Hyperbeat Earn

Green · 75/100

Executive summary

Hyperbeat Earn is a multi-vault yield protocol on Hyperliquid L1, scoring 77/100 (green band) with high data confidence (87/100).

  • Security: Audited by Nethermind (two full reviews covering withdrawal queue and multi-asset vault infrastructure; 1 critical, 2 medium, 20+ low/informational findings, all stated resolved before deployment) and Certora (vault infrastructure; 1 medium, 9 low, 8 informational). Bytecode match to deployed contracts is not verifiable as of 2026-09-06. Documentation claims additional audits by Hacken, Sherlock, ChainSecurity, Sigma Prime, and Zellic, but these reports are either for infrastructure partners (Midas) or could not be independently retrieved—treat as unverified marketing claims. Active Immunefi bug bounty with $3M max payout.
  • Incidents: No verified fraud, rug, insolvency, or enforcement actions. One prior Ultra HYPE vault pause/wind-down mentioned but current vault status is operational.
  • Governance & custody: No DAO governance; $BEAT token confers no governance rights. Operated by Zoeion Ltd Corporation (Panama/Cayman). HYPE Vault is a TransparentUpgradeableProxy; admin identity (EOA/multisig/timelock) not verifiable. Non-custodial vault design with user-controlled keys via Turnkey; upgrade-mediated drain risk exists but no direct drain function confirmed.
  • Top risks: (1) Vault contract/accounting failure could misprice shares or freeze withdrawals despite audits. (2) Underlying strategy loss: funds deployed across HyperEVM protocols (HyperLend, HypurrFi, Timeswap, others) and Hyperliquid perpetuals; allocation percentages and current failure status not verifiable. (3) Hyperliquid infrastructure dependency: funding can turn negative, liquidity/latency can unbalance hedges. (4) Oracle manipulation risk (validator-maintained feeds, RedStone). (5) Stablecoin/LST depeg exposure (USDC, USDT0, USDe, beHYPE). (6) Withdrawal liquidity: instant redemption with 0.5% fee when available, else 48h classic redemption; documentation states "up to 1 day" creating a contradiction.
  • Strengths: Automated yield optimization across multiple HyperEVM venues; capital flexibility and risk dispersion; transparent smart-contract delivery; $5.2M seed funding from ether.fi Ventures, Electric Capital, Coinbase Ventures, Anchorage Digital; simple UX for complex strategies.
  • Unverified: Founders/team not publicly identified. Exact TVL, allocation weights, and on-chain position data not verifiable as of 2026-09-06. Deployment chain contradiction: DeFiLlama lists Hyperliquid L1, docs describe HyperEVM; hbUSDT addresses are on HyperEVM/chain ID 999. No published reserves, treasury policy, or segregation framework. Audit coverage of deployed bytecode unconfirmed.
  • Recommended exposure: Conservative allocation (≤2–5% of DeFi portfolio) until bytecode-to-audit match, founder identities, and live allocation data are verified. Suitable for allocators comfortable with Hyperliquid L1 infrastructure risk, upgradeable proxy risk, and multi-protocol counterparty exposure. Avoid if transparency on admin keys, withdrawal liquidity depth, or audited-code deployment is a hard requirement. Monitor funding rates and HyperEVM protocol health.
  • Open questions: (1) Confirm deployed vault bytecode matches audited commits (Nethermind, Certora). (2) Identify proxy admin (EOA/multisig/timelock) and upgrade process. (3) Verify current allocation percentages across HyperEVM protocols and Hyperliquid perpetuals. (4) Obtain founder/team identities and track record. (5) Clarify withdrawal timeline (instant vs. 48h vs. "up to 1 day"). (6) Verify reserves, treasury address, and liability coverage. (7) Confirm Hacken/Sherlock/ChainSecurity/Sigma Prime audit reports or disregard claims.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 8 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-09)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $24,279,119 = 0% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 13/35 verified facts; 35/35 fresh (180d)

Identification

protocol identification

two sources

Hyperbeat Earn is a yield protocol built on Hyperliquid L1, offering automated basis‑trading style “vault” strategies for USDC and HLP margin accounts on the Hyperliquid perpetuals DEX. Identification

  • Name: Hyperbeat Earn
  • Website / App: app.hyperbeat.org (accessed via Hyperliquid app portal and direct URL)
  • Docs: A dedicated docs site is mentioned in community materials but not reliably discoverable via independent sources; detailed documentation location is Not verifiable as of 2026-09-04.
  • Category: DeFi yield protocol / automated trading vaults on a centralized order‑book chain (Hyperliquid L1).
  • Chains: Hyperliquid L1 only (no credible evidence of deployments on EVM chains or other L1s).
  • Native / Reward Token: Hyperbeat vaults use USDC as the primary deposit asset; a separate Hyperbeat governance or reward token is Not verifiable as of 2026-09-04 (no independent listing on major aggregators or explorers).
  • Launch date: Community posts and Hyperliquid ecosystem listings point to Hyperbeat as an early‑2025 addition to the Hyperliquid ecosystem, but an exact mainnet launch block/time is Not verifiable as of 2026-09-04. Main contract / technical setup Hyperbeat operates on Hyperliquid’s proprietary L1, which is not covered by standard EVM explorers or Dune; concrete contract addresses, their source code, and verification status are therefore Not verifiable as of 2026-09-04 using independent tooling. No reliable third‑party registry (e.g., Etherscan, Arbiscan, L2Beat) references Hyperbeat Earn, consistent with it being native to Hyperliquid. Fork lineage / design origin
  • Hyperbeat Earn is described in ecosystem materials as an original strategy vault built specifically for Hyperliquid’s perps and margin system, not as a direct fork of common EVM yield protocols such as Yearn, Gearbox, or GMX vaults.
  • No independent source documents Hyperbeat as a fork of any upstream DeFi codebase, and no GitHub repository with a clear fork relationship is discoverable; fork status is therefore Not verifiable as of 2026-09-04.
  • There is no publicly indexed audit report for Hyperbeat contracts on major audit platforms (e.g., OpenZeppelin, Trail of Bits, Quantstamp, Certora, CertiK), and no bug‑bounty listing on common platforms; the existence of private or non‑published audits is Not verifiable as of 2026-09-04.
  • No documented history of malicious modifications in Hyperbeat or named forks appears in independent incident databases or media; absence of evidence does not prove safety but suggests no publicly known exploit history as of this date. Given Hyperliquid L1’s non‑EVM architecture and lack of standard explorers, most on‑chain specifics (addresses, verification flags, exact deployment chronology) are Not verifiable as of 2026-09-04 and should be treated as a key diligence gap.
Evidence (4)

maturity

two sources

Hyperbeat Earn appears to be a real live app, not just a landing page: the web results show functional app routes such as /earn, /vaults, specific vault pages, and dedicated deposit/withdrawal flows, plus docs that describe concrete contract interactions and supported assets. The UX looks productized rather than template-only, because docs include vault-specific instructions, contract addresses, and withdrawal mechanics, and the portal has separate product areas like Earn, Pay, and vault pages. Live deposits/withdrawals are supported in the documented flow: Hyperbeat’s blog and docs describe deposit dialogs, supported assets, multiple deposit sources, and withdrawal destinations including external wallets and internal transfers.

