CIAN Yield Layer

Orange · 61/100

Executive summary

CIAN Yield Layer is a multi-chain vault-based yield aggregator routing deposits into leveraged DeFi strategies across Ethereum, Arbitrum, Avalanche, OP Mainnet, and Polygon, scoring 50/100 (orange band) with high data confidence but a 10-point penalty for unresolved incident remediation.

  • Security: Ackee Blockchain audited core Yield Layer contracts (0 critical, 0 high, 3 medium findings including insufficient pool-state validation and limited user control over funds); all 26 findings were reportedly fixed or acknowledged, but deployed bytecode match is not verifiable as of 2026-09-04. Additional audits by Paladin, Omniscia, and PeckShield cover earlier CIAN versions; scope and remediation status for current multi-chain deployments are not verifiable.
  • Incidents: Four unresolved or in-progress incidents: Berachain pre-deposit misallocation (compensation pending), Sonic Eco.Earn discontinuation (compensation plan announced but not completed), Renzo withdrawal delays (unresolved as of 2026-09-06), and Stader MaticX sunset wind-down (target August 31, 2026, completion not confirmed). One resolved incident (rsETH supply mismatch pause, no losses).
  • Governance & custody: Non-custodial ERC-4626 vaults with multisig-controlled fund allocation; no DAO governance or timelock verified. Ackee audit warns that protocol owners can set arbitrary exchange prices, artificially mint shares, and influence withdrawal amounts—materially centralized trust model. Multisig signer identities, threshold, and independence are not verifiable as of 2026-09-04.
  • Top risks: Admin keys can drain funds via upgradeable proxy; leveraged staking strategies amplify collateral depeg and liquidation risk; counterparty insolvency (Aave, Lido, Compound, Mellow) would directly impair vault NAV with no verified insurance or compensation mechanism; withdrawal delays and liquidity bottlenecks documented in multiple incidents; no legal entity, jurisdiction, or enforceable Terms of Service disclosed.
  • Strengths: Multi-protocol integration for diversified yield; documented multisig approval process for allocation changes; transparent on-chain strategy contracts; borderless, no-KYC access; no critical or high audit findings in latest Ackee report; ~$10.3M TVL and 1.8 years of operation with no recorded exploits or hacks.
  • Unverified: Current deployed bytecode match to audited commits across all chains; exact multisig threshold and signer identities; legal entity and jurisdiction; on-chain reserves, liabilities, and per-strategy exposure; native token existence and tokenomics; completion of incident compensation plans; oracle manipulation resistance and fallback logic.
  • Recommended exposure: Maximum 1–2% allocation for sophisticated allocators only, conditional on independent verification of: (1) current multisig signers and threshold ≥3-of-5, (2) deployed contract bytecode match to audited commits, (3) completion of all pending incident compensations, (4) legal structure and enforceability of terms, and (5) real-time monitoring of vault health factors and counterparty exposure. Avoid exposure until incident remediation is completed and legal/governance gaps are closed.
  • Open questions: What is the exact multisig threshold and who are the signers? Does deployed bytecode on all five chains match audited commits? What is the legal entity, jurisdiction, and enforceability of user agreements? What are current per-strategy allocations, leverage ratios, and counterparty exposures? Have all incident compensations been paid? What oracle feeds and fallback mechanisms protect against manipulation? What is the protocol's insurance or reserve policy for counterparty failures?

Score

Component Weight Raw Points Reason
Security 20% 80 16.0 7 audit(s); no fresh audit; no qualifying bug bounty
Audits 20% 50 10.0 last full audit 2025-02-25 is older than a year
Incidents 20% 100 20.0 4 open incident(s), $0 at risk (4 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 2 0.4 TVL $280,175,934 = 2% of reference ($17,538,184,136)
Data confidence 85 7/7 critical categories; 12/44 verified facts; 44/44 fresh (180d)

Identification

protocol identification

two sources

CIAN Yield Layer is a multi-chain vault-based yield aggregator / “yield layer” that routes user deposits into multi-step strategies across DeFi to optimize returns. Identification

  • Name: CIAN Yield Layer (part of the CIAN Protocol).
  • Category: DeFi yield aggregator / vault protocol and automation layer focusing on LST/LRT, BTC-LSTs, RWAs, and funding-rate strategies.
  • Website: cian-protocol.com (main) and yieldlayer.cian.app (app/tech interface).
  • Docs: docs.cian.app, including Yield Layer tech docs and contract references.
  • Chains (for Yield Layer): Arbitrum, Avalanche, Ethereum, OP Mainnet, Polygon. Other CIAN modules also run on Mantle, Optimism, Base, BNB Chain, Scroll, Berachain, etc., but the question’s scope is these five.
  • Native token: Not clearly documented in the retrieved sources; some references treat CIAN as a protocol brand rather than a token. Not verifiable as of 2026-09-04.
  • Launch date (Yield Layer): Media report notes CIAN “recently announced the launch of its groundbreaking Yield Layer” around late 2024, implying main Yield Layer go-live in 2024. Exact deployment block/date Not verifiable as of 2026-09-04. Main contract addresses & verification
  • Docs list a Yield Layer-related address 0x5085B552639cFC0e49Bb645Ae4637F6e55F0F01f, but chain context and role are not fully specified. Without explorer cross-check this is Not verifiable as of 2026-09-04.
  • The MrDeFi profile links to a specific vault URL on Ethereum (with a vault address in the path), confirming ERC-4626-style vaults exist on Ethereum, but contract verification status and full address set are Not verifiable as of 2026-09-04.
  • DIA and DefiLlama confirm active pools on Arbitrum, Avalanche, Ethereum, Optimism, and Polygon, but do not expose canonical contract lists or verification flags. Not verifiable as of 2026-09-04 for per-chain contract maps. Fork lineage / code provenance
  • Public sources describe CIAN as an original yield layer / aggregator, not explicitly as a fork of a named protocol.
  • Vaults are ERC‑4626, a standard pattern widely used in DeFi, but this does not by itself indicate a direct fork.
  • No sources identify CIAN Yield Layer as a fork of Yearn, Beefy, Pendle, or similar, nor detail upstream code changes.
  • Audit / fork-modification history specific to Yield Layer contracts is Not verifiable as of 2026-09-04.
  • No documented malicious-modification incidents in CIAN forks were found; risk analyses treat it as a distinct protocol with its own strategies rather than a contentious fork. Key structural characteristics
  • Uses ERC‑4626 vaults that accept assets (LST, LRT, RWAs, BTC-LSTs, etc.) and route them through integrated protocols such as Aave V3, Compound, Lido, Pendle, restaking platforms, and others.
  • Operates a “virtual yield layer” that consolidates sustainable yield sources and redistributes them across assets and chains.
Evidence (15)

maturity

one source

CIAN Yield Layer appears to be a real, functional product rather than a pure landing page: its documentation exposes a live app base URL, vault-specific pages, and user flows for deposit and withdrawal, including approval/deposit and withdrawal-request steps. The docs also describe a builder API and a points API, which indicates an open developer-facing API surface rather than a closed consumer-only portal. The user-facing experience is documented as a vault dashboard where users choose a deposit token, enter an amount, approve/deposit, sign in wallet, then later submit a withdrawal request; the docs say withdrawals are estimated to arrive in about 5 days.

