Version 0.2 · every figure on this site links back to the version that produced it.
Referenced from the figures they qualify. Nothing here is optional reading — a number whose limits are not understood is worse than no number — but it belongs beside the explanation rather than in front of the figure.
A dollar supplied to a lending vault, lent to a borrower, and supplied again into another vault on this list appears in the total twice. We cannot follow an individual dollar, so we state the ceiling rather than netting it out: the share of the total currently out with borrowers is the most that could be duplicated that way, not a measurement of how much is.
The ceiling is itself understated wherever a venue has not had its lending split read. Separately, we ask every vault contract what it holds; a vault that holds another tracked here is counted twice on purpose, and the figure is published. Vaults that do not answer — mostly perpetuals vaults, which have no deposit asset to name — make that a floor rather than a clean bill. A vault holding another indirectly, or as one allocation among many, is not visible to that method at all.
The three quantities added into the total are not the same kind of thing. Capital supplied to lending is gross. Strategy holdings are a net asset value. Perp account equity moves with the market even when nobody deposits or withdraws. They are printed separately for that reason.
Every published agent track record today is self-reported and survivorship-biased, and the bias is invisible — the strategies that failed are not on the leaderboard to be counted.
Leaderboards also rank by headline return. A vault that turned $2,000 into $5,000 over three weeks outranks one that compounded $8M for two years. We rank on risk-adjusted terms, show the drawdown next to every return, and state how confident we are. Where we cannot verify something we say so rather than omitting it, and closed vaults are kept forever — a list that drops them is the bias itself.
We can show that software decides, from execution timing and behaviour across a vault’s fills. We cannot show, from execution alone, whether that software is a trading script or a language model.
Only a signed declaration separates those, and none has been made yet. Any site telling you which vaults are "AI" is reporting a claim, not a measurement.
A realised return is read from the vault’s own share price at historical blocks — what a holder actually earned — and set against the rate its venue advertises. Venues publish a spot rate; nobody publishes what was delivered.
Four things stop the comparison being meaningful, and each is named on the figure rather than explained away. Rewards paid in tokens accrue outside the share price, so a vault paying them shows a shortfall that is not one. An advertised rate is spot and a realised return is history, so a rate that just rose legitimately outruns a trailing figure — the decisive window is recent. A vault whose share price is pinned to exactly 1.00 mints one share per unit of asset and cannot express a return at all, whatever holders receive by other routes. And a series that does not span enough days cannot be annualised.
We read public on-chain state and venue APIs. Exposure held on a centralised exchange is invisible to us, so a strategy’s full risk may be larger than what is shown here and we cannot tell you by how much.
Gaps are named rather than filled in. Where a figure could not be read, the page says which reading was missing instead of substituting an estimate that would look the same as a measurement.
Crowding is the same instrument held by strategies that would have to exit through the same door. From inside any one vault a market at full utilisation looks like a position; only something reading every curator at once sees an exposure — and the curators are not the ones who would notice.
Every figure behind it is public and none of it is published anywhere else.
Lending capital sitting in vaults at full utilisation is capital whose depositors are waiting on borrowers rather than on a market. It is not a loss and not a default; it is a queue, and it is invisible from inside any single vault.
The concentration figure beside it is the share of what we can attribute that is lent against a single collateral. What we cannot attribute is stated separately rather than assumed to be spread evenly.
The same reading answers the opposite question. A vault at full utilisation cannot be withdrawn from; a vault at low utilisation is perfectly liquid and earning nothing. Capital counted as unlent is at least 80% idle against its own supplied and borrowed figures — a return problem rather than a liquidity one, and the larger of the two.
A firm often operates under a separate record per venue. Merging them is what makes a track record a cohort rather than a selection, so the evidence for a merge is graded and only the conclusive kind merges on its own: a shared on-chain address, or a person who checked and said so.
Weaker evidence — two brand names reducing to the same string, or a name declaring its own abbreviation in parentheses — becomes a suggestion someone has to accept. A wrong merge attributes one business’s failures to another under its real name, which is worse than leaving two records apart.
A grade says how a record can be checked, not how good the returns are. A · attested means pre-trade committed, sequence complete, anchored on chain. A− · pre-registered means the claim was declared to us before going live, so it precedes the result. B · venue-verifiable means independently observable on chain or at the venue, though the operator’s full cohort is unproven. C and D are reported by an aggregator, or not checkable directly — mostly vaults we hold no contract address for.
The top two grades require an operator to register. That is the point of them: nothing we can compute on our own can earn them.
