Episode #7: YieldNest Finance

Listen to our latest episode featuring YieldNest and learn how supercharged vault architecture is bringing real-world yield on-chain while raising the bar for DeFi security.

In this episode, Nertila from Trading Strategy discusses with Deo and Dan from YieldNest. YieldNest is a DeFi protocol built as an on-chain alternative to traditional crypto funds, now grown to nine-figure TVL. Its site highlights the MAX vault architecture — a supercharged ERC-4626 standard designed for duration assets and multi-asset accounting — along with three live vaults spanning USD, ETH, and fixed-rate RWA yield.

Any questions? Join our community Discord server.

Transcript:

Intro: Welcome to TradingStrategy.ai, the podcast where you can learn more about the essentials of DeFi trading in the new world. This is your go-to show for automated trading strategies and market insights. Welcome to the conversation — this is your host, Nertila.

Nertila: Hello, everyone. Welcome to today's podcast. Different from previous conversations, this time we have two guests: Deo and Dan from YieldNest Finance. Welcome, guys!

Deo: Thank you for having us here. We're happy to be here and excited to get this conversation going.

Dan: Likewise — thanks for having us over.

Nertila: I'd love to hear more about you guys. What's your background, and how did you end up working in the crypto industry?

Deo: The first time I heard about crypto was around 2010, 2011 — a long time ago. Back then I was still a student and tried to experiment with it. I didn't fully understand it, but I got a little bit into it. Then in 2015, '16, I joined crypto more full-time.

At the time I was an IT consultant — my background is in computer science and economics — and it was like, "Wow, this is great," because crypto is finance and IT combined. So very quickly I quit the IT consultancy job I was doing in the Netherlands and started working for a crypto fund. That's how I got started.

From there, I developed a lot of interest and passion for decentralized finance, which I think is very important for the world — that we create systems that let us organize ourselves in more decentralized ways. That really motivated me to keep working in the industry through all the craziness we're going through right now, and have been going through. And then, instead of a more traditional fund structure, together with Dan I started YieldNest, which now offers something similar to what other crypto funds offer, but on-chain, in vaults. That's now all fully live. I have a passion for DeFi, and I still think it's very early days with a lot of work to do. So yeah — exciting.

Dan: In my case, it was pretty early in college when I started getting bothered by a trend we noticed in software related to the client-server model, and how most services online become very centralized. You'd look at Google, Facebook, Amazon — all these platforms that essentially control all your data. Execution of code is on their side, so you just have to trust that nothing bad ever happens. That seemed like a poor model for what are basically basic internet services — one that would eventually lead to some kind of censorship or top-down control.

I was fascinated with simple protocols that weren't even money-based, like BitTorrent, and I wanted to get into the crypto industry. But at that stage — probably 2014, '15 — it was really just the exchanges that were hiring, and maybe a couple of protocols here and there. I started working on some private, Ethereum-based blockchain projects around 2018, and then got a great chance to work in DeFi in 2020 on the Nexus Mutual protocol, which we built out to a nine-figure TVL.

That was really exciting, because it was DeFi summer — probably the most rapid growth DeFi has ever experienced. I've stayed in the ecosystem ever since and launched YieldNest in 2024. We've been going strong with it — more focused on the yield side of things, with some pretty cool products. We started out with restaking and hit nine-figure TVL with YieldNest as well, and now we're focusing more on generalized yield-generating vaults for ETH and USD, with our latest vault focused on RWAs.

Nertila: About YieldNest Finance — we'd like to know more about the venture and what you do on a day-to-day basis.

Dan: Day-to-day on my side, it's more of a focus on technology — you could say it's a CTO role. Realistically, we've been managing a team of different sizes and building out the YieldNest protocol and a front end users can interact with. That means building — and upgrading — smart contract systems that need to secure nine figures or more in value.

We went with a product-focused mindset, where we update our product and protocol over time to match market needs, and that has worked well. So day-to-day I'm mostly focused on that, plus general strategic moves in vault management for our top vaults — making sure yield is maximized, risk is minimized, and so on. And being very hands-on with building the on-chain protocol.

Deo: I'm involved in a bit of everything — the technical side, but also the whole operational side. DeFi is maturing and splitting into all these different lanes. My background is more on the research and analytics side, so that's what I bring to YieldNest: partnerships, integrations, making sure all our assets are working properly, thinking about what the next wave in DeFi will be and how YieldNest can play a role in it, and making sure all our vaults are safe and operational.