The tech docs also show concrete contract/function interfaces such as deposit and requestRedeem, which is another sign of a live integrated app workflow, not a template placeholder. No reliable web evidence in the gathered material confirms broken links, fake metrics, or template-site artifacts, so those are Not verifiable as of 2026-09-04. The same applies to the real-world success rate of deposits/withdrawals at the time of this snapshot, because that requires on-chain verification that is unavailable in this run. ## Assessment

  • Real portal vs landing: real portal with vault pages and documented app flows.
  • App functionality: deposit, approval, withdrawal-request, wallet-signing flow documented.
  • Live deposits/withdrawals: Not verifiable as of 2026-09-04.
  • Docs/UX: fairly mature, with step-by-step user and builder docs plus API references.
  • Broken links/template signs: Not verifiable as of 2026-09-04.
  • Open API: yes, at least for points and vault configuration/data endpoints, plus documented contract interfaces.
Evidence (5)

Security

bug bounty

two sources

Not verifiable as of 2026-09-04. No active bug bounty program for CIAN Yield Layer was found in the available sources. The accessible materials include audit reporting and protocol documentation, but no bug bounty platform listing, program terms, scope, payout tiers, start date, or reported bounty results were identified.

Evidence (3)

counterparty risks

unverified

Scope: The supplied address 0xB13a...877d is identified in CIAN’s contract registry as the Ethereum stETH Yield Layer, not a generic all-chain vault. The registry lists strategy implementations/adapters involving Lido/stETH, Aave V3, Mellow Steakhouse, Compound, rsETH and ezETH-related routes. This creates direct smart-contract, liquidity, liquidation, LST/LRT depeg and governance dependencies. External protocols and failure scenarios: Aave insolvency, bad debt, oracle error or liquidation cascade; Lido/stETH or LRT depeg/withdrawal impairment; Mellow/strategy-contract exploit; Compound market failure; and CIAN strategy reallocation or upgrade-key compromise.

Recursive or leveraged staking can amplify losses and make exits dependent on available lending and DEX liquidity. CIAN’s own documentation acknowledges that users must assess each integrated protocol; its claims of multisig, exchange-rate limits and audited contracts are protocol-supplied and therefore unverified marketing claims. Oracles/manipulation: CIAN documentation references Chainlink Oracles, but the exact feeds, heartbeat/deviation parameters, fallback logic and manipulation resistance for this vault were not independently verified. Not verifiable as of September 6, 2026. Bridges/custody/CEX/MM/RWA: No verified evidence was found tying this Ethereum stETH vault to a bridge, centralized custodian, CEX/market maker, or RWA issuer/SPV. Cross-chain exposure for Arbitrum, Avalanche, OP Mainnet and Polygon was not attributable to this specific vault. Not verifiable as of September 6, 2026. Prior finding check: The previously recorded EigenLayer/Pendle exposure was not re-confirmed for this vault; current registry evidence instead identifies the integrations above. Not verifiable as of September 6, 2026. Contradiction / data gap: CIAN publishes risk and liquidity assertions, but no current, independent position breakdown or exposure percentages were available.

On-chain balances, active incidents, and maximum dependency concentration require Dune; unavailable in this run. Not verifiable as of September 6, 2026. Failure assessment: No active failure was identified in the reviewed sources, but this is not an on-chain incident check.

Evidence (4)

crypto custody

one source

CIAN Yield Layer custody is organized around an ERC-4626 Vault contract that receives user deposits and mints share/LP tokens representing each depositor’s pro rata claim on the vault assets. The vault then allocates assets into separate on-chain strategy contracts for execution, with allocation ratios and parameter changes governed through a multisig wallet rather than a single operator. This points to non-custodial, smart-contract-based custody at the vault level, with operational control split across vault logic, strategy contracts, and multisig-approved allocation changes.

Withdrawal status is Not verifiable as of 2026-09-06. Segregated assets is Not verifiable as of 2026-09-06.

Evidence (3)

incident

unverified

CIAN reported that certain Berachain pre-deposit vault assets—wstETH/ylstETH, rsETH/ylrsETH and wBETH—were not allocated into Boyco because of miscommunication and liquidity issues. Withdrawals were opened; CIAN said wBETH had been returned and that users remaining in the replacement Sonic vault could receive compensation if Sonic rewards underperformed Boyco. No realised loss or reimbursement amount was disclosed, and completion of the compensation process was not evidenced as of September 6, 2026.

Current status: remediation_in_progress.

Date
2025-02-18
Cause
Liquidity issue
Status
remediation in progress
Event id
cian-berachain-p redeposit-misallocation-2025-02-18
Evidence (1)

incident

unverified

CIAN discontinued its Sonic Eco.Earn vault after Sonic stopped listing CIAN assets despite an earlier expected points/yield arrangement. All funds were stated to be immediately withdrawable and base yield was said to remain unaffected. CIAN recorded participating wallets and promised a compensation plan after Sonic’s season, but payment or final amounts were not evidenced as of September 6, 2026.

Current status: remediation_in_progress.

Date
2025-03-23
Cause
Other
Status
remediation in progress
Event id
cian-sonic-ecoearn-discontinuation-2025-03-23
Evidence (1)

incident

unverified

CIAN temporarily paused deposits and withdrawals for the stETH and rsETH Yield Layers after identifying an rsETH supply mismatch. CIAN stated that funds were safe, no losses had occurred, and rewards would continue accruing. The response was a precautionary pause and planned restoration; later CIAN announcements showed continued operation of these product lines, but no formal restoration notice or reimbursement was found. loss_usd: 0 based on the reported incident statement.

Current status: resolved.

Date
2025-05-01
Cause
Liquidity issue
Loss
$0
Status
resolved
Recovered
$0
Event id
cian-rseth-supply-mismatch-pause-2025-05-01
Evidence (1)

incident

unverified

CIAN x Renzo strategy-vault users experienced delayed withdrawals. Cause: Renzo allegedly discontinued or restricted the previously expected instant-unstake route, creating an exit-liquidity bottleneck; CIAN said funds remained safe and attributed the issue to Renzo rather than a CIAN strategy failure. A cited example involved a $6 million deposit, but total affected exposure was not disclosed.

CIAN escalated to Renzo and sought restoration of the withdrawal channel. No completed fix, recovery amount, or reimbursement was evidenced as of September 6, 2026. Current status: unresolved.

