Proof-of-Yield Teardown #002 — the control group: Aave, Uniswap, Pendle. Findings as of 2026-08-08.
Teardown #001 scored a suspect protocol at 28/100 — 24/100 on today's re-scan — and showed why. The obvious next question — the one that decides whether a score means anything — is what the same scanner does to protocols that are unambiguously real.
So we ran it against three: Aave, Uniswap, and Pendle. Not to praise them. To find out which of our checks actually carry the signal, and which ones we could delete tomorrow without losing anything.
All three lost points, and two of them raised an outright red flag. Here's exactly where, and what that says about scoring DeFi risk.
The numbers
| target | composite | verdict | red flags raised |
|---|---|---|---|
| nlo.finance (suspect, from #001) | 24 | HIGH_RISK_SIGNALS | 5 |
Aave (+ ethereum Pool 0x87870B…fA4E2) |
94 | STRONG_LEGITIMACY_SIGNALS | 1 — UPGRADEABLE_PROXY
|
Uniswap (+ ethereum v4 PoolManager 0x0000…8A90) |
99 | STRONG_LEGITIMACY_SIGNALS | 0 |
| Pendle | 87 | STRONG_LEGITIMACY_SIGNALS | 1 — NO_AUDIT_LINKS
|
Suspect 24 against the weakest control at 87 — a 63-point gap, with nothing landing in the 40–69 "mixed" band. That separation is the whole product. A scanner that can't put daylight between a bare-VPS-IP protocol and Aave is a random number generator with a UI.
But the interesting part is not the gap. It's the deductions.
Deduction 1: Aave is an upgradeable proxy, and we say so
Aave's Pool contract is an EIP-1967 proxy. The implementation resolves to 0x728a138a4823392c2efa55e028d434f526fe03cf. Our proxy check scored it 10/20 and raised UPGRADEABLE_PROXY.
That is not us calling Aave risky. It is us refusing to have a rule that says blue chips are exempt.
An upgradeable proxy is a real, permanent property of the contract you are approving: someone, under some governance process, can change the code your approval points at. For Aave that someone is a well-scrutinised DAO with timelocks. For a three-week-old protocol it might be one EOA on a laptop. The check reports the property; it does not pretend to read the governance.
So the deduction is deliberately note-grade — 10 of 20 points, not zero, and a single flag on a 94. Aave's proxy source is verified by all three explorers independently (Etherscan, Sourcify, Blockscout agree) and has been verified since 2023-09-12 — 1,061 days of published source at the time of writing. The compound that actually damns a contract is unverified source **and* upgradeable*: code you can't read, that can be swapped for code you also can't read. Upgradeable-and-verified is Tuesday in DeFi.
Aave's privilege scan, for the record: owner:0 mint:0 upgrade:2 pause:0 blacklist:0 — 20/20. Two upgrade selectors, exactly consistent with the proxy pattern, and no mint or blacklist machinery hiding in the implementation bytecode.
Deduction 2: Pendle's flag is our bug, not Pendle's
Pendle raised NO_AUDIT_LINKS and scored 16/25 on transparency: docs:5 audits:0 github:1 socials:3 — five documentation links discovered from the landing page, one GitHub org, and not a single audit link.
Pendle is audited. The audits are linked from the documentation, not from the landing page — and our Tier 1 discovery crawls the landing page.
We are publishing that flag rather than quietly special-casing it, because a scanner's failure modes are more useful to you than its successes. NO_AUDIT_LINKS means "not discoverable from the landing page," not "unaudited." On Pendle that's a false positive and a known limitation of landing-page-only discovery. On nlo.finance the same flag appeared alongside docs:0 github:0 and zero DeFiLlama presence — 20 outbound links on the page, all social. Same flag, opposite meaning, and only the surrounding evidence tells you which one you're holding.
Any tool that outputs a single number owes you the per-check breakdown. That's why ours returns one.
Deduction 3: even the 99 isn't a 100
Uniswap's v4 PoolManager raised zero red flags and still didn't score perfect. Its privilege scan came back owner:2 mint:0 upgrade:0 pause:0 blacklist:0 — 17/20. Two owner-related selectors in a non-upgradeable, three-source-verified contract, which is about as benign as a privilege finding gets, and we still deduct for it and still show you the selectors.
There is no ceiling reserved for protocols we like. A 99 means the instrument found two things worth mentioning and judged both minor — not that it stopped looking.
What the control group proved about our own checks
Here is the finding that changed how we weight things. Two of our six Tier 1 checks contributed no separation at all between the three real protocols and the suspect:
| check | nlo.finance (24) | Aave (94) | Uniswap (99) | Pendle (87) |
|---|---|---|---|---|
| TLS certificate | 6/10 | 6/10 | 10/10 | 6/10 |
| Yield-claim plausibility | 10/10 | 10/10 | 10/10 | 10/10 |
Read the TLS row, then read it again against the same row from our first run three weeks earlier — on 2026-07-16 it was nlo 10/10, Aave 6/10, Uniswap 6/10, Pendle 10/10. The suspect outscored two blue chips on that date. Today the suspect ties Aave and Pendle at 6/10 and Uniswap leads at 10/10.
Nothing about anyone's legitimacy changed in those three weeks. What changed is where each certificate happened to sit in its automated 90-day renewal cycle: nlo's Let's Encrypt cert rotated (79 days old then, 15 days old now), Uniswap's is 53 days into its cycle, Aave's is 9 days into a fresh one. That is the entire content of the signal — a cert-age check is a random number generator with respect to fraud. It ranked the scammer first in July and third in August, on the basis of nothing.
We are leaving the check in at 10 points and telling you it's noise, rather than deleting it, because "this site has valid TLS" is still worth reporting as an observation. What it is not is evidence.
The yield row is worse. Our yield-claim regex looks for implausible APY figures in rendered text. It found none anywhere — including on the protocol claiming to autonomously route capital across 170 DEXs. Modern yield scams don't print "4,000% APY" on the homepage any more. They print "AI-orchestrated, non-custodial, cross-chain" and let you assume.
So the two checks a normal person would build first — is the padlock green, does the APY look silly — contributed zero separation across this set. All 63 points of gap came from somewhere else.
Where the separation actually came from
| check | weight | nlo.finance | Aave | Uniswap | Pendle |
|---|---|---|---|---|---|
| DeFiLlama presence | 25 | 0/25 — 0 protocols, $0 TVL | 25/25 — 8 protocols, $14.89B | 25/25 — 6 protocols, $3.00B | 25/25 — 2 protocols, $1.18B |
| Domain age | 20 | 4/20 — 165d | 20/20 — 10,518d | 20/20 — 2,812d | 20/20 — 2,068d |
| Transparency (docs/audits/github) | 25 | 4/25 — docs:0 audits:0 github:0 | 25/25 — docs:1 audits:1 github:1 | 25/25 — docs:1 audits:1 github:2 | 16/25 — docs:5 audits:0 github:1 |
| Canonical URL hygiene | 10 |
0/10 — http://158.220.112.195/
|
10/10 | 10/10 | 10/10 |
| Contract source verification | 40 | no published contracts to check | 40/40 — 3-source consensus | 40/40 — 3-source consensus | — |
Every discriminating check has the same shape: it costs sustained time or money to fake.
You cannot backdate a domain registration. You cannot fake a billion dollars of TVL that third-party analytics independently track. You cannot get three independent block explorers to agree your source matches deployed bytecode without publishing source that matches deployed bytecode. You cannot retroactively have had a public GitHub for two years.
You can get a TLS cert in ninety seconds, hire a designer, and write "non-custodial" on a dark background for free. Surface trust is a commodity. Economic footprint is not. The control group is what let us say that with numbers instead of vibes — the checks that separated a 24 from a 99 are, without exception, the registry-grade ones.
(Every figure above is from a full four-target re-scan run on 2026-08-08, immediately before publishing; the original calibration run was 2026-07-16. TVL, cert ages and domain ages all drift, and the composites moved with them — nlo 28→24, Uniswap 96→99, Pendle 91→87, Aave 94 unchanged. No target changed band.)
The uncomfortable corollary
If the separating signals are all accumulated history, then a new, honest protocol scores like a scam.
That's true, and we're not going to paper over it. A legitimate two-month-old project with no TVL yet, no DeFiLlama listing, and a fresh domain will score in nlo's neighbourhood on Tier 1. The score is not a fraud verdict — it is a measure of how much verifiable economic footprint exists to back the claims being made.
Which is why the claim side matters as much as the footprint side. A new protocol saying "we're new, here's our verified contract, here's our audit, here's our GitHub" is a legible risk. A protocol with a 142-day-old domain claiming to orchestrate 25,000 pools across 170 DEXs is an incoherence — and incoherence between claimed scale and observable footprint is the thing that actually predicted trouble here.
Tier 2 exists for exactly this reason. A young protocol that publishes contracts can earn 40/40 on three-source verification on day one. History it can't fake; transparency it can choose.
The five-minute manual version (control-group edition)
Teardown #001 gave you five checks to run on a suspect. Run these three on anything that passes them:
- Check whether the audit link goes to the auditor's own domain. Pendle's audits are real but a landing-page crawl misses them; a scam's "audit" is a PDF that lives only on the project's own server. The location tells you more than the existence.
- If it's a proxy, find out who can upgrade it and how fast. "Upgradeable" is normal. "Upgradeable by one address with no timelock" is a different asset class. The proxy pattern is public; the governance around it is a five-minute read.
- Compare claimed scale against third-party trackers, not the project's own dashboard. DeFiLlama tracked $14.89B across Aave's entries and $0 across nlo's. Self-reported TVL is marketing copy.
And carry the negative result from this teardown: stop treating a valid TLS certificate as evidence of anything. On this set it ranked the suspect above two blue chips in July and mid-pack in August, purely on renewal timing.
The disclaimers that matter
These are automated observations from a specific date, not audits, not endorsements, and not financial advice. Aave, Uniswap and Pendle appear here as controls — protocols whose legitimacy is not in dispute, used to test whether our instrument can tell the difference. A high score is not a safety guarantee: our checks measure verifiable footprint and contract hygiene, and neither of those catches an economic exploit, an oracle failure, or a governance attack.
The two deductions above are the honest output of the scanner, including the one that is our own limitation rather than Pendle's shortcoming. We'd rather publish our false positive than hide it.
Scan it yourself
Proof-of-Yield's composite scan — ops forensics plus three-source contract verification — is live. Run any protocol through it before you approve anything.
Start here: https://poy.donnyautomation.com/v1/land?src=teardown-002
Free, no signup: one POST, straight at the API —
curl -X POST https://poy.donnyautomation.com/v1/scan \
-H "Content-Type: application/json" \
-d '{"url": "https://protocol-you-are-checking.xyz"}'
Rate-limited per IP; add chain and address to include contract forensics. Higher-volume access is coming via pay-per-call — watch this space.
More teardowns coming. If there's a protocol whose yield claims you want put under the lens, send it.
Built by the team behind the Uniswap v4 Hook Risk & Reality API. Same principle: three sources or it didn't happen.
Top comments (0)