DeFiPunk'd

Nest Credit

RWA

TVL $115.0M
Type RWA
Chains Plume Mainnet, Ethereum, Solana
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty Governance forum Docs docs.nest.credit
About

Nest (by Plume) is a non-custodial RWA yield protocol that lets users deposit stablecoins (USDC, pUSD, USDT) into ERC-4626/ERC-7540 vaults and receive liquid vault receipt tokens (e.g. nTBILL, nALPHA, nBASIS) representing proportional shares of curated institutional-grade real-world assets. Each vault bundles assets such as U.S. Treasuries, private credit, CLOs, and ETFs sourced from regulated fund managers including BlackRock, Blackstone, Apollo, and WisdomTree. Vaults are built on the Nucleus BoringVault architecture (now migrated to Nest-native contracts), deployed across Plume Mainnet, Ethereum, and BNB Chain, with Solana access via LayerZero OFT cross-chain bridges. The protocol is created and managed by the Plume Foundation (Kimber Labs Inc.) and incorporates AML/compliance screening via Predicate before vault entry.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 72 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 12 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Nest Credit has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 72addresses
  • 0verified source
  • 0proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-08-20.

BNB Chainadmin (OperatorRegistry — operator allowlisting)0xfabd…6835discovery
BNB Chainadmin (RolesAuthority — access control for all vaults)0x9378…5ba4discovery
BNB Chainguardian (NestShareSeizer — can seize vault shares)0xf6c0…0510discoveryguardian
BNB Chainother (NestRedeemOperator — redemption operator)0xd9b4…5440discovery
BNB Chainother (NestVaultPredicateProxy — compliance gating entrypoint)0xfc0c…9035discovery
BNB Chainvault (nACRDX USDT NestVault)0xba1d…faaediscoveryvault
BNB Chainvault (nALPHA USDT NestVault)0xf65b…8263discoveryvault
BNB Chainvault (nBASIS USDT NestVault)0xf388…f3c3discoveryvault
BNB Chainvault (nCREDIT USDT NestVault)0xe2d8…2acddiscoveryvault
BNB Chainvault (nTBILL USDT NestVault)0x109d…8a0cdiscoveryvault
BNB Chainvault (nWISDOM USDT NestVault)0xf6d6…a45bdiscoveryvault
Ethereumadmin (OperatorRegistry — operator allowlisting)0xfabd…6835discovery
Ethereumadmin (RolesAuthority — access control for all vaults)0x9378…5ba4discovery
Ethereumguardian (NestShareSeizer — can seize vault shares)0xf6c0…0510discoveryguardian
Ethereumother (NestRedeemOperator — redemption operator)0xd9b4…5440discovery
Ethereumother (NestVaultPredicateProxy — compliance gating entrypoint)0xfc0c…9035discovery
Ethereumtoken (nALPHA share token ERC-20)0x593c…88dbdiscoverytoken
Ethereumtoken (nTBILL share token ERC-20)0xe72f…8cb9discoverytoken
Ethereumvault (nCLOA USDT NestVault)0xb728…14a0discoveryvault
Ethereumvault (nOPAL USDT NestVault)0x5e94…7a2cdiscoveryvault
Ethereumvault (nTBILL USDC NestVault)0x250c…7f12discoveryvault
Plumeadmin (OperatorRegistry — operator allowlisting)0xfabd…6835discovery
Plumeadmin (RolesAuthority — access control for all vaults)0x9378…5ba4discovery
Plumeguardian (NestShareSeizer — can seize vault shares)0xf6c0…0510discoveryguardian
Plumeother (nALPHA NestVaultComposer — Solana OFT Plume-side composer)0x3eb8…5727discovery
Plumeother (nBASIS NestVaultComposer — Solana OFT Plume-side composer)0x22b4…42eediscovery