Nertila: When I was trying to schedule our meeting, you mentioned Real-World Assets and the TradFi–DeFi fusion several times. What are your opinions on these?

Deo: In the early days of DeFi — around 2019, when it was still called open finance — we already saw RWAs, right? I always make the joke that I refuse to get excited a fifth time about RWAs, because we've been there many times: "Hey, the herd is coming, the institutions are coming." My opinion is that it doesn't really matter. As an industry, we've built amazing infrastructure for creating new financial and vault products, for coordinating, and for finding new decentralized structures for forming capital around a shared goal. It's early days for the RWA side, but we've been there from the beginning. It was always, "Oh, now we get a Uniswap pool, or a CDP — a collateralized debt position — on MakerDAO, or a Curve pool, or lending markets." But how are we going to use that? With crypto assets, where is the real yield coming from?

In the beginning — remember the DeFi summer days — there were a bunch of protocols popping up, shitcoins everyone was farming around. I wouldn't necessarily call that real value creation, but it created money flows and APYs on-chain, and that persisted for some time. Then we had a big crash in DeFi, similar to what we're going through right now. What's important for the decentralized ecosystem and for our industry is that we find a way to bring real-world assets — uncorrelated yields — on-chain, get that live and integrated in DeFi, and not rely only on token incentives or token emissions, because that is coming to an end.

You need real productive capital on-chain that pays out different layers of the stack, and that's what we've been focusing on. The only challenge is that DeFi is used to instantly redeemable assets. It's very normal in DeFi to deposit a token and withdraw it a few blocks later — within ten seconds, basically. But that's impossible if you want productive capital. So we're trying to crack the nut of duration assets, and we do that with buffers and different techniques we can zoom in on later. I think it's really important for DeFi and for our industry to become more and more useful for the world: get real productive assets on-chain and integrate them into the amazing DeFi infrastructure we have today.

Dan: Those are all true things, and very well said. What I'd add is that RWAs are part of fulfilling the promise of the crypto industry: building a settlement layer for the financial world in a different, transparent way — one that prioritizes the user by creating bearer assets, yielding control back to the user, and giving more power back to the investor.

So I think it's absolutely key that we lock in certain ways of doing things — permissionless, non-KYC, maximizing the liberty that market participants have in these products. And we'll see how it actually plays out. We've focused primarily on yield — on private credit, which we can cover a little later. Essentially, it gives you a stable-value share in a vault that accrues yield over time, which is great. Other people are tackling price exposure, or — who knows — maybe at some point you even get some form of bearer asset for owning stocks. We focus on yield because I think it's the most accepted model and the most attractive in terms of risk and returns.

One more thing worth highlighting: beyond the great programmatic qualities and interoperability of the DeFi market — these components you can string together, combining lending markets with pools into a fast-flowing, transparent, composable financial ecosystem — we have a great opportunity to offer access to yield sources globally that you would otherwise never be able to tap into. Or it would be very difficult, because you face hurdles like: I'm not a citizen of country X, I don't have access to this particular business network, I don't have the right standing with this bank or financial institution — therefore I have no access to that opportunity at all.

That's what we've actually been doing with our RWA asset. We've opened up an investment opportunity that would be basically impossible to access for probably over ninety-nine percent of people on the planet. So I think there's a great opportunity there — one that's not just blockchain-focused, but enabled by our way of doing things.

Nertila: I'm curious about the liquid assets you're building with YieldNest.

Deo: YieldNest started with liquid restaking, now over two and a half, three years ago. That was the first step toward building a yield aggregator. Then with YieldNest we built our own vault architecture, which makes it possible to create our own vaults, with our own control over them and our own parameters. We know all the ins and outs of that architecture — that was the first step we took some time ago.

From there we created multiple vaults, and we're now focused on three: ynUSDx, ynETHx, and ynRWAx. Currently there's a USD yield from 5 to 15%, an ETH yield from around 3–4% up to 6–7%, and the RWA vault with a fixed 11% APY but a one-year maturity. Those are the three assets we currently have live, and we're building them out. It's a hard time in the DeFi markets in terms of liquidity — the ETH price has taken quite a beating — so the vaults are in a defensive mode at the moment. Once the market cools down, more buffer liquidity and redemptions will flow in. It's a different kind of vault structure and architecture than other people have, but it gives a higher yield and can integrate anywhere in DeFi. Maybe Dan also wants to say something about the vault architecture we built.

