Yield Vault Development with Auto-Compounding

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
Yield Vault Development with Auto-Compounding
Complex
~1-2 weeks
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1189
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

A user deposited 100 ETH into a vault on Curve, but due to a missed harvest over a month, the APY ended up 30% lower than projected. This is a typical scenario: without auto-compounding, compound interest doesn't work, and manual reward collection (harvest) requires time and gas costs. We build yield vaults — smart contracts that automatically reinvest yields, eliminating manual harvest. This key DeFi component addresses challenges like who pays for compound, how to avoid slippage when selling reward tokens, and how to protect against reentrancy via tokens with hooks. Our engineers, with 5+ years of experience in DeFi, have launched 10+ vaults on mainnet, and we're ready to share best practices.

How Does a Yield Vault with Auto-Compounding Work?

A yield vault accepts user funds, places them in a protocol (Aave, Compound, Curve, Convex), collects accumulated reward tokens, and reinvests them back. In practice, non-trivial issues arise: who pays for compound, how to avoid slippage when selling rewards, and how to not fall victim to reentrancy via tokens with hooks.

Who Calls Harvest and Who Pays?

Auto-compounding requires periodic calls to the harvest() function — collecting rewards and reinvesting. Someone must pay for this transaction.

  • Permissionless harvest: Anyone can call harvest() and receive a bounty (typically 0.5-1% of collected rewards). This is 10x cheaper than a keeper but less reliable for low TVL. With low vault TVL, harvest happens rarely, APY is lower than advertised.
  • Keeper-based harvest: According to Chainlink Automation documentation (https://docs.chain.link/chainlink-automation), configuring a trigger takes minutes. Chainlink Automation or Gelato Network calls harvest() on a schedule or when a reward threshold is met. More reliable than permissionless, but requires LINK funding. Gelato deducts payment from the rewards themselves via the IAutomate interface.
  • Harvest on each deposit/withdraw: The simplest option, but on the first deposit into a new vault, you pay gas for harvesting zero rewards.

We typically use a hybrid: scheduled keeper with permissionless harvest as fallback.

Compounding Math and Accumulation Errors

APY with compounding: (1 + r/n)^n - 1, where r is the annual rate and n is the number of compounding periods per year. With daily compounding (n=365) and 20% APR, APY is 22.13%. With weekly compounding (n=52), APY is 21.94%. The difference is small, but incorrect frequency on the frontend disappoints users.

Rounding error: each compound operation shares * pricePerShare does not always divide evenly by totalAssets. The cumulative error over thousands of compounds can become significant. Solution: store totalAssets as an exact value, update it atomically on each operation. The compound interest effect works without loss.

How to Set Up a Chainlink Automation Keeper

  1. Deploy the vault contract and register an upkeep on Chainlink Automation.
  2. In checkUpkeep(), return true when accumulated rewards exceed a threshold (e.g., 1000 tokens).
  3. In performUpkeep(), call harvest() and burn the keeper fee.
  4. Set the check interval (minWaitSeconds) and budget in LINK.

This guarantees regular compound even at low TVL.

Strategy — The Core of the Vault

Integration with Curve + Convex

Classic strategy: deposit USDC → Curve 3pool (USDC/USDT/DAI) → receive 3CRV → stake in Convex Finance → get CRV + CVX rewards → sell CRV/CVX for USDC → add back to 3pool. The interaction curves in Solidity:

// Deposit into Curve
ICurvePool(POOL_3CRV).add_liquidity([amount, 0, 0], minLpTokens);
// Stake LP in Convex
IConvexBooster(BOOSTER).deposit(pid, lpAmount, true);
// Claim rewards
IConvexRewardPool(REWARD_POOL).getReward(address(this), true);
// Sell CRV via Uniswap V3
ISwapRouter(UNISWAP_ROUTER).exactInputSingle(params);

Risk of slippage when selling rewards: if the vault accumulates 50,000 CRV and sells them all in one swap, price impact is 2-5%. Solution: split the sale into multiple parts (slicedSell) or use 1inch for optimal routing through multiple pools.

Fee Management

Standard fee structure for a yield vault:

  • Performance fee: 10-20% of accumulated yield per harvest. Goes to the protocol treasury. For a vault with $10M TVL, a 15% fee generates $1.5M annually.
  • Management fee: 0.5-2% annual on TVL. Accrued continuously by increasing totalAssets in favor of the treasury.
  • Withdrawal fee: 0-0.1%. Optional, to discourage short-term deposits.

Implementation of management fee without separate transactions: on each totalAssets() call, calculate elapsed_seconds * annualFeeRate / SECONDS_IN_YEAR * tvl and subtract from the return value. Treasury shares are minted on harvest.

Harvest Model Comparison

Harvest Model Comparison
Model Advantages Disadvantages Gas Costs
Permissionless bounty Zero keeper costs Unpredictable frequency OPEX on bounty (0.5-1% rewards)
Keeper (Chainlink) Guaranteed periodicity LINK costs $2-5 per upkeep per day
On deposit/withdraw Simplicity, no external dependencies Rare harvest at low TVL Included in user's gas

What Risks Arise When Working with Yield Vaults?

