One hundred dollars. One dollar and thirty cents the next day. The capital does not need to be entrusted to an asset manager or locked on an unfamiliar platform. It remains in your own wallet, under your control, denominated in USDC, one of the world’s largest dollar-backed stablecoins. At first glance, three concerns seem to disappear at once: volatility, loss of custody and complexity.

That is precisely where the problem begins.

During a recent exchange about the practical uses of decentralized finance, Atlas Limits was introduced to a mechanism described as a “USDC farm.” The principle sounded almost ordinary: hold at least 100 USDC in a wallet and receive approximately $1.30 per day. The money would remain visible in the wallet. Nothing would need to be sent anywhere, nothing would need to be locked. The USDC would provide liquidity to infrastructure connected to Ethereum, and the commissions generated by that activity would then be distributed among participants.

The number deserves attention. A return of $1.30 on $100 represents 1.3% per day, or 474.5% of the initial capital over one year without even reinvesting the proceeds.

Crypto markets have produced spectacular yields before. Some protocols distribute tokens aggressively to attract capital, periods of market stress can create exceptional returns, and some strategies rely on leverage. The level of return alone therefore does not establish the nature of a mechanism. But the further a yield moves away from the ordinary cost of capital, the harder one question becomes to avoid: who is paying?

In this case, the answer seemed to come down to one word: USDC.

That is where the reasoning begins to fracture.

Circle designed USDC to maintain a reference value of one dollar and states that the units in circulation are backed by corresponding reserves. But holding USDC does not, by itself, generate this kind of return. The assets making up those reserves may produce income; that does not turn every USDC held in a wallet into an interest-bearing investment.

If 100 USDC produces $1.30 tomorrow, something therefore has to happen between the two.

A borrower can pay interest. A market maker can collect fees. A protocol can distribute incentives. A strategy can take risk, use leverage or deploy capital into a liquidity pool. There are many ways to manufacture yield in decentralized finance. They all have one thing in common: the return comes from an additional mechanism. The stablecoin is merely the asset entering it.

The stability of the digital dollar can therefore conceal a deeper confusion. One USDC can remain worth exactly one dollar while the strategy using it becomes illiquid, a smart contract is compromised, incentives disappear or a permission granted by the user allows a third party to move the tokens.

The dollar can remain stable while everything around it does not.

The explanation provided for the source of the income raised a second difficulty. The USDC held by participants was supposedly providing the liquidity required to process ETH activity on Ethereum. The commissions generated by that activity would then fund the return.

Ethereum does not work that way.

Since its transition to proof-of-stake in 2022, the network has relied on validators who stake ETH, participate in consensus, propose blocks and attest to their validity. Transactions are executed within that infrastructure, and gas fees belong to that economy. Circle does not require a pool of USDC held by individual users in order for Ethereum to process transactions.

A poor explanation does not automatically turn a product into a fraud. Users sometimes understand the instruments they use imperfectly; DeFi mechanisms are complex and attempts to simplify them can easily produce shortcuts. But when a return of several hundred percent a year rests on a mechanism whose explanation does not correspond to the operation of the network being invoked, understanding the infrastructure stops being a technical curiosity.

It becomes the first step in risk analysis.

Atlas Limits therefore followed the proposed path.

Not with 100 USDC. With zero.

The experience begins in a remarkably ordinary way. A crypto application distributed through conventional channels. An account. Then an on-chain wallet. On the screen, a balance of $0.00. Nothing resembling the crude imitation of a financial website that can sometimes trigger suspicion at first sight.

A few screens later, a Web3 browser appears. Established decentralized-finance protocols are displayed. A search bar also allows the user to enter the address of a dApp directly.

Only at this point is an external address provided.

Before opening it, we ask for the smart contract address. The objective is straightforward: identify the protocol, examine the contract on-chain and understand what is actually generating the return.

The contract address does not arrive.

Customer service must be contacted.

But accessing that service introduces another condition: “mining privileges” must apparently be obtained first.

The paradox is immediate. To obtain the information needed to understand the mechanism, one would first have to begin entering the mechanism.

The experiment stops there.

No USDC was purchased for the occasion. No assets were transferred. The wallet was not connected to the external dApp. No message was signed and no smart contract was granted permission.

We therefore do not know what the contract would have requested.

And that is precisely what makes what follows more interesting than the individual case.

