Skip to main content
If a supported pool shows signs of elevated risk, the Agent is designed to move capital away from that pool and into safer alternatives. Zyfai uses complementary defense layers to protect user positions during DeFi incidents: autonomous detection and human override for underlying protocol risk, plus an onchain kill switch if the Session Key / executor layer itself is compromised.

1. Autonomous Agent Detection

Most DeFi incidents create one of two risk patterns:
  • Collateral depeg: a collateral asset loses its expected value or backing. This can happen because of excessive token minting, flawed protocol design, compromised keys, or oracle issues.
  • Liquidity trap: a lending market becomes impossible to exit because borrowers cannot repay debt, liquidity dries up, or the pool enters economic insolvency.
The Agent continuously monitors onchain signals for both patterns. When a depeg or liquidity squeeze is detected, it exits the affected position within minutes, before losses spread further through the market.

2. Human-in-the-Loop Override

Zyfai also maintains a human risk override system. When a major incident occurs, the Zyfai quants team is alerted and can manually flag a pool as not-live on the Risk Dashboard. Once a pool is flagged, the Agent stops allocating capital to it and begins moving existing user positions away from the affected pool. Response workflow:
  1. The Zyfai team is alerted about a DeFi hack, depeg, key compromise, liquidity issue, or collateral backing concern.
  2. Impacted pools are identified across all supported protocols.
  3. Affected pools are switched from live to not-live.
  4. The Agent exits all positions from flagged pools.
  5. Capital is reallocated to safer opportunities or left unallocated when no suitable alternative is available.

3. Session Key Kill Switch

Sections 1 and 2 cover incidents in underlying DeFi protocols. If an incident instead affects the Session Key or Guarded Executor Module layer, Zyfai can halt delegated execution globally. The Zyfai 3/5 multisig owns the Guarded Executor Module and can call pause() (0x8456cb59) on the module contract. Once paused, all Session Key-driven execution through the module stops immediately: no Agent can move capital via Session Keys until the module is unpaused. User funds remain in their Smart Accounts. Pausing only disables Agent execution via Session Keys; it does not move or seize capital.

Proven Track Record

The protocol-risk layers above have already protected Zyfai users’ capital during real DeFi incidents. Each case below recaps the threat and what the Agent did. In each case, automated monitoring combined with human risk override moved user capital away from unsafe conditions before losses reached Zyfai users.

Stream Finance

Threat. Stream disclosed a ~$93M off-chain loss on 4 November 2025. xUSD depegged and the damage spread through lending markets that still priced the collateral at $1, leaving bad debt and frozen liquidity. Sonic Silo markets, including MEV Capital Sonic, were directly exposed to xUSD. What the Agent did. Agents classified those pools as risky and withdrew before the public disclosure. Isolated Smart Accounts meant no shared-vault contagion; capital stayed withdrawable. Example exits on Sonic, 2-3 November 2025: Full post-mortem

Resolv / wstUSR / RLP

Threat. A compromised Resolv backend key minted unbacked USR. wstUSR and RLP depegged. Morpho vaults with that collateral, including Extrafi XLend USDC, became unsafe. Some automated vaults kept depositing into the market because utilization looked like high yield. What the Agent did. Collateral-health checks fired a 15 bps depeg warning. Agents on four separate Smart Accounts exited Extrafi XLend USDC in parallel and moved USDC into safer venues (Euler, Fluid, Morpho). Steakhouse started exiting the same market about 20 minutes later. Conservative Zyfai pools had no exposure. Example rebalances on Base, 22 March 2026: Full post-mortem

Aave / Kelp DAO

Threat. A Kelp rsETH bridge misconfiguration released unbacked rsETH. The attacker posted it as Aave collateral and borrowed WETH. Utilization on WETH (and then stablecoin) markets raced toward 100%, which would have trapped remaining depositors. Markets on each chain were hit at different times, so exits landed on different hours of 18 April 2026. What the Agent did. The ZyFUD Agent picked up the incident early, including Marc Zeller’s warning on WETH Aave pools, and routed it to pool-health monitors. Execution Agents left Aave V3 WETH on Ethereum, Base, and Arbitrum and moved into safer WETH venues (or left funds unallocated). The quant team then delisted the affected pools. Example rebalances, 18 April 2026: Full post-mortem