Reentrancy via ERC-777 and Callback Tokens

The harvest function makes several external calls: claim → swap → deposit. ERC-777 tokens call the tokensReceived hook on the recipient. If the vault accepts ERC-777, during claim the hook may call deposit or withdraw before harvest completes. Protection pattern: nonReentrant on harvest, deposit, withdraw.

Sandwich Attacks on Harvest Swaps

Public harvest() is visible in the mempool. MEV bots execute a sandwich: buy CRV before the harvest swap, sell after. Mitigation: deadline on swap (max 1-2 blocks), strict minAmountOut using a TWAP oracle instead of spot price. TWAP price is 3x more accurate than spot price in volatile markets. amountOutMin = twapPrice * amount * (1 - maxSlippage). TWAP over 30 minutes — Uniswap V3 observe(). Alternative: Flashbots Private Transactions.

Price Manipulation via Flash Loans

A strategy that reads spot price from an AMM to compute the compound ratio is vulnerable: a flash loan temporarily shifts the price. Solution: never use spot AMM price for decision-making on amounts. Only use TWAP or Chainlink for price calculations.

Development Stack

Solidity 0.8.x + OpenZeppelin 5.x (ERC-4626, ReentrancyGuard, Pausable, AccessControl). Foundry for testing with fork tests on mainnet. Chainlink Automation for keeper. 1inch Fusion API for optimal swaps.

Risk Vector Protection
Reentrancy ERC-777 hooks in claim nonReentrant on all state-changing functions
Sandwich Public harvest TWAP minAmountOut + Flashbots
Price manipulation Spot AMM prices Chainlink / TWAP for calculations
Accumulative fee error Imprecise totalAssets Exact accounting, update on every operation
Too rare compound Insufficient TVL Keeper + permissionless with bounty

Work Process

  • Analysis (2-3 days). Target protocols, fee structure, compound frequency, keeper requirements.
  • Design (3-5 days). ERC-4626 vault architecture, separate strategy contract for upgradeability, fee accounting.
  • Development (2-4 weeks). Vault → strategy → keeper integration → frontend (wagmi + viem).
  • Testing. Foundry fork tests: full cycle deposit → earn → harvest → withdraw on mainnet state. Fuzz on amounts and timing.
  • Audit. External audit required when TVL > $500k. Our vaults undergo formal verification.

What's Included in the Result?

  • Source code of smart contracts (verified on Etherscan)
  • Architecture documentation and deployment instructions
  • Configured Chainlink Automation keeper
  • Integration with 1inch for optimal swaps
  • Audit report (if required)
  • Team training and support during launch

Time and Cost Estimates

Simple vault on one protocol with Chainlink Automation — 1-2 weeks. Multi-strategy vault with optimal reward routing and sandwich protection — 4-8 weeks. Cost is determined after the strategy and security requirements are defined. Discuss the details — we'll prepare a custom proposal.

Order yield vault development with auto-compounding — get a free consultation. Our engineers with 5+ years of DeFi experience have implemented 10+ vaults for well-known protocols. Describe your task, and we'll offer the optimal solution.

DeFi Protocol Development

We design modular DeFi protocols where the math of stablecoins, liquidity, and oracles works flawlessly. Mango Markets is a stress test: the attacker manipulated the spot price through a single account, took a loan against inflated collateral, and withdrew $114 million. The oracle took the price from a single source without TWAP. Not a code bug—it was an architectural decision that became a vulnerability. Our experience shows: any DeFi protocol is a system of bets that all components, from calculations to economic incentives, are correctly aligned simultaneously.

We don't write code under the 'if it works, don't touch it' mindset. We model stress scenarios: cascading liquidations, depegs, flash loans. Only then do we build events that won't break the protocol.

Why are oracles a critical component of DeFi?

Most major DeFi hacks started with oracle manipulation. Let's break down the three layers we use in every project.

Spot price as oracle—not an option. Uniswap v2 spot price can be shifted by a flash loan in one transaction. The price at the end of the block is the only one that enters the state, and the oracle reads it. Attack scheme: borrow via flash loan → buy asset into the pool → price rises → take a loan against inflated collateral → sell asset → repay flash loan. One transaction.

TWAP as protection. Uniswap v3 observe() averages the price over a period (30 minutes). Manipulation requires maintaining the price for several blocks—this is expensive. But TWAP reacts slowly to legitimate changes, opening a window for arbitrage on liquidation during sharp movements.

Chainlink Price Feeds are an aggregation from multiple data providers with a median. Standard for lending. Problem: heartbeat 1–24 hours and deviation threshold 0.5%. If the price doesn't move, the feed may not update for a day. In volatile markets—lag.

Oracle Mechanism Manipulation Protection Latency
Chainlink Median from independent providers High (decentralization) Up to 24h at 0% movement
Uniswap v3 TWAP Average price over N blocks High (hard to maintain) 30 min – 1 h
Pyth Network Cross-chain low-latency Medium (dependent on publisher) Seconds

In production, we use a two-tier check: Chainlink aggregator + Uniswap v3 TWAP as a verifier. If the discrepancy exceeds N%, the transaction is rejected and the system is paused.