Throughout the journey, almost every visible component could be perfectly legitimate. The application could be authentic. The wallet could function normally. The USDC could be genuine. Ethereum could execute exactly the operations submitted to it.

The question was gradually moving somewhere else: away from the individual components and toward the relationship between them.

An app store verifies the distribution of an application; it does not guarantee every address a user may later open through its Web3 browser. A wallet protects private keys; it does not decide on behalf of its owner which permissions should be granted. A blockchain can flawlessly execute an instruction that proves financially disastrous for the person who authorized it.

Programmable finance introduces a subtle break here with one of the most deeply rooted instincts of traditional finance.

We instinctively associate losing money with money moving.

A transfer leaves the account. A payment is made. Securities are sold. A balance falls. Something moves from one place to another.

In a Web3 wallet, the boundary is less visible.

The ERC-20 standard used across a vast part of the token economy includes the functions approve, allowance and transferFrom. Their purpose is essential to decentralized finance: a user can authorize an address or smart contract to use a specified amount of tokens. A decentralized exchange or lending protocol can then perform the requested operation without requiring every movement to be reconstructed manually.

But the same architecture creates a less intuitive consequence.

The money can still be displayed in the wallet even though the right to move it has already been partially delegated.

The decisive transaction is therefore not always the one that transfers the funds.

It can be the one that authorizes their future transfer.

Sometimes the button to watch is not Send.

It is Approve.

The phenomenon has been documented extensively enough to attract the attention of US authorities for years. In July 2022, the FBI’s Internet Crime Complaint Center published an alert dedicated to so-called “liquidity mining” scams.

The scenario described by the agency often begins far away from technology. A relationship develops through social media or a messaging platform. A crypto-yield opportunity gradually enters the conversation. The contact then assists the person in acquiring crypto assets, setting up a wallet and accessing a liquidity-mining application.

The returns cited by the FBI can range from 1% to 3% per day.

The victim believes the crypto assets can remain in their own wallet while generating income. They are then directed toward an application or dApp and may grant a smart contract permissions that allow access to tokens held in the wallet. In its 2022 alert, the agency reported more than $70 million in losses associated with this model since January 2019.

That description does not turn every “liquidity farm” promising high returns into a fraud. Nor does it allow conclusions to be drawn about a service whose contract has not been examined.

It does, however, explain why some details that appear reassuring are not necessarily so.

“Your money stays in your wallet” is one of them.

The phrase relies on a conception of ownership inherited from the bank account: what is still visible in my account must still be exclusively under my control. In programmable finance, that equivalence is no longer absolute. Where an asset is located and what rights have been granted over that asset are two different pieces of information.

This is where the paradox of self-custody becomes deeper.

The crypto movement built part of its philosophy around a phrase that became famous: not your keys, not your coins. Taking possession of one’s keys was supposed to remove dependence on the intermediary holding assets on the owner’s behalf.

The promise remains real.

But removing the intermediary does not remove the decisions that intermediary once made on your behalf.

It gives them back to the user.

Which network to use. Which application to open. Which contract to connect. Which message to sign. Which permission to grant. What amount to authorize. Which approval to revoke.

Financial sovereignty and technical responsibility increase together.

That may be where the real change introduced by programmable finance lies. Risk no longer necessarily resides inside an identifiable institution. It circulates between several layers, each of which, taken separately, may be functioning exactly as intended.

A stablecoin can be properly backed.

A wallet can be authentic.

A blockchain can be intact.

A smart contract can execute exactly what its code instructs it to execute.

And the user can still lose the money.

Not because any one of those elements necessarily failed, but because their combination created a power the user did not realize had been granted.

The next generation of financial education will therefore have to teach a distinction the previous one rarely encountered: holding an asset and retaining the exclusive power to move it are no longer necessarily the same thing.

In traditional finance, danger generally becomes visible when the money leaves the account.

In programmable finance, it can begin while the money is still displayed in the wallet.

MAIN SOURCES

Circle — USDC Terms and documentation on USDC reserves and transparency.

Ethereum Foundation — technical documentation on proof-of-stake, validators and transaction execution.

Ethereum Improvement Proposals — EIP-20: Token Standard, particularly the approve, allowance and transferFrom functions.

FBI Internet Crime Complaint Center — Scammers Target and Exploit Owners of Cryptocurrencies in Liquidity Mining Scam, July 21, 2022.