Dan: That was a good explanation. What I'd add is that we started out feeling the need for an evolution of the vault architecture. There was a premium type of implementation built by Yearn — and variations of it — for instant deposit-and-withdrawal vaults following the ERC-4626 standard. That was very good, and they did a great job in a lot of ways. But the adaptation we face now is that we're dealing with duration vaults, which have to impose some restrictions on withdrawals and redemption times. That's the new adaptation. In practice, we've also dealt with the need to manage multiple assets in one vault in an easy, seamless way.

So we built our vault architecture with these things in mind, while not running too far from the standards. If you look at our vaults, they still look a lot like a 4626, and they even have a buffer to offer users limited withdrawal capability within the size of the buffer. But on top of that, they have all these extra features — it's like a supercharged 4626. We call it the MAX vault. It can hold and price multiple assets in terms of a base asset, which is great for the price-stable type of vault you want to build. Say you have ynETHx: it's denominated in ETH and keeps accruing value in ETH. We've found this framework very reusable — the base vault is extremely reusable. It allows us to build our system and adapt to new things quickly, so it was pretty easy to get the RWA vaults going, and all sorts of other things. It's a great framework for that.

Nertila: Considering the current market conditions, and beyond the fallout of the bridge hacks, what do you think are the next steps the industry needs to take to get into a better position?

Deo: That's the big question, right? We're basically in a constant fight between attackers and defenders, and what we need to do is get our shit together. Knock on wood, but YieldNest has operated very well — we haven't had any major security issues, so far so good. We do that through many steps: anything we deploy goes through so many checks, and we have our own white-hat AI hacker swarm of agents that we use. Unfortunately, in DeFi and crypto, it went from "security is very important, and you need to spend a lot of time and money on it if you want to survive" to "you need to spend even more time and money on it."

That's unfortunate, but I do think the barrier to entry for these products has gone up a bit due to all the recent developments in AI and security. At the same time, I see a way forward — I don't know if Dan agrees with me or not — but the best way forward I see from here is more formal verification. I'm very happy with our MAX vault design; it's very minimal. In coding, and in security, less is more. You want very elegant code with a very low attack surface: little packages of information, isolated risk parameters, and very clearly defined components.

That's where we need to go as an industry. The bar went up because of AI, and we need to learn how to operate in that new environment without being too scared of it. There's a lot of fear out there — "oh, quantum," "oh, every protocol gets hacked." It's true, but at the same time there are also a lot of protocols that don't get hacked. So we need to get our shit together, do more checks, and try to stay ahead of the attackers.

Dan: If I may add to that: it probably takes everything we've got to solve this problem — stacking multiple types of solutions. Amadeo mentioned formal verification; that's already employed by a lot of protocols, and it's a practice we want to make an industry norm at some point. I also think DeFi still needs some type of insurance layer, and it needs to be more standardized. There are a lot of protocols and companies trying to tackle that problem, still looking for the perfect solution, and it's going to take some time to get there.

And I think we need to lean heavily into LLMs for this. They're massively over-hyped in a lot of industries, and there's going to be some displacement of jobs and so on. But aside from those narratives, realistically, attackers got a momentary boost, because their job is basically to find vulnerabilities and exploit them. The job of builders is to build and then secure the system — there's more effort required on the builders' side. So we need to lean into this heavily, because you need to counter-attack.

LLMs open up the opportunity not only to find vulnerabilities, but to surface all the details of a particular project or system in much more depth. We used to do these risk reports — we've done a bunch of collaborations with the LlamaRisk team, and Amadeo was a founder of that. What LLMs enable is doing that in a much more rapid, up-to-date fashion. We should have the ability to scan protocols and quickly compute their status in terms of access control, upgrades, and parameter changes — and flag anything that looks strange, poorly configured, or like a security risk.

Take the recent issue related to LayerZero, for example. Imagine that when you tried to deposit into the protocol that had the issue — or into Aave itself — you'd get a report that zooms in and flags the particular weak point across the stack: a poorly configured validator set, or, in the case of LayerZero, the misconfigured bridge. You could get these detailed reports. That's what LLMs are good at: processing a lot of data and flagging things.

So there's a lot of ground to cover, and we need an approach where we use all of these solutions together and stack them. Classic audits are still important. Then you can have automated audits that use LLMs. Then supervision systems and risk-report systems that analyze the whole stack — because the big problem with DeFi is that protocols stack onto each other and the risk compounds, but you don't have full visibility into the final outcome or how it changes over time. Not only do you have upgradable protocols that might introduce new problems on an upgrade; you can also have changing parameters, or access control that isn't solid. Maybe there's an EOA that controls some kind of power in the system — that would be the worst situation — or a multisig with a very low threshold. Ideally, we should be able to scan for those and flag all of them, because some are pretty low-hanging fruit.

