DeFi Yield, Honestly
Decentralized finance promises yield. Double-digit APYs, paid in dollars or tokens, with no bank, no credit check, no minimum balance. It sounds like magic. It is not magic. It is a collection of mechanical relationships between lenders, borrowers, traders, and speculators, all mediated by smart contracts that can and do fail. Every percentage point of yield carries a corresponding point of risk, and most of that risk is invisible on the dashboard that shows you the APY.
This page maps the entire territory of DeFi yield: where it comes from, what it actually costs, which risks are real and which are overstated, and how to distinguish a genuine yield source from one that is simply paying you with inflated token emissions. Each section below opens a question that the spoke pages answer in full. If you are new to DeFi, start here. If you are experienced, you will still find the traps you have not yet stepped in.
Where yield actually comes from
DeFi yield has three honest sources and one that is marketing dressed up as revenue. The honest sources are liquidity provision, lending, and network security. The dishonest source is token inflation that looks like yield until the token price drops.
When you provide liquidity to an automated market maker exchange like Uniswap, you earn a share of the swap fees that traders pay to execute against your pool. The page on how do liquidity providers actually make money in DeFi breaks down the math precisely, including why fee revenue is not profit until you account for impermanent loss. A concentrated liquidity position on Uniswap V3 might earn 0.3% per trade in a 1% pool, but if the price moves through your range, you can lose more in divergence than you earn in fees over weeks.
Lending protocols like Aave and Compound generate yield by connecting depositors to borrowers. A borrower puts up 125-150% collateral in ETH or another asset, borrows stablecoins at a variable rate, and pays interest. The depositor earns a share of that interest minus protocol fees. The page how do lending protocols generate yield for depositors explains the margin mechanics and why a lending pool can still lose money if a collateral asset crashes and the borrower defaults before liquidation completes.
Network security yield is simpler. Proof of stake networks pay stakers newly minted tokens plus a share of transaction fees for validating blocks. Ethereum currently offers about 3-4% annualized for native staking. The page where do staking rewards come from in proof of stake networks traces the economic logic: the yield is the network's cost of security, paid in inflation that every holder absorbs.
Then there is the dishonest source. Liquidity mining incentives pay you in a protocol's governance token on top of the fee revenue. A pool shows 40% APY, but 35% of that is in a token that has no revenue claim and is being sold by every other farmer. The page what are liquidity mining incentives and how long do they last explains why most of these programs are temporary subsidies that dilute the token and why the "APY" is not a yield at all once you account for token price decay.
The decisions you actually have to make
Every yield opportunity forces a tradeoff. There is no free lunch in DeFi, only lunch you have not read the fine print on yet.
The most common fork is liquid staking token vs native staking directly. Stake ETH natively and you earn the consensus yield but your ETH is locked until the network's withdrawal queue clears, which can take days. Hold Lido stETH or Rocket Pool rETH and you get a token that trades and can be used in other protocols, but you take on the risk that the liquid staking derivative depegs from the underlying. The page on this comparison walks through the specific conditions under which stETH has traded below ETH and what it cost holders who needed to exit during that window.
The second major fork is stablecoin LP vs volatile pair LP. A USDC-DAI pool on Uniswap looks safe because both sides are stablecoins. But if one stablecoin depegs, the pool rebalances, and you can end up holding the depegged asset while losing the other. A ETH-USDC pool has impermanent loss risk from price movement, but both assets stay liquid. The page comparing these two pool types shows the exact scenario where the stablecoin pool loses more than the volatile pair, which is the opposite of what most people assume.
The third fork is auto-compounding vault vs manual reward harvesting. A vault on Yearn or Beefy automatically claims your rewards, sells them, and reinvests them. It charges a performance fee, typically 2% of yield. Harvesting manually costs gas every time you do it. The page on this tradeoff calculates the breakeven portfolio size where manual harvesting becomes cheaper than the fee, and it is smaller than most people guess.
Then there are the open questions with no settled answer. Points programs, real-world asset yield, restaking on EigenLayer - these are all emerging and the track record is thin. The pages covering these topics flag where the data is insufficient and where the volatility layer is highest.
What it costs: the fees you cannot ignore
Every DeFi action involves a sequence of transactions, and every transaction has a cost. The most obvious is gas fees - the amount you pay to have your transaction included on the Ethereum network or a layer 2. On Ethereum mainnet, a simple swap through Uniswap costs roughly $5-50 depending on network congestion. A complex strategy that involves depositing, approving, and staking can cost $50-200 in gas just to open the position. The page what gas fees actually cost in DeFi and how to pay less breaks the fee into its components - base fee, priority fee, and calldata cost - and explains which levers you can actually pull to reduce them.
Less obvious but more dangerous is impermanent loss. When you provide liquidity to a volatile pair, the automated market maker rebalances your position as the price moves. If ETH goes from $3000 to $4000 while you are providing liquidity to an ETH-USDC pool, you will have less ETH and more USDC when you withdraw than if you had simply held. The loss is "impermanent" only if the price returns to the entry point. The spoke page on liquidity provision includes a calculator and a rule of thumb: a 50% price change in one direction turns into a 20% loss on your position.
Slippage is the third major cost. When you swap a large amount relative to pool depth, the price moves against you. A 100 ETH trade on a thin Arbitrum pool can cost 3-5% in slippage. The error warning "price impact too high" is your signal to stop, not a suggestion to click confirm anyway. The page on gas fees also covers how to set slippage tolerances that do not get you frontrun.
Then there are the costs that are not denominated in dollars. Token approval transactions require gas upfront and grant on-chain permissions that can be exploited. The page what does approving a token on MetaMask actually allow explains the ERC-20 approval mechanism, the difference between an approval of exactly the amount you need and an infinite approval, and how a compromised protocol can drain tokens that you approved years ago.
The risks: what actually goes wrong
Smart contract risk is the one everyone knows. A protocol gets exploited, funds are drained, no one gets made whole. The page how to check if a DeFi protocol is safe before depositing goes beyond the audit badge to the actual signals: whether the contract is upgradeable, who holds the admin keys, whether the protocol has a bug bounty program, and how long the contracts have been live without incident. A protocol that is audited but has no timelock on upgrades is a protocol that can change its rules overnight.
Stablecoin depeg risk is the one that cascades. When a stablecoin trading at $1 drops to $0.95, every lending protocol that accepted it as collateral triggers liquidations. Borrowers who were using that stablecoin as collateral get their positions closed at a loss. The page what happens when a stablecoin depegs and how it cascades through DeFi traces the exact chain reaction from UST's depeg in May 2022 through the bankruptcies that followed.
Oracle manipulation is the attack that does not get enough attention. A lending protocol that uses a single-source price feed can be tricked if an attacker executes a flash loan, manipulates the exchange price on a thin pool, and borrows against inflated collateral. The page how oracle price manipulation steals money from DeFi lending protocols walks through the mechanics of a real exploit and explains why multi-oracle solutions are not foolproof.
Governance attacks are slower but just as destructive. If an attacker accumulates enough governance tokens, they can pass a proposal that changes the protocol's fee structure, freezes withdrawals, or even sends treasury funds to a wallet they control. The page what is a DeFi governance attack and can it steal your deposited funds answers the specific question of whether a governance attacker can drain your individual deposit directly - the answer is complicated and depends on the protocol's architecture.
Bridge risk is the one that comes into play when you move assets to a layer 2 for higher yield. A bridge exploit means your assets are stranded on the source chain with no path back. The page what are the real risks of bridging assets to layer 2 for yield breaks down the difference between canonical bridges, third-party bridges, and the specific exploits that have drained hundreds of millions from each type.
The misconceptions that cost money
The biggest lie in DeFi is the APY number on a dashboard. That 12% number on a lending pool assumes no withdrawals, no liquidations, no change in utilization, and no change in token price. The page why the APY shown in DeFi is not what you will actually earn lists every factor that reduces the displayed rate to the actual return, including variance in block times, compounding frequency, and the spread between the deposit rate and the borrow rate that gets paid out.
The second biggest lie is that an audited protocol is a safe protocol. Audits find bugs, not fraud. A protocol can pass three audits and still have a function in its contract that allows the admin to mint unlimited tokens. The page on protocol safety includes a checklist that starts with "Find the admin address and check what it can do" and continues through each governance mechanism.
The third biggest lie is that high TVL means low risk. Total value locked is a measure of how many people have deposited, not a measure of how safe those deposits are. A protocol with $10 billion TVL can have an unpatched bug that drains everything. The page on safety covers why DeFiLlama TVL is a starting point for investigation, not a conclusion.
The fourth lie is that yield aggregators eliminate protocol risk. Yearn vaults and Beefy pools deploy your funds into underlying protocols. If Aave gets exploited, your Yearn vault deposited into Aave gets exploited too. The spoke page on vault tradeoffs explains the additive risk: you are exposed to both the vault's smart contract risk and every protocol the vault touches.
The tools you need to actually see what is happening
You cannot manage yield in DeFi with just a MetaMask wallet. You need block explorers, portfolio trackers, and permission managers. MetaMask itself is the entry point, but the page how to protect your MetaMask seed phrase from theft and phishing covers the specific attack vectors - phishing sites that ask for your seed phrase, malicious browser extensions that read your seed from local storage, and hardware wallet integration that eliminates the software seed entirely.
Etherscan is the first tool after the wallet. Every transaction should be checked on the block explorer before you confirm it. The page on protocol safety walks through how to read a transaction trace to see exactly what a contract can do with your tokens.
Rabby wallet is gaining adoption because it simulates the transaction before you sign it, showing you exactly what the contract will do rather than the vague "Interact with contract" message that MetaMask displays. The spoke page on approvals explains why transaction simulation is not a luxury but a necessity for anyone managing more than a few thousand dollars.
DeFiLlama provides the TVL numbers and yield dashboard. Token Terminal provides financial metrics like revenue and P/E ratios for protocols that have revenue. Revoke.cash lets you see every token approval you have ever granted and revoke the ones you no longer need. The page on approvals links directly to Revoke.cash and explains how to run a quarterly approval clean-up.
The Aave vs Compound comparison page and the Lido stETH vs Rocket Pool rETH page both include specific instructions for how to use these tools to monitor your positions, including what to check daily versus weekly.
Where the territory gets volatile
The sections above cover the established DeFi yield landscape. Below them is the volatile frontier: new mechanisms with short track records and no settled risk profile.
Points programs are the current hype vehicle. Protocols offer "points" that may or may not convert to tokens at an unknown ratio on an unknown date. The page on liquidity mining incentives covers why points are strictly worse than token emissions: there is no market for points, no way to price them, and no guarantee that the eventual token launch will even cover your gas costs. A points program is an option on a future token that might never be exercised.
Real-world asset yield sounds safe because it references mortgages, bonds, or invoices. But the yield depends on the same borrowers actually repaying, and the protocols tokenizing those assets add layers of smart contract risk on top of the credit risk. The page comparing yield sources explains why RWA yield is not simplistically "safer" than crypto-native yield - it is simply correlated with a different set of failure modes.
Restaking on EigenLayer and Symbiotic promises to extend cryptoeconomic security across multiple services. In exchange for higher yield from restaking rewards, you accept the risk of slashing across all those services. A single service's bug can slash your entire deposit. The page on restaking tradeoffs explains the mathematical relationship between number of services and probability of slashing, and why the yield premium may not compensate for the non-linear increase in risk.
Layer 2 yield looks higher than mainnet yield because gas is cheaper and liquidity is newer. But the bridge risk is real, and the liquidity can disappear when markets turn. The page on bridging breaks down the risk the same way: as a probability of loss multiplied by the amount at risk, compared to the yield premium.
The Final Question
Every DeFi yield opportunity eventually reduces to one question: who is paying you, and why? If you provide liquidity, traders pay you for execution. If you lend, borrowers pay you for access to capital. If you stake, the network pays you for security. If the answer is "token holders" or "future users" or "the DAO treasury," you are in a subsidy that will end.
The spoke pages beneath this one answer each question in full, with exact numbers, named protocols, and real horror stories. Read them before you deposit. Read them before you approve. And if you are using a wallet that shows you generic "Interact with contract" messages without simulation, fix that first. The yield you are chasing will still be there tomorrow. The permission you approve today might not be revocable after the exploit.
Not financial advice. brooder.tech publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.