Date
2026-01-15
Cause
Liquidity issue
Status
unresolved
Event id
cian-renzo-withdrawal-delay-2026-01-15
Evidence (1)

incident

unverified

Stader’s Polygon MaticX sunset forced CIAN to wind down its 6x and 3x MaticX/MATIC recursive-staking strategies. Affected users were told to exit before the sunset; remaining positions were to be redeemed/deleveraged through a coordinated CIAN process. CIAN warned that manual exits could incur swap fees or slippage and later required approval/EIP-2612 authorization.

No realised loss, attacker proceeds, recovery amount, or completed reimbursement was disclosed. The announced completion target was August 31, 2026, but completion was not independently confirmed as of September 6, 2026. Current status: remediation_in_progress.

Date
2026-06-19
Cause
Liquidity issue
Status
remediation in progress
Event id
cian-maticx-sunset-2026
Evidence (2)

key management

two sources

CIAN’s key management appears to be organized around a multi-signature wallet that sets allocation ratios and authorizes fund-allocation decisions for the Vaults. The GitHub technical documentation states that users deposit into Vault contracts, strategy fund allocation ratios are set using a multi-signature wallet, and this multisig structure is intended to require consensus from multiple parties for security and transparency. The docs also list a dedicated WalletFactory alongside Vault, VaultImplementation, ERC2612Verifier, and Automation contracts, which suggests a structured contract system rather than a single owner key.

What is *not verifiable* from the available sources is the exact multisig threshold, signer identities, key custody model, or whether the same multisig controls all chains (Arbitrum, Avalanche, Ethereum, OP Mainnet, Polygon). Not verifiable as of 2026-09-04. The best-supported interpretation is that operational control is split between on-chain Vault/strategy contracts and off-chain or governance-managed multisig signers, with automation handling some routine actions while privileged parameter changes remain under multisig control.

Evidence (3)

smart-contract

two sources

Assessment: HIGH admin/trust risk; incomplete multi-chain verification. Scope verified only for the supplied Ethereum stETH vault. Arbitrum, Avalanche, OP Mainnet and Polygon vault addresses were not matched. Not verifiable as of September 6, 2026. Address map (documentation/explorer; not Dune-verified):

  • Vault proxy: 0xB13aa2d0345b0439b064f26B82D8dCf3f508775d
  • Current implementation: 0xA1Dc0B6A02AB091580DC57bDd5Fe8a9E577E0842
  • Manager: 0x6d425B3D302DD82cC611866eC8176d435307b616
  • RedeemOperator: 0xdAc6748CbB7CD9DA1868eB7aD598273122f012db
  • TimeLock: 0x0cbee811c47c3a5cb4637f1e58d98b0abbb4c54f
  • Documented multisig / proxy initial owner: 0x8FA9aa69a6e94c1cd49FbF214C833B2911D02553. Architecture: ``text User -> TransparentUpgradeableProxy (Vault) | ERC-1967 implementation v VaultImplementation -> Manager -> strategy implementations/proxies | | +-> RedeemOperator +-> DeFi venues/oracles | +-> documented TimeLock / multisig governance path ` The vault is a TransparentUpgradeableProxy. Its upgrade route is an OpenZeppelin ProxyAdmin controlled by an owner; the proxy exposes upgradeToAndCall through that admin. Therefore a compromised proxy-owner key can replace the implementation, alter accounting/withdrawal/fee/oracle/strategy logic, and potentially transfer or strand assets. The owner is documented as an EOA-labelled deployer, not independently verified here as a threshold multisig. Ackee’s audit found no critical or high findings in its reviewed scope, but explicitly reported centralization and “almost no control” for users over deposited funds; strategies were excluded from scope. This does not establish that the live deployment matches the audited commits. Exit/rug assessment: users appear dependent on vault redemption logic, RedeemOperator, strategy liquidity and administrator-controlled upgrades. Whether users can always exit without admin, whether pause/fee/oracle/strategy setters exist, whether roles were renounced, and the effective on-chain timelock delay: Not verifiable as of September 6, 2026. A key compromise creates upgrade/rug and freeze risk; malicious strategy or redemption control could also delay or redirect withdrawals. Contradiction: documentation labels a multisig, while explorer evidence identifies the proxy constructor’s initialOwner as 0x8FA9…2553`; threshold ownership is not proven. Structured fields: admin_can_drain=true; audited_deployment=null; upgradeable=true; unresolved_critical=0; unresolved_high=0.
Admin can drain
Yes
Upgradeable
Yes
Unresolved critical
0
Unresolved high
0
Evidence (5)

audit

one source

Ackee Blockchain — Cian Yield Layer Audit Report

Auditor
Ackee Blockchain Security
Report date
2025-02-25
Scope
Ethereum; commit 54e953, all contracts excluding strategies; revision 1.1 on commit 06f333 covering remediation review.
Findings
Critical: 0. High: 0. Medium: 3 — M1 invalid intermediary-division calculations; M2 insufficient pool-state validation; M3 users have almost no control over deposited funds. No critical/high findings reported.
Fix status
Ackee states all 26 findings were fixed, partially fixed, or acknowledged with comments; exact per-finding status is not reproduced in the public summary. Covers the audited commits, not demonstrably the current vault bytecode.
Evidence (2)

audit

unverified

CIAN’s published audit index lists a separate PeckShield report for CIAN v1.0 on Avalanche. The publication date, detailed scope, severity counts, remediation status and bytecode match could not be independently extracted from the available report/index content.

Auditor
PeckShield
Report date
2026-09-06
Scope
Avalanche; CIAN v1.0. Exact contract list and exclusions: Not verifiable as of 2026-09-06.
Findings
Critical/high/medium counts and issue descriptions: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06; current Avalanche deployment coverage is also Not verifiable as of 2026-09-06.
Report url
https://docs.cian.app/security-and-risk/audit-report
Report id
doc:012e226eeac14355
Evidence (1)

audit

one source

Published Paladin report for CIAN (Ethereum). The report states it was an extension of the Avalanche audit and documents live-code matches for assessed Ethereum contracts at audit time; this does not establish a match to the current Yield Layer vault.

Auditor
Paladin Blockchain Security
Report date
2022-09-24
Scope
Ethereum contracts: adapters, FeeBoxes, Automation, ControllerLib/Sub, ControllerLink, BalancerERC3156, verifiers, Timelock and dependencies; AccountManager was not deployed.
Findings
Critical: 0. High: 0. Medium: 10, including wrong-function handling, flash-loan and position-transfer issues, FeeBox transfer logic, VerifierBasic validation, referral storage and multicall behavior. Low: 5; Informational: 20.
Fix status
35 findings total: 21 resolved, 2 partially resolved and 12 acknowledged. Acknowledged items included stable-rate borrowing support, some privilege/control concerns and other recommendations.
Report url
https://paladinsec.co/assets/audits/20220924_Paladin_CianEthereum_Final_Report.pdf
Report id
doc:450509831bd934be
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published Paladin report for CIAN (Avalanche). Paladin’s project page identifies the audited contracts and provides the severity/remediation table; the report is an earlier CIAN automation architecture, not a verified match to the current Yield Layer vault.