A vault trading a book decides what to buy and sell. A lending vault decides where deposits sit, moving them between markets as rates change — the allocation is automated but it takes no directional view. Both are software deciding; neither is the other, and averaging their returns together produces a number about nothing.
There is no registry of these and self-declaration is unreliable in both directions, so it is inferred and the evidence is attached to every claim. The autonomy badge on each vault says why we believe it and how sure we are.
A program sharing no code with this site calls the published API as a customer would, checks the answers against the chains and the venues themselves, and prints what it finds. It runs unattended every few hours.
Findings are published whole, including when the finding is our own error. It has caught one: a vault reported at twice its real size after a price feed valued a dollar token at $2.07. A report that shows its passes and hides its failures would not be worth reading.
An observation is a pattern in a vault’s record that has more than one explanation. Each is measurable, each has a perfectly ordinary reading, and a ledger cannot tell those apart — so what is reported is what was measured and what it is equally consistent with.
Inference may raise a question; only a declaration from the operator can settle one. These exist so you know which figures elsewhere need reading differently, not so a suspicion can be scored.
One number for how much can go wrong, built only from risk and never from return: what a vault has already lost, how much of its book it shares with everybody else, how close it sits to liquidation, whether you could get your money out today, how few wallets could empty it, and whether it kept operating. Higher is worse.
Mixing return into a risk score is how a risk score becomes a recommendation. It is kept out deliberately.
A ranking without its qualifier is how a list of vaults becomes a recommendation. Each leader is printed with the figure that makes the ranking readable — concentration under the largest, our own observation window under the oldest, return under the steadiest.
The observation window matters most: a vault is not old because we have watched it a long time, and a record measured from our first sighting says when we arrived rather than when the strategy started.
A strategy declared here before it ran. A declaration cannot be edited — any change breaks its signature — and it is never removed, so a strategy that went wrong stays visible beside one that did not.
The rows worth reading are the ones nobody would have submitted afterwards. That is the entire point of asking for them in advance.
Move one price, revalue every book it touches, and compare the resulting equity against the resulting maintenance requirement. Liquidation is an account-level event.
A test that walks positions one at a time answers a question the exchange never asks: a hedged book fails it and survives in reality.
The list shows the largest vaults by capital, not the whole perimeter — the count of both is printed on the page, and the rest is in the API and on the platforms page. This page once said "the full perimeter" over the largest few hundred, and an outside reviewer caught it against the perimeter the methodology publishes.
Non-agent vaults are included because correlation and coverage cannot be measured without them. They are context, not the product, and the comparison between the two is itself a finding.
Every strategy we can see a firm has run, best to worst, with the closed ones included. A leaderboard shows you the survivor; this shows you the denominator.
Where a firm operates under more than one record, the cohort spans them only if somebody has linked those records on conclusive evidence.
Every return figure on this platform is measured across vaults that still exist. A survival rate cannot be computed from the survivors, and the ones that died are counted nowhere else.
This page exists so that first sentence is never load-bearing without evidence behind it.
Every other page answers what is true now, which you can look up whenever you like. This answers what moved — which you cannot look up afterwards, from here or anywhere else, because it requires having been watching at the time.
Every venue we know of is listed, including those we cannot yet read vault by vault. A coverage gap should be visible rather than hidden by its own absence — a list of only what we can read looks identical to complete coverage.
What gets declared, what a record has to survive to be graded, what is fixed in place so it cannot be edited afterwards, and how to re-derive the whole thing without taking our word for any of it.
Every number on this site rests on one of three things: a contract we read, a venue’s own history, or a signature somebody put their name to.
Agents buy work from other agents: one posts a task, another delivers it, and the fee settles on chain. Read from the balance trackers of the mech marketplace, one row per settled fee — not from the marketplace contract, which emits nothing that can be priced.
Fees are shown in each chain’s own token and never added together. We hold no price for those tokens at the moment each task settled, and a total mixing them would not be a quantity. A payment made outside this marketplace — a subscription, an API bill, a private arrangement — is invisible here, so this is a floor on what agents spend and not a measure of it.
The window is what could be read within a fixed request budget, not a fixed number of days: thirty days is ten million blocks on some chains and a few hundred thousand on others. Each run publishes the days it actually covered.
A task is dated from the block it settled in and that chain’s block time, not from a fetched block header — one header read per event would be hundreds of thousands of requests for a field used only to group by day. Within a window this is accurate to minutes; it is not a timestamp to quote.
The first and last days are left out of the trend. Both are partial by construction — the reader started part-way through one and stopped part-way through the other. Dropping only the last was the first version of this, and it understated the early half of the window and so flattered every trend measured against it.
The trend compares mean tasks a day over the later half of the window against the earlier half. It is a direction, not a growth rate, and a window of a few weeks cannot tell a trend from a busy fortnight.
Each period shows what it actually returned, not an annual rate. Venues publish these annualised, and over a thirty-day window that stops meaning anything — one vault here is stated at 3,540,778% a year, which is a 137% month compounded twelve times.
The venue’s own figure is kept underneath. What is shown is that figure undone.
Read off the vault account on chain, exact: everything put in, less everything taken out. It is not the vault’s value today — a profitable vault holds more than was put into it and a losing one less.
Where we hold no value series for a venue, that vault stays out of the stress ladder and the redemption scenarios rather than being estimated into them.
The venue has not said the vault is closed; we concluded it from what we observed, so the figures shown are what we last saw rather than a live position.
If money arrives in it again the page says so. The judgement is remade every twelve hours and reverses as readily as it is reached.
A record rebuilt from public on-chain data is real, and it cannot show what is deciding the trades, whether this is the operator’s only strategy, or what they intended before it ran.
A declaration fixes all three going forward. It is free, it takes a signature from the vault’s own key, and it cannot be edited or withdrawn afterwards.
Several counts on this site look like they should agree and do not, because they are measuring different sets. Each is defined here with the query behind it, and every one is read from the same place the pages read it, so two pages disagreeing is impossible rather than unlikely.
| Number | Count | What it is, and what it excludes | Dataset |
|---|---|---|---|
| Vaults tracked | 1,354 | Open vaults across every platform we ingest. Closed ones are excluded, which is why this is the smallest of the vault counts. | Vault, isClosed = false |
| Vaults ever recorded | 1,456 | Everything we have written a row for, open or closed — 102 of them have since closed. A provenance grade attaches to this set, not to the open one, which is why the certification page counts more than the front page. | Vault, all rows |
| Graded B or better | 803 | Vaults whose record is independently observable from chain or venue data. Every vault carries a grade by construction — the column is not nullable and defaults to D — so "graded" is not a count worth publishing; the distribution is. Currently 208 D, 803 B, 445 C. A grade says how much of the record can be checked, never whether the returns are good. | Vault, provenance in (A, A−, B) |
| Machine-managed, open | 467 | Open vaults where we hold evidence that software decides — trading a book or allocating deposits. Absence of evidence is not counted as a human. | Vault, isAgentManaged, isClosed = false |
| Vaults on the venue | 9,469 | Every vault Hyperliquid has ever listed, counted whether or not we rate it — 6332 of them closed or abandoned. Far larger than anything above, because most are dust and sit under our ingest floor. This is the denominator for any survival claim. | CensusSnapshot, hyperliquid, latest day |
| Platforms with vault data | 29 | Platforms we hold individual vaults for, of 64 in the registry. The rest are known to exist and not yet ingested. | Platform, hasVaultData |
| Operators | 463 | Distinct managing addresses or teams behind the vaults above. One firm can appear more than once where we have not yet linked its identities. | Operator, all rows |
As of 2026-08-24 21:53Z. Counts move as vaults open and close.
Return over observed history, worst peak-to-trough drawdown, downside-adjusted risk-return (Sortino), the length of live history, and a confidence figure derived from how much history and how many observations support the rest. Confidence is reported separately and never folded into a score: thirty days of data must not look like three years.
The question behind “is this current”, answered as a distribution rather than as a worst case. 99.98% of the capital on this site was re-read within the last twelve hours.
| Last confirmed | Vaults | Capital | Share |
|---|---|---|---|
| Within 2 hours | 842 | $5.92B | 99.98% |
| 2 to 12 hours | 10 | $44.1k | <0.01% |
| 12 to 36 hours | 36 | $32.1k | <0.01% |
| Over 36 hours | 248 | $797.2k | 0.01% |
| Never timestamped | 218 | $108.2k | <0.01% |
The tail is real and is mostly dust: vaults that have dropped out of the venue list that reports them, so the last figure we hold is the last one anybody published. They are counted rather than dropped, and shown here rather than averaged away.
Three kinds of knowing, and they are not the same. This section said two of them yesterday and was wrong about 306 vaults for it.
Read from the contract. 450 vaults holding $4.51B: totalAssets() asked of the vault and priced by the asset the contract itself names. This is what the vault held at the block we asked about, and it is the only one of the three that cannot go stale.
Read from the venue. 306 vaults holding $425.56M, from the API of the venue that holds the money. Hyperliquid is all of it — its vaults live on HyperCore rather than as EVM contracts, so there is nothing to call and nothing to verify independently. But a venue’s account of its own book is not a third party’s stale snapshot either, and calling it one understated what we have.
Taken from an aggregator. 377 vaults holding $989.04M, because we hold no address we can call and no venue reader covers them. These are a snapshot of whenever that aggregator last looked, and we inherit the staleness without inheriting any way to measure it — one here read 28% above the chain for a day for exactly that reason, and the nightly checks caught it rather than a reader.
Not yet recorded. 221 vaults holding $94.1k were written by readers that predate this column. They are shown as their own line rather than folded into the weakest of the three, because defaulting them to “aggregator” would be a guess dressed as a fact — which is the failure this section exists to stop making.
One vault is deliberately left on the aggregator’s figure against a contract reading of zero: it reports no assets while still reporting shares outstanding, which is not a measurement of an empty vault but a contract disagreeing with itself. Where a vault has genuinely emptied, its share supply falls with its assets — three did in the same run and the contract was believed about all three.
Most records here are grade B — verifiable at the chain or the venue. Nothing is A until the attestation SDK ships, and the distribution above is the current count rather than a claim about it. What each grade requires, and how an operator earns one.
No registry of agent-managed vaults exists, and self-declaration is unreliable in both directions — marketing-led operators overclaim autonomy, serious quantitative teams underclaim it. So we infer, and we publish the evidence and the confidence alongside every claim.
| Signal | Status | Records | What it rests on |
|---|---|---|---|
| Operator declaration | not yet used | 0 | Nobody has declared. It would outrank everything below. |
| Venue classification | live | 171 | The venue hosts only automated strategies, or names this one as automated. |
| Execution timing | live | 169 | Fills across the clock: rate, evenness over 24 hours, trading through every window. |
| Name signal | live | 32 | The strategy names what it is. Weakest of the three and never sufficient alone. |
| Trade-size entropy | not built | — | Would separate a script from a person sizing by hand. |
| Reaction latency | not built | — | Would separate a reaction from a schedule. |
Counts are evidence records across machine-managed vaults, read 2026-08-20; a vault may carry more than one. What none of them separate is a trading script from a language model — only a signed declaration does that, and none has been made.
A standing rule: inference may raise a flag, but only a declaration or an attestation by the operator can lower a rating.
Three sources of evidence, ranked by how hard each is to fake, and every claim carries the evidence behind it.
The overnight signal is undefined below a day of observation, and its weight is redistributed rather than counted as zero: absence of evidence is not evidence of a human. Confidence grows with sample size and observation span, never with the verdict. And the standing rule — inference may raise a flag, but only a declaration or an attestation by the operator can lower a rating.
How much capital a strategy could absorb before its own market impact erodes the edge. Two limits are computed and the tighter one wins: the ratio of realised edge to realised cost, and a 10% ceiling on the share of venue daily volume any strategy is assumed able to take. Both describe a trade size, which is then scaled to capital using the strategy’s own ratio of capital to trade size.
Three bounds keep the result honest. A measured per-trade edge above 100bps is clipped, because at that level it is a directional move that happened to go the right way rather than repeatable alpha, and squaring it would turn one lucky month into a billion-dollar claim. The result is capped at 50× current capital, beyond which it is unfalsifiable. And where either cap binds, the figure is published as a floor rather than an estimate.
A headline return is a claim about skill; what it usually contains is a market move minus costs nobody itemised. We decompose it into gross realised profit, trading fees, funding paid or received, and unrealised marks kept separate because they are not money until closed. Fees are exact per fill and funding exact per position.
Slippage is not separated. Without a book snapshot at the moment of each fill it cannot be measured, so it remains inside gross and is declared rather than estimated. An invented slippage line would be worse than an honest omission.
Exposure is compared across vaults on signed positions, so hedged opposites score as opposites rather than as similar. Instruments are flagged only when both conditions hold at once: a material share of venue open interest, and heavily one-sided positioning. Either alone is survivable; together they unwind as a group.
No crowding figure is published without a coverage ratio against venue open interest. A cluster size with no denominator is a guess wearing a suit. Book clusters use single-linkage grouping, so a cluster’s average similarity can sit below the joining threshold — transparent and arguable, which we prefer to a clever method nobody can interrogate.
Of the 471 agent-managed vaults we track, 178 carry a risk score — 99.80% of the $1.27B under them. Scope is the agent-managed set only; the vaults we carry for comparison were never in it, and counting them here would invent a gap.
The largest thing we have not scored is FC Genesis - Quantum on Hyperliquid, at $2.16M. Most of the rest are venue-side vaults with no contract for us to read. A further 1 holds no TVL figure we trust, counted in neither half of that ratio rather than folded into the denominator.
All 415,722 registrations the registries have issued. Checked against the registries themselves rather than asserted: each issues its agent identifiers from a counter that only goes up, so the largest identifier we have seen is a floor on how many exist, and the difference is what we are missing.
| Chain | Registrations held | Highest identifier | Not read | Share |
|---|---|---|---|---|
| Base | 68,118 | 68,118 | 0 | 100.0% |
| Binance Smart Chain | 296,531 | 296,531 | 0 | 100.0% |
| Ethereum | 50,445 | 50,445 | 0 | 100.0% |
| Polygon | 628 | 628 | 0 | 100.0% |
Deposits and withdrawals are read forward from a stored cursor, and where there was none the reader began a week before its first run. So for most platforms the history starts when we started, not when the vaults did. We hold no deposit or withdrawal history at all for 22 vaults on 6 chains. A further 261 do not implement ERC-4626, so the deposit and withdrawal events this reader looks for do not exist on them. A further 227 existed before we began reading their flows — up to 21 months earlier on Morpho (base).
| Platform | Vaults | Flows from | Oldest vault | Predating our flows | Whose limit |
|---|---|---|---|---|---|
| Morpho (polygon) | 3 | nothing held | 2025-02-12 | — | nothing read yet — cause not established |
| Morpho (world) | 4 | nothing held | 2025-04-03 | — | nothing read yet — cause not established |
| Morpho (optimism) | 1 | nothing held | 2025-10-08 | — | nothing read yet — cause not established |
| Euler (bnb) | 10 | nothing held | 2025-04-15 | — | nothing read yet — cause not established |
| Morpho (katana) | 3 | nothing held | 2025-06-23 | — | nothing read yet — cause not established |
| Morpho (unichain) | 1 | nothing held | 2025-05-20 | — | nothing read yet — cause not established |
| Morpho (base) | 35 | 2026-02-25 | 2024-05-31 | 35 | ours — 21 months unread |
| Euler (unichain) | 7 | 2026-08-07 | 2025-05-02 | 7 | ours — 15 months unread |
| Euler (base) | 22 | 2026-02-25 | 2024-11-27 | 19 | ours — 15 months unread |
| Morpho (hyperevm) | 12 | 2026-04-20 | 2025-04-24 | 12 | ours — 12 months unread |
| Euler (linea) | 5 | 2026-07-26 | 2025-08-11 | 5 | ours — 12 months unread |
| Euler (hyperevm) | 12 | 2026-04-20 | 2025-12-11 | 12 | ours — 4 months unread |
| Morpho (monad) | 1 | 2025-12-01 | 2025-11-26 | 1 | ours — 0 months unread |
| Morpho (ethereum) | 84 | 2024-01-05 | 2024-01-03 | 54 | ours — 0 months unread |
| Euler (arbitrum) | 11 | 2025-06-25 | 2025-06-24 | 7 | ours — 0 months unread |
| Euler (monad) | 26 | 2025-11-25 | 2025-11-24 | 25 | ours — 0 months unread |
| Euler (ethereum) | 71 | 2024-08-18 | 2024-08-18 | 50 | ours — 0 months unread |
| Krystal Auto-Farm Vault (ethereum) | 15 | nothing held | 2025-05-17 | — | not ERC-4626 — emits neither event we read |
| Krystal Auto-Farm Vault (base) | 88 | nothing held | 2025-04-09 | — | not ERC-4626 — emits neither event we read |
| Krystal Auto-Farm Vault (arbitrum) | 16 | nothing held | 2025-05-19 | — | not ERC-4626 — emits neither event we read |
| Hyperliquid (hyperliquid) | 306 | 2023-05-05 | 2023-02-26 | — | the venue’s ledger |
| Krystal Auto-Farm Vault (bnb) | 132 | nothing held | 2025-04-30 | — | not ERC-4626 — emits neither event we read |
| Euler (sonic) | 11 | 2026-08-06 | 2025-02-03 | — | the venue’s ledger |
| Euler (avalanche) | 15 | 2026-08-11 | 2025-03-24 | — | the venue’s ledger |
| Morpho (arbitrum) | 10 | 2025-05-12 | 2025-05-08 | — | the venue’s ledger |
| Krystal Auto-Farm Vault (polygon) | 10 | nothing held | 2025-05-06 | — | not ERC-4626 — emits neither event we read |
Hyperliquid’s floor really is the venue’s — its flows come from the venue’s own ledger and begin when that does. The others are ours. Any figure built from flows — net flows, depositor counts, exit behaviour — is bounded by the date in that column and not by the life of the vault.
Ratings are free and public. There is no paid placement, no sponsored ranking and no advertising. We do not trade on our own data.