How to protect a DeFi protocol from flash loan attacks?

Flash loans turn any user into an owner of unlimited capital for one transaction. Therefore, when designing contracts, we assume: everyone has access to unlimited capital. This completely changes the threat model.

Legitimate uses of flash loans are arbitrage, liquidation, and self-liquidation. But the protocol must verify that the loan is not used for manipulation: the oracle must not read the price from a pool that can be shifted in one transaction. We add checks on block.timestamp and minimum liquidity depth.

Key Components of DeFi Architecture

Protocol Type Core Mechanism Main Risk
DEX (AMM) x*y=k or concentrated liquidity impermanent loss, oracle manipulation
Lending collateral ratio, liquidation bad debt during cascading liquidations
Yield aggregator auto-compounding strategies rug via strategy upgrade
Derivatives / Perps funding rate, mark price liquidation cascades, socialized losses
Liquid staking stETH-style rebasing depegging on mass unstake

AMM: From x*y=k to Concentrated Liquidity

Uniswap v2 uses x * y = k. LP tokens are ERC-20—each pool issues its own token proportional to the share. Problem: liquidity is spread across the entire curve, most of it unused.

Uniswap v3 and ERC-721 positions: concentrated liquidity—LPs provide liquidity in a range [priceLow, priceHigh]. Capital efficiency up to 4000x for stable pairs. But ERC-721 breaks vault strategies built for ERC-20. Range management is a separate engineering challenge: a position falls out of range when the price moves, stops earning fees, and becomes single-asset. Protocols like Arrakis Finance automatically rebalance. If you build a vault on top of v3, you need your own range manager or integration with an existing one.

Slippage in v3 is calculated via sqrtPriceX96—96-bit fixed-point math. Errors on the frontend lead to discrepancies between visible and actual slippage.

Curve for pairs with close prices (stablecoin/stablecoin, stETH/ETH) uses an invariant combining constant product and constant sum. Lower slippage within the peg range. Contracts are in Vyper, code is mathematically dense, auditing is difficult.

Lending Protocols: Collateral, Liquidation, Bad Debt

LTV defines the maximum loan against collateral. Liquidation threshold is the level for liquidation. The difference is the buffer for the liquidator. Typical example: LTV 75%, liquidation threshold 80%, bonus 5%. If the price drops 20%+, the position is open for liquidation.

Cascading liquidations: many positions are liquidated simultaneously → liquidators sell collateral → price drops → next wave. LUNA/UST 2022 is a classic cascade.

If collateral devalues faster than liquidation, the protocol incurs bad debt. Aave uses a Safety Module (staked AAVE), Compound uses reserves. Without a backstop, bad debt is socialized via dilution of the supply token or netting.

Designing a liquidation system requires modeling stress scenarios: a single liquidation bot failure, high gas, collateral delisting.

Yield Farming and Incentive Mechanics

Liquidity mining distributes governance tokens to LP providers. Problem: mercenary capital—farmers come, sell tokens, leave. TVL is illusory.

Sustainable mechanics: protocol-owned liquidity (Olympus bonding), veToken (CRV locked → boost + governance), locked staking with penalty. The ve-model, if implemented incorrectly, creates governance concentration. A timelock on gauge weight changes and limits on voting power are needed.

What Our DeFi Protocol Development Includes

  • Architectural documentation: contract interaction diagrams, liquidation stress tests, oracle calculations.
  • Implementation in Solidity 0.8.x with OpenZeppelin 5.x (AccessControl, ReentrancyGuard, Pausable, TimelockController) and Solmate for gas-optimized base contracts.
  • Foundry fork tests on real mainnet (Uniswap, Chainlink, Aave) — pre-deployment tests cover all scenarios.
  • Audit: at least two independent auditors for TVL over $1M. Code4rena or Sherlock for bug bounty.
  • Deployment with Gnosis Safe 3/5 multisig + timelock 48–72 hours.
  • Monitoring via Tenderly (alerts, simulations), OpenZeppelin Defender (automation), Forta (on-chain threat detection).
  • Post-launch support: updates, patches, upgrades via proxy.

Our Expertise and Experience

We have been developing DeFi protocols since 2020, delivering 30+ projects with a combined TVL of over $150 million. Our clients include protocols in the top 20 by TVL on Ethereum, Arbitrum, and Base. The team consists of certified Solidity developers who have completed ConsenSys Diligence audit tracks.

DeFi basic principles that we apply in practice.

Timelines

  • DEX with AMM (Uniswap v2 fork): 6–10 weeks
  • Lending protocol (Aave-style, single collateral): 3–5 months
  • Yield aggregator with multiple strategies: 2–4 months
  • Full-fledged DeFi protocol with governance: 5–8 months including audit

Cost is calculated individually—contact us for a project estimate.

Get a consultation on DeFi protocol architecture—we will analyze the risks and propose an optimal solution.