Auditor
Paladin Blockchain Security
Report date
2022-10-25
Scope
Avalanche: ProxyWallet/WalletFactory, ControllerLib, Automation, ERC2612Verifier, adapters, FeeBoxes, Timelock and dependencies; several removed or non-deployed contracts are explicitly listed.
Findings
Critical: 0. High: 7. Medium: 14. Low: 23. Informational: 49.
Fix status
93 findings total: 74 resolved, 7 partially resolved and 12 acknowledged. High: 6 resolved/1 partial; Medium: 13 resolved/1 partial; Low: 16 resolved/7 acknowledged; Informational: 39 resolved/5 partial/5 acknowledged.
Report url
https://paladinsec.co/assets/audits/20221025_Paladin_Cian_Final_Report.pdf
Report id
doc:a839563a7d2af50e
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
1
Evidence (1)

audit

one source

Published Paladin report for CIAN (Polygon). The report states it is an extension of the Ethereum audit and records live-code matches for the listed Polygon contracts at audit time; no current-vault bytecode match is established.

Auditor
Paladin Blockchain Security
Report date
2023-01-03
Scope
Polygon: OneInch, Aave V3, Balancer V2, FeeBoxMATIC, QuickSwap, Stader, WmaticGateway, Automation, ControllerLib/Sub, verifiers, StaderAirdrop and Timelock.
Findings
Critical: 0. High: 1 — adapter does not return leftover balances. Medium: 4 — fee-on-transfer incompatibility, withdrawal blocking, privilege-escalation bypass and other adapter issues. Low: 7; Informational: 9.
Fix status
21 findings total: 9 resolved, 1 partially resolved and 11 acknowledged. The high finding was resolved; one medium issue was partially resolved and another acknowledged.
Report url
https://paladinsec.co/assets/audits/20230103_Paladin_CianPolygon_Final_Report.pdf
Report id
doc:b3cd99aa9fb32467
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published Omniscia report for CIAN’s stETH vault. Omniscia’s project index dates the CIAN audit entry to April 6, 2023, while the report itself is dated May 9, 2023. It is not a demonstrated bytecode match to the current Yield Layer vault.

Auditor
Omniscia
Report date
2023-05-09
Scope
Ethereum stETH–ETH vault; vault, wrapper, strategy proxy, lending, flash-loan and supporting contracts, with repository revisions through commit e8fef863c7.
Findings
Critical: 0 reported. Major: 10. Medium: 6. Major issues included arbitrary swap data, improper 1inch-result decoding, centralization of vault assets, initialization/address errors, withdrawal-asset errors and potential permanent DoS.
Fix status
Several findings were addressed after review, but the report records multiple items as insufficiently dealt with or acknowledged; flash-loan components required follow-up review. Current remediation and deployed-code coverage are Not verifiable as of 2026-09-06.
Report url
https://1717361315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FO9IZAEayToLEPbAGTwkL%2Fuploads%2FNtBm4xZQWc0M3QiltaN3%2FOmniscia_Audit_Report_CIAN.pdf?alt=media&token=0682a4fc-ba08-47fd-80c5-a2074c5b046e
Report id
doc:ca44c86b0cfc8ebd
Covers deployed code
No
Unresolved critical
0
Evidence (1)

audit

one source

The CIAN documentation page lists an Omniscia audit report for CIAN (Omniscia_Audit_Report_CIAN.pdf). Independent risk aggregators state that CIAN “has 4 audit reports on record from firms including Ackee Blockchain, PeckShield, Omniscia”. From context, Omniscia’s work likely covered additional parts of the Yield Layer smart-contract system—potentially Ethereum or other-chain deployments—though specific chain and module coverage cannot be derived from snippets.

No public summary with methodology or contract list is visible; full report content is Not verifiable as of 2026-09-04.

Auditor
Omniscia
Report date
2025-01-16
Scope
Generic “CIAN” smart contracts; precise scope (Yield Layer core vs. strategies, which chains/versions) is **Not verifiable as of 2026-09-04** based on available snippets.[1][6]
Findings
Neither CIAN docs nor independent summaries reproduce Omniscia’s severity breakdown or issue list.[1][6] As a result, **counts of critical/high/medium findings, and their descriptions, are Not verifiable as of 2026-09-04**.
Fix status
There is no external remediation summary specific to Omniscia; CIAN’s site only links the PDF.[1] No independent platform confirms fix status per finding.[6][10] Thus **fix status for Omniscia’s findings, and whether the audited code exactly matches current deployments on Arbitrum, Avalanche, Ethereum, OP Mainnet, Polygon, is Not verifiable as of 2026-09-04**.
Evidence (2)

audit

one source

CIAN’s documentation lists a PeckShield audit report for CIAN v1.0 on Avalanche (PeckShield-Audit-Report-CIAN-v1.0.pdf). This indicates an audit focused on Avalanche deployment(s), likely covering the Yield Layer or closely related vault contracts on that chain. Exact contract list, severity breakdown, and methodology are not visible in the snippet; full PDF content is Not verifiable as of 2026-09-04.

There is no independent summary confirming which modules (core layer vs. strategy vaults) were in scope, nor whether later versions or deployments on other chains were re‑audited. Bytecode-match to currently deployed Avalanche contracts is Not verifiable as of 2026-09-04.

Auditor
PeckShield
Report date
2025-01-16
Scope
“CIAN v1.0” on Avalanche, likely core vault/Yield Layer contracts on that chain; exact contract list, version tags, and exclusions (e.g., strategies) are **Not verifiable as of 2026-09-04** from available snippets.[1]
Findings
The doc snippet exposes only the file name and chain (Avalanche) but no issue list.[1] Independent aggregators confirm “multiple audits (Ackee Blockchain, PeckShield, Omniscia, Paladin)” exist but do not reproduce findings.[3][5][6] Therefore **specific critical/high/medium counts, issue descriptions, and remediation notes for the PeckShield audit are Not verifiable as of 2026-09-04**.
Fix status
CIAN docs merely list the PeckShield PDF; they do not state whether all findings were fixed, partially fixed, or acknowledged.[1] No external independent source provides a remediation summary.[3][5][6][10] Accordingly, **fix status for PeckShield findings is Not verifiable as of 2026-09-04**. Coverage of current Avalanche, Arbitrum, Ethereum, OP Mainnet, Polygon deployments relative to this report is likewise **Not verifiable as of 2026-09-04**.
Evidence (2)

Team & Reputation

founders

two sources

CIAN appears to be a real, long-running DeFi team rather than a pure web-front, but several “reality check” items remain only partially verifiable from the sources available. Public sources identify Luffy He as founder/CEO, with CIAN launched in 2022 and an active public presence since at least March 2022 on X. CIAN’s own materials describe a team spanning smart-contract engineering, protocol design, on-chain analytics, and product, and one company page says most engineers came from DeFi-native backgrounds; however, that remains unverified marketing claim unless independently corroborated.

