A Systematization of Knowledge on DeFi Vaults: Architectures, Curation Mechanisms, and Strategy Design
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "A Systematization of Knowledge on DeFi Vaults".
Elias: Decentralized finance (DeFi) vaults are smart-contract-based asset management systems that pool deposits, execute programmable strategies, and mint tokenized shares representing claims on underlying assets and strategy performance.
Nadia: First, who's behind it and why it matters.
Paper summary: Elias: So we've spent time looking at how this paper organizes the knowledge around DeFi vaults. The authors, Mancino and Pennella, are essentially arguing that existing work often tackles specific primitives in isolation without providing a comprehensive framework for the entire vault system. Nadia They achieve this by proposing a unified system model—that tuple (V, U, A, S, C, K)—and then building three complementary taxonomies to cover exposures, governance mechanisms related to curators, and strategy execution patterns.
Priya: I think what’s compelling about the conclusion is how they bridge the gap between the theoretical architecture and the practical realities of on-chain operation, especially by linking operational dependencies like latency to specific accounting drift failures. Elias They’ve also mapped out specific security threats, like sandwich attacks or oracle manipulation vaults, and what countermeasures are expected for them.
Nadia: The main implication here is that this work provides a structured way for researchers and developers to move past ad-hoc design by applying these formal definitions to build systems that are designed around known failure modes rather than just hoping they don't happen. Elias It’s about shifting from reactive patching to proactive, systemic design.
Priya: For the wider world observing this space, it means we get a standardized vocabulary to discuss the health and security of these pooled assets, which is incredibly valuable for building trust in decentralized financial applications. Nadia It gives us a better tool to assess not just if a vault *can* function, but how robust its control plane is under stress.
Elias: And looking at the title, "A Systematization of Knowledge on DeFi Vaults: Architectures, Curation Mechanisms, and Strategy Design," it really captures the comprehensive nature of their contribution to this topic. Priya It sets a baseline for how we should be thinking about these systems moving forward—not just as isolated smart contracts but as interconnected layers where design choices cascade through governance and strategy execution.
Nadia: I agree, it lays out the necessary structure for anyone looking to audit or build in this space to understand the dependencies they’re dealing with. Elias It’s a very practical contribution because it doesn't just theorize; it gives you the components to start analyzing things properly.
Priya: So, in short, this paper offers a formal language and a structured analysis tool for navigating the complexity of DeFi vaults, which is what we need right now to ensure safer financial applications.
Conclusion: Nadia: So, we've seen how this paper maps out the structure of DeFi vaults using these three taxonomies. Elias, what do you make of their title and who they are?
Elias: The authors are Mancino and Pennella, and their title really emphasizes that they're not just looking at one aspect; they're trying to build a complete system model for the whole vault landscape. That systematization approach is what interests me from a cryptographer's standpoint—they’re trying to define the rules of the game for these complex protocols.
Priya: I think their focus on formal definitions for share accounting and operational dependencies is actually really interesting because it moves us past just looking at surface-level mechanics. It makes the underlying structure transparent enough for us to analyze what's actually happening on chain.
Nadia: Exactly, Priya, that transparency is what we need when we're trying to figure out who can exploit these systems and how much it would cost them. Elias, you mentioned the system model—(V, U, A, S, C, K)—does that tuple actually hold up under stress tests?
Elias: It provides a solid framework for thinking about dependencies; the way they define keeper actions triggering strategy modules gives us a clear point of failure to trace. The parameters they assume are pretty standard in terms of smart contract interaction but the assumptions about oracle updates causing drift are where I'd want to probe deeper later.
Priya: From a measurement perspective, what this means is we now have specific metrics for things like "strategy execution patterns" and "curator governance," which allows us to measure the risk profile of different vault types more accurately than before. It’s about getting better data on the ecosystem's health.
Nadia: So, in simple terms, the paper is giving us a blueprint for understanding these vaults by defining their components and risks systematically. Elias, what do you think is the biggest real-world implication of this level of detail?
Elias: The real implication is that it sets a common language for discussing security vulnerabilities; when we talk about "Share Inflation Attacks" or "Sandwich Attacks," we have a defined mechanism to explain how they work and what the intended mitigations are. It helps us build better defensive layers.
Priya: And I think the impact is on privacy too, because if we can map out exactly how data flows through these systems—like which assets are exposed in different vault types—we can design tools that help users understand their exposure better.
