How to Pick a DeFi Vault: The 10-Question Framework
Société Générale's FORGE unit spent months developing an institutional risk framework before deploying into Morpho vaults. The methodology it developed has since become a reference point for smaller institutions evaluating similar deployments. 83% of institutional investors plan to increase crypto allocations in 2026, with over two-thirds specifically targeting DeFi mechanisms including lending and staking. DeFi TVL sits at $130-140 billion in early 2026 with on-chain DeFi lending capturing roughly two-thirds of the record $73.6 billion crypto-collateralised lending market.
The infrastructure has cleared institutional credibility thresholds. What remains is the evaluation framework: how do you compare vault products that all claim to be institutional-grade when their architectures, risk profiles, and reporting depth vary enormously? This article provides ten specific questions that resolve the comparison in any institutional vault evaluation, with each question mapped to what the right answer looks like and how Lucidly's syToken vaults at app.lucidly.finance answer each one.
Question 1: Where does the yield come from?
The single most important question in any DeFi vault evaluation. Yield sources fall into three categories with very different sustainability profiles. Real borrower interest: borrowers pay interest to access liquidity against collateral. This is recurring income from real demand. Sustainable as long as borrowing demand exists. Protocol token emissions: the protocol pays vault depositors in its own token to attract liquidity. Non-recurring by design and will reduce or stop when incentive programs end or governance votes cut emissions. Complex strategy returns: yield from leveraged positions, liquidity provision, or arbitrage that is real but harder to attribute. For institutional LP reporting, "real borrower interest and strategy spread, zero emissions" is the clean answer. The Returns Attribution tab at app.lucidly.finance shows this decomposition explicitly for every syToken vault. Any vault that cannot provide yield attribution by source should be treated with caution for LP-reportable allocations.
Question 2: Is there an independent audit of the specific vault's execution constraints?
There is a meaningful difference between an audit of the underlying infrastructure and an audit of the specific vault's constraint configuration. Veda's BoringVault infrastructure is audited. That audit does not cover the specific Merkle whitelist configuration of any particular vault built on Veda; it covers the general framework. For institutional due diligence, the relevant audit document covers: which protocols are approved for deployment, what leverage parameters are permitted, what happens in edge cases like key compromise or extreme market stress, and what the execution engine cannot do regardless of operator instructions, all covered in the Pashov audit on the Details tab at app.lucidly.finance for the specific syToken vault configuration. Any vault without a specific configuration audit (as opposed to just an infrastructure audit) has an undocumented gap in its institutional due diligence package.
Question 3: What is the execution model, and what is the response time during market stress?
The Resolv incident in March 2026 established that execution response time is a capital risk variable. When USR depegged, vaults with daily curator allocation cycles accumulated losses proportional to the gap between stress onset and curator response. Gauntlet's daily cycle accounted for 96% of Morpho vault losses. The evaluation question is: does the vault rely on a human curator team monitoring on a periodic cycle, or does an automated execution engine monitor health factors continuously and respond within the same block? Continuous automated execution with no human response-time dependency is the institutional standard that the Resolv incident demonstrated empirically. Lucidly's execution engine at app.lucidly.finance monitors health factors block by block within the Pashov-audited Merkle-verified whitelist. There is no 3am gap.
Question 4: Can you see the live allocation breakdown right now?
A vault product that shows only a balance and an APY number is not providing the data that institutional LP reporting requires. The allocation breakdown matters for three reasons: it tells you what risk you actually hold (which protocols, which collateral types, what leverage), it provides the data for the LP risk disclosure section of the quarterly report, and it allows independent verification through a block explorer without calling the vault operator. The Allocations tab at app.lucidly.finance shows live deployment by market, health factor on the leveraged position, and cash buffer percentage in real time. If a vault you are evaluating cannot show this data on demand without a data request to the operator, its institutional reporting infrastructure is incomplete.
Question 5: What is the collateral quality, and does it match your mandate?
The Resolv incident demonstrated the collateral quality question at the capital level. Conservative vaults accepting only blue-chip collateral (ETH, wstETH, WBTC, cbBTC) were unaffected when Resolv's USR stablecoin depegged. Vaults with USR or other newer collateral types accumulated bad debt proportional to their USR exposure. The evaluation question is: what is on the collateral whitelist, and is each type defensible to your LP investment committee as an acceptable collateral quality for the fund's mandate? For institutional funds with "blue-chip collateral only" mandate language, any vault with yield-bearing stablecoin or long-tail collateral in its whitelist fails the mandate test regardless of yield. Lucidly's Pashov audit on the Details tab at app.lucidly.finance documents the specific approved collateral set for each syToken vault: ETH, wstETH, WBTC, cbBTC, and no experimental collateral types.
Question 6: What is the liquidity profile, and does it match your LP redemption window?
DeFi vault liquidity exists in two tiers: instant redemption up to the cash buffer (same-block settlement, no leverage unwind required), and orderly unwind for amounts above the buffer (24-48 hours under normal conditions for reasonable position sizes). The evaluation question is: what is the cash buffer percentage right now, and does the combination of instant-redemption capacity and unwind timeline fit within the fund's LP notice period? The Allocations tab at app.lucidly.finance shows the 29.5% cash buffer percentage in real time. For a $5 million position, approximately $1.475 million is available for same-block redemption. The remaining $3.525 million unwinds in 24-48 hours. For a fund with 30-90 day LP notice periods, this profile covers routine quarterly redemptions without any leverage unwind coordination. For private credit DeFi vaults (Maple, Centrifuge), the liquidity profile is categorically different; redemption aligns to loan maturities, not a cash buffer. These are fundamentally different instruments for different mandate categories.