On prior projects/outcomes, the clearest independently surfaced signal is that Luffy is also referenced as founder of Bondify in a CIAN AMA announcement, suggesting he has worked on more than one DeFi project. No reliable source in this pass established prior exits, failed projects, or documented hacks tied to the founders; the public security profile we found says CIAN has no recorded security incidents, but that is an aggregator claim and should be treated as a cross-check rather than primary truth. CIAN also published an external audit report reference on its docs site, which is a positive credibility signal, though I could not independently assess the full report here.

On business footprint, I found no independently verified office address, incorporation jurisdiction, or clear onshore/offshore structure; Not verifiable as of 2026-09-04. Likewise, I could not confirm whether the team is fully public or partially anonymous beyond the named founder/CEO and a few role-based references; Not verifiable as of 2026-09-04. In institutional terms, the current evidence supports “real protocol with a visible founder and some external validation,” but not yet “fully transparent company with confirmed legal substance.”

Evidence (6)

general reputation

two sources

CIAN Yield Layer currently has a mainstream, generally positive reputation as a yield aggregator with growing TVL and no public records of fraud, rug pull, insolvency, or regulatory actions. Not verifiable as of 2026-09-04 for on-chain evidence. Protocol reputation & usage

  • DIA and other data platforms describe CIAN Yield Layer as a live, vault-based yield aggregator with about $270M+ TVL across 5 chains and 7 pools, operating for ~1.8 years, which indicates sustained usage and no obvious blow‑ups.
  • Third‑party explainers (Gate Learn, Hindenrank, The Grid) present CIAN as an advanced, automated yield layer integrating LST/LRT, RWA and funding‑rate strategies and routing deposits through protocols like Aave v3, Compound, Mellow, Pendle. This coverage is neutral‑to‑positive and treats CIAN as a legitimate DeFi protocol, not a high‑risk or scam project.
  • Media like CryptoBriefing frame CIAN as a “battle‑tested DeFi yield strategy protocol” launching a yield layer to improve TVL and liquidity sustainability, again suggesting an established, functioning project. Audits & security reputation
  • CIAN’s own docs reference audit reports by Ackee and PeckShield for the Yield Layer smart contracts. These are standard‑tier DeFi auditors and improve perceived security, but this remains an unverified marketing claim until cross‑checked directly with the auditors.
  • DIA explicitly notes: “CIAN Yield Layer has not published audit reports,” i.e., no public audit files visible via their platform. This is an important discrepancy and indicates limited transparency around audits. > Contradiction box >
  • Protocol docs: Yield Layer audited by Ackee and PeckShield (unverified marketing claim). >
  • DIA: “CIAN Yield Layer has not published audit reports.” > Gap: audit existence vs. public availability; lack of independently verifiable audit artifacts is a risk finding. Founders, investors, governance
  • Publicly available profiles focus on the product, not the team; there is no clear founder or investor roster in independent coverage. This is a transparency gap for institutional allocators.
  • No visible formal on‑chain governance or DAO structure is highlighted in third‑party sources. Sentiment, criticisms, and concerns
  • Current commentary is largely descriptive and mildly promotional, with no major public criticisms or exploit reports in the surfaced sources.
  • Key unresolved concerns for a risk memo:
  • Limited independently verifiable audit publication (see contradiction above).
  • Sparse disclosure on team identities, track record, and investor base.
  • Complex, leveraged staking/restaking strategies and CeFi integrations increase strategy and counterparty risk, though this is a structural DeFi risk rather than a specific controversy. Legal / regulatory / sanctions
  • No reports of regulatory investigations, sanctions, or legal actions against CIAN or its operators in the retrieved material. Not verifiable as of 2026-09-04 across official sanction lists. Overall, CIAN appears operational, growing, and generally positively perceived, but with material transparency gaps around audits (public artifacts) and team/investor disclosure that should be flagged for institutional due diligence.
Evidence (7)

Economy

TVL: $280.2M

model

one source

Scope correction / contradiction: The supplied Ethereum vault 0xB13aa…8775d is documented as the stETH Yield Layer, not rsETH. The documented rsETH vault is 0xd87a19…DE4e; therefore, previously recorded rsETH-specific findings should not be applied to this address. Economic model: ERC-4626-style vault: users deposit the underlying asset and receive receipt shares; assets are allocated dynamically among strategy contracts. For the supplied vault, the documented strategy set includes Aave V3/Lido, Compound-rsETH, Aave V3-rsETH and other ETH/LST-related implementations.

Strategies may lend, borrow, swap and leverage assets. This is directional ETH/LST exposure, not market-neutral: returns depend on staking/restaking yield, lending spreads, borrow costs, LST/LRT exchange rates and liquidation/market risks. Leverage / external exposure: Recursive lending/borrowing and flash-leverage helpers are supported in the contract registry. Current allocation, collateral, debt, health factor and realized leverage are Not verifiable as of September 6, 2026 because Dune is unavailable.

The advertised rsETH page is not evidence for this supplied stETH vault. Yield quality: Base yield appears to come from staking/restaking and Aave/Compound lending spreads; points, incentives and ecosystem rewards may supplement APY. The organic/subsidized split is Not verifiable as of September 6, 2026. Sustainability is rate-sensitive: borrow-rate increases, LST depegs, utilization shocks or liquidation can make leveraged carry negative. Liquidity / mechanics: Withdrawals use requestRedeem; settlement is estimated at approximately five days, so liquidity is gated rather than instant.

Frontend minimums/capacity may apply; direct-contract limits can differ. Fees / revenue: 8% performance fee on profits plus a 0.02% exit fee; the exit fee returns to the vault. No management fee was confirmed in the available evidence. Protocol revenue is therefore primarily performance-fee income; current realized revenue is Not verifiable as of September 6, 2026. TVL / APY: Current TVL, product/chain split, trend, APY history and volatility are Not verifiable as of September 6, 2026.

A stale DeFiLlama snapshot showed $712.45m total, dominated by Ethereum ($708.34m), but it conflicts with the requested chain scope and is not treated as current.

Evidence (4)

reserves

one source

As of 2026-09-06 — Reserves / Treasury assessment On-chain balances: Not verifiable as of 2026-09-06. Dune MCP was unavailable in this run, so no raw-chain balance, asset, liability, or custody query was executed. Consequently, liquid reserves and liabilities are both Not verifiable as of 2026-09-06; no USD values are reported. Scope identity: The supplied Ethereum vault 0xB13aa2d0345b0439b064f26B82D8dCf3f508775d matches CIAN’s documented stETH Yield Layer vault.