Nadia: It’s exciting to see this level of detail emerge from the research community; it gives us a much sharper focus for our work on auditing these platforms. So, what does this mean for how we approach the next stage of analysis in DeFi?
Davide Mancino, Luca Pennella
University of Milano-Bicocca · University of Luxembourg
cs.CR, cs.CE, cs.CY
Submitted: 2026-10-01
Updated: 2026-10-01
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 82/100
The gist: Decentralized finance (DeFi) vaults are smart-contract-based asset management systems that pool deposits, execute programmable strategies, and mint tokenized shares representing claims on underlying
Key concepts
- System Model (V-U-A-S-C-K)
- This is a formal structure defining all core components of a DeFi vault: the Vault contract (V) managing deposits, Users (U), underlying Assets (A), Strategy Modules (S), Curators (C) who select strategies, and Keepers/Automation Agents (K). It shows how these elements interact to manage assets.
- Taxonomy 1: Vault Types by Exposure
- This classifies vaults based on where they generate yield. Examples include Lending Vaults for borrower interest or LP Vaults for trading fees. Each type has a specific risk profile, such as impermanent loss for LPs or protocol exploits for lending, helping users understand the primary financial exposure.
- Curator Systems and Curation Markets
- This taxonomy categorizes how curators make decisions. They can operate via decentralized governance, delegated curation, or third-party systems with explicit whitelisting. It also defines their control scope—what they can manage, like setting risk limits or approving price feeds—and the accountability mechanisms used.
- Strategy Design and Execution
- This classifies how vaults use capital. Strategies range from static (deploy once) to adaptive (adjust based on market signals). It also covers how rewards are handled, such as auto-compounding versus manual harvesting, and liquidity management techniques like withdrawal queues.
Terminology
Summary
Decentralized finance (DeFi) vaults are smart-contract-based asset management systems that pool deposits, execute programmable strategies, and mint tokenized shares representing claims on underlying assets and strategy performance. This paper systematizes DeFi vault architectures and curator-mediated control planes through a unified system model and three complementary taxonomies covering vault exposures, curator governance, and strategy execution patterns together with their failure modes.
The gist
This paper provides formal definitions for share accounting, roles, and operational dependencies in DeFi vaults while developing three complementary taxonomies covering vault exposures, curator governance, and strategy design coupled with failure modes to support rigorous analysis and safer design of blockchain-based financial applications.
System Model and Core Components
The research introduces a unified system model defined as a tuple (V, U, A, S, C, K), where V is the vault contract managing deposits and shares; U is the set of users; A is the set of supported underlying assets; S is the set of strategy modules; C is the curator set; and K is the set of keepers/automation agents. The core mechanics involve users calling deposit functions to receive shares, with a canonical conversion mapping an asset deposit 'd' to minted shares 's = d · St/At'. Strategy execution and fee accrual are managed by curators selecting strategies (sj ∈ S) and keepers submitting transactions to trigger strategy actions, which may cause "temporary accounting drift due to reporting latency, oracle updates, or unrealized P&L."
Taxonomy 1: Vault Types by Exposure
The paper classifies vaults into several types based on primary exposure and yield source. Key categories include Lending Vaults (yielding from borrower interest), Liquidity Provider (LP) Vaults (yielding from trading fees and liquidity mining rewards), Delta-Neutral Funding, Options Premium, Liquid Staking Consensus, Restaking AVS incentives, RWA Off-chain yield, and Stablecoin Rate differ. The risk profiles are characterized by specific metrics such as Protocol exploit
for lending vaults or impermanent loss [36]
for LP vaults. For instance, Delta-Neutral Vaults require sophisticated margin management and the primary failure mode is liquidation from insufficient margin during volatility spikes.
Taxonomy 2: Curator Systems and Curation Markets
This taxonomy classifies curator systems by decision-rights structure, scope of control, and incentive/accountability layers. Curators can operate under various models: Protocol governance
(decentralized but slow), Delegated curation
(faster iteration requiring selection), Third-party curator systems
(permissioned allocation with explicit strategy whitelisting), or Permissionless+Scoring
(maximal innovation reliant on robust scoring infrastructure). Scope of control is defined by what curators manage, such as selecting which contracts the vault can deploy to, setting risk limits (Exposure caps, leverage limits
), and determining approved price feeds (Oracle curation determines approved price feeds
). Accountability mechanisms include Reputation and scoring systems,
where Challenges include gamification, lack of standardized metrics, and attribution ambiguity.
