Research summary
AFI Protocol receives an adverse research assessment because its operator is entirely hidden. AFI runs an ERC-4626 vault, afiUSD, that combines stablecoin lending, Pendle principal-token accumulation, and leveraged PT loops. It also runs a second, currently institutional-only vault backed by tokenized real-world assets from a separate entity. AFI's own Terms of Use, custody framework, and KYC policy do not name an operating entity. The closest thing to a legal disclosure is that Nevis law governs the Terms, which include no arbitration clause and name no counterparty. This review found no team member, founder, or investor identity in any source it could access. The flagship vault currently requires an invite code obtained through Telegram, an unusual gate for a product sold as permissionless. An August 2025 Cantina audit found a critical-severity issue in AFI's main token contract and reports that AFI fixed it. Even after that fix, the anonymous team and offshore legal wrapper with no disclosed principal each provide enough reason to reject it.
Observable review triggers
- A named operating entity and jurisdiction of incorporation are disclosed
- Team, founder, and investor identities are publicly disclosed
- The invite-code access gate is removed or explained, resolving the tension with the product's permissionless marketing claim
- The afi-rwaUSDi vault's custody, redemption, and eligibility terms are publicly documented once it reopens beyond institutional-only access
Facts on file
- Verdict
- Rejected
- Type
- Other
- Chains examined
- Base, Ethereum, Monad
- Reviewed
- Last confirmed