DeFiPunk'd

Concentrator

Yield

TVL $64.3M
Type Yield
Chain Ethereum
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty Governance forum forum.aladdin.club Docs docs.aladdin.club
About

Concentrator is a yield enhancement protocol by AladdinDAO on Ethereum that allows Convex liquidity providers to stake their Curve LP tokens and automatically harvest rewards, converting them into top-tier auto-compounding receipt tokens such as aCRV (cvxCRV compounder), aFXS (cvxFXS compounder), afrxETH, asdCRV (sdCRV compounder), asdPENDLE, aFXN, and arUSD. Users deposit Curve LP tokens into Concentrator Harvester vaults; rewards are periodically harvested, swapped to the target asset, and deposited into the corresponding Concentrator Compounder, which issues a share token representing an ever-growing balance of the underlying. The protocol charges a 10% treasury fee and a 2% harvest keeper fee on yields, governed by CTR/veCTR token holders via Snapshot.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 42 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 10 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Concentrator has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 46addresses
  • 4verified source
  • 0proxies
  • 0of 1 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-04-26.

ethereumConvexToken0x4e3f…9d2bTVL
ethereumcvxCrvToken0x62b9…0aa7TVL
ethereumCurve DAO Token0x365a…bb09TVLgovernance
ethereumTetherToken0xdac1…1ec7TVL0xc6cd…a828
Ethereummultisig (CLever treasury)0xfc08…0c5ediscoverymultisig
Ethereummultisig (Concentrator treasury)0xa0fb…4e99discoverymultisig
Ethereummultisig (f(x) treasury)0x26b2…7bbfdiscoverymultisig
Ethereummultisig (governance management)0xc405…e23fdiscoverymultisig
Ethereumother (aCRV FeeDistributor)0xa5d9…458cdiscovery
Ethereumother (AladdinZap)0x1104…dc8adiscovery
Ethereumother (AMOConvexCurveStrategy for abcCVX)0x29e5…f1b4discovery
Ethereumother (CompounderGateway)0x883f…df1fdiscovery
Ethereumother (Concentrator Harvester)0xfa86…c515discovery
Ethereumother (ConcentratorGateway)0xd069…92b1discovery
Ethereumother (ConcentratorSdCrvGaugeWrapper)0x09b0…3bf1discovery
Ethereumother (ConverterRegistry v1 deprecated)0xa617…fb2bdiscovery
Ethereumother (ConverterRegistry v2)0x997b…ea90discovery
Ethereumother (CTR Vesting)0x8341…8742discovery
Ethereumother (CvxCrvStakingWrapperStrategy)0x94cc…f345discovery
Ethereumother (CvxFxnStakingStrategy)0x2d8b…ef6cdiscovery
Ethereumother (CvxStakingStrategy)0x8375…08f8discovery
Ethereumother (GatewayRouter)0x6a97…14d8discovery
Ethereumother (GaugeRewardDistributor)0xf57b…87b0discovery
Ethereumother (PlatformFeeDistributor Concentrator)0xd279…e973discovery
Ethereumother (PlatformFeeSplitter Concentrator)0x3236…80c8discovery
Ethereumother (SmartWalletWhitelist)0x3557…3318discovery
Ethereumother (StakeDAOLockerProxy)0x1c0d…ad09discovery
Ethereumother (veCTR vote-escrow)0xe4c0…4968discovery
Ethereumother (VeSDTDelegation)0x6037…ff64discovery
Ethereumproxy_admin0x12b1…62a0discovery
Ethereumtoken (CTR governance token)0xb3ad…90b8discoverygovernance
Ethereumvault (abcCVX compounder)0xdec8…e359discoveryvault
Ethereumvault (AladdinConvexVault deprecated)0xc8ff…e0e8discoveryvault
Ethereumvault (AladdinCRV / aCRV compounder)0x2b95…0884discoveryvault
Ethereumvault (AladdinETH / afrxETH compounder)0xb15a…5abadiscoveryvault
Ethereumvault (AladdinFXS / aFXS compounder)0xdaf0…3ec9discoveryvault
Ethereumvault (AladdinFXSConvexVault / aFXS harvester vaults)0xd6e3…99e1discoveryvault
Ethereumvault (arUSD ERC4626 compounder)0x07d1…5f9adiscoveryvault
Ethereumvault (arUSD ERC5115 compounder)0x5497…f240discoveryvault
Ethereumvault (ConcentratorAladdinETHVault / afrxETH harvester vaults)0x50b4…346ddiscoveryvault
Ethereumvault (ConcentratorIFOVault / aCRV harvester vaults)0x3cf5…50b5discoveryvault
Ethereumvault (ConcentratorVaultForAsdCRV / asdCRV harvester vaults)0x5986…a3dediscoveryvault
Ethereumvault (CvxCompounder)0xb090…b777discoveryvault
Ethereumvault (CvxFxnCompounder / aFXN compounder)0x00ba…9545discoveryvault
Ethereumvault (SdCrvCompounder / asdCRV compounder)0x43e5…9922discoveryvault
Ethereumvault (SdPendleCompounder / asdPENDLE compounder)0x6064…fecfdiscoveryvault

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@0xconcentrator
Governance forum
https://forum.aladdin.club/

Security

[:] Source: DEFI@home quorum
Audits
8 audits
Bug bounty
unknown
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Voting token
CTR Ethereum: 0xb3Ad645dB386D7F6D753B2b9C3F4B853DA6890B8
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-08-10 07:25 UTC