Yearn OG USDC
Risk reportEthereum0xf9bd…ec49
Risk
Depositing into Yearn OG USDC means underwriting risks you usually can't see: how much you could lose, whether you'd get out in time, and what would cover it.
Collateral and oracle exposure
Each token you're exposed to, and the market it backs. If that market breaks, this is how much the vault loses, in dollars and as a share of the vault. Open a row for the price feed, stress curve, and supply-cap detail. Below, the oracles those prices depend on and what is at stake if one is compromised.
Driven by OETH −30% 6% · siUSD −30% 5% · PT-USD3-17DEC2026 −30% 3% · other 4% · −100% 90% modeled all-to-zero bad-debt ceiling
OETHMarketChainlink34%of vault · bad debt · $3.29mOracle exposure 4%37%of vault · $3.67m34%of vault · $3.29m4%separate path
What it's made of
OETH is priced via ETH / USD, quoted in USDC / USD — 2-hop market-rate feeds (Chainlink).
- → USDC86% LLTV0xe8ad…edb0Chainlink
If it breaks
−30% default
siUSDHybrid23%of vault · bad debt · $2.24mOracle exposure 3%26%of vault · $2.57m23%of vault · $2.24m3%separate path
What it's made of
siUSD is priced from an exchange-rate/NAV leg (Chainlink-formatted InfiniFi RT Oracle, Dummy feed with 12 decimals, ERC4626 vault share-rate) — no market-rate feed, so it tracks redemption value, not market price.
- → USDC92% LLTV0xd2cc…fa6d
If it breaks
−30% default
PT-USD3-17DEC2026Hybrid14%of vault · bad debt · $1.41mOracle exposure 1%16%of vault · $1.53m14%of vault · $1.41m1%separate path
What it's made of
Mixes market and exchange-rate inputs — partial depeg insulation, partial market exposure.
- → USDC86% LLTV0xe5e6…8d72
If it breaks
−30% default
USD3AUM / rate10%of vault · bad debt · $989,796.02Oracle exposure 1%11%of vault · $1.09m10%of vault · $989,796.021%separate path
What it's made of
Priced off an exchange rate / AUM — insulated from spot depegs, but exposed to rate-provider corruption.
- → USDC92% LLTV0x68b4…9c06
If it breaks
−30% default
cbBTCMarketChainlink7%of vault · bad debt · $690,939.94Oracle exposure 0.8%8%of vault · $765,312.647%of vault · $690,939.940.8%separate path
What it's made of
cbBTC is priced via BTC / USD — market-rate feed (Chainlink).
- → USDC86% LLTV0xa6d6…182aChainlink
If it breaks
−30% default
LBTCMarketRedStone / Chainlink0.8%of vault · bad debt · $80,832.96Oracle exposure 0.1%0.9%of vault · $85,757.350.8%of vault · $80,832.960.1%separate path
What it's made of
LBTC is priced via Redstone Price Feed × BTC / USD — 2-hop market-rate feeds (RedStone + Chainlink).
- → USDC86% LLTV0xdcc0…29dbRedStone / Chainlink
If it breaks
−30% default
YFIMarketChainlink0.7%of vault · bad debt · $68,070.71Oracle exposure 0.1%0.8%of vault · $75,633.640.7%of vault · $68,070.710.1%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC77% LLTV0x6370…4ad5Chainlink
If it breaks
−30% default
WOUSDAUM / rate0.1%of vault · bad debt · $11,690.92Oracle exposure <0.1%0.1%of vault · $12,989.420.1%of vault · $11,690.92<0.1%separate path
What it's made of
Priced off an exchange rate / AUM — insulated from spot depegs, but exposed to rate-provider corruption.
- → USDC92% LLTV0x7c65…7d80
If it breaks
−30% default+2 markets with no current position
Oracle dependencies
2 feeds · 2 control pointsUp to10%of vault drainable if these feeds are mispriced · $1.02m
Each price traces to a feed and the on-chain admin that can move it. Compromise either to misprice the collateral and borrow against it. Per-row amounts overlap and are not summed.
- Chainlink / RedStone·a 4/9 Safe multisigprices cbBTC, LBTC, stcUSD, tBTC, OETH, YFI0x21f7…73ca5% of vault · $460,352.09drainable if it is compromised
- RedStone / Chainlink·a 2/3 Safe multisigprices LBTC, weETH, stcUSD0x6906…4472<1% of vault · $5,373.06drainable if it is compromised
- Unidentified feeds· vendor and on-chain control not resolvedprices siUSD, PT-USD3-17DEC20265% of vault · $455,507.66mispriceable if these feeds lie
- On-chain exchange rate· no external feed or adminprices USD3, WOUSD1% of vault · $105,487.55mispriceable only via the issuing contract
Loss scenarios
Each row is a distinct failure, and every loss is a share of your deposit — the same percentage whatever you deposited. Loss is that share at a −30% collateral crash, the standard stress; Worst case is the ceiling if everything goes wrong, a conditional loss if it happens rather than a likelihood. Open a row for the loss at every crash depth, the dollar amounts, conditions, and the math.
| Full-deposit & protocol-level(2) | ||||
| 100% | Full deposit | Instant | ||
| 18% | up to 90% | Instant | ||
| Price-driven collateral stress(1) | ||||
| 18% | up to 90% | Instant | ||
| Oracle & liquidation failures(5) | ||||
| 18% | up to 90% | Instant | ||
| 18% | up to 90% | Instant | ||
| 3% | up to 26% | Instant | ||
| 5% | up to 23% | Instant | ||
| — | up to 10% | Instant | ||
| Vault role & allocator(4) | ||||
| — | Full deposit | 3 days | ||
| — | Full deposit | Instant | ||
| — | up to 50% | 3 days | ||
| — | up to 25% | Instant | ||
Trust and control
The people and processes that can change this protocol under you.
Vault operators
The roles that can actually move your deposit — the real principal-loss path.
Role timelock 3 days to exit before owner/curator actions land
Allocators4 · 2 contracts · 2 EOAsReaches deposit · instant
Moves funds between markets the curator has ALREADY approved — instantly, with NO timelock and no exit window. Cannot reach a brand-new market, but can concentrate you into an approved-but-stressed market or order withdrawals so you hit weak liquidity first.
- contract0xffb8…0862
- contract0xfd32…c75d
- single key (EOA)0x50b7…a8fa
- single key (EOA)0x75a1…780d
Audits
- Certora· Dec 15, 2025report
- Blackthorn· Dec 4, 2025report
- Spearbit· Dec 4, 2025report
- Blackthorn· Sep 15, 2025report
Governance & control
Protocol-wide governance: bounded context, not the path to your deposit.
Dependencies that can affect your deposit
10 things this pool relies on but doesn't control. Select one for its story.
Every Morpho Blue market chooses an immutable oracle contract at creation; implementations can be Chainlink-like, exchange-rate, fixed-price, or custom. Failure modes: attacker-favourable price feed (covered in market-oracle-compromise) or price() revert / staleness blocking liquidations (covered in oracle-liveness-or-malfunction).
No quantified loss scenario references this dependency directly.