# Lagoon Finance

> The Infrastructure for On-Chain Asset Management

Lagoon provides the complete stack for onchain asset management, combining proven ERC-7540 vault technology with institutional-grade fund administration tooling. It enables any digital asset strategy to become a tokenized product: scalable, composable, and accessible to LPs.

## Stats
- **Total Value Locked**: $-
- **Fees Distributed**: $2.6M+
- **Active Vaults**: 120+
- **Unique Addresses**: 14,000+
- **Chains Supported**: 18+

## Strategy Types
- Delta-Neutral
- RWA
- Yield Farming
- Lending
- Staking
- Arbitrage

## Vault Roles
### Investors
Deposit assets and receive vault shares representing their position.

Capabilities:
- Request deposits and redemptions
- Hold ERC-20 vault shares
- Monitor performance
- Discover and evaluate strategies

### Valuation Manager
Proposes Net Asset Value updates based on portfolio valuation.

Capabilities:
- Select your preferred NAV methodology
- Calculate portfolio valuation
- Propose NAV updates based on portfolio valuation
- Submit NAV proposal directly on-chain

### Curator
Reviews and accepts valuations to trigger share settlement.

Capabilities:
- Accept or reject NAV proposals
- Settle pending deposits/redemptions
- Oversee vault operations
- Manage settlement timing

### Vault Admin
Configures vault parameters and manages access controls.

Capabilities:
- Set fee structures
- Set up allowlist
- Manage role permissions
- Update vault settings

## Solutions
### Valuation
Automate NAV calculations or appoint Lagoon as your auditor.

Features:
- Deploy flexible valuation methodologies
- Support any strategy
- Track valuations on-demand

### Custody & Permissions
Let Lagoon be your permission manager.

Features:
- Secure assets via Multi-sig and MPC support
- Integrate permissions with Zodiac
- Enforce permissions with Fordefi
- Enforce KYC/KYB gating for vaults

### Reporting
Generate comprehensive data for admins, investors, and compliance.

Features:
- Automate monthly factsheets
- Export tax and compliance reports
- Issue detailed investor statements

### Whitelabel Solution
Accelerate time-to-market and reduce costs while you focus on strategy.

Features:
- Showcase your vaults on a custom interface
- Customize branding and UI
- Host on your own domain

## FAQ
### What is Lagoon?
Lagoon is the preferred destination for Curators to launch, manage, and scale on-chain yield products. Whether on behalf of DAOs, DeFi protocols, Ecosystems or directly for themselves and their users.

### How do we differentiate ourselves from other vault providers?
Not all vaults are created equal. Many DeFi protocols that use the word "vault" refer to a single use-case: lending, staking, CDP or custom strategy.

Lagoon provides open, general-purpose, secure vault infrastructure to build and scale on-chain yield products.

What makes it powerful:
• Permissionless deployment via the Factory contract on most EVM chains;
• Fully compatible with any wallet solution, custody setup, and permissions layer;
• Support for any strategy implementation (on- and off-chain);
• Separation of powers between the valuation provider, curator, and vault admin;
• Built-in fee logic with High-Water Mark (HWM) tracking;
• Asynchronous deposits and withdrawals (sync mode available for deposits).

Lagoon provides a unified framework for vault lifecycle management, from inception to closure — and everything in between.

### What is a Lagoon Vault?
This refers to our very own Vault standard, emphasizing security and flexibility.

A Lagoon Vault is made of:
• 1 Vault's ERC-7540 smart contract (asynchronous vault standard);
• 1 ERC-20 token distributed to depositors and burned upon withdrawals;
• 1 Silo contract which contains pending deposits and withdrawals.

A Lagoon Vault must be connected to:
• 1 Management hub per blockchain (Multisig or MPC solution).

Appropriate permissions should be implemented to enforce the curator's mandate.

By design, the protocol turns every asset into a yield bearing opportunity.

Note: ERC-7540 adds asynchronous flows, extending ERC-4626 capacities. It is also possible to enable synchronous deposits.

### How much does it cost to launch a vault?
You pay for smart contract deployment.

Starting November 2025, Lagoon will take 10% of fees collected by curators at each settlement across all vaults and route them to the protocol treasury.

This mechanism does not apply to vaults without active fees.

### Is the vault deployment permissionless?
You can write directly to the Factory contract through supported block explorers. An onboarding guide is available in our docs, and we're working to make this process available directly in our web app.

### Can an existing investment setup be migrated to Lagoon?
Absolutely! The transition begins with a special procedure at vault creation, where shares are minted and distributed to initial stakeholders on a pro rata basis. A full migration guide is available in the Lagoon documentation.

### Are deposits and withdrawals instant?
Lagoon vaults follow the ERC-7540 standard, which introduces asynchronous deposits and withdrawals.

In practical terms, you must first submit a request and then wait for the curator's next settlement to enter or exit the vault. Frequency is determined by the curator, with the ability to activate synchronous deposits if needed.

### Which opportunities come with holding shares?
Each vault issues a unique ERC-20 yield-bearing token, whose value fluctuates over time, based on price-per-share updates. It keeps the books in order and tracks users' balances through a mint-or-burn mechanism.

By design, shares are composable. However, this is the vault curator's responsibility to build the relevant integrations with other protocols or seed token liquidity.

## Links
- App: https://app.lagoon.finance
- Docs: https://docs.lagoon.finance
- API (GraphQL): https://api.lagoon.finance/query
- GitHub: https://github.com/hopperlabsxyz/lagoon-v0
- DefiLlama: https://defillama.com/protocol/lagoon
- Twitter: https://x.com/lagoon_finance
- LinkedIn: https://www.linkedin.com/company/lagoon-finance/posts/?feedView=all

## Discoverability
- llms.txt: https://lagoon.finance/llms.txt
- A2A agent card: https://lagoon.finance/.well-known/agent-card.json
- MCP server card: https://lagoon.finance/.well-known/mcp/server-card.json
- RSS feed: https://lagoon.finance/feed.xml
- JSON feed: https://lagoon.finance/feed.json

# Blog

## Corporate bonds onchain: launching a tokenized bond fund

> Tokenized corporate bonds passed $1.7B onchain in 2026. How asset managers use ERC-7540 vaults to launch compliant, tokenized bond funds.

