New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Safe Yield? Navigating the DeFi Minefield — Engn33r | Yearn Finance

ETH Belgrade CommunityTue, Oct 6, 2026, 12:00 AM

Transcript

Okay, welcome. Thank you for joining. So, uh, here we see my title slide. And I guess I thought that a conference in the Balkans, it would be kind of dark humor and funny to have a title with the word minefield. Uh, but whether you think that's funny is up to you.

Okay. Uh, quick summary of what we're going to talk about today. Uh basically we're going to start with how yearn vaults work and how the logic can actually apply to every user of DeFi because the thought pattern is similar. And then of course when we talk about vaults and investment and funds in DeFi, we need to talk about risk because you don't want to be losing money. And we will examine how urine manages risk and maybe how this can even help you with some of the same tooling.

Let's see if I can switch slides here. There's probably a trick. Is there a trick for uh changing slides? Perhaps uh can we switch to the next slide? I

perhaps that is the trick. Yeah, let's see. Uhhuh. There we go. Okay.

Uh before we get into the actual content, uh very quick intro. I'm engineer. I read and write code. Uh I am at Year as you might be able to tell from my shirt. Uh and then previously I've been at Twine and Y audit.

Sort of used to do security stuff. Uh and having a security and paranoid mindset is very helpful in DeFi for basically anything you do. But now let's get to how how urine vaults work. Let's go back in time to the prehistoric era when dinosaurs roamed the blockchain. And this was before vaults and automation.

And what you had to do if you were getting yield is you put assets in a place and you get maybe reward tokens. You have to swap those tokens. It's a whole process. It is not easy. Everything's manual and uh yeah, you're basically banging rocks together.

Uh this was about 6 years ago. Um and now now we live in the future. Everything is very seamless. You deposit, you do nothing, you earn, you withdraw. Uh any reward tokens that you get automatically sold, swapped in the background.

You don't have to worry about it. Life is good. And what year is trying to do is provide this seamless experience uh with APY, diversify yield sources, rebalancing. But I have underlined the very crucial goal that some people forget. And this is something that we all have to be aware of in DeFi and that is don't lose funds.

Uh this is something which unfortunately we see often in the space. It is not a rare occurrence. That is a problem. U but this is the number one goal and it should be for any protocol. How does urine work?

Uh at a high level urine is a bit different than some yield sources in the space. If you are depositing into let's say a or Morpho, it's usually borrowing lending that gives you yield. Uh urine is a bit different because we diversify yield sources. We actually connect to different protocols. You are not just getting yield from one protocol.

Uh this offers a benefit where if one protocol's APY increases, we can rebalance to give you better yield and if another protocol's APY decreases, we can withdraw and we can give you better APY. So really the the thought logic of how your involves work, it's very similar to any DeFi user. You want high APY. You probably don't have all your funds in one place. In fact, show of hands, who has all their money in a single place?

Anyone? Anyone? No Bitcoin maxis. Okay. Um, so the the thought logic for urine vaults is the same for many users.

You want to diversify where your funds are. you want to manage it. Uh but what's different is you're in a team and the team has a risk team and a security team and these guys see things differently because the external protocols here look normal. This is how risk and security sees it. Uh these are not things to be taken lightly.

If you're putting funds somewhere and you don't know what's going on over there, they could disappear. So you have all these alarm bells, warning lights, like anything that you don't understand fully is a risk. But with that said, the risk and security team is extremely paranoid. So they really see all of DeFi like this. Uh which is not ideal.

But you want these people to manage your security and risk. You don't want someone who is very chill. You want the paranoid guy. And so when we are trying to come up with ideas for where to get yield, it's difficult because you want the high yield, but you want the low risk, but then maybe you want some high yield, but no, that's not low risk. So it's a bit of a a difficult decision.

And I would say in general, what urine has chosen is the the lower risk option at the expense sometimes of high yield. Um, but what's very crucial is that you understand the risks. And how do you understand the risks? You measure all the risks. But let's begin first with identifying the risks.

Now, I'm just going to simplify things. There's like security risk, which I'm sure you hear a lot about with hacks and bugs and all these problems. And then there's dependency risk. And we're just going to focus on dependency risk today because security risk is its whole own topic that we could have multiple talks about. In fact, we did on a different stage where I was MC.