That said, exact live usage, success rates, and whether all flows are currently working end-to-end are not verifiable as of 2026-09-04. Open API: Not verifiable as of 2026-09-04. The available web evidence shows documentation and contract-level interaction details, but no clearly documented public REST/GraphQL API or developer API reference surfaced in the search results.

Broken links / fake metrics / template signs: Not verifiable as of 2026-09-04. The search results do not provide a reliable crawl of the site for broken-link detection, nor a defensible basis to claim fake metrics or template reuse. The strongest visible signal is that the site is more than a static landing page because it exposes operational vault pages and docs.

Evidence (5)

Security

bug bounty

unverified

Hyperbeat appears to have an active public bug bounty channel via Immunefi. The available public evidence says reports should be submitted through the HyperBeat bug bounty program on Immunefi, with rewards ranging from $500 for low severity to $3,000,000 for critical vulnerabilities. The public snippet does not state the program launch date, detailed scope/parameters, or any disclosed bounty results/paid findings, so those fields are not verifiable from the gathered evidence as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$3.0M
Evidence (2)

counterparty risks

unverified

As of September 6, 2026. Dune/on-chain verification was unavailable: Not verifiable as of September 6, 2026. Exact dependency weights and current failure status are therefore unknown. Structured fields

  • dependency_failure_active: null
  • max_exposure_pct: null Dependency map and risk assessment
  • Primary concentration — Hyperliquid: Hyperbeat’s delta-neutral products execute spot/perpetual strategies on HyperCore. Yield depends on Hyperliquid funding, order-book liquidity, margining, liquidation and uptime. Funding can turn negative; volatility, latency or shallow liquidity can temporarily unbalance hedges and delay withdrawals.
  • External DeFi protocols: Earn vaults allocate across HyperEVM protocols. Documented integrations include HyperLend, HypurrFi, Timeswap, HyperSwap, Upshift and Silhouette; other materials name Felix, Theo, ether.fi and Nunchi/Ventuals. This creates smart-contract, governance, liquidity, oracle and bad-debt contagion risk. Allocation percentages are Not verifiable as of September 6, 2026.
  • Oracles: Hyperliquid relies on validator-maintained price oracles, creating manipulation/liquidation risk. Hyperbeat/Morpho markets also reference RedStone feeds and fundamental vault-token feeds. A stale, manipulated or unavailable feed could cause mispricing, liquidation or impaired redemption.
  • Stablecoins/LSTs/restaking: Exposure can include USDC, USDT0, USDe, USR, beHYPE, kHYPE/stHYPE and dnTokens. Risks include issuer depeg/insolvency, LST redemption delays, validator/slashing risk and recursive collateral contagion. beHYPE redemption normally requires a seven-day process; instant exit charges 0.5%.
  • RWA/issuer risk: The XAUt vault adds tokenized-gold issuer, reserve, custody and redemption risk. The issuer/SPV and exact exposure are Not verifiable as of September 6, 2026.
  • Bridges/custody/CEX-MM: Hyperliquid documentation identifies Arbitrum bridge risk for the perp system. Hyperbeat describes vaults as non-custodial, but strategy managers, keepers, execution agents and withdrawal contracts remain operational trust boundaries. No specific CEX or named external market-maker exposure was verified. Failure scenarios: external-protocol exploit; stablecoin/LST depeg; oracle manipulation; Hyperliquid halt; negative funding; forced hedge unwind; liquidation; bridge failure; or redemption-liquidity shortfall. > Contradiction / data-quality callout: The prior finding characterized Hyperbeat mainly as a Hyperliquid-perpetuals product. Current documentation shows materially broader HyperEVM lending, liquidity, LST, tokenized-gold and HIP-3 dependencies. Official XAUt pages also conflict on strategist, infrastructure and fee terms; exact current configuration is Not verifiable as of September 6, 2026.
Evidence (4)

crypto custody

one source

Hyperbeat Earn is organized as non-custodial DeFi vault access: the vaults are described as automated, non-custodial strategies, and Hyperbeat states it does not take possession, custody, or control of users’ crypto-assets. For the broader Hyperbeat stack, assets are described as living in a self-custodial smart wallet, with the user retaining control of private keys while the backend has only limited operator permissions for settlement actions within user-defined limits. The Earn vaults deploy deposited assets into HyperEVM protocols and partner protocols to generate yield rather than holding them on a company balance sheet.

Withdrawal pausing was not clearly evidenced for the current Earn vaults in the gathered sources; a prior Ultra HYPE vault pause/wind-down was mentioned separately, so current withdrawal status is Not verifiable as of 2026-09-06. Asset segregation between users is not explicitly documented in the gathered sources, so segregated_assets is Not verifiable as of 2026-09-06.

Evidence (6)

key management

unverified

Hyperbeat Earn’s key management is organized around a non-custodial smart-wallet model: users hold the controlling keys for a ManagementAccount, and Hyperbeat says the protocol does not custody user funds or directly access user private keys. The documented implementation uses Turnkey to generate and protect each user’s on-chain signing key, which becomes the owner of the ManagementAccount; Turnkey applies policy-based signing so signatures are constrained to approved actions and the key cannot be used arbitrarily. For convenience, Turnkey also issues short-lived session keys with limited permissions for actions like viewing balances or trading, while explicitly preventing them from moving assets or changing permissions.

Recovery is described as passkeys, hardware keys, and social recovery, allowing users to regain access without Hyperbeat acting as custodian. Hyperbeat’s own marketing also claims “12+ independent nodes” and threshold signatures for its wallet/bridge stack, but that claim is not independently verifiable from the provided sources, so it should be treated as an unverified marketing claim.

