YielnaOpen

Credibility

What a badge means, and what it takes

A badge confirms that a protocol or pool meets every requirement below, verified against on-chain data and its public record. Protocols can earn green or gold; pools can earn green. Thresholds are not published, so they cannot be targeted. No badge means a requirement is not met or could not be verified.

Protocols

Green — first level

  • All contracts on record have published, verified source code.
  • No single key controls the protocol: admin actions require several signers, are held by on-chain governance, or do not exist.
  • Upgrades and parameter changes pass through a timelock, so users are notified before they take effect.
  • An operating history measured in months.
  • No unresolved exploit: users were repaid in full, or the incident is well in the past with none since.
  • Significant TVL, as reported by DeFiLlama.
  • Stable deposits, with no severe TVL decline in recent months.
  • A risk meter reading below High.

Gold — highest level

  • Every green requirement.
  • Stronger control: a larger multisig requiring broad agreement, or on-chain governance, behind a longer timelock.
  • An operating history measured in years.
  • No exploit, or every exploit repaid in full with a public post-mortem.
  • Continued operation through a market-wide stress event, such as the UST collapse, the FTX collapse or the USDC depeg.
  • TVL at a scale reached by few protocols.
  • A published audit by an established security firm.

Alternative paths

Some protocols cannot meet the standard control requirements by design. For these, the missing requirement is replaced by the protection that applies to their holders. Every other requirement still applies, and no path accepts an anonymous single key.

Tokenized real-world assets

Green and gold

The timelock is replaced by an identified issuer under a financial regulator and evidence that the assets exist: published reserve reports, or a licensed fund with its net asset value published. A multisig is still required. Assets that also have a timelock can qualify through the standard path.

Funds run by regulated institutions

Green · labelled issuer-controlled

The multisig and timelock are replaced by a regulated issuer, evidence that the assets exist, and redemption directly with the issuer. Regulation requires these funds to keep direct control of their contracts; the risk meter treats that key as a supervised institution's.

Products of major exchanges

Green · labelled custodial

The multisig and timelock are replaced by issuance from one of the largest regulated exchanges, published proof of reserves, and redemption directly with the exchange. Not eligible for gold, which requires self-custody.

Pools

Pools have a single badge level, green. It appears beside the pool's name, separate from its protocol's badge. Protocol badges have ten lobes; pool badges have eight.

Verified pool

  • Its protocol has no critical failure: no single-key admin, no unverified contract, no unresolved exploit.
  • Most of the yield comes from fees or interest, not token incentives.
  • An operating history measured in months.
  • Significant TVL.
  • Withdrawals on demand: no lock-up, cooldown, vesting, unbonding period or fixed term.
  • An identified price source: a named oracle, or prices from its own reserves or accounting.
  • No impermanent loss: it does not pair two tokens with fluctuating prices.
  • A risk meter reading of Low or Moderate.

How a protocol affects its pools

  • A critical failure blocks every pool. If a protocol has a single-key admin, an unverified contract or an unresolved exploit, none of its pools can be verified. Pools already verified enter the grace period, except after an exploit.
  • A missing protocol badge does not. A protocol that is new or not yet fully verified has not failed a requirement. Its pools are assessed on their own, and the pool page states that the protocol is not yet verified.

The risk meter

Every protocol and pool page has a risk meter reading Low, Moderate, Elevated or High. The Health page shows the same reading for each protocol, as a level and as a score out of 100.

Not enough data is shown instead of a level when too little can be established to place a reading.

Inputs

Contract soundness and history, control and governance, the source of a pool's yield, and liquidity. A protocol's reading covers the first two; a pool's covers all four.

Weighting

Weighted by the causes of past losses in DeFi. A serious red flag, such as single-key control, a very new pool, incentive-driven yield or impermanent loss, cannot be offset by strengths elsewhere.

Incomplete data

Each reading states its data coverage and names any input that could not be read. A reading is never Low while data is missing.

Role in badges

A protocol's reading must be below High; a pool's must be Low or Moderate. Badges are evaluated separately and do not affect the meter.

Validation

Tested against past failures using only information available before each event, and retested as new events occur.

Limitations

The meter measures structural and historical risk. It does not forecast returns or guarantee safety.

How badges are awarded and removed

  • Awarded only in full. A badge is granted only when every requirement is met and verified. A requirement that cannot be verified is treated as not met, and no badge is ever granted with an alert.
  • Grace period. If a badge holder stops meeting a requirement, including TVL, operating history, verified code, multisig control or the timelock, the badge stays for a limited time with an alert stating the issue and the deadline. If the issue is not resolved in time, the badge is removed.
  • Immediate removal. A badge is removed at once only after an exploit, or when a pool becomes exposed to impermanent loss.
  • Daily re-evaluation. Badges and risk readings are recalculated every day from on-chain data and public sources. No badge is granted manually.
  • Not a guarantee. A badge confirms the requirements were met at the last evaluation. Audited, well-governed contracts can still fail.

Request a review

Protocol and pool teams who believe a fact is incorrect or missing can submit a review request. Every request is read by a person. A request does not change a badge by itself; only corrected evidence does.

View badges in the app

Every protocol and pool page shows its audits, admin control, exploit history and risk reading, with or without a badge.

Open the app