And strengthening things like oracles — there's a lot of ground to cover there as well. Even state-of-the-art protocols like Aave, which obviously have good security practices and strong teams, still have a ton of room for improvement in, for example, how oracles behave. We just saw the incident with the CAPO oracle, and we could definitely come up with better designs there. Combining multiple solutions will eventually get us there. I don't think it's as bearish as some people say — that this may not work in the end. I disagree, because in the end you're being compared to traditional finance, which is essentially not transparent. You always take counterparty risk; there's no world with zero risk. So it's always a question of whether our solution, and the trade-offs we offer, are superior to what else you can get in the market.

Mid-roll: Before we get back to the episode: if you're interested in getting access to over 25,000 trading datasets, including performance and risk metrics, visit our website, tradingstrategy.ai, for free data and professional subscriptions. Now, let's get back to the episode.

Nertila: How can we use AI to stop optimizing for speed, and instead build the high-quality, secure systems required for a safe agent-to-agent economy?

Deo: Right now we're suffering, as I said, from the fact that both attackers and defenders have AI. But for code that was produced before all these crazy AI tools existed, the attackers have a jump ahead: they can start scanning all the code and attacking, while the defenders have to re-scan and go over all their code. Open source is probably going to be more resilient to this, because there are more people who care; closed source is going to have some issues, in my opinion. So right now, the biggest impact is on security and defense — how are attackers and defenders going to use all this tooling?

Over time, we'll see more and more new concepts of agent-to-agent economies, where the web and everything else is served differently. There will be more modular UI structures, really tailored toward certain use cases or personalized for certain needs. And we're going to get more agent-to-agent communication. Take the x402 protocol: everybody's super bullish on it, but it's not used at all right now, because there's a missing link in actually making it useful. I'm not sure exactly what it will look like, but people will figure out how to use x402 for on-chain payments and agent-to-agent — or agent-to-human — communication, where if a human asks a question, it can pay specialized agents, still with human control in the loop, to do things. That's the next frontier for agents, in my opinion.

Dan: I outlined most of the points I wanted to make about AI in my previous answer, and I think this is a great direction as well with regard to the agent economy. In the end, we need to get to a point where the probability of these incidents — hacks and exploits — is greatly reduced, with well-priced insurance to catch the remaining cases, so that investors have clarity: this is a low-probability event, and if it happens, there's recourse and a way to recover the funds. There are structures that help with that too — junior-senior tranching is one we've explored.

You can probably never guarantee that a system is unhackable. Even if you prove the code correct, you can still have an operational failure at some point if the system allows flexibility — say, an admin, or a manager or curator of a vault, taking certain actions that cause a security vulnerability or some other kind of loss. So it's impossible to guarantee, but we can reduce the probability and add a layer to insure the funds.

AI also helps us cover more ground quicker, although it's not a magic bullet — and we definitely cannot lean on what the internet calls "vibe coding" for this. What we've realized is that for system software and critical execution paths, you cannot afford to have unsupervised AI building them. You can have it look for issues. But it does add a force multiplier for builders. Things that didn't happen simply because we don't have the bandwidth as an industry — given the total number of people working on these problems — the force multiplier could allow for. You could get more polish, essentially, because that's what LLMs add to a builder's toolbox. Before, you could deliver the products; now, maybe it's not a question of delivering them much faster, but of delivering them with a much higher degree of quality.

So I don't think it's just about shipping quickly — which is obviously a good objective — but we could shift that energy and say: "Hey, we have more resources. Why don't we ship much, much higher quality stuff?" Because, to be honest, software in general has a quality problem. It's always had a quality problem — that's why we've always had bugs. Maybe the mindset shift should be less "we want to ship a lot quicker" and more "let's use that extra power, that amplifier, to ship much higher quality things." That would be a good shift, in my opinion.

Deo: Yeah, definitely. In the past, if you built shitty software, the hackers wouldn't necessarily find it right away. Now, with all this tooling, any mistake gets sniffed out immediately.

Nertila: So which is more favorable for DeFi users long-term: fixed-rate lending or variable-rate lending?