But uh for dependency risk, I'm gonna first put this disclaimer because everyone loves disclaimers. You know, you get the legal team involved. And I have to disclaim that the following risk analysis is publicly available and free online and also open source. Uh we had no lawyers come up with this. I just thought it was funny.

Um, but this is the website and at a high level it has some colorful visuals. You can see a nice big number in the upper right. This is the score for flex, a relatively new protocol I recommend people look at. Has some interesting mechanics. And just for comparison, this one is all green.

Origin ARM, another product. Um, but let's look at the actual categories that were on that site. So we have audit and historical category. Here we look at security posture, code quality, the typical security audit stuff. And the second one we have centralization and control.

So this is governance. We have programmability. Um basically like how centralized is this? Uh third funds management. Uh is everything over collateralized?

How is that managed? Provability. Uh making sure it doesn't get undercolateralized if there's a DPEG. Uh liquidity risk. Number four, uh can you actually withdraw?

Like is is the money there to withdraw immediately? Uh finally, operational risk. Like is the team legit? Do they have documentation? Uh what are their processes?

Is is it legit or are they just winging it? And the reason that we chose these specific categories is we need to focus on edge cases because on a normal day, I think today's a normal day. I haven't checked the markets, but I think everything's good today. like we're not in a crazy liquidation cascade scenario or something. So everything seems perfect today.

Things are functioning. We don't see any massive issues. But on other days that will not be true. And that's the type of risk we need to be understanding the edge cases. Let's look at a very simple one.

Anyone recognize this this little chart? Hands up. Anyone? Anyone? Okay.

Might be a little bit familiar to some of you. Um this is a screenshot from a it's basically saying like uh how much borrowing is going on and let's just assume that this is setting the interest rate the amount of borrowing sets interest rate on a and if there's 100% of assets borrowed 100%. How do you withdraw? You can't because everything's borrowed. 100% of the funds are borrowed.

You can't withdraw. Now you might be getting some good APY but this is a scenario where if you want to withdraw you just can't you have to wait like uh it's not ideal and of course the system is designed to avoid this scenario but this is a problem we have to think about on any lending protocol basically and the risk team does see other stuff that we just choose not to look too carefully at because yeah when you see a protocol where governance can rug everyone it's not great. Um but this stuff is in existence in DeFi and you have to be careful. Okay, we found the risks. Now what?

We have to measure the risks. So who where can we put our money? Like where can we get this yield that's not going to go to zero? Uh we have to have some way of measuring this stuff. And what we've done at ern is we focused on onchain yield sources where we can see and understand every piece of the puzzle.

Uh this tweet is actually from a protocol that was mentioned in the previous talk where you could not see all the pieces of the puzzle and we all know how that ended. Um yeah when you have a tweet that includes advice from legal counsel it's generally a very bad sign uh is all I can say. So keeping things fully on chain this makes it possible to understand and follow like okay the funds moved from here to there. The code that's managing it is is this code. We can see and understand what's going on.

Now I mentioned the categories earlier but we've assigned different weights to these categories and this is all in an effort to reduce our overall risk. Uh now I'm not going to explain and justify the specific weights here but I do want to show some examples of what we consider higher risk and lower risk. So under collateralized loans basically bad debt. This is a higher priority than good quality documentation. We can work around the bad quality documentation.

The security stance of a protocol is more important than market depth for trading swapping of a token. Uh a very secure protocol is is an important thing to weigh. Uh external dependencies is more important than past performance. Uh like if it underperformed in the past that doesn't mean it's insecure. It might just be that it did underperform in the past and it'll do better in the future.

We don't know. Now, this risk evaluation process we go through is not static. We cannot do all the work in January and chill for the rest of the year. Doesn't work that way because the ecosystem is changing, the code is changing, the markets are changing, liquidity is changing. Even if the code doesn't change, the amount of tokens in circulation can change and the liquidity can change.

So we are constantly updating the analysis and reports that we do. Let's look at a few examples of some protocols where things have changed over time and risks may have changed. Athena, you may have heard of Athena. They had like few billion TVL at least last year. I think it's been on the decline since uh they were famous for having a delta delta neutral position that gives you very good yields, amazing yields actually.