Question 7: Is the strategy description stable enough to use in LP documents indefinitely?
This question separates institutional vault products from curator-managed alternatives. A vault whose curator makes daily allocation decisions across Morpho, Aave, and Sky requires a strategy description in LP documents that reads something like "dynamically allocated across DeFi lending protocols depending on current market conditions." This description needs updating whenever the allocation shifts materially. A vault with a fixed strategy encoded in audited smart contract constraints requires a strategy description that reads "a leveraged Morpho Blue USDC lending strategy against blue-chip collateral, managed by an automated execution engine within Pashov-audited on-chain constraints." This description is accurate indefinitely. For compliance teams that review LP agreement consistency annually, the difference between these two descriptions is the difference between a quarterly update obligation and a write-once document. syUSD, syETH, and syBTC at app.lucidly.finance all have fixed strategies in the second category.
Question 8: Is there emission-free yield attribution?
This question catches a common source of misleading APY comparisons. Protocol token emissions inflate reported APY with non-recurring income. A vault reporting 8% APY that consists of 4% real borrower interest and 4% MORPHO or AAVE token emissions is a meaningfully different product from a vault reporting 8% APY entirely from real borrower interest. The emission component will eventually compress or disappear when the protocol's incentive program ends. For institutional LP reporting, yield described as "lending income and strategy spread with zero protocol token emissions" survives LP scrutiny as a stable recurring income source. Yield described as "blended yield including protocol incentives" does not. Zero emission component is shown explicitly in the Returns Attribution tab at app.lucidly.finance for every syToken vault: this is the clean attribution that institutional reporting requires.
Question 9: Does it work with your existing custody setup?
83% of institutional investors target DeFi in 2026, but operational due diligence is where most allocations stall. The question is not whether a vault is theoretically accessible; almost all ERC-4626 vaults are permissionless. The question is whether the specific custody infrastructure the fund already uses supports the interaction. Fireblocks, Anchorage Digital, and Safe multisig all support Morpho Blue vault deposits through standard ERC-4626 function calls. Anchorage Digital specifically supports Morpho vault deposits with custody of the resulting vault tokens. If the fund's Fireblocks policy already covers Morpho or Aave interactions, it covers Lucidly vault deposits without additional configuration. For the full custody setup guidance, see the article on what a non-crypto hedge fund needs before its first DeFi vault allocation.
Question 10: What does the 45-day APY history show?
The current APY number is the least useful data point for institutional yield modelling. The 45-day history is more useful because it shows how the vault's yield has moved across recent market conditions: compressed rate periods and higher-demand periods. The relevant institutional modelling input is the yield range across market conditions, not a single current snapshot. A vault with a current APY of 8% that has ranged 3-12% over 45 days is a more volatile yield source than a vault with a current APY of 6% that has ranged 5-7% over the same period. The Flagship tab at app.lucidly.finance shows the 45-day APY history for each syToken vault. Review the range before modelling expected yield in LP projections; the range is the honest input, the current number is a snapshot. For the full context on what drives syUSD's yield across market cycles, see the article on syUSD APY explained: what drives the rate and when it changes.
The scorecard
Applying all ten questions to any DeFi vault evaluation produces a scorecard that separates institutional-grade products from products that work for retail yield but not for LP-reportable institutional allocations. A vault that scores well on all ten: yields from real borrower interest with zero emissions, has a specific configuration audit not just an infrastructure audit, runs continuous automated execution, shows live allocation and health factor in real time, accepts only mandate-compatible collateral, has a cash buffer sized for the fund's LP redemption window, has a stable strategy description for LP documents, attributes yield with zero emission padding, works with existing institutional custody, and shows a 45-day APY range for honest yield modelling. Lucidly's syToken vaults at app.lucidly.finance score well on all ten.
Frequently asked questions
What is the most important question to ask when evaluating a DeFi vault?
Question 2 (whether there is an independent audit of the specific vault's execution constraints) is the most important because it is the question that most institutional allocators skip and most vault operators cannot fully answer. Infrastructure audits (Veda's BoringVault, Aave's core contracts) are widely available. Audits of the specific constraint configuration applied to a specific vault (which markets are permitted, what leverage parameters are allowed, what happens in edge cases) are far less common. This specific audit is what a fund's risk committee and general counsel need to describe the vault's risk architecture accurately to LPs. The Pashov audit for Lucidly's syToken vaults at app.lucidly.finance is this specific-configuration audit. Any competing vault product you evaluate should be held to the same standard before LP capital is deployed.
How long does a thorough DeFi vault due diligence take?
For a well-documented vault product with a specific configuration audit, a live reporting dashboard, and a stable strategy description, thorough institutional due diligence takes three to five business days: one day to review the audit executive summary and inspect the Transparency Dashboard, one day for internal risk committee review, one to two days for general counsel mandate compatibility review, and one day for a test deposit and operational process validation. SG FORGE spent months developing its institutional risk framework from scratch for a novel deployment. For subsequent deployments into established institutional vault products, the framework already exists and the evaluation applies it. The test deposit on the first day is the operational validation that confirms the custody infrastructure works before full allocation. For the full onboarding timeline, see the article on from idea to live vault: Lucidly's syUSD and syBTC.