The documentation lists a manager at 0x6d425B3D302DD82cC611866eC8176d435307b616 and a shared multisig at 0x8FA9aa69a6e94c1cd49FbF214C833B2911D02553. It also lists strategy contracts involving ETH conversion, Aave V3/Lido, Mellow Steakhouse, Compound rsETH, ezETH, and rsETH routes. These are implementation and control addresses—not evidence of current reserve balances or treasury ownership. Composition: The documented strategy set indicates potential exposure to ETH/LST/LRT and lending-protocol positions, but current per-asset composition, allocation percentages, idle liquidity, encumbrances, and cross-chain exposure are Not verifiable as of 2026-09-06. Custody and control: CIAN documentation claims multisignature approval for fund allocation and parameter changes, but the independent Ackee audit describes a materially centralized trust model: withdrawals require external confirmation, and protocol owners influence withdrawal amounts.

The audit also recorded warnings that the protocol owner could set arbitrary exchange prices and artificially mint vault shares. The audit scope excluded strategies and therefore is not a complete reserve or custody audit. Reserve policy / attestations: CIAN’s risk disclosure says it evaluates proof-of-reserves frequency and validity, but no independently published reserve statement, attestation, custodian report, reserve cadence, or liability reconciliation was located. This is an unverified marketing/process claim, not evidence that reserves exist or are sufficient. Contradiction / key finding: The protocol documentation emphasizes transparency and on-chain strategy visibility, while the available evidence does not establish a complete treasury map, reserve amount, liabilities, or independent reserve attestation.

The gap remains unresolved.

Evidence (4)

tokenomics

two sources

CIAN Yield Layer appears to have no live native token as of the latest available data; past and upcoming token claims are not verifiable on-chain in this run and most details come from marketing materials. Because Dune/on-chain queries are unavailable in this run, all on-chain-related checks fall under the rule: “Not verifiable as of 2026‑09‑04.” ## 1. Existence of a native token

  • Public sources describe CIAN primarily as a yield and automation layer for restaking/LRTs on multiple chains (Ethereum, Arbitrum, Optimism, Polygon, Avalanche), but do not show a deployed, actively trading CIAN token with consistent ticker, contract, and market data across major aggregators.
  • Major analytics platforms (DefiLlama, CoinGecko, CoinMarketCap) either have no listing for “CIAN Yield Layer” or list only the protocol TVL, not a fungible governance/reward token. Finding: As of 2026‑09‑04, the protocol should be treated as non‑tokenized (no native tradable token) for risk analysis purposes. Any references in blogs, social posts, or docs to future token plans are unverified marketing claims. ## 2. Token-level metrics (not verifiable) Given no reliable evidence of a live native token:
  • Name / ticker / contract addresses per chain: Not verifiable as of 2026‑09‑04.
  • Total vs circulating supply; market cap; FDV: Not verifiable as of 2026‑09‑04.
  • DEX liquidity depth and listings: No robust, cross‑confirmed pool data for a CIAN token on the specified chains; Not verifiable as of 2026‑09‑04. ## 3. Token utility, governance, and economics
  • Any described token utility (governance, revenue share, staking rewards, buybacks, burns, fee discounts) appears only in roadmap/marketing content and cannot be tied to an existing on‑chain token contract.
  • Therefore, governance role, revenue share, buyback/burn mechanics, staking rewards, emissions schedule, and unlock schedule are unverified marketing claims if mentioned at all. ## 4. Allocations, unlocks, and holder concentration
  • Team / investor / treasury / community allocations: Not verifiable as of 2026‑09‑04.
  • Unlock schedule and whether unlocks occurred on‑chain: Not verifiable as of 2026‑09‑04.
  • Top‑holder concentration and insider wallets: Not verifiable as of 2026‑09‑04.
  • Mint / blacklist / fee‑switch functions and controllers: Not verifiable as of 2026‑09‑04. ## 5. Risk analyst takeaway For institutional risk purposes, treat CIAN Yield Layer currently as a non‑token protocol; any prospective tokenomics are speculative and unverified until a concrete token contract and on‑chain history are observable.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For CIAN Yield Layer, a Bitcoin drop below $10,000 is not directly verifiable as a protocol-wide stress trigger from the available sources. The only BTC-specific public claim in the search results is that CIAN’s FBTC Yield Layer lets BTC holders keep Bitcoin exposure while routing it into diversified on-chain yield; the materials do not specify a BTC-price liquidation threshold, reserve policy, or protocol-wide insolvency mechanism tied to BTC at $10,000. What *is* verifiable is that CIAN’s general design for leveraged yield strategies can face liquidation and deleveraging risk when collateral values fall or LTVs approach safety thresholds.

CIAN’s documentation and technical materials describe automated deleveraging / protection mechanisms intended to reduce liquidation risk, and the risk writeups note that leveraged staking loops can amplify losses during adverse price moves or depegs. For the requested stress scenario, the most defensible assessment is:

  • BTC-linked vaults may experience severe pressure if collateral, hedges, or borrow legs are BTC-sensitive.
  • Automatic deleveraging would likely be the first line of defense in leveraged structures, but the exact trigger levels for BTC at $10,000 are Not verifiable as of 2026-09-04.
  • Protocol-wide impact across Arbitrum, Avalanche, Ethereum, OP Mainnet, and Polygon is Not verifiable as of 2026-09-04 because the available sources do not provide chain-by-chain exposure, TVL, or position composition for this BTC stress case. One important distinction: sources that discuss “looping risk” and “exit problems” describe general DeFi stress behavior, not a BTC-specific insolvency test for CIAN. So the correct conclusion is that a BTC crash below $10,000 would be a high-stress event for any BTC-exposed CIAN strategy, but the magnitude of losses, liquidation scope, and chain-level exposure are not verifiable from the accessible evidence.
Evidence (8)

stress scenario - largest collateral depegs 20%,

two sources

Under a 20% depeg of the largest collateral, the main stress effect for CIAN Yield Layer is a faster deterioration of vault health factors, which can trigger automatic deleveraging and forced collateral sales in leveraged strategies. CIAN’s own documentation says its strategies continuously monitor LTV and deleverage smoothly to keep positions safe, while audit commentary flags depeg of ETH-based assets as a known risk in the yield-layer design. The most exposed strategies are the leveraged staking loops on ETH/stETH-type collateral, where a collateral discount directly reduces the value supporting borrowed funds and can create a liquidation spiral if liquidity is thin.

Third-party risk analysis specifically notes that leveraged staking strategies can amplify exposure to stETH depeg events and that a sustained discount may cascade across vaults through deleveraging and DEX selling pressure. For users, the likely impact is lower NAV / principal erosion in affected vaults, plus possible withdrawal delays if multiple positions de-risk at once. The literature on CIAN also highlights that recursive leverage and concentrated deposit behavior can increase vulnerability to coordinated exits during stress.

What cannot be verified from the available web sources is the protocol’s current chain-by-chain exposure to the largest collateral, the exact liquidation thresholds, and the dollar loss under a 20% shock. Not verifiable as of 2026-09-04.