Evidence (3)

smart-contract

two sources

Assessment date: September 6, 2026. Dune MCP was unavailable; therefore no on-chain role, proxy, timelock, event, balance, or function verification was performed. All such items are Not verifiable as of September 6, 2026. Scope/chain contradiction. DeFiLlama lists Hyperbeat Earn on Hyperliquid L1 (100% exposure), while Hyperbeat’s own Earn documentation describes the vaults as operating on HyperEVM. The published hbUSDT integration addresses are explicitly on HyperEVM/chain ID 999, not demonstrably HyperCore/L1 contracts.

This is a material deployment-identification gap. Addresses found (HyperEVM, not L1-verified): hbUSDT vault 0x5e105266db42f78FA814322Bce7f388B4C2e61eb; insurance/deposit contract 0xbE8A4f1a312b94A712F8E5367B02ae6E378E6F19; redemption contract 0xC898a5cbDb81F260bd5306D9F9B9A893D0FdF042. A complete Earn contract set and verified source-code mapping are Not verifiable as of September 6, 2026. Verification and audit status. Hyperbeat documentation claims three hbUSDT audits (two Hacken, one Sherlock), but accessible independent data says no published audit reports; the exact reports, deployment commit, scope, and remediation status were not established. Treat the audit claim as an unverified marketing claim.

The independent Zellic audit located concerns Hyperbeat Pay, not Earn vault deployments, and reported one critical finding in that separate scope. Upgradeability/admin controls: proxy architecture, implementation/admin addresses, owner/role holders, emergency pause, withdrawal blocking, fee/oracle/strategy setters, renounced roles, and timelock delay: Not verifiable as of September 6, 2026. The documentation states users can redeem instantly or through a roughly 48-hour classic process, but classic status/processing uses an off-chain Midas API; independent permissionless-exit verification is unavailable. Architecture (provisional, documentation-based): User → Insurance/Deposit Contract → hbUSDT shares → Strategy/DeFi venues User → Redemption Contract → USDT0 Unknown privileged layer → fees / strategy allocation / liquidity / emergency controls Worst case: a compromised privileged key or upgrade authority could potentially redirect strategy assets, alter redemption/fees/oracles, pause withdrawals, or upgrade implementation; capability is unverified. The principal current risk is opaque deployment and administration, creating meaningful rug/freeze uncertainty.

Evidence (5)

audit

two sources

Certora — Vault infrastructure assessment. The public repository contains a Certora PDF under Vault-Infra; the audit window is reported as October 15–28, 2025. Publication date: Not verifiable as of 2026-09-04.

Scope: Hyperbeat vault infrastructure; exact contract list/commit is Not verifiable as of 2026-09-04. Findings: 0 critical, 0 high, 1 medium, 9 low, 8 informational (secondary transcription; verify against the linked primary PDF). Fix status: the medium finding was reported fixed; remaining findings were acknowledged.

Covers deployed code: Not verifiable as of 2026-09-04; no bytecode-to-audited-commit match was established. CONTRADICTION: Hyperbeat documentation claims hbUSDT was audited three times by Hacken/Sherlock, while HyperEVMScan reports no audit submitted and DIA reports no published audits for Hyperbeat Earn. These Hacken/Sherlock reports were not independently retrievable, so they are excluded as report items.

Auditor
Certora
Report date
2025-10-28
Scope
Vault-Infra; exact files/commit Not verifiable as of 2026-09-04
Findings
0 critical; 0 high; 1 medium; 9 low; 8 informational. Counts sourced from an analytics transcription; primary PDF linked.
Fix status
Medium reported fixed; remaining findings acknowledged. Deployed-code coverage Not verifiable as of 2026-09-04.
Evidence (4)

audit

unverified

Hyperbeat documentation claims Ultra HYPE vault is audited by ChainSecurity. No independent ChainSecurity report for Hyperbeat Earn was found.

Auditor
ChainSecurity
Report date
2025-10-22
Scope
Claimed scope: Ultra HYPE vault vault infrastructure for Hyperbeat Earn on Hyperliquid; details and bytecode match are unverified marketing claims.[3]
Findings
Not verifiable as of 2026-09-04 (no public report identified; only protocol claim).
Fix status
Not verifiable as of 2026-09-04 (no remediation or deployed-code coverage confirmed).
Evidence (1)

audit

one source

Corrected split of the previously merged Nethermind engagement: First report — withdrawal queue security review for Hyperbeat liquid-staking/vault infrastructure underpinning Earn. Public case study published April 15, 2026; underlying report publication date Not verifiable as of 2026-09-06. Findings: 1 critical, 0 high, 0 medium, 4 low, 1 informational, 1 best-practice.

Principal issue: sequential withdrawal processing could permanently block the queue when a receiver could not accept native transfers. Fix status: withdrawal mechanism redesigned to remove sequential dependency; Nethermind states all vulnerabilities were resolved before deployment. Covers deployed code: Not verifiable as of 2026-09-06; no bytecode-to-audited-commit match established.

Auditor
Nethermind Security
Report date
2026-04-15
Scope
Withdrawal queue security for Hyperbeat liquid-staking and multi-asset vault infrastructure; underlying report date Not verifiable as of 2026-09-06.
Findings
1 critical; 0 high; 0 medium; 4 low; 1 informational; 1 best-practice. Critical theme: withdrawal queue blocking.
Fix status
Nethermind states all vulnerabilities were resolved before deployment; specific remediation is described for the withdrawal queue. Deployed-code coverage Not verifiable as of 2026-09-06.
Report url
https://github.com/0xhyperbeat/Audits/blob/main/Vault-Infra/Nethermind.pdf
Report id
doc:00151864e2878a52
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

New published Nethermind security review: Hyperbeat Liquid Banking architecture, including ManagementAccount, mode transitions, whitelist enforcement, and Morpho Blue integration. Publication date: April 10, 2026. Scope is not explicitly confirmed as the deployed Hyperbeat Earn contracts on Hyperliquid L1.

Findings: 0 critical, 0 high, 2 medium, 11 low, 14 informational, 3 best-practice recommendations. Fix status: a subset was remediated during the engagement; remaining findings were acknowledged with documented rationale and risk acceptance. Covers deployed code: Not verifiable as of 2026-09-06.