Taxonomy 3: Strategy Design and Execution
Strategies are categorized by execution model, capital allocation pattern, reinvestment, and liquidity management. Execution models range from Static strategies deploy capital once
to Adaptive strategies dynamically adjust parameters based on market signals.
Capital allocation patterns include Single-venue allocation
(maximizing simplicity but concentrating risk) versus Multi-venue dynamic shifts capital between venues based on yield, risk, or capacity signals.
Reinvestment options are analyzed as either Auto-compounding automatically harvests and reinvests rewards
or Manual Harvest Low Operator-triggered.
Liquidity management includes mechanisms like a Withdrawal Queue
to protect user liquidity.
Security, Risk, and Failure Modes
The analysis maps specific failure modes to mitigation controls and observable on-chain indicators. Key vulnerabilities include Reentrancy in Deposit and Withdraw Vaults,
which are mitigated by checks-effects-interactions, reentrancy guards.
Other critical risks involve Share Inflation Attacks,
where mitigations include initial seeding/locked shares
or virtual share offsets.
For execution risks, the paper highlights Sandwich and Execution Attacks,
countered by explicit slippage bounds, batching or delayed execution.
Furthermore, it addresses external dependencies such as Oracle Manipulation Vaults,
mitigated by using TWAP and multi-source aggregation. Strategy-level risks include Liquidation cascades
(mitigated via conservative LTV) and Keeper failure
(mitigated via redundancy). The final section maps these to observable indicators, such as High PPS on first deposit
for share inflation or PPS collapse, wd failures
for insolvency.
Protocol Landscape Mapping
A representative snapshot of 22 production vault systems is mapped across the developed dimensions. This mapping illustrates how modular architectures, heterogeneous curator and manager roles, and stronger dependence on off-chain coordination
shape the ecosystem.
Improvements for AI systems
To improve AI systems using the insights from this paper, I would focus on integrating structured DeFi vault knowledge into the architecture, control, and risk management layers of autonomous agents or financial models.
Here are specific improvements and what they enable:
-
The improved system can implement a
Vault-Aware
agent architecture by incorporating the formal system model as its core state representation: -
The improved AI can perform rigorous, on-chain state reconciliation and accounting verification for any DeFi protocol interaction.
-
The improved AI can dynamically adapt its strategy based on the identified Vault Exposure Taxonomies (RQ1), allowing it to optimize for specific risk/return profiles (e.g., switching from a high-yield LP vault strategy to a low-volatility Delta-Neutral funding rate capture when market indicators suggest increased volatility).
-
The improved AI can incorporate
Curator-Mediated Control Planes
by designing decision logic that mimics the taxonomy in RQ2, allowing it to simulate or adhere to delegated authority structures (e.g., operating under a defined set of risk parameters and fee schedules provided by a curator proxy). -
The improved AI can utilize the Strategy and Failure-Mode Taxonomy (RQ3) to proactively model strategy execution risks. For instance, if the system is running an
Adaptive Strategy
withThreshold-based Rebalancing,
it can trigger pre-emptive risk checks against known failure modes likeOracle Manipulation
orMEV Sandwich Attacks
before executing a high-value transaction. -
The improved AI can develop specialized monitoring modules for each identified failure mode (Table 4), translating on-chain indicators (like PPS drift, slippage bounds, or keeper liveness) into actionable alerts rather than generic error flags.
-
The improved AI can be designed with modularity in mind, favoring
Modular Vaults
architectures to allow for rapid iteration of strategy modules without requiring a full system redeployment when a specific market condition changes.
This integrated AI system would move beyond simple execution and become an autonomous, risk-aware financial architect capable of:
-
Verifying the true economic Net Asset Value (NAV) by accounting for reporting latency and share inflation.
-
Making informed, context-aware capital allocation decisions based on predefined risk tolerance profiles.
-
Operating within a simulated or actual delegated governance structure that respects defined accountability boundaries.
-
Proactively detecting and mitigating risks inherent in complex, multi-protocol strategies (like cross-chain or adaptive range management).
Sources
- SoK: Yield Aggregators in DeFi
- Designing a Token Economy: Incentives, Governance, and Tokenomics
- Impermanent Loss in Uniswap v3
- SoK: The Evolution of Maximal Extractable Value, From Miners to Cross-Chain
- Stacked tensorial neural networks for reduced-order modeling of a parametric partial differential equation
- A Taxonomy of Real-World Asset Tokenization for Blockchain-Based Financial Infrastructure
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs