YO v2: Your Funds, Secured by a Closed Loop

YO v2: Your Funds, Secured by a Closed Loop

By YO Team

The next generation of YO is live. Every dollar you deposit now has only two places it can go: into an approved yield strategy, or back to you.

That rule is not a policy. It is enforced by code, verified on every transaction, and independently audited. YO v2 is closed-loop by design.

Each vault now runs on a targeted set of exposures. Fewer exposures means fewer risks. And the experience stays just as simple: deposit once, earn continuously, withdraw whenever you like.

What YO v2 is

YO is the yield engine for the crypto economy. You deposit once and YO continuously allocates your capital to the best risk-adjusted yield across chains and protocols, so you never need to actively manage yield generation again.

v2 is a ground-up revamp of the core protocol, and it changes two things at once: what your money is exposed to, and how your money is allowed to move.

Exposure is targeted. Each vault algorithmically allocates across a small list of positions, each one selected on the quality of its collateral, its liquidity, its audit history, and the risk of everything it depends on, and published in full on the vault page.

Movement is closed-loop. Every path a dollar can take is written into immutable adapters and timelocked registries: from the vault, into an approved position, and back to the vault. There is no other route.

That is what we mean by closed-loop by design. A closed set of exposures. A closed set of paths. All of it verifiable by anyone.

Notion image

What's new in v2

New

  • Onchain Adapters: Immutable, single-purpose contracts between the vault and every protocol. The receiver is hardcoded to the vault, approvals reset to zero after each use, and adapters can neither call arbitrary contracts nor be upgraded.
  • Targeted exposures: Each vault allocates across a short list of positions, each selected on collateral quality, liquidity, audit history, and dependency risk. The full list is published on every vault page and onchain.
  • Approval Registry: Onchain, timelocked caps on how much of each asset a vault may approve to each contract: vault, asset, contract, and amount fixed in advance.
  • Crosschain Bridge Adapters: One immutable adapter per bridge. Token pinned at deployment, fees capped in code, never holding funds between transactions.
  • Bridge Route Registry: Every cross-chain route allowlisted down to the vault, adapter, token, destination chain, and recipient. Same asset in, same asset out.
  • 48-Hour Timelock: Every upgrade is audited, queued, and published on a public dashboard with a mandatory 48-hour delay and sign-off from a 4-of-6 multi-sig of geographically distributed signers.

Carried forward, now inside the loop

  • Automated Offchain Simulation: Every transaction replayed against live chain state and rejected if the outcome differs from the intent, with price-impact and slippage checks and automated co-signers.
  • Oracle Guard: Share prices validated against a rolling anchor; manipulated or zero prices rejected.
  • Roles Authority: Onchain access control that now forms the outer gate of the loop: vaults are configured to call adapters only, never external protocols directly.

Follow a dollar through YO v2

The easiest way to understand v2 is to watch a deposit move through it.

1. You deposit. You put USDC into the yoUSD Edge vault and receive yoUSD Edge: a token whose value rises as the vault earns. YO is non-custodial. The assets sit in a vault contract onchain, in plain view, and you hold yoUSD Edge in your wallet.

2. The engine picks from a targeted list. yoUSD Edge doesn't allocate to everything that pays. It allocates across a short list of exposures that have earned their place, weighted for risk-adjusted return, and pulls back from any position whose risk profile changes. Fewer exposures means deeper diligence on each one, tighter monitoring, faster exits, and a list you can read in one glance. Quality over quantity is the v2 rule.

3. Your dollar travels through an adapter. The vault never calls Morpho, Aave, or Lido directly. It calls an Onchain Adapter: a small, immutable contract built for one job. For example, the Lido adapter can stake WETH into stETH, request an unstake, and claim the withdrawal back as WETH. That is its entire vocabulary. It cannot call arbitrary contracts, cannot be upgraded, always returns funds to the vault it serves, and resets its approvals to zero after every use.

4. The amount is capped before it leaves. The Approval Registry fixes, onchain and behind the timelock, the maximum of each asset a given vault can approve to a given contract: for example, the yoETH vault to the Lido adapter, up to 500 WETH. A request outside the predefined vault, asset, contract, and amount is simply rejected.

5. Every move is simulated first. Before any transaction is submitted, YO replays it against live chain state and inspects the result: every transfer, every balance change. If the outcome differs from the intent, it is rejected before it is ever sent. Trades are checked for price impact and slippage, automated co-signers screen for unexpected flows and recipients, and an Oracle Guard validates share prices against a rolling anchor so a manipulated price can't be acted on.

6. If it crosses chains, the loop crosses with it. Each bridge gets its own immutable adapter. The CCTP adapter moves native USDC through Circle's CCTP and nothing else, with the token pinned at deployment, fees capped in code, and no funds ever held between transactions. The Bridge Route Registry allowlists every route down to the vault, token, destination chain, and recipient. Same asset in, same asset out.

7. It comes home. When you withdraw, the vault unwinds through the same adapters it entered by, funds return to the vault, and your yoUSD Edge is redeemed for USDC in your wallet. That is the loop: one way in, one way out, and no way to redirect either.

Check out the full architecture here

Verified and Audited

The new v2 stack (including Onchain Adapters, Bridge Adapters, and Registries) was audited by Cantina, followed by a full re-review of the fixes. YO has been audited continuously since launch, by nine independent security firms in total: Cantina, Spearbit, Zellic, Offbeat, Aether Labs, Paladin, Aetheryc, Accretion, and Hunter. Every report is public, and an open bug bounty on Immunefi stands behind them.

What this means for you

If you deposit with YO: you can read your entire exposure on one screen, watch every proposed change to the protocol before it happens, and verify for yourself, rather than take our word, that your funds can only go to work and come back. The yield is still native, earned by the positions themselves, with $YO rewards on eligible vaults. The vaults are still yoUSD, yoUSD Edge, yoETH, yoBTC, yoEUR, yoSOL, and yoGOLD. Withdrawing still takes one click.

If you build on YO: nothing changes in your integration. The wallets, exchanges, and fintechs that embed YO received every v2 guarantee the moment it went live.

What's next

v2 closes the loop on what your money touches and how it moves. The next step is who decides what goes in it.

Every YO vault includes decisions like which upgrades go live, which pools earn a place on the list, and more. v2 was built so those can be governed, not administered, and we'll be handing them to $YO holders. More soon.

Targeted exposure. Closed-loop execution. Community governance. Two of the three are live today.

Deposit at app.yo.xyz · Read the architecture at docs.yo.xyz · Watch upgrades at app.yo.xyz/upgrade