Uh and that used to be what they were famous for. Now the exact same thing that had them become famous is only 2% of the assets in the protocol now. 2%. It's the smallest slice in this pie chart. And now they're doing other stuff.

But I really think the majority of people who think about this use this protocol have no idea that that's what's happening. So the entire risk posture of this protocol changed and how many people know about that like it's not being advertised. They don't want it advertised to be honest I would think even though this data is from their website. So understanding how fast the ecosystem changes is crucial to managing risk. Now another incident this is from last year I think around October uh Moonwell uh there was an issue with a price oracle um this is the sad tweet after the incident uh but this is the chart of the pricing and I would really like okay it might be very hard to actually see the numbers on the left hand side um but the left hand side of the scale the y- axis is actually logarithmic so it goes from one to about a million And you'll see there's a few vertical green lines.

I'll highlight them here for you. Oracle went from about one to 1 million for a few blocks. Didn't take long, but that's all it takes for a massive exploit to happen. Uh, and it's very unfortunate. I think anyone with half a brain can look at this and be like, well, the price shouldn't go from one to a million for just a second and then jump back.

like that's that's not how it should work. So you could have added guard rails like if it goes above 10 ignore and something that simple would have saved them. Uh but unfortunately this was a million dollar loss potentially 2 million I forget the exact number and how did this happen? Well the price oracle depends on multiple parties voting on the price or like contributing data. And in this case it was very close.

It was five against five. It was like a tie. But on a few blocks, the five that reported the 1 million value won. So when you have multiple people contributing data, you have to understand who are you relying on. And in this case, it's these 10 people, these 10 data providers.

Uh unfortunately, some of them either were malicious uh accidental uh problems with data reporting. Um but you're getting in a relationship with all these data providers if you're relying on them. And how many people think about that? Uh so yeah, very unfortunate incident, but this is how deep you have to go. You have to go to the root source of where the data comes from and make sure there's no risks there.

It's hard. We also have this tool to map dependencies like okay, this protocol sends money here. It comes from there. This is governance. It's pretty complicated.

How do we even know this works? It's it's tough stuff. Can we check the answers in the back of the book? There is no easy way. This is still a very new process.

Many teams are trying to figure it out. And unfortunately, one of the ways we can check is when we see this happen. When there's like a massive fire in crypto and we rated them as high risk, we're like, well, okay, we saw that one coming. Uh, at least that works. It's not a fun feeling because, you know, someone's losing money, but this is one check that we can use.

I would say what we see more of is actually a lack of this risk awareness risk knowledge. Has anyone seen this page on Morpho? Uh potentially it's when you visit Morpho and it's like the default interface and if you filter by USDC you will be greeted with uh many more than the seven options I have shown here. Uh but on the far right you will see different APY numbers. Now, a normal person would probably just filter by APY and take the highest APY, right?

It's all USDC. You have USDC you want to get rid of and get some yield. So, let's get the highest yield. Uh there's zero risk data here. The user is supposed to figure it out.

The protocol is not providing that. You're just given a list and like here you go. It's DeFi. Do what you want. That's what that's what you're supposed to do, I guess.

Um, but there's a lot of risk there. It's not advertised. And that's why this process that urine has come up with could be useful for anyone because actually thinking through these risks is a critical part of how anyone in the space survives in the long run. Now, we know that crypto is different than stratfi. Stock investors at minus 5, crypto investors at minus 50.

I think uh we're about in the minus 50 around now. So I hope you're all wearing your hat, your sunglasses, and staying chill. Uh but there is another level because in Tradfi, the idea of minus50 is is simply catastrophic. Like for a single asset, it's possible, but it's just catastrophic. Like the sky is just falling.

But in crypto, this is like we're chill. We've seen this before. Life is good. We just got to huddle. There is another level which is the minus 100.

Yeah. [sighs] And I don't know if we call this loser, but I'm going to call it loser. Uh, and this can actually happen in crypto. This is like the worst case scenario. And I don't think risk in the trady sense considers this at all.

Like minus 100% is unfathomable in trad practically short of a bankruptcy or something. But welcome to DeFi. We have these things. Uh so you have to be pessimistic when you think about stuff because this risk has a lot more downside and uh you have to be more pessimistic than normal. Um now speaking of pessimism and optimism, I'd like to throw in a quick local joke.