Deo: It depends, right? Real-world assets most of the time have durations — it's very rare that a real-world asset has no duration, unless it's just a stablecoin. With durations, if you have lending markets or use them, I think variable rates make a bit more sense: when these markets are under stress, the people lending out the money should earn from that.

So fixed-rate for lending is hard, and variable for lending is better. But I think it's the other way around for assets: not only for lending, but as an asset class, we need more fixed-income assets on-chain. That's what we built with ynRWAx — a fixed 11% APY, a fixed 11% coupon, with a one-year maturity. A very predictable fixed-yield instrument, which I think is very important. It really depends on your use case: fixed rates mostly come with lockups, and variable rates are more flexible. So it depends on what kind of structuring the end user does — and at the end of the day, a combination of both is probably best.

Nertila: And this will be the last question: what are some of the hard lessons you've learned so far in crypto?

Deo: That's the big question — let me try to keep it short. What I've learned most is that our industry is becoming more and more important for human progress. If we're living in a world where all finance is gatekept and you need to prove you're some sort of approved person in order to get credit, that would be a horrible future to live in, right? I hope DeFi offers a way out. So the biggest lesson is: we're working on a big mission, and it's very important that we keep going and keep our values up.

The other thing: security first, always — don't rush into things. And especially around raising structures or capital structures, always communicate and articulate expectations and mechanisms very well. That's really hard, because the complexity in DeFi is huge — if you need to explain every little nuance, it's too much. People need to do more of their own research before entering certain products. Overall, as an industry, we need to do a better job of educating people and winning back trust in decentralized markets over TradFi markets.

The biggest lesson overall: there's no free lunch, and there are no short-term gains. Have a long-term horizon. If you go into crypto thinking you'll get rich quick, that's going to be a downer, because it's a lot of hard work. If you want to enter DeFi or crypto, understand that this is definitely a longer-term play. If you don't have conviction, you're not going to survive it — in the first downtrend, like the one we're seeing now, with ETH almost below 1,600. Crazy, right? If you don't have conviction, or another, bigger reason to stay in this industry, you won't survive. So have conviction and passion for what you do. That's the most important thing I've learned.

Dan: Along those lines, just to double down: for a lot of the people who stick around, there's more than just a business opportunity. That's true for our team and for a lot of people who have been building protocols for a long time. There's this larger objective of seeing whether we can shift the balance of power in how finance works globally, and give more power back to individuals managing their own money. That's not an easy task at all, since we often do things similar to how the real financial system works, but we're underpowered and have to use clever mechanisms to achieve our goals.

So I agree — one lesson is that we need to stick it out for the long term, and there are no guarantees. There's no guaranteed payoff at the end of this, so you have to aim at your goal and stick to it, and accept that you might not see a payoff in the foreseeable future — or maybe ever. That's a demoralizing thought in a way, but I don't think there's any other way out of it. Otherwise, we're always going to be locked into KYC hell, or whatever the alternative is — a top-down control system. If the objective is to achieve something other than that, it's not going to be an easy road, and some directions will lead to dead ends, for sure.

But as I said earlier, we're offering this digital medium with really nice programmatic properties: immutable contracts, systems that offer bearer assets, and tools against censorship that make your transactions uncensorable. And I do think we're also opening up opportunities in the real world that are otherwise inaccessible. RWAs sound like they're not DeFi — and I guess they're not, since the funds have to travel to investments outside the chain — but in combination with DeFi, they will unlock a lot of things.

The other lesson: we're not just building a cool alternative to the old ways the banks used — slow then, super fast and automated now. We should also be unlocking opportunities for people that were completely inaccessible in the current system, whether because they didn't have the right passport, the right physical location, or the right connections and network. We should focus on that and tie it to the global community as a whole. Can you actually bring more value than just "this is a nicer programmatic abstraction, and it's much more efficient"? Can you unlock new opportunities for people to tap into — ideally to earn a living, invest securely, and at some point sleep well at night on their investments, instead of being as stressed out as they are now? That's my take on it.

Nertila: Thank you so much — great insights. I hope you enjoyed this conversation as much as I did. Anything else you want to tell our listeners?

Deo: It was a great interview, and I'm looking forward to doing this again in a better market. These things happen, and especially in down markets, I think it's very important to look around. For the people still listening to this podcast, still active in the industry: look at who's actually building, who's actually active — because this is when you'll see the real people who care about the industry, not the ones just here for a quick buck.

Nertila: Thank you again, guys.

Dan: Thanks so much. Appreciate it.