Auditor
Nethermind Security
Report date
2026-04-10
Scope
Hyperbeat Liquid Banking codebase; ManagementAccount, mode switching, credit-service switching, whitelist boundaries, and Morpho Blue integration. Hyperliquid L1 Earn deployment coverage is Not verifiable as of 2026-09-06.
Findings
0 critical; 0 high; 2 medium; 11 low; 14 informational; 3 best-practice recommendations.
Fix status
Subset remediated during engagement; remaining findings acknowledged with documented rationale and risk acceptance. Bytecode match to deployed Earn contracts Not verifiable as of 2026-09-06.
Report url
https://www.nethermind.io/blog/auditing-hyperbeats-liquid-banking-architecture
Report id
doc:c7d76560f4c2fe72
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Hyperbeat docs state the LST vault and liquidHYPE vault are audited twice by Hacken, referencing Midas vault and Midas smart contract audit reports hosted via GitBook. These appear to be audits of the vault infrastructure partner (Midas) rather than a native Hyperbeat Earn contract on Hyperliquid L1.

Auditor
Hacken
Report date
2023-09-25
Scope
Midas smart contracts and Midas vault infrastructure, reused by Hyperbeat LST and liquidHYPE vaults; these are infrastructure-partner audits, not directly confirmed Hyperbeat Earn audits for deployed Hyperliquid L1 contracts.[1][10][13]
Findings
Underlying Hacken reports are for Midas vault infrastructure; detailed severities for Hyperbeat Earn-specific deployments on Hyperliquid L1 are not verifiable as of 2026-09-04.[10][13]
Fix status
Not verifiable as of 2026-09-04 for Hyperbeat Earn on Hyperliquid L1 (no explicit statement that deployed bytecode for Earn vaults equals the audited Midas contracts).
Evidence (1)

audit

two sources

Nethermind — Multi-asset vault infrastructure assessment. Nethermind reports a review covering withdrawal processing and vault valuation/cross-chain accounting; the engagement is reported as September 19–October 1, 2025. Publication date: Not verifiable as of 2026-09-04.

Findings: 0 critical, 0 high, 2 medium, 5 low, 2 informational. Key issues included cross-chain valuation manipulation and inaccessible/stuck funds inflating valuation. Fix status: both medium findings were fixed before the final report; three low findings were acknowledged.

Covers deployed code: Not verifiable as of 2026-09-04; no bytecode-match evidence was available.

Auditor
Nethermind Security
Report date
2025-10-01
Scope
Multi-asset vault infrastructure; withdrawal and valuation/cross-chain accounting
Findings
0 critical; 0 high; 2 medium; 5 low; 2 informational. Medium issues: cross-chain supply/valuation distortion and stuck-funds accounting.
Fix status
Both medium findings fixed before final report; three low findings acknowledged. Deployed-code coverage Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Hyperbeat docs state Nunchi (HIP-3) nLP vault audited by Nethermind Security and Certora, with links to a GitHub directory of Vault-Infra audits. These are infrastructure audits; direct association with Hyperliquid L1 deployed Nunchi vault bytecode is not confirmed in public data.

Auditor
Nethermind Security & Certora (Nunchi HIP-3 nLP vault)
Report date
2026-08-09
Scope
Vault infrastructure used by Nunchi (HIP-3) nLP vault; chain and deployment coverage for Hyperbeat Earn on Hyperliquid L1 are unverified marketing claims.[5]
Findings
Not verifiable as of 2026-09-04 from public snippets (no severity breakdown for Nunchi vault found without direct access to reports).
Fix status
Not verifiable as of 2026-09-04 (no clear remediation summary or confirmation that audited code equals deployed Hyperliquid L1 contracts).
Evidence (2)

audit

one source

Hyperbeat docs state that the LST vault and liquidHYPE vault are audited once by Sherlock, linking a contest page for Midas vaults. This again refers to the shared vault infrastructure rather than a natively deployed Hyperbeat Earn contract on Hyperliquid L1.

Auditor
Sherlock
Report date
2023-12-01
Scope
Midas vault infrastructure used by Hyperbeat LST and liquidHYPE vaults; impact on currently deployed Hyperbeat Earn contracts on Hyperliquid L1 is unverified.[10][13]
Findings
Sherlock contest page (for Midas vaults) is not specific to Hyperbeat Earn; no critical/high issues for Hyperbeat Earn on Hyperliquid L1 can be confirmed as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04 (no explicit remediation or bytecode match to Hyperliquid L1 Earn deployments).
Evidence (2)

audit

unverified

Hyperbeat documentation claims Ultra HYPE vault is audited by Sigma Prime. No independent Sigma Prime report for Hyperbeat Earn could be located in public sources.

Auditor
Sigma Prime
Report date
2025-10-22
Scope
Claimed scope: Ultra HYPE vault infrastructure on Hyperbeat Earn; actual audited contracts, chain, and deployed-code coverage are unverified marketing claims.[3]
Findings
Not verifiable as of 2026-09-04 (no public report identified; only protocol claim).
Fix status
Not verifiable as of 2026-09-04 (no evidence of remediation status or bytecode match for Hyperliquid L1 Earn deployment).
Evidence (1)

audit

one source

Security assessment of Hyperbeat Pay. Hyperbeat docs state that the Ultra HYPE vault is audited by Zellic, but public Zellic report is explicitly scoped to Hyperbeat Pay, not clearly to Hyperbeat Earn vault contracts.

Auditor
Zellic
Report date
2025-10-31
Scope
Hyperbeat Pay contracts; protocol documentation claims Ultra HYPE vault audited by Zellic, but chain, contract list and bytecode match to Hyperliquid L1 Earn deployment are unverified marketing claims.[3][14]
Findings
Public summary states a security assessment of Hyperbeat Pay, but does not enumerate issue severities in the snippet available.[14] Detailed findings for Earn vaults not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04 (no publicly confirmed remediation report or explicit match to Hyperliquid L1 Earn vault bytecode).
Evidence (2)

Team & Reputation

founders

two sources

Hyperbeat Earn’s founders and core team are not publicly identified by name, and there is no clear corporate profile (legal entity, offices, jurisdiction) available from independent sources. Not verifiable as of 2026-09-04. ### 1. Team, founders, and background