Uh what do you call an optimistic person in Serbia? Tourist. Yeah. Okay. Moving on.

Uh so for risk evaluation the the key thing is we don't have a good metric system a good measurement system in place and it's an open problem to compare different protocols because urine has risk analysis but that's different from risk analysis somewhere else and there's an opportunity here if you want to build vaultbe to compare different vaults different yield sources uh there is vaults.fyi FYI that attempts to at least compare the APY numbers in a cons consistent way because you can calculate APYs in many different ways, but we're still in the early stages. Uh because this stuff is hard. It's hard and it it's not a solved problem yet. Now, on to the last segment of the talk, monitoring systems.

Once you've figured out where your risk is and you've implemented a plan and you have funds deployed, you need to monitor for hacks, for incidents, for changes because we already looked at how change happens and you need to be aware of when change happens. Now, I don't know if anyone remembers these PES shield tweets. They used to be like non-stop a year or two ago, but there was even a joke about them. Uh, three certainties of life. Yeah, death, taxes, peck shield tweeting to take a look.

But uh if you don't remember this era of Twitter, that's fine. It's just a bad inside joke. Uh so we also have the monitoring system from urine public live free open source. Uh terrible things I know. Uh but we also have a telegram chat for it.

If you love getting spammed with all the changes on different protocols and risks and stuff, this channel is for you because man, I have like over a hundred unread things in this channel. Uh and I and they just keep coming. Uh but here's an example of some of the things we're actually monitoring. It's not just a single variable on one protocol. For Morpho alone, we have eight monitors.

Some of the other protocols, it's like 20 monitors for a single protocol. Um so we have bad debt ratio, market allocation. I'm not even going to read all of these, but it's all online. So you can take a look. Here are some examples of the alerts that trigger.

So we have a low liquidity warning. This might indicate that uh like people are withdrawing and perhaps we should consider withdrawing if everyone's trying to I don't know uh get their funds out after an incident or perhaps we just need to manage risk if there is a chance our users want to withdraw and there's not enough liquidity. Uh we also have governance proposals. We're alerted when like there's going to be a vote that could change how the Dow operates. Uh and then also large transfers like if there's a lot of money moving quickly this could be a signal for something happening.

So, a lot of these do require manual review. Like a large transfer doesn't actually mean that there's a problem. It could just be a guy with $10 million uh moving his funds. You never know. Uh I will say having these monitoring systems look kind of useless and annoying until you actually need them.

And I think people might remember the kelp a layer zero incident from April. Uh yeah, this is even from Forbes saying withdraw now. That's a pretty bad look for this space, I have to say. And then stream finance plunging uh massively last year. Uh yeah, I think all of you know these sort of headlines, but this this is why you want a monitoring system.

And if you're depositing into the same places as UR, you can leverage what UR has built and made open source. Here is UR's reaction from the uh the incident with RS ETH. Uh yeah, basically in April, we checked any exposure. No. Cool.

Back to business. And so this is what we also can rely on for checking if our risk analysis is accurate. Now, when things do go bad, you want to have emergency procedures. We also have these in place. I would argue urine was one of the first to push this idea of like emergency procedures checklist maybe back in 2021 or 22 when it was published.

Uh so yeah just planning for the worst because you don't want to be uh optimistic uh on chain. Yeah I think uh this space is very relaxing. Yes is all I can say. Yep. So in conclusion hopefully I am on time here.

Uh when it comes to risks the risks need to be identified and compared. You need to know what is a risk and what is not as important. You need to deep dive. You cannot just assume that these other protocols are doing what they advertise or what they should do. People are dumb.

Developers can also be dumb. It may come as a surprise to some of you. Uh but you know verify other people's work. Verify what's actually happening in the system. Deep diving is necessary.

Having standardized systems to manage this complexity. It's a complex world out there and no one's going to manage it for you. So having an approach for this is key. When you look at risk, you can't just deposit and forget about it because the risks will change over time. It's uh it's a constantly changing world.

And finally, having multi-layer defenses. Monitoring is definitely a key part of the picture. Uh even just understanding when funds are moving from your own wallet can be a very simple monitoring approach to use. Um but then monitoring the protocols that you rely on would be the next level. So that's all.

Thank you.

[applause]

Automatic transcript — names and jargon may be misspelled.