Evidence (7)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

Scope / identification. The supplied Ethereum vault (0xB13a…775d) is CIAN’s stETH Yield Layer. Its published strategy set includes Aave V3/Lido, Compound/rsETH, Mellow, and converter strategies; the vault is ERC-4626-like and issues LP shares. Exposure ranking: Not verifiable as of September 5, 2026. Dune was unavailable, so current per-strategy balances, leverage, and chain-by-chain exposure cannot be confirmed.

The scenarios below are therefore structural, not quantified. ### 1) Aave V3 insolvency / bad-debt event — primary direct risk

  • Loss path: collateral supplied to Aave and WETH/ETH debt become partially unrecoverable, or withdrawals are frozen. Aave failure can also force deleveraging at distressed prices.
  • Who absorbs it: vault LP holders through a lower NAV/exchange rate; CIAN does not publicly promise principal protection. CIAN explicitly disclaims control over integrated-protocol failures.
  • Compensation: no CIAN insurance, reserve, or contractual compensation mechanism was identified; recovery would depend on Aave governance/backstop or insolvency recoveries. Not verifiable as of September 5, 2026.
  • Contract impact: the strategy’s withdraw/deleverage calls cannot retrieve missing Aave assets; the Vault’s asset calculation marks only recoverable balances, reducing LP redemption value. Position-protection limits may prevent liquidation but cannot cure counterparty shortfall. ### 2) Lido / stETH impairment or insolvency
  • Loss path: stETH redemption/liquidity impairment or a persistent stETH–ETH discount reduces collateral value and may trigger Aave liquidations.
  • Who absorbs it: LP holders, via NAV loss, liquidation penalties, swap slippage, and potentially bad debt.
  • Compensation: no documented CIAN guarantee; Not verifiable as of September 5, 2026.
  • Contract impact: exchange-rate safeguards can revert unsafe swaps, but cannot restore stETH value; withdrawals may require DEX conversion and become delayed or partial. ### 3) CIAN manager/operator insolvency
  • Loss path: strategy rebalancing, batched withdrawals, or emergency actions stop.
  • Who absorbs it: LP holders bear illiquidity and market risk; assets remain subject to deployed strategy contracts.
  • Compensation: no public deposit-insurance or bankruptcy-remoteness guarantee identified. Not verifiable as of September 5, 2026.
  • Contract impact: multisig/timelock-controlled allocation and redemption operations may cease, trapping funds until governance or users can execute permitted exits.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For the committed fraud by the DAO or owners stress scenario, I found no verifiable evidence in the supplied sources that CIAN’s DAO or owners have committed fraud. The available materials are limited to audit and risk summaries, protocol documentation, and third-party commentary; none of them document fraud, theft, or an owner/DAO misconduct incident. What can be verified is that the protocol has owner-controlled risk surfaces.

Ackee’s audit summary states that the protocol owner can set arbitrary exchange price to pools and artificially mint Vault shares, which means a malicious or compromised admin could potentially harm users even without an external exploit. That is a centralization / governance risk, not proof of fraud. There is also a contradiction worth noting: CIAN’s documentation claims a “flawless security record with no exploits or liquidations for 2 years,” but this is a protocol-provided statement and is unverified marketing claim in this context.

Independent sources do not provide evidence of fraud; they only discuss general risk, composability, leverage, and audit findings. So, in a stress test for DAO/owner fraud, the appropriate assessment is: Not verifiable as of 2026-09-04. The main concern is that privileged roles could potentially abuse pricing or share issuance if governance were compromised, but no source here shows that such fraud actually occurred.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario where the primary yield source is negative over the last 30 days, the relevant conclusion is that CIAN Yield Layer’s vault economics would be under pressure, but the exact impact is not verifiable as of 2026-09-04 from the available web results because no on-chain or vault-level 30d return series was provided. What can be stated from the sources is that CIAN’s Yield Layer is designed to consolidate and redistribute yield from multiple underlying DeFi sources, including lending, staking, restaking, and other protocols. That structure means a negative primary source does not necessarily make the whole system negative, but it does increase dependence on secondary sources and on the strategy’s leverage, borrowing costs, and rebalancing logic.

The main stress implication is that net APY can compress quickly if the main source underperforms while borrow costs, hedging costs, or slippage remain elevated; leveraged strategies are especially exposed because negative carry can compound losses and trigger deleveraging. Hindenrank also notes that CIAN strategies can use leveraged staking loops and that adverse moves in underlying assets can force automated deleveraging, which would be the main transmission channel in a weak-yield regime. If you need a protocol-risk framing, the best concise assessment is: negative primary yield over 30d = elevated return-drag and potential strategy unwind risk, but not enough evidence here to quantify protocol-wide loss or chain-by-chain exposure.

Chain-specific exposure across Arbitrum, Avalanche, Ethereum, OP Mainnet, and Polygon is Not verifiable as of 2026-09-04 from the provided results.

Evidence (6)

Governance & Legal

governance

one source

Assessment as of September 13, 2026. CIAN Yield Layer is not demonstrably DAO-controlled. The published deployment map assigns each listed Yield Layer a common multisig (0x8FA9…2553) plus chain/vault-specific Managers; it does not document token-holder voting, binding proposals, a DAO constitution, or a sovereign governance contract. Control surface. Independent DefiScan review material reports that vault and strategy proxies are upgradeable; owners can replace implementations, and a malicious owner could drain user funds. Managers can perform operational actions such as rebalancing, compounding, and position changes.

The review states that listed permissioned calls execute immediately and found no timelock. This makes effective control operationally CIAN-team/multisig-centric rather than DAO-sovereign. Governance/proposals. The only located “voting” process is Discord feedback/proposal voting connected to Voyage Points and potential rewards, not binding protocol governance. Therefore DAO governance appears symbolic or absent for contract parameters and upgrades. Multisig and concentration. Signer identities, threshold, signer independence, and top token/vault holders: Not verifiable as of September 13, 2026.

Dune MCP was unavailable for this run, so no on-chain holder or multisig query was executed; no substitute analytics figure is presented. Frontend/company control. The Terms state that CIAN owns the Services and may modify or discontinue them, restrict access, and update the Terms at its discretion. They do not identify the legal operating entity, jurisdiction, registration number, or directors in the located text. Contradiction / risk finding: The Terms claim users retain control and that CIAN has no custody/control over funds, but the contract-permission review identifies privileged owners/managers able to upgrade implementations and potentially drain vault assets. The on-chain permission risk takes precedence over the marketing/legal characterization.

Structured fields: timelock=false; timelock_delay_hours=0; multisig_threshold=null; multisig_owners=null; admin_can_drain=true; emergency_bypass=null; dao_governance=false.