  • Multiple independent write‑ups describe Hyperbeat as built by “early Hyperliquid users turned native builders” and “experienced Ethereum developers and early Hyperliquid contributors,” but none name individuals or give verifiable biographies.
  • A detailed ecosystem review states Hyperbeat raised a $5.2m seed round co‑led by ether.fi Ventures and Electric Capital, with Coinbase Ventures and Anchorage Digital also participating. This indicates institutional VC backing, but that still does not reveal founder identities or board.
  • Hyperbeat Earn is one product in a broader stack (beHYPE liquid staking, Meta Yield vaults, Morphobeat credit, Hyperbeat Pay, Hyperfolio), suggesting a multi‑product team rather than a single strategist. Reality check:
  • Founders: Not verifiable as of 2026-09-04. No independent source provides names, prior roles, or track record (successes or hacks).
  • Team composition: Marketed as Hyperliquid‑native builders with Ethereum background, but this is a marketing claim unless backed by named identities and résumés. ### 2. Public vs anon; credibility
  • Social presence is via @0xHyperBeat / @hyperbeat accounts and protocol docs, with no doxxed core contributors, no “Team” page, and no visible LinkedIn‑style disclosures. Not verifiable as of 2026-09-04.
  • VC participation from Electric Capital, ether.fi Ventures, Coinbase Ventures, Anchorage Digital is a strong external signal that some level of KYC and technical diligence has occurred, but those reports are not public.
  • Community research pieces describe Hyperbeat as validator‑aligned, chain‑scaling yield infrastructure, again without personal identities. ### 3. Corporate setup: office, jurisdiction, real business
  • No independent source specifies a registered company name, jurisdiction, or office address. Not verifiable as of 2026-09-04.
  • The product footprint (Visa card, fiat ramps, “Liquid Banking”) implies partnerships with regulated payment providers, but counterparties are not named and cannot be verified from current public data.
  • Hyperbeat is clearly an active protocol with non‑custodial vaults and multi‑product infrastructure on Hyperliquid L1, but it operates as a web-native, protocol-first business, not a traditional onshore financial institution. ### 4. Prior projects, outcomes, hacks
  • No independent evidence of prior projects run by the founders, nor of past hacks or blow‑ups tied to this team. Not verifiable as of 2026-09-04. Institutional takeaway:
  • Governance and execution appear VC-backed but operationally anonymous, with real traction on Hyperliquid but no verifiable founder identities or corporate footprint. This is a material risk point for institutional allocators despite the strong investor roster.
Evidence (14)

general reputation

two sources

Hyperbeat Earn currently has a generally positive but still emerging reputation, with no public evidence of fraud, rug, or insolvency allegations, and no visible regulatory or sanctions actions as of 2026‑09‑04. Founders / team / investors

  • Public materials focus on Hyperbeat as a Hyperliquid‑native “liquid banking” stack (passkey smart wallet, Earn vaults, beHYPE liquid staking, credit, payments).
  • A Hindenrank risk review states Hyperbeat has $5.2M in seed funding from Ether.fi and Electric Capital, both well‑known crypto investors, which is a reputational positive.
  • The mobile app listing shows a Panamanian legal address via Paralelaw, indicating some level of corporate structuring but not necessarily strong regulatory oversight.
  • Individual founders are not prominently profiled in independent sources; this is a transparency gap for institutional risk assessment. Protocol reputation & sentiment
  • Analytics platforms describe Hyperbeat Earn as Hyperliquid’s native yield layer with Meta‑vaults, delta‑neutral strategies and HYPE liquid staking, and highlight “onchain solvency proofs” as a design feature.
  • Independent ecosystem directories mark Hyperbeat Earn as a “yield optimization platform – audited”, but do not link auditor names or reports; this is an unverified marketing claim until auditor documentation is found.
  • Commentary and guides (including Binance Square and HypeWatch‑style listings) present Hyperbeat positively as a primary yield hub on Hyperliquid, focusing on UX and capital efficiency, not on controversies. Audits, security, bug bounties
  • Multiple listings state the protocol is audited, but none in the retrieved data link directly to a named auditor’s report; audit status is therefore Not verifiable as of 2026‑09‑04 and must be treated cautiously.
  • No independent evidence of formal bug bounty programs was found; Not verifiable as of 2026‑09‑04. Criticisms, incidents, legal/regulatory
  • The Hindenrank article is framed as risk analysis, discussing strategy complexity and leverage, but does not report hacks, insolvency, or governance crises.
  • No credible reports of fraud, rug‑pulls, sanctions, or enforcement actions were identified; Not verifiable as of 2026‑09‑04 whether any non‑public investigations exist. Unresolved concerns for institutional risk
  • Limited founder identity disclosure and lack of independently verifiable audit reports.
  • Jurisdictional setup (Panama) and cross‑border fiat/card rails may raise KYC/AML and licensing questions, which require separate legal review.
  • Complex delta‑neutral and leveraged strategies increase model and operational risk, even absent reputational scandals.
Evidence (10)

Economy

TVL: $24.3M

model

one source

Economic model. Hyperbeat Earn is a multi-product vault suite, not one homogeneous strategy. Meta Vaults dynamically allocate deposited assets across HyperEVM/HyperCore opportunities, including lending, liquidity provision and partner incentives; exact live allocations are Not verifiable as of September 6, 2026. The USDT vault accepts USDT0 (and documented integrations include USDe/USR), deploys capital into HyperEVM protocols, and issues composable hbUSDT shares.

It charges a 20% performance fee; liquidity provision creates impermanent-loss and smart-contract/counterparty exposure. Yield and exposures. Yield is a mixture of underlying lending/LP returns, Hyperliquid funding payments, liquid-staking yield where applicable, and partner incentives. Delta-neutral dnTokens pair a spot or yield-bearing asset with a matched Hyperliquid perpetual short, targeting near-zero delta; funding can turn negative, and execution, order-book, downtime and basis risks remain. dnTokens charge 10% of positive performance and have asset-level TVL caps. This is market-neutral by design only for the dnToken products; other vaults may be directional or incur LP price exposure. Withdrawals / constraints. USDT has instant redemption when liquidity is available with a 0.5% fee, or classic redemption generally within 48 hours without the stated fee.

The app currently describes the period as “up to 1 day,” creating a documentation contradiction. dnToken withdrawals were documented as 1–3 days during bootstrapping and require closing both legs, incurring trading, spread and slippage costs. No minimum/maximum deposit is stated for dnTokens, but caps apply. General lock-ups, gates, collateral requirements and product-specific limits are otherwise Not verifiable as of September 6, 2026. TVL / revenue. DeFiLlama reports $25.69m TVL, 100% Hyperliquid L1, +4.9% over 30 days; 30-day fees are $105,502 and protocol revenue $13,600, defined as Hyperbeat’s performance-fee share.

Dune verification, product-level TVL, block-height as-of data, and Dune-vs-Llama trend comparison are Not verifiable as of September 6, 2026. APY history, volatility and sustainability are also Not verifiable as of September 6, 2026; the app currently displays no trailing APY for USDT.

Evidence (4)

reserves

one source

As of September 6, 2026 — Hyperbeat Earn / Hyperliquid L1 Conclusion: Reserves and treasury are not independently quantifiable. Not verifiable as of September 6, 2026. Dune/on-chain verification was unavailable in this run; therefore no on-chain balance, latest block, execution ID, or reserve composition should be inferred.

  • Size: DeFiLlama reports approximately $42.7m TVL for the combined Hyperbeat parent protocol, with $42.63m on Hyperliquid L1 and $73,684 on Ethereum. This is protocol TVL, not treasury or liquid reserves.
  • Earn vault composition/custody: Hyperbeat documentation describes Earn as automated, non-custodial smart-contract vaults whose assets are deployed into HyperEVM strategies. Strategists and infrastructure providers vary by vault; examples include Hyperbeat Core/RockawayX for USDC and USDT vaults, and Edge UltraYield/August for HYPE and UBTC vaults.
  • Addresses: Public documentation lists vault contract/token addresses, including USDC 0x057ced81348D57Aad579A672d521d7b4396E8a61, USDT 0x5e105266db42f78fa814322bce7f388b4c2e61eb, and other Earn vaults. These are vault addresses, not a verified Hyperbeat treasury/reserve address.
  • Reserve policy/control: No independently verified treasury policy, reserve minimum, segregation framework, signer set, multisig threshold, or withdrawal-liability schedule was found. Not verifiable as of September 6, 2026.
  • Hyperbeat USD distinction: DeFiLlama attributes about $1.85m of beatUSD backing reserves to USDC/USDG held on Ethereum and HyperEVM, but this is a separate product and should not be counted as Hyperbeat Earn reserves.
  • Attestations/audits: Documentation references “proof of solvency” for vaults and lists audits from infrastructure partners, but these are not a comprehensive reserve-and-liability attestation. Contradiction / data-quality callout: The parent-protocol TVL figure is available from an analytics aggregator, while treasury size, custody balances, and liabilities remain unverified. TVL must not be substituted for reserves. Structured fields:
  • liquid_reserves_usd: null
  • liabilities_usd: null
Evidence (5)

tokenomics

one source

Hyperbeat Earn currently appears to have no native token deployed on Hyperliquid L1 or any other chain. All yield and positions are denominated in the underlying assets (e.g., USDC), not in a proprietary governance/revenue token. Because Dune MCP and direct on-chain queries are unavailable in this run, any on-chain-specific checks are: Not verifiable as of 2026-09-04. ### 1.

Existence of a native token

  • Public information on Hyperbeat focuses on its role as a yield layer on Hyperliquid using vaults and structured products, with no mention of a token ticker, contract address, or token-based rewards.
  • Common DeFi data aggregators that would typically list protocol tokens (e.g., DeFiLlama, CoinGecko-style datasets) show no entry for “Hyperbeat Earn” or “Hyperbeat” token as of the current date.
  • The Hyperbeat app and docs pages describe products (vaults, earn strategies) but do not expose any token contract, symbol, or tokenomics section. > Given the search scope and absence of independent listings, the working risk-analyst assessment is: Hyperbeat Earn operates without a native fungible token at this time. Any future token plans would be unverified marketing claims until independently listed. ### 2. Tokenomics items requested (all not applicable / not verifiable) Since there is no identified native token, the following items are either Not applicable or Not verifiable as of 2026-09-04:
  • Token name/ticker and contract address – Not applicable.
  • Total vs circulating supply; market cap; FDV – Not applicable.
  • Token utility; governance role; revenue share; buybacks; burns; staking rewards – Not applicable; protocol appears to rely on product-level yield, not token incentives.
  • Emissions schedule; unlock schedule; team/investor/community allocations – Not applicable.
  • Verification that announced unlocks happened on-chain – Not verifiable as of 2026-09-04.
  • Top-holder concentration; insider wallets; mint/blacklist/fee-switch functions – Not verifiable as of 2026-09-04. ### 3. DEX liquidity and listings
  • No credible listing of a “Hyperbeat” or “Hyperbeat Earn” token on major DEXs or CEXs covering Hyperliquid-related assets was found.
  • Consequently, DEX liquidity depth and main listings for a native Hyperbeat token are not applicable. Risk takeaway: for now, token-related risks (emissions, unlocks, governance capture) are absent, and analysis should focus on strategy risk, counterparty risk to Hyperliquid, smart-contract risk on Hyperliquid L1, and operational risk of Hyperbeat, not tokenomics.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Hyperbeat Earn appears to be a set of automated vaults on HyperEVM that deploy capital into other DeFi protocols, with vaults such as UBTC, USDC, USDT, and HYPE exposed in the product docs and app. A Bitcoin crash below $10,000 would mainly stress any vaults or strategies that hold BTC-related exposure directly or indirectly; based on the available sources, that creates a clear *market-price and liquidation risk* scenario, but the exact loss transmission for Hyperbeat Earn is Not verifiable as of 2026-09-04 without on-chain position and allocation data. The most relevant documented stress points are:

  • Direct BTC-vault drawdown: the UBTC vault would be the most directly affected if it holds BTC or BTC-linked assets, because its NAV would fall with BTC.
  • Downstream protocol contagion: Hyperbeat Earn vaults are described as deploying across multiple HyperEVM protocols, so a BTC crash could amplify losses if those protocols use BTC as collateral or if correlated liquidations cascade through integrated venues.
  • Liquidity and redemption pressure: if users rush to withdraw after a sharp BTC move, TVL could fall and vault execution could worsen, but the magnitude is Not verifiable as of 2026-09-04 from the available sources. What is not established by the sources:
  • The share of Hyperbeat Earn TVL in BTC or BTC-correlated strategies: Not verifiable as of 2026-09-04.
  • Whether any vault has explicit BTC delta, leverage, or hedges in place: Not verifiable as of 2026-09-04.
  • The protocol’s actual loss under a BTC < $10,000 shock: Not verifiable as of 2026-09-04. The only concrete protocol-level takeaway from the web material is that Hyperbeat Earn markets itself as a multi-vault DeFi strategy layer on HyperEVM, which means the stress outcome depends on each vault’s live allocation and leverage profile rather than the headline BTC price alone.
Evidence (6)

stress scenario - largest collateral depegs 20%,

one source

Hyperbeat Earn’s documentation indicates its vaults allocate funds across multiple liquid collateral markets to optimize risk-adjusted yield, but it does not publish a verified depeg loss model for a 20% collateral shock in the sources available here. Based on that structure, a 20% depeg in the largest collateral asset would most directly reduce vault NAV by the vault’s exposure to that asset; the loss magnitude cannot be calculated from the provided sources because the chain-level holdings and allocation weights are not verifiable as of 2026-09-04. What can be stated from the available evidence is limited:

  • Hyperbeat Earn uses market/strategy vaults on Hyperliquid L1 and markets them as allocating across liquid collateral markets.
  • The docs emphasize yield and performance-fee mechanics, but they do not disclose stress-test assumptions, collateral concentration, or liquidation thresholds in the retrieved material.
  • An independent review notes composability and downstream-protocol risk, including the possibility that a loss in one integrated protocol can transmit to vault NAV and trigger liquidations, but that is a qualitative risk assessment rather than a quantified 20% depeg scenario. Stress result: Not verifiable as of 2026-09-04. The missing inputs are the vault’s current asset mix, the identity of the largest collateral, and the exact depeg pass-through rules for that market on Hyperliquid L1. Without those, any percentage NAV impact would be speculative.
Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

Scope limitation. Hyperbeat Earn spans HyperEVM strategies and, for USDC, basis-trade allocations to dnTokens using HyperCore. The largest live counterparty/exposure cannot be established without Dune or a reproducible position report: Not verifiable as of September 5, 2026. ### Stress case: largest underlying counterparty becomes insolvent | Exposure | Expected loss path | First loss absorber / compensation | Smart-contract transmission | |---|---|---|---| | HyperEVM lending venue or borrower | Borrower defaults; collateral liquidation is delayed or executes below debt value, creating bad debt. | Depositors in the affected market/vault absorb the shortfall pro rata. No Hyperbeat guarantee, insurance fund, or sponsor recapitalization was identified: Not verifiable as of September 5, 2026. | Hyperbeat’s vault NAV and hbUSDC/hbUSDT exchange rate fall; redemptions may be delayed until liquidity is available.

Morpho-style allocations explicitly carry counterparty, oracle, liquidation, and liquidity risk. | | Unit Protocol / HyperCore hedge or funding counterparty | The failed leg cannot return collateral or settle P&L; the nominally delta-neutral position becomes directional or unhedged. Loss equals unrecovered collateral plus adverse market move during unwind. | dnToken holders and the allocating Earn vault absorb it; future yield stops or turns negative.

No stated principal protection or compensation was found: Not verifiable as of September 5, 2026. | dnToken redemption/exchange rate declines; vault share price follows. The strategy may pause minting, rebalance, or queue withdrawals, but exact emergency permissions are Not verifiable as of September 5, 2026. | | Liquidity/DEX or LP counterparty | Pool insolvency, exploit, depeg, or forced unwind causes impermanent loss and slippage. | Vault depositors absorb mark-to-market loss; no contractual compensation identified. | Vault assets fall; instant redemption may be unavailable or economically punitive, while classic redemption requires an unwind period. USDT documentation cites 0.5% instant-redemption fee and a two-day process; USDC cites up to three working days.

| Bottom line: absent an explicit reserve, insurance, senior-loss tranche, or sponsor guarantee, the economically likely waterfall is: counterparty collateral/recoveries → affected strategy NAV → Hyperbeat vault depositors. Hyperbeat’s 20% performance fee is a fee, not a stated loss-absorption mechanism.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

I found no verifiable evidence that Hyperbeat Earn’s DAO or owners have committed fraud. Based on the available sources, the strongest statements are that Hyperbeat publishes terms and product docs, and third-party commentary raises risk concerns, but none of the retrieved material documents an actual fraud event, theft, or enforcement action against Hyperbeat Earn. For a stress scenario, the realistic impact of committed fraud would be severe: user trust could collapse, withdrawals could spike, vault TVL could fall sharply, and counterparties on Hyperliquid L1 could rapidly reprice or unwind exposure.

That is an inference from how DAO/DeFi fraud investigations typically proceed and from the protocol structure described in the sources, not a confirmed incident at Hyperbeat. What is verifiable is limited:

  • Hyperbeat’s public terms and docs exist, but they do not themselves prove good conduct or prevent fraud.
  • Third-party writeups describe Hyperbeat Earn as carrying smart-contract and strategy risk, including reliance on downstream protocols, but these are risk analyses, not fraud findings.
  • Some pages contain broad scam warnings, but they are not reliable evidence of wrongdoing by this specific protocol without corroboration. So the answer to the core question is: not proven; not verifiable as of 2026-09-04. If you want, I can next assess this as a governance/control-risk case by mapping who controls upgrade keys, fee settings, and treasury access, but that would require stronger source coverage than is currently available.
Evidence (6)

stress scenario - primary yield source negative 30d,

two sources

For Hyperbeat Earn, the main stress-case for a negative 30d primary yield source is that vault APYs can fall to zero or below when the underlying strategy depends on rate capture or funding spreads that turn unfavorable. Independent risk coverage specifically notes that delta-neutral/funding-rate strategies can generate zero or negative yield when funding rates compress or flip negative. What that means in practice depends on the vault type:

  • For delta-neutral strategies, negative funding or carry can directly reduce NAV and may produce losses instead of income.
  • For meta-vault allocations, the system can rotate into other opportunities, so the stress impact is usually a lower realized APY rather than an immediate protocol-wide loss, but that fallback is not verifiable here for current allocations. Not verifiable as of 2026-09-04.
  • For vaults where yield is sourced from exchange-rate growth or external protocol incentives, a negative 30d primary source can still leave the vault with positive carry only if other legs outperform; otherwise reported yield can compress materially. The most important risk finding is that a negative 30d primary yield source is not just a marketing issue; it can indicate the strategy is being paid less than expected, or is actively losing money before fees, especially for funding-dependent vaults. I cannot verify the current on-chain allocation mix or which specific Hyperbeat Earn vault is the dominant yield source from the available sources alone. Not verifiable as of 2026-09-04.
Evidence (4)

Governance & Legal

governance

two sources

Assessment — as of September 13, 2026. Hyperbeat Earn has no verifiable material DAO governance. The official $BEAT airdrop terms expressly state that tokens confer no governance rights and that Foundation decisions remain at its sole discretion. No public proposal forum, voting contract, quorum, DAO executor, or governance-controlled upgrade process was verified.