- URL: https://lagoon.finance/blog/tokenized-corporate-bonds
- Date: 2026-06-18
- Author: Lagoon
- Category: RWA

<Callout>
Corporate debt is moving onchain through two distinct routes: native digital bonds issued directly by borrowers like Siemens, and tokenized bond funds that wrap credit exposure into onchain shares. Lagoon vaults serve the second route, giving asset managers the fund wrapper to launch a compliant, tokenized bond or credit product.
</Callout>

## Introduction

Asset managers keep asking the same question: can a corporate bond live onchain, and if so, how? The answer has two parts, and confusing them leads to the wrong conclusions.

At Lagoon, we build onchain asset management infrastructure across 18+ chains, with more than 120 active vaults. That vantage point shows us how managers actually bring fixed income onchain, and where the real infrastructure gaps sit.

Two facts frame the moment. Siemens settled a 300 million euro digital bond in central bank money in minutes rather than days. And tokenized corporate bonds passed $1.77 billion onchain in early 2026, one of six asset categories to clear the $1 billion mark. Corporate debt is going onchain. The open question is which route fits your product.

## Two ways a bond goes onchain

The phrase "bond onchain" hides two very different structures, and the infrastructure for each is different.

**Native digital bond issuance** is when the borrower issues its debt directly as a token. The issuer creates the security, investors hold it, and the token is the bond. Siemens did this with a 300 million euro one-year bond in September 2024, issued under Germany's Electronic Securities Act (eWpG) and settled in central bank money through the Bundesbank's trigger solution. The [European Investment Bank](https://www.eib.org/en/press/all/2021-141-european-investment-bank-eib-issues-its-first-ever-digital-bond-on-a-public-blockchain) (EIB) has issued digital bonds in euro and sterling across public and permissioned chains. This route relies on a securities issuance platform, a registrar, and a settlement venue. It is not what a vault does.

**A tokenized bond fund** is a wrapper. A manager pools capital, buys bonds or credit, and issues fund shares to investors. The shares are tokens; the bonds sit inside the fund. This is how Apollo's tokenized credit fund (ACRED) and BlackRock's BUIDL reach onchain investors. A vault is exactly this kind of wrapper.

![Native digital bond issuance versus a tokenized bond fund](https://storage.googleapis.com/lagoon-blog-media/blog/tokenized-corporate-bonds/fig1-two-ways-bond-onchain.webp?v=2)

The distinction matters because the two are different activities. Issuing a bond is a borrowing event for one entity. Launching a bond fund is an asset management event open to many investors. Lagoon vaults serve the second.

## Corporate debt is moving onchain

The total value of tokenized real-world assets (RWAs) reached roughly $32.5 billion in June 2026, according to [rwa.xyz](https://app.rwa.xyz/). Tokenized U.S. Treasuries lead that figure (for the broader picture, see [the state of onchain vaults](/blog/state-of-onchain-vaults-2026)), but corporate credit is the fastest-moving frontier.

![The 2026 onchain corporate debt landscape](https://storage.googleapis.com/lagoon-blog-media/blog/tokenized-corporate-bonds/fig2-onchain-corporate-debt-2026.webp?v=2)

Three data points define the trend. First, tokenized corporate bonds stood at about $1.77 billion onchain in early 2026, small against a global corporate bond market measured in the tens of trillions, but growing from near zero. Second, [McKinsey](https://www.mckinsey.com/industries/financial-services/our-insights/from-ripples-to-waves-the-transformational-power-of-tokenizing-assets) counts more than $10 billion in tokenized bonds issued over the past decade, and in its base case projects bonds at around $0.3 trillion within a roughly $2 trillion tokenized market by 2030. Third, the fund route is scaling fastest: Apollo's ACRED grew past $100 million and now circulates across six chains as collateral in decentralized finance (DeFi), while BlackRock's BUIDL is the largest tokenized fund at about $2.5 billion.

Issuers and allocators are both moving. In December 2025, JPMorgan arranged a $50 million tokenized commercial paper issuance for Galaxy Digital on Solana, bought by Coinbase and Franklin Templeton. Each transaction normalizes the next.

What the data shows is demand outpacing tooling. Treasuries tokenized first because they are simple and liquid. Corporate credit is harder: it needs independent valuation, investor eligibility checks, and orderly redemptions. That is the infrastructure gap a vault fills.

## Launching a tokenized bond fund with a vault

A Lagoon vault is an [ERC-7540](/blog/erc-7540-explained) contract, the asynchronous extension of the ERC-4626 tokenized vault standard. Asynchronous settlement matters for credit. Deposits and redemptions follow a request-then-claim pattern, and shares are priced at settlement (forward pricing) rather than at the moment of request. That mirrors how a traditional fund strikes a net asset value (NAV) and processes subscriptions.

![Tokenized bond fund lifecycle on a vault](https://storage.googleapis.com/lagoon-blog-media/blog/tokenized-corporate-bonds/fig3-tokenized-bond-fund-lifecycle.webp?v=2)

A manager launches a tokenized bond fund in a few steps. The vault is deployed permissionlessly from the [Vault Factory](/blog/deploy-permissionless-vault). [Four governance roles](/blog/vault-governance-roles) are then assigned: the vault administrator sets parameters, the curator runs the strategy, the valuation provider posts NAV, and the whitelist manager controls who can invest. A third-party service independent from the manager calculates the share price, which keeps valuation objective for an asset class that does not trade continuously.

From there the fund operates. Whitelisted investors, cleared through know-your-customer and know-your-business (KYC and KYB) checks, subscribe. The curator allocates into tokenized bonds or a credit portfolio, and coupons and yield accrue to NAV. Redemptions settle asynchronously, which gives the manager time to free up underlying positions. Custody stays flexible: a manager can use a Safe multisig, an MPC (multi-party computation) wallet such as Fireblocks or Fordefi, or a hybrid of both.

## Compliance and the institutional reality

Tokenization changes the wrapper, not the legal nature of the asset. In January 2026, the U.S. Securities and Exchange Commission (SEC) [stated plainly](https://www.sec.gov/newsroom/speeches-statements/corp-fin-statement-tokenized-securities-012826-statement-tokenized-securities) that tokenized securities are still securities, echoing Commissioner Hester Peirce's point that blockchain is "enchanting, but not magical." Existing registration and exemption rules apply.

Europe reaches a parallel position through different instruments. The Markets in Crypto-Assets regulation (MiCA) explicitly excludes tokenized financial instruments; those fall under existing securities law (MiFID II) and the [EU DLT Pilot Regime](https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/dlt-pilot-regime), which since March 2023 has let tokenized bonds and fund units trade and settle under targeted exemptions.

| | United States | European Union |
|---|---|---|
| Core principle | Tokenized securities are still securities (SEC, Jan 2026) | Tokenized financial instruments sit outside MiCA |
| Governing framework | Securities Act registration or an exemption | MiFID II plus the EU DLT Pilot Regime (since March 2023) |
| Bond-specific note | Same disclosure path as a traditional issue | Pilot covers tokenized bonds within set issuance thresholds |

For a manager, the practical implication is agency, not restriction. A regulated manager can choose to launch a tokenized bond fund in the jurisdiction that fits its mandate, for any strategy and any underlying asset, and use the vault's role-based permissions and whitelisting to meet the eligibility and reporting obligations that jurisdiction imposes. Good infrastructure makes those obligations easier to fulfil; it does not decide them for you.

<KeyTakeaways>
- **Two routes, one phrase.** "Bond onchain" means either native digital issuance (the borrower mints the security) or a tokenized bond fund (a manager wraps credit into shares). Vaults serve the second.
- **The trend is real and sourced.** Tokenized corporate bonds reached about $1.77B onchain in early 2026, inside a roughly $32.5B real-world asset market, with fund vehicles like Apollo ACRED and BlackRock BUIDL scaling fastest.
- **A vault is the fund wrapper.** An ERC-7540 vault provides asynchronous subscription and redemption, forward-priced net asset value (NAV), four governance roles, and independent valuation, the machinery a bond fund needs.
- **Compliance follows the asset, not the token.** US and EU regulators treat tokenized bonds as securities; a manager fulfils its obligations in its chosen jurisdiction using whitelisting and role-based controls.
- **Infrastructure is the gap.** Treasuries tokenized first; corporate credit needs valuation, eligibility, and redemption logic, which is exactly what vault infrastructure supplies.
</KeyTakeaways>

<CTA href="https://app.lagoon.finance">Bring a credit strategy onchain: deploy an ERC-7540 vault and wrap a tokenized bond fund with independent valuation, KYC whitelisting, and asynchronous redemptions built in.</CTA>

---

## More than vaults: Lagoon's open data layer

> Lagoon vaults are onchain. On top sits a data layer: an SDK that reads contracts directly, a public GraphQL API with no key, and an MCP server.

- URL: https://lagoon.finance/blog/lagoon-api-sdk-mcp
- Date: 2026-05-28
- Author: Lagoon
- Category: Product

<Callout>
Lagoon vaults are ERC-7540 contracts onchain: that is the source of truth. On top sits a data layer with three ways to read it: an SDK that reads the contracts directly, a public GraphQL API (no key) that indexes and enriches them, and a Model Context Protocol (MCP) server that answers in plain English.
</Callout>

## Introduction

Ask most people what Lagoon is and they will say vaults: [ERC-7540 contracts](/blog/erc-7540-explained) that hold deposits and run a strategy. That is the foundation, and it is deliberately onchain. Balances, shares, fees, and valuations live in the contracts themselves, which makes the vault the source of truth. Nothing about a Lagoon vault depends on a server staying up.

On top of that foundation, we built a data layer. Across 18+ chains and 120+ vaults, reading every contract by hand is not how anyone wants to work, so Lagoon offers three ways into the same data, each at a different level. One reads the contracts directly. One indexes and enriches them. One answers questions about them in plain English. You pick the level that matches how you build.

## A data layer on top of the vaults

A Lagoon vault is a smart contract, so the data about it ultimately comes from the chain. The question is how you get at it. Reading raw contract storage works, but it is low-level, and some of the most useful views are not a single onchain read. A vault's performance over time, where its assets are actually deployed, an address's positions across every chain: those have to be indexed and computed.

So the data layer has three surfaces, stacked from closest to the chain to furthest from it.

![The vaults are onchain; a data layer sits on top, with the SDK reading contracts directly, the API indexing the chain, and the MCP server reading the API](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-api-sdk-mcp/fig1-data-layer-architecture.webp?v=2)

_Figure 1: the vaults are the onchain foundation. The SDK reads them directly, the API indexes and enriches them, and the MCP server reads the API._

Because all three trace back to the same onchain vaults, the numbers reconcile. The state a developer reads from a contract, the history the API computes, and the answer an AI assistant gives all derive from the same source.

## Read the vaults directly: the SDK

Closest to the chain is the SDK, an [open-source TypeScript library](https://github.com/hopperlabsxyz/sdk-v0) published on npm (the MIT-licensed `@lagoon-protocol` packages, built on [viem](https://viem.sh)). It does not call a Lagoon server at all. It reads the vault contracts directly onchain and hands back typed objects.

Fetching a vault's complete state is a single call. Under the hood the SDK uses a stateless query contract to batch the reads, so one request returns the whole picture:

```ts
import { Vault } from "@lagoon-protocol/v0-core";

const vault = await Vault.fetch(vaultAddress, client);
vault.totalAssets; // balances and share supply
vault.feeRates; // management and performance rates
```

Because it talks to the chain and nothing else, the data is as live and as trustless as the contract itself. The SDK mirrors the Lagoon contracts closely, so the vault, fee, and [governance](/blog/vault-governance-roles) concepts you find onchain are the ones you find in the types. It also simulates fees and price per share locally, so you can show a user exactly what they will pay before they sign. Our own backend reads vaults through this same SDK: it is the foundation the rest of the data layer is built on.

None of it needs permission. Run `npm install` and you are reading live vault data straight from the chain.

## Indexed and enriched: the public API

Reading a contract gives you its current state. It does not give you last month's performance, a breakdown of where a vault's assets are deployed, or one investor's positions across every chain at once. Those views require indexing onchain history and pulling in data from the wider DeFi ecosystem. That is what the API does.

Lagoon runs a backend that indexes vault events across every supported chain, computes analytics on top, and serves the result from a single public GraphQL endpoint at `api.lagoon.finance/query`. It is public: no key, no sign-up.

The simplest possible request asks for the protocol's total value locked (TVL) across every vault and chain:

```graphql
{
  getGlobalTVL
}
```

That one line returns a single number, the same aggregate that feeds the headline figure on the site. Because the schema is introspectable, you do not have to guess what else is there. Point any GraphQL client at the endpoint and it lists every type and field. What is on offer is the enriched, indexed view that a single contract read cannot give you:

| Data         | What the API adds on top of the chain                              |
| ------------ | ------------------------------------------------------------------ |
| Performance  | Weekly, monthly, and annualized APR; net asset value (NAV) over time |
| Composition  | Where each vault's assets sit, protocol by protocol, token by token |
| Portfolios   | One address's positions across every vault and chain, in one query |
| Transactions | The full indexed deposit, redemption, and settlement history       |
| Reference    | Chains, assets, curators, and protocol-wide aggregates             |

The composition data is worth calling out, because it is the kind of transparency [traditional fund reporting](/blog/onchain-vaults-vs-traditional-funds) cannot match. The API breaks each vault's balance down into the underlying protocols and token positions it holds, each with a dollar value and a share of the whole. You can see exactly where the money is, live.

There is no key to leak and no quota to request. The endpoint caps query depth and complexity so a single request cannot overload it, but for most dashboards, indexers, and research scripts that is the only constraint you will meet.

## Plain English: the MCP server

The SDK and the API both assume you write code. Plenty of the people who care about vault data do not, and should not have to: fund managers running due diligence, analysts comparing strategies, allocators monitoring positions. The MCP server is for them.

Lagoon publishes an [MCP server](https://github.com/hopperlabsxyz/lagoon-mcp), also open-source on npm. The Model Context Protocol is the emerging standard for connecting AI assistants to live data and tools, supported by clients like Claude and Cursor. It sits on top of the public API: connect it once and your assistant can answer questions about any vault in everyday language, fetching real data through the API instead of guessing.

The questions look like the ones you would actually ask:

- "Find every USDC vault on Arbitrum with more than $1M total value locked."
- "Compare these three vaults and tell me which has the best risk-adjusted return."
- "How has this vault performed over the last 30 days, and where are its assets allocated?"

Behind that conversational surface, the server calls the same GraphQL API as everything else, then adds analysis on top. It can score a vault's risk across several factors, compare a set of vaults side by side, or export a vault's transaction history to a spreadsheet for accounting. A fund manager can run a first pass of due diligence, or pull the numbers for a monthly report, without filing a single engineering ticket.

It stays strictly informational. Every answer the server returns carries a reminder that it is data, not financial advice.

## Which surface should you reach for?

The three surfaces are levels, not competing options, and most teams end up using more than one. Reach for the one that matches the job in front of you: the SDK when you are building an app and want to read or act on a vault directly, the API when you need history or a cross-chain view, the MCP server when you would rather ask a question than write a query.

![Three ways to read the same vaults: the SDK reads onchain, the API serves indexed GraphQL, the MCP server answers in plain English](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-api-sdk-mcp/fig2-three-ways-to-read.webp?v=3)

_Figure 2: the same vaults, read three ways. The right level depends on whether you write TypeScript, GraphQL, or plain English._

<KeyTakeaways>
- **Vaults are the foundation:** Lagoon vaults are ERC-7540 contracts onchain, where balances, shares, and valuations live. The data layer sits on top of them.
- **Read the chain directly:** the open-source TypeScript SDK (built on viem) reads vault contracts straight onchain and returns typed objects, with local fee simulation. Our own backend is built on it.
- **Indexed and enriched:** the public GraphQL API at `api.lagoon.finance/query` adds what a single contract read cannot, including performance history, composition, and cross-chain portfolios, with no key.
- **Plain English:** the MCP server sits on the API so fund managers and AI assistants can query and compare vaults conversationally, with no code.
- **An ecosystem, not just contracts:** the data layer is what turns Lagoon vaults into something you can build products, dashboards, and reports on top of.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance">Explore the Lagoon docs to start building on the SDK, API, and MCP, or query api.lagoon.finance/query directly to see the data for yourself.</CTA>

## Going further

- **The code:** the [Lagoon SDK](https://github.com/hopperlabsxyz/sdk-v0) and the [Lagoon MCP server](https://github.com/hopperlabsxyz/lagoon-mcp), both open source on GitHub.
- [Lagoon v0.6 is live: security, autonomy, and modularity](/blog/lagoon-smart-contracts-v0-6-preview): the latest contract capabilities the data layer reads from.
- [Vault governance roles: who does what in an onchain fund](/blog/vault-governance-roles): the four-role model exposed through every surface.
- [What is onchain asset management?](/blog/what-is-onchain-asset-management): the bigger picture the vaults and data layer fit into.

---

## Lagoon v0.6 is live: security, autonomy, and modularity

> Lagoon v0.6 ships PPS guardrails, a Security Council, dual access modes, entry/exit fee caps, and seven more capabilities. Live and audited.

- URL: https://lagoon.finance/blog/lagoon-smart-contracts-v0-6-preview
- Date: 2026-05-19
- Author: Lagoon
- Category: Product

<Callout>
  Lagoon v0.6 is live and audited, shaped by feedback from the managers running
  on Lagoon today. Eleven new capabilities prioritize deeper security, manager
  autonomy and modularity. Full app integration is rolling out.
</Callout>

## Introduction

Across 120+ vaults deployed on Lagoon and 18+ EVM chains, the patterns of what managers ask for have become clear. They want finer monetization controls. Access that adapts to their jurisdiction. Safeguards that compose rather than freeze the vault when something goes wrong.

v0.6 is our response. Eleven new features, grouped into four areas: fees, access, risk, and vault lifecycle. The contracts are live and [audited](https://docs.lagoon.finance/resources/audits), build on [ERC-7540](/blog/erc-7540-explained), and can be used today via any blockchain explorer. The full app integration is rolling out and tracked on the [version history page](https://docs.lagoon.finance/resources/version-history). Each capability is optional, and each was prioritized because managers asked for it.

![Side-by-side comparison of Lagoon smart contracts v0.5.1 baseline (management and performance fees, single whitelist, four governance roles, sync and async flows) and the v0.6 additions grouped into four buckets: fees, access, risk, and lifecycle](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-smart-contracts-v0-6-preview/fig1-v05-vs-v06-capabilities.webp?v=9)

_Figure 1: v0.5.1 baseline versus v0.6 additions. Eleven new capabilities across four areas._

## Monetization that fits the strategy

Different strategies need different fee models. A regulated yield fund, a leveraged trading vault, and a perpetual real-world asset (RWA) strategy do not share a monetization shape. v0.6 widens the manager's toolkit and tightens investor guarantees at the same time. The v0.5.1 fee structure (management and performance) remains the baseline.

- **Entry and exit fees** are new in v0.6, capped at 2% each in the contract. Useful for discouraging short-term flows on strategies that need a minimum holding period.
- **Haircut fee**, capped at 20%, applies only to synchronous redemption and is burned from the redeemer's own shares. A frictional cost that protects long-term holders, with no payment to the manager.
- **Averaged AUM accrual** for the management fee. v0.6 takes the average of start-of-period and end-of-period total assets instead of the single snapshot at settlement, which is fairer on vaults with volatile flows.
- **Cooldown delay removed for all fee updates.** v0.5.1 gated every fee change behind a cooldown window. v0.6 drops the cooldown entirely; updates take effect immediately across all fee types. Investor protection moves into the contract's hard caps and the monotonic constraint below, rather than a timing buffer.
- **Entry and exit rates can only decrease.** The contract enforces a monotonic constraint on these two rates specifically, so the entry and exit cost an investor paid in at cannot rise after deposit.

The two-sided design (wider toolkit, harder caps) is the point. Managers tune monetization to their strategy. Investors get an onchain guarantee that entry and exit costs cannot drift up after they deposit.

## Access that fits the jurisdiction

A regulated KYC fund and a permissionless DeFi yield are different products. v0.5.1 forced both into a single access primitive. v0.6 turns access into a configurable layer that adapts to the manager's regulatory framework, without redeploying the contract.

![Diagram of the v0.6 access control architecture: a vault runs in either whitelist mode (closed-by-default, KYC-friendly) or blacklist mode (open-by-default, sanctions-screening-friendly), with switchAccessMode toggling between them. A compliance features layer shows the Operator role and the redeem-on-behalf capability, both available when the manager grants permission](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-smart-contracts-v0-6-preview/fig2-access-control-modes.webp?v=3)

_Figure 2: Access control in v0.6. One mode at a time. Operators with the right role can act on behalf of KYC'd users where the manager has granted permission._

- **Dual modes.** Every vault runs in whitelist (closed-by-default) or blacklist (open-by-default) mode. Mutually exclusive. Switchable atomically via `switchAccessMode()`.
- **Sync/async modes.** Configure `SyncMode` to `Both`, `SyncDeposit`, `SyncRedeem`, or `None`. The manager picks which flows are synchronous and which are forward-priced async: a high-velocity strategy can keep both sync, a regulated fund can lock everything to async, and anything in between is one parameter away.
- **External sanctions oracle.** Optional integration with an onchain sanctions list (e.g. Chainalysis) screens deposits in either mode, including permissionless vaults.
- **Operator role for KYC'd integrators.** A privileged role that custodians, prime brokers, and integrating protocols can use to deposit and redeem on behalf of users they have already KYC'd, without re-onboarding each user into the vault's access list.
- **Redeem on behalf of users.** Operators with the right permission can call `redeem()` on behalf of a user via the controller argument. Useful for legal holds, trustee accounts, and orderly wind-downs without involving the user in every transaction.

The same contract supports regulated funds and permissionless strategies. The manager chooses the model; the protocol does not gate the choice.

## Defense in depth, by design

Mispriced settlement is the single biggest tail risk in async vaults. v0.5.1 leaves price safety to off-chain controls. v0.6 brings it into the contract, with narrow-scope roles so no single key controls both funds and safety.

![Three-column grid showing v0.6 risk controls paired with the threats they address: price-per-share guardrails against valuation errors, Security Council against slow incident response when only broadly-scoped roles can intervene, and vault capacity cap against strategy over-capacity](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-smart-contracts-v0-6-preview/fig3-risk-management-layers.webp?v=3)

_Figure 3: Three risk controls, three threat models. Managers compose the combination that fits their strategy._

- **Price per share (PPS) guardrails.** Annual upper and lower bounds, configured in basis points and checked at every settlement. Out-of-range valuations are rejected before they touch share supply.
- **Security Council.** A new role, scoped only to the guardrails. It can update bounds and override a non-compliant valuation. It cannot move funds, change fees, or grant access. The narrow scope is the point: managers can staff it with independent parties without surrendering operational control.
- **Vault capacity cap (`maxCap`).** Hard per-vault deposit ceiling, enforced at deposit time. Prevents over-concentration and supports fund-of-fund exposure limits.

These compose. A short-duration trading vault may run tight PPS bounds and lean on the Security Council as a circuit breaker. A long-duration RWA vault may rely on the capacity cap. The combination is the manager's call; the contract enforces it.

## Operational continuity

Vaults are long-lived contracts. Drawdowns happen. Fund families consolidate. Custody keys rotate. v0.6 adds the lifecycle moves v0.5.1 missed, without forcing a redeployment.

- **High water mark (HWM) reset.** The vault administrator enables an `allowHighWaterMarkReset` flag at deployment. With it, the Safe can re-anchor the HWM to current price per share after a drawdown. The flag is visible to investors before they deposit, so the manager's policy is public.
- **Clean migrations.** New vaults can initialize with non-zero `initialTotalAssets`, with the Safe receiving pre-minted shares. Any v0.5.1 vault can be migrated onto v0.6 without liquidating the strategy. The upgraded vault starts at 0% entry and exit fees, preserving the v0.5.1 fee structure for the inherited investor base; the monotonic constraint then prevents those rates from being raised after the fact.
- **Post-deploy metadata.** The vault owner can update the ERC-20 name and symbol after launch. Rebranding no longer requires a redeploy.
- **Post-deploy Safe rotation.** The vault owner can rotate the Safe address — the role that holds custody of vault assets — without redeploying the contract. Custody key migrations, signer changes, and Safe upgrades become a single transaction.
- **Redeem cancellation.** Investors can cancel a pending redeem request before settlement and recover their shares, reducing the lock-up risk that institutional allocators flag as a constraint on async vaults.

<KeyTakeaways>
- **Deeper security:** Price-per-share guardrails, a single-purpose Security Council, capacity caps without enlarging any role's scope.
- **Manager autonomy:** Granular fees, dual access modes, post-deploy metadata and Safe rotation, and HWM reset put strategy parameters in the manager's hands within hard, investor-friendly caps.
- **Strategy modularity:** The same contract supports KYC funds and permissionless strategies; the `SyncMode` parameter switches between sync, async, or mixed deposit/redeem; no redeploy required to change shape.
- **Non-disruptive rollout:** v0.6 applies to new deployments. v0.5.1 vaults continue unchanged and can opt in for the upgrade.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance/resources/version-history">
  Read the v0.6.0 deployment details on the Lagoon version history page. The
  contracts are live today; the app rollout is tracked there.
</CTA>

## Going further

- [ERC-7540 Explained: Async Vaults for Real-World Assets](/blog/erc-7540-explained): the underlying standard that v0.6 builds on.
- [Lagoon's fee structure: the four fee types, explained](/blog/lagoon-fee-structure): the management, performance, and protocol fee mechanics that v0.6 builds on.
- [Vault Governance Roles: Who Does What in an Onchain Fund](/blog/vault-governance-roles): the four-role model v0.6 augments with the Security Council and Operator role.
- [Onchain Fund Custody: MPC, Multisig, and Safeguards](/blog/onchain-fund-custody): the custody background that informs the Operator role and redeem-on-behalf capability.

---

## Lagoon's fee structure: the four fee types, explained

> Lagoon vaults charge four fee types: management, performance, entry/exit, and protocol. The formulas, caps, and accrual mechanics, in plain terms.

- URL: https://lagoon.finance/blog/lagoon-fee-structure
- Date: 2026-05-05
- Author: Lagoon
- Category: Product

<Callout>
Lagoon vaults charge four fee types encoded onchain: management (linear, max 10% annually), performance (applied only to profits above the high-water mark, max 50%), optional entry and exit fees, and a 10% protocol fee on what the vault collects. All are paid as newly minted shares at every settlement, not by moving assets.
</Callout>

## Introduction

Fee design is where three interests meet: how much a curator earns, how much an investor trusts the vault, and how the protocol itself sustains. Get any one wrong and the other two suffer. In traditional funds, these tradeoffs sit in a limited partnership agreement and take weeks of negotiation to change. In an onchain vault they are code, specific parameters written into the smart contract at deployment and visible to every investor before they deposit.

Across more than 120 vaults deployed on Lagoon spanning 18+ EVM chains, fee configuration is one of the few knobs every curator tunes deliberately. Four fee types sit in a Lagoon vault's smart contract, each with its own accrual method and its own protocol-enforced cap.

## The four fee types at a glance

Every Lagoon [ERC-7540](/blog/erc-7540-explained) vault supports four fee categories. All of them are charged on the vault state at a single moment in time, the settlement, which is when the curator accepts a new valuation and processes pending deposit and redemption requests.

![The four fee types supported by a Lagoon vault: management, performance, entry/exit, and protocol fees, with caps and accrual method for each.](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-fee-structure/fig1-four-fee-types.webp)

*Figure 1: The four fee types, their accrual method, and their hard caps.*

| Fee Type | Charged On | Who Receives It | Hard Cap |
|---|---|---|---|
| Management | Total assets under management (AUM) | feeReceiver address | 10% per year |
| Performance | New profits above the high-water mark | feeReceiver address | 50% of new profits |
| Entry and Exit | New deposit and redemption requests | feeReceiver address | Configured per vault |
| Protocol | Fees collected by the vault | Lagoon | 30% (currently 10%) |

The first three fees are configured by the vault admin at deployment. The protocol fee is set at the protocol level and currently stands at 10%. The onchain limit is 30%, which gives room for future governance decisions without requiring any contract migration.

All four are denominated in basis points (bps), where 10,000 bps equals 100%. So a 2% annual management fee is expressed as 200 bps in the contract, a 20% performance fee is 2,000 bps, and so on.

## Management and performance: the manager's economics

Management and performance fees are the two levers that determine curator compensation. They are computed differently (linear time-based accrual vs. gain-gated accrual) and serve different purposes (covering operating costs vs. rewarding alpha), but they use the same basis-point system and accrue at the same moment.

### Management fee

Management fees are the simpler of the two. They accumulate linearly between settlements, proportional to the vault's current size and the elapsed time:

```
managementFee = (assets × rate / 10,000) × (timeElapsed / 1 year)
```

A $100M vault with a 150 bps (1.5%) management rate accrues $1.5M of management fees over a full year. If settlement happens every three months, each settlement crystallizes roughly a quarter of that amount. The longer the gap between settlements, the larger the single accrual event, but the total over any given year is unchanged.

Two operational points follow from this design. First, the cap is 10% per year, which is enforced at the contract level and cannot be exceeded regardless of vault admin intent. Second, management fees are charged even when the strategy loses money; they compensate the curator for operating infrastructure, not for producing returns.

### Performance fee and the high-water mark

Performance fees behave differently. They only apply when the current price per share exceeds the high-water mark, which is the highest price per share the vault has ever reached. This design is deliberate: managers should earn on genuine new gains, never on recovering losses they previously exposed investors to.

The formula runs only when the high-water mark is breached:

```
If pricePerShare > highWaterMark:
  profit = (pricePerShare - highWaterMark) × totalSupply
  performanceFee = (profit × rate) / 10,000
```

![A chart showing price per share fluctuating across eight settlement cycles, with the high-water mark stepping up only at new peaks. Performance fees are charged on cycles that exceed the prior HWM; no fees are charged during the recovery period.](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-fee-structure/fig2-high-water-mark.webp)

*Figure 2: The high-water mark steps up only when the price per share sets a new peak. Performance fees accrue on fee-gated cycles; recovery cycles produce no fee.*

The high-water mark is tracked onchain at every settlement. When the vault sets a new peak, the HWM is raised. When the vault dips, the HWM stays put. This is the mechanism that prevents what TradFi investors call the "fee reset" problem: in a poorly designed structure, a manager who loses 20% and then gains 20% back would charge performance fees on the recovery, effectively double-charging investors. With onchain HWM tracking, the reconciliation disputes that often stretch across quarters in a traditional fund are replaced with a deterministic smart contract read.

The protocol caps performance fees at 50% of gains above the high-water mark. In practice, the market usually lands in the 10% to 25% range, but the ceiling exists to protect investors from fee structures that would capture most of their upside.

## Entry, exit, and protocol fees

Beyond the two core levers, a Lagoon vault supports two additional fee types: optional entry/exit fees on deposits and redemptions, and a protocol-level fee that accrues to Lagoon itself.

### Entry and exit fees

Entry and exit fees are charged on the size of incoming deposits and outgoing redemption requests, collected at the same settlement that processes them. They are set to zero in most vaults but can be useful when the curator wants to discourage short-term flows, for example a strategy that relies on a minimum holding period to generate yield. Because settlement batches all pending requests together, the entry fee is applied once per settlement per investor, not per transaction.

### Protocol fee

The protocol fee is different from the other three in one important way: it is not set by the vault admin. Lagoon takes a percentage of fees that the vault itself collects, at the same settlement. The rule is simple and proportional: if a vault computes 200 shares worth of management and performance fees, and the protocol fee rate is 10%, Lagoon receives 20 of those shares. The remaining 180 go to the curator's feeReceiver address.

This is a fee on fees, not a fee on deposits or AUM directly. A vault with zero curator fees generates zero protocol revenue; the protocol only earns when the vault earns. Starting November 2025, Lagoon charges 10% of curator fees at each settlement for non-zero-fee vaults. The onchain cap is 30%, which gives Lagoon governance room to adjust the rate upward or downward without a migration.