Timelock
No
Timelock delay hours
0
Admin can drain
Yes
Dao governance
No
Evidence (4)

legal & regulatory

two sources

Based on available information, CIAN appears to operate as a globally accessible, non‑custodial DeFi yield and strategy protocol with no clear, finalized legal wrapper or public regulatory status, and no user‑facing KYC, which materially increases regulatory and legal uncertainty for institutional users. ### Entity & Jurisdiction

  • The public materials (website, docs, governance posts) do not disclose a concrete legal entity name or place of incorporation for CIAN / CIAN Yield Layer.
  • A draft Terms of Service explicitly leaves placeholders for “legal entity name” and “jurisdiction”, and states it “has not been reviewed or approved by a qualified legal professional” and is “not an enforceable agreement.”
  • Team composition and contacts (e.g., Founder/CEO Luffy He, Head of Growth Chris Dahmen) are disclosed in Arbitrum governance proposals, but no corporate registration details are provided. Result: entity and jurisdiction are Not verifiable as of 2026‑09‑04. ### Terms of Service / User Restrictions
  • The only ToS found is explicitly labeled draft, not yet effective, and cannot be relied on as a binding contract.
  • The main app marketing page advertises “No KYC, Borderless – True DeFi sovereignty – participate globally without identity verification.”
  • No specific geographic restrictions (e.g., US, EU, sanctioned countries) are disclosed in public user‑facing materials. ### KYC / AML
  • Retail protocol use: explicitly no KYC.
  • Institutional side: in Arbitrum grant and LTIPP applications, the team acknowledges that they will be subject to KYC requirements for receiving Arbitrum DAO funding.
  • No visible public description of a formal AML program, sanctions screening regime, or compliance officer for end users. ### Regulatory Classification & Legal Structure
  • CIAN describes itself as a non‑custodial DeFi yield/automation middleware, with assets held in audited smart contracts and users able to withdraw anytime.
  • It integrates with multiple underlying DeFi protocols and uses structured strategy vaults focused on LSTs, LRTs, RWAs, and delta‑neutral/automation strategies.
  • No public statement classifying the protocol as a VASP, investment manager, fund, or broker, and no license numbers or regulator registrations are disclosed. ### Warnings, Enforcement, Sanctions, Court Cases
  • No public records (media or governance) indicating regulatory warnings, enforcement actions, court cases, or sanctions targeting CIAN or a known operating entity were found. ### Data Protection / Privacy
  • No finalized privacy policy or data protection statement (e.g., GDPR) is visible; the ToS draft is generic and not in effect. ### Institutional Risk Takeaways
  • Key structural risk: absence of a verified legal entity and jurisdiction; draft, non‑effective ToS; no user‑facing KYC/AML framework.
  • Regulatory exposure: potential classification risk as unlicensed investment or VASP activity in stricter jurisdictions, especially for institutional LPs.
  • Operational risk: reliance on informal governance and external grants (e.g., Arbitrum) without a clear corporate wrapper increases counterparty and recourse uncertainty. Because no concrete regulator action or sanction listing could be identified, both active_enforcement and sanctioned are **Not verifiable as of 2026‑09‑04`.
Evidence (9)

legal registries

two sources

No exact GLEIF LEI record for 'CIAN Yield Layer'. OFAC SDN screening of 'CIAN Yield Layer': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • CIAN Yield Layer
Sanctioned
No
Evidence (4)

Stability

stability

one source

CIAN Yield Layer does not appear to issue its own stablecoin; it is a yield aggregator that accepts third-party stablecoins such as USDC, USDT, USDe, and USDS, so own_stablecoin is false. Stablecoin depeg history for the protocol’s used assets is not verifiable as of 2026-09-06 from the available sources, because the sources reviewed identify supported deposit assets but do not provide a complete protocol-specific incident history with measurable depeg events. Therefore stable, depeg_count, max_depeg_pct, and last_depeg_date are not verifiable as of 2026-09-06.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDT
  • USDe
  • USDS
Evidence (3)

Risks & Strengths

risks

one source

CIAN Yield Layer is a multi-chain yield aggregator whose risk is determined by its vault contracts, strategy operators, integrated lending/staking protocols, and the underlying networks. The protocol documents controls such as multisig approvals, timelocks, exchange-rate limits, LTV protection, audits, and withdrawal processing; however, these controls and current deployment coverage were not independently verified on-chain. Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Strategy contract or integration failureA bug, unsafe adapter, malicious strategy, or faulty upgrade could misroute assets, impair accounting, or cause partial or total loss. Audit existence does not prove current deployed bytecode is safe.HighMediumProtocol reports audits, contract-based strategy restrictions, multisig approvals, timelocks, and on-chain accounting.High residual risk because deployed versions, audit scope, remediation status, and all strategy contracts were not independently verified. Not verifiable as of September 5, 2026.
Underlying protocol counterparty failureLosses may arise from Aave, Lido, DEX, lending-market, oracle, or other integrated-protocol exploits, insolvency, bad debt, or governance actions.HighMediumProtocol reports partner due diligence, asset traceability checks, preference for established venues, and LTV monitoring.Medium-High; diversification and monitoring cannot eliminate correlated DeFi contagion or third-party contract risk.
Liquidation and collateral volatilityRapid price moves, oracle delays, utilization spikes, or collateral devaluation can trigger liquidation, bad debt, negative carry, or forced deleveraging.HighMediumProtocol reports protection thresholds below liquidation LTV, actual-LTV monitoring, and exchange-rate safeguards.Medium-High, particularly during disorderly markets; monitoring may not execute before prices gap.
Withdrawal and liquidity mismatchUnderlying positions may be illiquid, subject to cooldowns, withdrawal queues, slippage, utilization constraints, or stressed-market liquidity shortages, delaying or reducing redemptions.HighMediumProtocol reports immediate-deleveraging analysis, DEX exit checks, 1–2% slippage assumptions, and dedicated exit channels.Medium-High; stated liquidity checks are not independently validated and normal-market assumptions may fail under stress.
Multi-chain and bridge dependencyOperating across Ethereum, Arbitrum, Avalanche, OP Mainnet, and Polygon adds chain outages, sequencer/finality, bridge, messaging, liquidity-fragmentation, and deployment-consistency risk.HighMediumProtocol lists chain-specific deployments and uses chain-native strategy integrations; audits are listed for selected networks.High because chain-by-chain exposure, bridge paths, permissions, and current deployment consistency were not verified on-chain. Not verifiable as of September 5, 2026.
Evidence (4)

strengths

two sources

CIAN Yield Layer’s top strengths are: capital efficiency—it is designed to generate multi-source yield per asset and claims up to 13x capital efficiency; cross-protocol interoperability—it integrates with major DeFi protocols and supports cross-chain asset deployment; security architecture—the docs describe multi-signature controls, on-chain strategy contracts, and strict exchange-rate limits; transparency—strategy contracts and asset calculations are stated to be viewable and performed on-chain; and borderless accessibility—users can participate without KYC, making it globally accessible. The strongest verifiable takeaways from the available sources are the protocol’s focus on optimized APY, modular strategy execution, and transparent on-chain asset management.

Evidence (4)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 14 two independent sources, 22 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-31.