defirisk.co
rubric v1.7.0

Admin has mint() with unlimited max

Yearn Finance's assessment for RD-F-042 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

YFI token (0x0bc529c00C6401aef6D220BE8C6Ea1667F6Ad93e) has mint(address, uint256). Supply cap: 36,666 YFI (enforced in contract). Minting controlled by minters mapping gated by governance address (currently ychad-controlled). Not unlimited: supply cap enforced on-chain. Minter additions require governance action. Yellow: mint exists, multisig-governed, cap enforced but not timelocked at the minter-add level.

Sources #

  • Etherscan
    YFI Token — EtherscanYFI token 0x0bc529c00C6401aef6D220BE8C6Ea1667F6Ad93e — mint() function, Max Total Supply 36,666retrieved 2026-05-16
  • Docs
    YFI Token — Yearn Docsdocs.yearn.fi/contributing/governance/yfi — governance controls mintingretrieved 2026-05-16

Methodology #

Determine whether an admin-callable `mint` on a protocol token has no supply cap or an unlimited maximum supply.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol yearn-finance factor RD-F-042 score yellow collected_at 2026-05-16 08:34:32