## Settlement: how fees become shares

All four fee types resolve to a single mechanism at settlement: new shares are minted to the feeReceiver address. Nothing is sold. No assets move out of the vault. The curator's share of the fees, and Lagoon's share, both arrive as freshly minted claims on the vault's future performance.

![A three-step flow showing how fees are computed at settlement: Step 1 summarizes vault state, Step 2 calculates management and performance fees using the current formulas, Step 3 mints new shares. A bar at the bottom shows the shares split 90 to the curator, 10 to the protocol.](https://storage.googleapis.com/lagoon-blog-media/blog/lagoon-fee-structure/fig3-fee-share-mint.webp)

*Figure 3: At settlement, fees are computed from vault state, minted as new shares, and split between the curator and the protocol.*

The mechanics: at the moment of settlement, the contract reads four inputs (total assets, total supply, time elapsed since last settlement, current price per share) and uses them to compute the management fee, the performance fee, and any applicable entry/exit fees. It converts the total fee amount into a share quantity, using the current price per share as the denominator. Those shares are then minted and distributed: Lagoon's protocol cut goes to a protocol-controlled address, the remainder goes to the vault's configured feeReceiver.

Three consequences of this design are worth noting for curators and their counterparties.

1. Strategy capital is preserved. Because fee shares are minted rather than extracted, the vault's working capital never dips at settlement. A trading strategy that relies on being fully invested does not see a drawdown on fee days.
2. Fee recipients are aligned with performance. A feeReceiver that holds minted shares continues to participate in future vault upside, not just the current period. Curators who receive their fees as shares are exposed to the same net asset value (NAV) movement as their investors.
3. Audit trails are continuous. Every mint event is visible on the vault's ERC-20 ledger. Investors can reconcile fees against the contract state without waiting for a quarterly report. For institutional allocators conducting periodic verification, this replaces spreadsheet-based reconciliation with a direct query against onchain data.

The [vault governance roles](/blog/vault-governance-roles) model reinforces this: the vault administrator sets rates at deployment; the curator executes strategy and triggers settlement; the valuation provider submits NAV; the whitelist manager gates access. No single role can unilaterally redirect fees or change caps without a governance path that is itself encoded onchain.

<KeyTakeaways>
- **Four fee types, all encoded onchain:** management (linear, max 10% per year), performance (gated by high-water mark, max 50%), optional entry and exit, and a 10% protocol fee
- **High-water mark is tracked per settlement:** performance fees apply only when the price per share exceeds the previous peak, eliminating double-charging on recovery
- **Basis points are the unit:** 2% = 200 bps, 20% = 2,000 bps, all rates encoded as uint16 in the contract
- **Fees are paid as newly minted shares:** nothing leaves the vault; the curator's feeReceiver address participates in future performance
- **Protocol caps are hard:** the 10% management cap, 50% performance cap, and 30% protocol cap are enforced by the contract, not by policy
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance/vault/fees">
See the exact parameters, setter functions, and accrual flow in the Lagoon fee documentation.
</CTA>

## Going further

- [Vault Governance Roles: Who Does What in an Onchain Fund](/blog/vault-governance-roles): the four-role model that gates who can configure what, including fee rates.
- [How Onchain Vaults Cut Fund Operations from Weeks to Hours](/blog/onchain-vaults-fund-operations): the broader operational case for encoding fund administration in smart contracts.
- [ERC-7540 Explained: Async Vaults for Real-World Assets](/blog/erc-7540-explained): the settlement mechanism that all fee accrual hooks into.

---

## Multi-chain vault deployment: why 18+ networks matter

> Liquidity lives across 18+ EVM chains. Here's how vault curators deploy identical strategies across networks with zero custom integration.

- URL: https://lagoon.finance/blog/multi-chain-vault-deployment
- Date: 2026-04-08
- Author: Lagoon
- Category: DeFi

<Callout>
DeFi TVL is spread across 18+ EVM chains, with 32% of capital sitting outside Ethereum. Vault curators who deploy on a single chain leave that capital untouched. Lagoon's Vault Factory deploys identical ERC-7540 contracts across every supported network, with the same governance, fees, and audit coverage.
</Callout>

## Introduction

Ethereum still commands roughly 68% of all DeFi total value locked (TVL), but the other 32%, over $40 billion, is distributed across Layer 2s (L2s), alt-L1s, and emerging chains. Base alone holds $4.1 billion. Arbitrum sits at $2.8 billion. Avalanche, Sonic, and a growing list of newer networks each carry hundreds of millions to billions in capital.

At Lagoon, we have deployed over 800 vaults across 18+ EVM chains to date. That cross-chain visibility shows us something consistent: capital follows opportunity, and opportunity is not chain-specific. A stablecoin lending strategy that works on Ethereum works just as well on Arbitrum, often with lower gas costs and different LP demographics. The question is not whether to go multi-chain; it's how to do it without fragmenting your operational overhead.

## Where DeFi capital actually lives

The common assumption that "everything is on Ethereum" stopped being accurate in 2024. By April 2026, the distribution looks like this:

![DeFi TVL distribution by chain showing Ethereum at 68%, Base at 5.3%, Arbitrum at 3.6%, and other EVM chains making up the remainder](https://storage.googleapis.com/lagoon-blog-media/blog/multi-chain-vault-deployment/fig1-defi-tvl-by-chain.webp)

Base grew from $3.1 billion in January to a peak above $5.6 billion in October 2025, capturing roughly [46% of all L2 DeFi TVL](https://www.theblock.co/post/383329/2026-layer-2-outlook). Arbitrum and Base together represent over 75% of the L2 category. But the long tail matters too: Sonic, Mantle, Linea, and HyperEVM are each building ecosystems with native DeFi protocols and unique LP bases.

For vault curators, this distribution creates a straightforward calculus. Deploying only on Ethereum means competing for the most crowded liquidity. Deploying on L2s means access to less competitive yield sources and LPs who are native to those ecosystems.

The practical challenge has always been friction: writing chain-specific deployment scripts, managing different RPC endpoints, verifying contracts on each block explorer, and maintaining operational tooling across networks. This is the problem a permissionless Vault Factory solves.

## How the Vault Factory works across chains

Lagoon's Vault Factory is a single smart contract that produces identical ERC-7540 vaults on every supported chain. The process is the same whether you're deploying on Ethereum, Arbitrum, or Monad: select a network, pick an underlying asset, assign governance roles, set fees, and deploy. The full walkthrough is covered in [How to deploy a permissionless vault on Lagoon in minutes](/blog/deploy-permissionless-vault).

