withdrawal controls differ

A v3 emergency manager can irreversibly shut a vault, zero deposit capacity and gain debt-management power to pull strategies down. Strategy code has its own emergency admin and withdrawal paths.

The retrieved VaultV3 code checks a pause flag before redemption and enforces the configured withdrawal hook’s available limit. An emergency manager can change that pause flag. This conflicts with the reviewed technical specification’s statement that withdrawals cannot be paused; neither document alone establishes the live settings of every deployed vault. Even when a withdrawal is permitted, illiquid collateral, downstream pauses, oracle failure or accepted max-loss settings can constrain recovery.

Governance remained partly human execution

YIP-61 described constrained delegation: holders assign powers, contributor groups decide within domains, and yChad writes and executes transactions with veto power. YIP-81 extended veYFI rules but kept Snapshot until full on-chain execution.

Treasury policy moved too. YIP-56 replaced staking payouts with buybacks; YIP-65 aimed to reuse bought-back YFI for locking and rewards. Neither makes protocol revenue an automatic legal dividend.

An entityless protocol looked for a legal wrapper

Yearn began without an issuer promising redemption. YIP-87 later proposed placing yChad in an ownerless Cayman foundation BORG because signer duties, treasury custody and social execution lacked legal clarity.

The proposal itself says Snapshot decisions were executed by custom and social consensus, not an enforceable duty. Its checks and balances cannot turn YFI into equity or make every vault debt a foundation obligation.

The 2025 yETH exploit sharpened product boundaries: Yearn reported v2/v3 vaults unaffected and yETH self-governed by its depositors. A shared brand does not create a shared balance sheet.

How the project changed

  1. 2020-07
    Fair launch

    Thirty thousand YFI entered liquidity mining with no founder or investor reserve.

  2. 2020-07-21
    Mint power transferred

    A 6-of-9 multisig received governance while the founder removed himself as minter.

  3. 2021-01-15
    v2 remains experimental

    A January 15 community discussion described v2 vaults as experimental and still awaiting public release while audits continued.

  4. 2021-02-04
    yDAI exploited

    A v1 strategy interaction lost about 11 million DAI.

  5. 2021-02
    Supply expands

    YIP-57 executed the 6,666 YFI mint for contributors and treasury.

  6. 2021-06-29
    Disclosure prevents loss

    GenLevComp strategies were unwound after responsible disclosure.

  7. 2021-12
    Tokenomics evolves

    YIP-65 connected bought-back YFI to future locking and rewards.

  8. 2023-08-15
    v3 launch proposal

    YIP-75 proposed ratifying the v3 specification and endorsing deployment. Its August 15 publication is recorded here as a proposal, not proof of approval or completed launch.

  9. 2024-12
    On-chain governance prepared

    YIP-81 retained Snapshot while defining veYFI and Guardian rules.

  10. 2025-11-30
    yETH exploited

    A separate self-governed pool failed; v2/v3 vaults were reported unaffected.

Evidence and primary sources

Last evidence review: 2026-09-05

What is yearn.finance?

Yearn builds yVaults that accept an underlying asset, issue accounting shares and allocate capital to strategies. v1 used controllers, v2 let one vault hold several strategies under debt ratios and a withdrawal queue, and v3 split vault accounting, tokenized strategies and permissioned allocators into modular contracts.

YFI is the Ethereum governance token at 0x0bc529c00C6401aEF6D220BE8C6Ea1667F6Ad93e. Its famous 30,000-token fair launch was followed by a governance-approved 6,666 mint in 2021. The contract can still authorize minters, so 36,666 is governed supply, not an immutable code cap.

What problem does yearn.finance solve?

Yield strategies move through lending markets, AMMs, bridges and incentive systems whose rates and risks change. Yearn tried to make that work reusable: strategists encode positions, allocators set debt, and keepers call maintenance at useful times.

Automation does not remove judgment. Someone still approves a strategy, selects exposure, changes debt limits, reports profits and reacts to emergencies. Each vault’s share value depends on recoverable assets after fees and losses, rather than a promised deposit balance.

How does yearn.finance work?

In v2, governance, management and guardian roles add or revoke strategies, set debt ratios, order withdrawals and trigger emergency shutdown. Keepers execute harvest/report routines; they do not acquire ownership of funds. Shutdown halts deposits and recalls positions as market conditions allow.

In v3, a role manager grants granular permissions. Debt managers allocate to strategies; report roles accept accounting; emergency managers can irreversibly shut a vault. The reviewed technical specification says withdrawals cannot be paused, but the retrieved VaultV3 code differs: an emergency manager can set a pause that blocks redemption, and an optional withdrawal hook can limit the amount withdrawn. These are capabilities of that code snapshot; each deployed vault’s version and configuration require separate verification. External strategy liquidity can also affect recovery and loss.

YFI governance has moved among on-chain voting, Snapshot and veYFI delegation. The yChad 6-of-9 Safe executes and may veto. Treasury buybacks and rewards are policies approved and revised through this structure, not contractual dividends.

Key facts

  • YFI contract: Ethereum 0x0bc529c00C6401aEF6D220BE8C6Ea1667F6Ad93e, 18 decimals.
  • Launch distribution was 30,000 YFI with no premine, sale, founder or VC reserve.
  • YIP-57 minted 6,666 more: about one third vested retention and two thirds treasury.
  • YFI code retains governance, minter assignment and uncapped mint; 36,666 is not hard-coded.
  • v1 used separate Controller and Strategy contracts under governance.
  • v2 supports multiple strategies, debt ratios, withdrawal queues, management and guardian roles.
  • v2 emergency shutdown stops deposits and recalls capital, without guaranteeing lossless immediacy.
  • v3 uses role managers, debt allocators, keepers, accountants and tokenized strategies.
  • v3 shutdown is irreversible and stops deposits; the specification targets zero strategy debt, while the retrieved VaultV3 code can also block redemption through a pause or limit it through a withdrawal hook. Deployed versions must be checked individually.
  • Factory governance controls protocol fees, recipient and new-vault shutdown within code limits.
  • yChad is a 6-of-9 Safe that executes delegated decisions and has a Guardian veto.
  • A vault share, YFI or past reimbursement is not principal insurance or a corporate claim.

Official links

Categories

Related coins

Frequently asked questions

Is Yearn one pool?

No. Each vault has its own asset, address, strategies, roles, fees and risk. v1, v2 and v3 contracts also behave differently.

Was YFI capped at 30,000?

That was the launch supply. Governance minted 6,666 in 2021, and the token code still allows governance to appoint a minter.

What does a keeper control?

A keeper triggers eligible maintenance or reports. Strategy admission, debt limits, emergency powers and role assignment belong to other authorized accounts.

Can Yearn stop withdrawals?

It depends on the deployed version and configuration. The reviewed technical specification says withdrawals cannot be paused, whereas the retrieved VaultV3 code lets EMERGENCY_MANAGER set a pause that blocks redemption and applies any configured withdrawal-hook limit. Permanent shutdown stops deposits and supports debt recovery; it does not guarantee immediate, lossless access to external strategy assets.

Do buybacks pay every holder?

No direct payment is guaranteed. YIP-56 routed funds to market buybacks and treasury; later governance changed how bought-back YFI could support tokenomics.

Who owes depositors if a vault loses money?

The share contract determines recovery. The 2021 yDAI restoration was described as one-off; YFI holders, contributors and treasury are not a standing insurer.

External trackers

Choose a tracking site for yearn.finance: