Moderate risk — novel self-custody yield aggregation pattern with multi-chain reach, but downstream protocol exposure and shared smart contract codebase across 18+ chains create compounding risk layers
Risk Breakdown
Top Risks
vfat.io deploys Sickle smart contract wallets across 18+ chains, creating a massive multi-chain attack surface — a vulnerability in the shared Sickle contract would be exploitable on every chain simultaneously.
As a yield aggregator, vfat.io has composability risk across all underlying protocols it deposits into. A hack in any downstream protocol (AMM, lending, farm) directly impacts vfat users.
The Sickle contract wallet pattern gives the protocol significant control over user funds for automated operations like compounding and rebalancing, creating smart contract risk beyond standard approve-and-deposit patterns.
Frequently Asked Questions
Is vfat.io safe to use?
What are the main risks of using vfat.io?
What is vfat.io's risk score breakdown?
How does vfat.io compare to other Yield protocols?
Has vfat.io ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.