DAO is therefore symbolic/non-operative, not real protocol control. Control surface. The platform operator is Zoeion Ltd Corporation. Terms describe Earn vaults as automated vaults that may be co-operated or co-managed with third parties; the frontend and legal interface are therefore company-controlled. The HYPE Vault is a TransparentUpgradeableProxy with an upgrade/admin interface and a separately identified implementation, creating an upgrade-centralization risk.

The explorer does not establish whether the proxy admin is an EOA, multisig, DAO, or timelocked controller. Funds. Users receive vault-share tokens, while assets are deployed through vault logic and partner protocols. Because the vault is upgradeable, an admin-controlled upgrade could potentially alter fund-handling logic without a token-holder vote; the exact effective admin and whether direct withdrawal/drain functions exist are Not verifiable as of September 13, 2026. The admin_can_drain field is conservatively marked true for upgrade-mediated risk, not as proof of an executed drain. Governance mechanics and concentration. Proposal process, voting concentration, top holders, timelock delay, multisig signers/threshold, signer independence, and Dune-based holder analysis are Not verifiable as of September 13, 2026 because Dune MCP/on-chain query execution was unavailable.

No verified public timelock or multisig configuration was found. Company/KYC. Public materials identify Panama City, Panama as the jurisdiction/address and Panama law/CECAP arbitration in the Terms. A registry-mirror record lists RUC 155768175-2-2025 and Mercantil folio 155768175; this is not an official registry extract. Directors are Not verifiable as of September 13, 2026.

Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

one source

Hyperbeat Earn appears to operate through Zoeion Ltd Corporation, with its privacy policy naming Zoeion Ltd Corporation at a Panama City, Panama address as the data controller for hyperbeat.org and app.hyperbeat.org. The terms of service are governed by Cayman Islands law and require users not to be in restricted jurisdictions; they also reference AML/background checks, sanctions compliance, and other legal restrictions. The privacy policy states personal data may be transferred outside the user’s jurisdiction, including to the U.S.

The terms are framed as platform terms, not a securities law classification; no public court case, regulator enforcement action, or sanctions designation against Hyperbeat Earn or Zoeion Ltd Corporation was verifiable from the gathered sources. Legal structure versus actual risk: the legal documents indicate centralized legal wrapper(s) and compliance gating, but the protocol’s on-chain and operational risk cannot be fully verified here. Not verifiable as of 2026-09-04.

Active enforcement
No
Sanctioned
No
Entity
Zoeion Ltd Corporation
Jurisdiction
Panama (entity/data controller); Cayman Islands (governing law in terms)
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Zoeion Ltd Corporation', 'Hyperbeat Earn'. OFAC SDN screening of 'Zoeion Ltd Corporation', 'Hyperbeat Earn': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Zoeion Ltd Corporation
  • Hyperbeat Earn
Sanctioned
No
Evidence (4)

Stability

stability

unverified

Hyperbeat Earn does not appear to issue its own stablecoin; the gathered material describes it as a vault protocol that accepts external stablecoins such as USDC, USDT, USDe, USDT0, and uses USDhl in Hyperbeat Pay, but no source shows Hyperbeat minting a proprietary stablecoin. The stablecoin depeg question is not verifiable from the available web sources, so no depeg count, last depeg date, or max depeg percentage can be confirmed.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDT
  • USDe
  • USDT0
  • USDhl
Evidence (3)

Risks & Strengths

risks

two sources

Hyperbeat Earn concentrates risk in automated vault code, underlying HyperEVM strategies, withdrawal liquidity, and dependence on Hyperliquid infrastructure. Contradiction: Hyperbeat documents multiple partner audits, while DIA reports no published audits and no pool data; this discrepancy is unresolved. On-chain TVL, allocation, concentration, and loss history: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Vault contract and accounting failureA bug in vault, share-price, accounting, or integration logic could misprice shares, freeze withdrawals, or cause direct loss. Partner audits reduce but do not eliminate this exposure; audit coverage is not independently reconciled.HighMediumAudits are documented for selected vault infrastructure; withdrawal and valuation logic has received security review.Medium-High
Underlying strategy and counterparty lossFunds are deployed across third-party HyperEVM protocols and may face exploit, insolvency, bad debt, oracle, liquidation, or impermanent-loss events.HighMediumStrategy curation, stated risk oversight, and vault-specific allocation management are in place.Medium-High
Withdrawal liquidity mismatchRedemptions may be delayed while strategies unwind; the USDT vault documents instant redemption only when liquidity is available and classic redemption within two days.HighMediumInstant and classic redemption paths exist; the documented instant path charges a 0.5% early-withdrawal fee.Medium
Hyperliquid infrastructure dependencyHyperliquid L1 or HyperEVM downtime, consensus faults, oracle problems, congestion, or ecosystem-wide liquidity stress could impair valuation, execution, or withdrawals.HighMediumVaults operate on the target ecosystem and use strategy-specific controls; no independent fallback chain is documented.Medium-High
Operator and strategy-manager concentrationControl over strategy selection, parameters, integrations, and operational execution can create governance, key-management, censorship, or adverse-change risk.HighMediumNamed strategists, risk-oversight providers, audits, and documented withdrawal controls provide partial checks.Medium-High
Evidence (5)

strengths

two sources

Hyperbeat Earn’s top strengths are its automated strategy allocation, capital flexibility, risk dispersion across multiple protocols, transparent smart-contract delivery, and simple user experience. The docs state that Earn uses smart-contract vaults and Meta Vaults to optimize across HyperEVM and HyperCore, offering higher base yields, optimized liquidity, and greater capital flexibility. Multiple sources describe the core mechanism as continuously reallocating capital to the best risk-adjusted opportunities, including across lending and liquidity venues, which supports a risk-spreading advantage versus single-protocol yield exposure.

  • Automated yield optimization: the vaults continuously rebalance to chase available yield without manual portfolio management.
  • Capital flexibility: users can access a broader set of opportunities on HyperEVM while keeping funds in a vault structure designed to improve liquidity handling.
  • Diversification of strategy risk: Meta Vaults spread exposure across several protocols and strategy types, reducing dependence on one venue or one yield source.
  • On-chain, non-custodial design: the protocol is described as smart-contract based and non-custodial, so users retain self-custody rather than depositing into a centralized balance sheet.
  • Simplified access to complex DeFi yields: the platform packages yield strategies into a single interface, making it easier for users to participate in strategies that would otherwise require active monitoring and execution. A useful caution: several claims about audits, “bulletproof security,” and exact APYs appear only on protocol-controlled or weakly verified sources, so they should be treated as unverified marketing claims rather than strengths you can independently confirm from the provided results.
Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 13 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-29.