Plumeother (nCLOA NestVaultComposer — Solana OFT Plume-side composer)0xb940…dd90discovery
Plumeother (NestAdapter)0x2de3…13eadiscovery
Plumeother (NestBundler)0x09a2…d6dddiscovery
Plumeother (NestCCTPRelayer — cross-chain CCTP relay)0x7de0…d8bediscovery
Plumeother (NestRedeemOperator — redemption operator)0xd9b4…5440discovery
Plumeother (NestUnlooper)0xb7e2…392adiscovery
Plumeother (NestVaultPredicateProxy — compliance gating entrypoint)0xfc0c…9035discovery
Plumeother (nFXCF NestVaultComposer — Solana OFT Plume-side composer)0xbcad…0648discovery
Plumeother (nLCRD NestVaultComposer — Solana OFT Plume-side composer)0x63c7…6295discovery
Plumeother (nOPAL NestVaultComposer — Solana OFT Plume-side composer)0x9053…62c9discovery
Plumeother (nTBILL NestVaultComposer — Solana OFT Plume-side composer)0x719e…d873discovery
Plumeother (nWISDOM NestVaultComposer — Solana OFT Plume-side composer)0x312a…4974discovery
Plumetoken (nACRDX share token ERC-20)0x2a3e…61cbdiscoverytoken
Plumetoken (nALPHA share token ERC-20)0x593c…88dbdiscoverytoken
Plumetoken (nAXI share token ERC-20)0x7488…6d79discoverytoken
Plumetoken (nBASIS share token ERC-20)0x1111…e94bdiscoverytoken
Plumetoken (nCLOA share token ERC-20)0x6381…9e13discoverytoken
Plumetoken (nCREDIT share token ERC-20)0xa5f7…066cdiscoverytoken
Plumetoken (nFXCF share token ERC-20)0x066d…bdffdiscoverytoken
Plumetoken (nLCRD share token ERC-20)0xdf45…0ee8discoverytoken
Plumetoken (nOPAL share token ERC-20)0x119d…9165discoverytoken
Plumetoken (nTBILL share token ERC-20)0xe72f…8cb9discoverytoken
Plumetoken (nWISDOM share token ERC-20)0x29bf…0240discoverytoken
Plumevault (nACRDX pUSD NestVault)0xa7d4…66b3discoveryvault
Plumevault (nACRDX USDC NestVault)0xf991…1f2bdiscoveryvault
Plumevault (nALPHA pUSD NestVault)0x9bb9…f4f0discoveryvault
Plumevault (nALPHA USDC NestVault)0x0342…3c34discoveryvault
Plumevault (nAXI pUSD NestVault)0x7592…4b13discoveryvault
Plumevault (nAXI USDC NestVault)0xe154…ebd0discoveryvault
Plumevault (nAXI XUPL NestVault)0x99ed…327bdiscoveryvault
Plumevault (nBASIS pUSD NestVault)0xe74f…7d0bdiscoveryvault
Plumevault (nBASIS USDC NestVault)0x5f35…dbb1discoveryvault
Plumevault (nCLOA pUSD NestVault)0x856f…79a0discoveryvault
Plumevault (nCLOA USDC NestVault)0x84c1…d9e3discoveryvault
Plumevault (nCREDIT pUSD NestVault)0xdd38…4572discoveryvault
Plumevault (nCREDIT USDC NestVault)0xec59…abeediscoveryvault
Plumevault (nFXCF pUSD NestVault)0x74c9…4c05discoveryvault
Plumevault (nFXCF USDC NestVault)0x4738…c5e7discoveryvault
Plumevault (nLCRD pUSD NestVault)0x67b2…edc2discoveryvault
Plumevault (nLCRD USDC NestVault)0x7195…6c8ediscoveryvault
Plumevault (nOPAL pUSD NestVault)0xfbfe…9a48discoveryvault
Plumevault (nOPAL USDC NestVault)0xd258…05c0discoveryvault
Plumevault (nTBILL pUSD NestVault)0xd263…baeddiscoveryvault
Plumevault (nTBILL USDC NestVault)0x250c…7f12discoveryvault
Plumevault (nWISDOM pUSD NestVault)0x4ecd…e25bdiscoveryvault
Plumevault (nWISDOM USDC NestVault)0x6330…a651discoveryvault

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@nestcredit

Security

[:] Source: DEFI@home quorum
Audits
10 audits
Bug bounty
unknown
Security contact
security@plume.org

Technical

[:] Source: DEFI@home quorum
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-08-10 07:25 UTC