Evidence-based risk context, not a safety rating or investment recommendation.
Last updated 2026-08-25
Observed risk summarizes available evidence. It does not predict probability of loss and is not an audit, guarantee, credit rating, or investment recommendation.
Contract age, audit evidence, bug bounty presence, exploit history, and identity verification.
Examples: Audit reports, deployment history, incident records.
Why it matters: Smart-contract flaws or unresolved incidents can cause loss even when rates look attractive.
Upgradeability, admin key type, timelocks, and pause authority.
Examples: Multisig admin, timelock duration, emergency pause scope.
Why it matters: Governance can change economics or halt markets after you deposit.
Oracle dependence, provider identity, single-source risk, and incident history.
Examples: Chainlink feeds, custom oracles, recent oracle manipulation events.
Why it matters: Oracle failures or manipulation can break markets independent of core contract quality.
Stablecoin classification, depeg history, bridged representations, and volatile exposure.
Examples: Fiat-backed vs algorithmic stablecoins, bridged wrappers, multi-asset pools.
Why it matters: Asset risk can turn stable yield into principal loss quickly.
TVL scale, recent TVL change, and historical coverage.
Examples: Thin pools, sharp TVL drawdowns, missing TVL observations.
Why it matters: Exit capacity affects whether you can leave when conditions change.
Reward share, current rate vs median, volatility, and promotional end dates.
Examples: Incentive-heavy rates, spikes above 30-day median, promotional tiers.
Why it matters: Headline APY may not persist if incentives or demand shift.
Product type complexity, impermanent loss, leverage, and restaking layers.
Examples: LP impermanent loss, vault strategies, restaking slashing exposure.
Why it matters: Complex strategies stack risks that headline APY does not show.
Operator identity, withdrawal terms, proof of reserves, and rehypothecation disclosure.
Examples: Centralized earn products, unclear withdrawal controls.
Why it matters: Custodial products introduce platform risk not present in noncustodial markets.
Lockup, unbonding, withdrawal queues, and whether material terms are known.
Examples: 30-day lockup, 14-day unbonding, unknown redemption terms.
Why it matters: Exit friction can extend beyond the APY horizon you are comparing.
External protocol dependencies, bridge reliance, and restaking layers.
Examples: Cross-chain bridges, stacked protocol dependencies.
Why it matters: Failures in dependent systems can affect products that appear standalone.
Field lineage, asset identity confidence, history coverage, and freshness.
Examples: Missing lineage, symbol-only identity, stale observations.
Why it matters: Risk and return summaries are only as reliable as underlying observations.
Risk concern and evidence confidence are separate.
Moderate observed risk with high confidence can coexist when strong evidence reveals meaningful concerns.
Yield.ly uses Unknown when material evidence cannot be verified instead of assuming a neutral value.
Oracle marked Unknown does not mean no oracle risk. It means Yield.ly could not verify enough information.
Risk methodology version: risk@1.0.0. Last updated 2026-08-25.