Skip to content

Beefy Review

Eight named auditors, no licence file

of 10

Beefy states plainly that it never locks or owns user funds and names eight audit firms, but publishes no specific fee percentages and ships its official contracts repository with no licence file at all.

No money changes hands. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links. Links to the services below earn us nothing. Every overall score is the plain average of the criteria shown on the page, so you can check the arithmetic yourself — see our rating methodology and how the site is funded.

Performance fee

A percentage of harvest rewards; figure not published

Withdrawal fee

Some vaults charge one; figure not published

Zap fee

0.05%

Custody

Funds never locked; Beefy does not own staked funds

Licence

No LICENSE file

Scores

Fee disclosure
4.0
Licence & code openness
1.0
Audit disclosure
10.0
Custody & control
10.0
Strategy transparency
6.0

Each criterion carries equal weight. The overall score is the average of these 5 scores — (4.0 + 1.0 + 10.0 + 10.0 + 6.0) ÷ 5 = 6.2.

Pros

  • States user funds are never locked and that Beefy does not own funds staked in vaults
  • Eight auditors named: DeFiYield, CertiK, Zellic, OpenZeppelin, Cyfrin, Certora, Sherlock and Electisec
  • A 0.05% zap fee is published for the Zap V2 feature
  • Vaults described as auto-compounding yield-farming strategies

Cons

  • The core beefy-contracts repository has no LICENSE file and no licence field in package.json
  • No specific performance or withdrawal fee percentage is published on the vaults page
  • Strategy allocation and historical performance are not documented

The clearest custody statement here

Beefy states outright that user funds are never locked in any vault and that Beefy does not own funds staked in vaults. That unambiguous non-custodial language, plus eight named audit firms — DeFiYield, CertiK, Zellic, OpenZeppelin, Cyfrin, Certora, Sherlock and Electisec — are the two strongest parts of this entry.

The licence gap

Against that, the official beefy-contracts repository has no LICENSE file and no licence field in its package.json. A vault holding deposits under code with no grant of rights is the weakest position on the licence criterion, and it sits oddly beside otherwise strong disclosure. We score the missing file, not the presumed intent.

Fees, described but not quantified

The vaults page states that most vaults take a percentage of harvest rewards and that some charge a withdrawal fee, without publishing either figure; only the 0.05% zap fee is given as a number. A user cannot work out the cost of a vault from the documentation alone.

How it compares

Sources

Scored from published primary sources rather than hands-on use. Every figure above comes from one of the pages below, on the date shown. Manufacturers change prices and specifications without notice — if something here no longer matches the source, tell us and we will correct it.

  1. 1.Beefy — vaults (fees and custody) — checked
  2. 2.Beefy — contracts repository (no LICENSE file) — checked
  3. 3.Beefy — audits and bug bounty — checked

Frequently asked questions

Does Beefy take custody of my funds?

No. Beefy states user funds are never locked and that it does not own funds staked in vaults.

Is Beefy open source?

The official beefy-contracts repository has no LICENSE file, so the code reserves all rights by default despite being public.

Nothing here is financial advice. Editorial policy · How we score · How we're funded.