Beefy Review
Eight named auditors, no licence file
of 10
Beefy states plainly that it never locks or owns user funds and names eight audit firms, but publishes no specific fee percentages and ships its official contracts repository with no licence file at all.
No money changes hands. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links. Links to the services below earn us nothing. Every overall score is the plain average of the criteria shown on the page, so you can check the arithmetic yourself — see our rating methodology and how the site is funded.
Performance fee
A percentage of harvest rewards; figure not published
Withdrawal fee
Some vaults charge one; figure not published
Zap fee
0.05%
Custody
Funds never locked; Beefy does not own staked funds
Licence
No LICENSE file
Scores
Each criterion carries equal weight. The overall score is the average of these 5 scores — (4.0 + 1.0 + 10.0 + 10.0 + 6.0) ÷ 5 = 6.2.
Pros
- States user funds are never locked and that Beefy does not own funds staked in vaults
- Eight auditors named: DeFiYield, CertiK, Zellic, OpenZeppelin, Cyfrin, Certora, Sherlock and Electisec
- A 0.05% zap fee is published for the Zap V2 feature
- Vaults described as auto-compounding yield-farming strategies
Cons
- The core beefy-contracts repository has no LICENSE file and no licence field in package.json
- No specific performance or withdrawal fee percentage is published on the vaults page
- Strategy allocation and historical performance are not documented
The clearest custody statement here
Beefy states outright that user funds are never locked in any vault and that Beefy does not own funds staked in vaults. That unambiguous non-custodial language, plus eight named audit firms — DeFiYield, CertiK, Zellic, OpenZeppelin, Cyfrin, Certora, Sherlock and Electisec — are the two strongest parts of this entry.
The licence gap
Against that, the official beefy-contracts repository has no LICENSE file and no licence field in its package.json. A vault holding deposits under code with no grant of rights is the weakest position on the licence criterion, and it sits oddly beside otherwise strong disclosure. We score the missing file, not the presumed intent.
Fees, described but not quantified
The vaults page states that most vaults take a percentage of harvest rewards and that some charge a withdrawal fee, without publishing either figure; only the 0.05% zap fee is given as a number. A user cannot work out the cost of a vault from the documentation alone.
How it compares
Yield Yak
MIT-licensed, no deposit or withdraw fees
Sommelier
Apache-licensed cellars, audits unverified
Harvest Finance
Named audits, ISC only in package.json
Idle Finance
Apache-licensed with net APY and named audits
Pendle
Yield tokenisation with a flat 5% fee
Aura Finance
MIT-licensed with a published fee ceiling
Origin (OUSD)
Rebasing yield stablecoin, MIT and net APY
Convex Finance
MIT-licensed with fees published to the basis point
Yearn Finance
AGPL-licensed with a named audit record
Sources
Scored from published primary sources rather than hands-on use. Every figure above comes from one of the pages below, on the date shown. Manufacturers change prices and specifications without notice — if something here no longer matches the source, tell us and we will correct it.
- 1.Beefy — vaults (fees and custody) — checked
- 2.Beefy — contracts repository (no LICENSE file) — checked
- 3.Beefy — audits and bug bounty — checked
Frequently asked questions
Does Beefy take custody of my funds?
No. Beefy states user funds are never locked and that it does not own funds staked in vaults.
Is Beefy open source?
The official beefy-contracts repository has no LICENSE file, so the code reserves all rights by default despite being public.
Nothing here is financial advice. Editorial policy · How we score · How we're funded.