![Vault Factory architecture showing one standard deployed across 18+ chains with identical ERC-7540 contracts, governance roles, fee logic, and security](https://storage.googleapis.com/lagoon-blog-media/blog/multi-chain-vault-deployment/fig2-vault-factory-architecture.webp)

What stays constant across every chain:

- **ERC-7540 standard**: async deposits, forward pricing (exchange rate set at settlement, not request time), request-then-claim settlement
- **4 governance roles**: vault admin, curator, valuation provider, whitelist manager (each with independent permissions)
- **Fee logic**: management fees and performance fees with high-water mark tracking, enforced by the contract
- **Security**: 8+ audits from NethermindSec and Trail of Bits, time-locked parameter changes, silo architecture for pending deposits

No custom contracts. No chain-specific modifications. No re-auditing. A curator who knows how to operate a vault on Ethereum already knows how to operate one on Base or Sonic.

### Supported networks

As of April 2026, the Vault Factory is live on: Ethereum, Arbitrum, Base, Optimism, Polygon, Avalanche, Sonic, Linea, Mantle, HyperEVM, Monad, Sei, Unichain, Worldchain, Katana, Plasma, and TAC. Additional chains can be added on request, since deploying the Factory contract to a new EVM chain is a standard operation.

## Chain selection: a framework for curators

Not every chain is worth deploying on. The decision depends on four variables: liquidity depth, gas economics, ecosystem access, and LP demographics.

**Liquidity depth** determines whether your vault can source yield efficiently. Ethereum has the deepest DeFi liquidity ($52.9 billion in TVL), which means more lending markets, more DEX volume, and more composability with other protocols. For strategies that need to move large positions without slippage, Ethereum is still the default.

**Gas economics** matter most for strategies with frequent rebalancing. A delta-neutral strategy that rebalances daily on Ethereum might cost $50 to $200 per settlement cycle in gas. The same operations on Arbitrum or Base cost cents. For high-frequency strategies, L2s are not optional; they are the only economically viable execution environment.

**Ecosystem access** varies by chain. Base has a direct pipeline to Coinbase's user base. Sonic (formerly Fantom) has rebuilt its DeFi stack with native protocols optimized for speed. HyperEVM ties into HyperLiquid's perpetuals infrastructure. Each ecosystem offers yield sources that are unique to that chain.

**LP demographics** are the most underappreciated factor. Ethereum LPs tend to be larger, more institutional, and slower to move. L2 LPs skew smaller, more active, and more responsive to new vault launches. A curator launching a new strategy might attract initial depositors faster on Base than on Ethereum, then expand to Ethereum once the strategy has a track record.

| Factor | Ethereum | Arbitrum | Base | Emerging (Sonic, Monad...) |
|---|---|---|---|---|
| Liquidity depth | Very deep ($52.9B) | Deep ($2.8B) | Growing ($4.1B) | Shallow but growing |
| Gas costs | High ($5-50+) | Very low (under $0.01) | Very low (under $0.01) | Very low |
| DeFi ecosystem | Most mature | Strong | Fast-growing | Early but incentivized |
| LP profile | Institutional, large | Active DeFi users | Coinbase-adjacent | Early adopters |

## Cross-chain execution patterns

Once you decide to go multi-chain, there are two distinct architectural patterns. Each involves trade-offs, and the right choice depends on your strategy type and operational setup.

![Cross-chain execution comparison: Pattern A uses a single vault with bridging curator, Pattern B deploys separate vaults per chain](https://storage.googleapis.com/lagoon-blog-media/blog/multi-chain-vault-deployment/fig3-cross-chain-execution-patterns.webp)

### Pattern A: single vault, bridging curator

Deploy one vault (typically on Ethereum or an L2) and use the curator wallet to bridge capital to other chains for execution. Safe wallets with bridging modules make this possible without leaving the multisig security model.

This works well for strategies that aggregate yield across chains but want a single LP entry point. The trade-off is bridge risk on every capital movement and more complex net asset value (NAV) computation, since the valuation provider needs to track positions across multiple networks.

### Pattern B: one vault per chain

Deploy separate vaults on each chain using the Vault Factory. Each vault has its own deposits, its own share token, and executes strategies locally. LPs deposit on their preferred chain.

This pattern has cleaner operational boundaries. NAV is computed per-chain with no cross-chain dependencies. There is zero bridge risk per vault. The trade-off: LPs must choose which chain to deposit on, and the curator manages multiple vault instances.

### Which to choose

Most curators we work with start with Pattern B, deploying separate vaults on 2 to 3 chains where they have the strongest strategy thesis. Pattern A makes sense for advanced curators running complex cross-chain strategies (arbitrage between chains, cross-chain lending optimization) where capital mobility is the edge itself.

The Vault Factory makes both patterns practical by removing the deployment friction. Spinning up a vault on a new chain takes minutes, not weeks of custom integration.

<KeyTakeaways>
- **32% of DeFi TVL sits outside Ethereum**, spread across Base ($4.1B), Arbitrum ($2.8B), and a growing list of L2s and alt-L1s. Single-chain vaults leave this capital untouched.
- **Lagoon's Vault Factory deploys identical ERC-7540 contracts** across 18+ EVM chains with the same governance, fee logic, and 8+ audits from NethermindSec and Trail of Bits on every network.
- **Chain selection depends on four factors**: liquidity depth, gas economics, ecosystem access, and LP demographics. Not every chain is worth deploying on.
- **Two cross-chain patterns exist**: single vault with bridging (unified LP entry, bridge risk) or one vault per chain (clean NAV, zero bridge risk). Most curators start with Pattern B.
- **Permissionless deployment removes the friction**: spinning up a vault on a new chain takes minutes, making multi-chain expansion a strategic choice rather than an engineering project.
</KeyTakeaways>

<CTA href="https://app.lagoon.finance/deploy">
Deploy your next vault on a new chain. The Vault Factory is live across all 18+ supported networks.
</CTA>

---

## Vault Governance Roles: Who Does What in an Onchain Fund

> Learn how four governance roles secure onchain funds: vault admin, curator, valuation provider, and whitelist manager, each enforced by smart contracts.

- URL: https://lagoon.finance/blog/vault-governance-roles
- Date: 2026-04-07
- Author: Lagoon
- Category: Product

<Callout>
Every onchain vault needs clear rules about who can value assets, who can move funds, and who can grant access. Lagoon enforces these through four governance roles scoped at the smart contract level: vault administrator, valuation provider, curator, and whitelist manager. Here is what each role does, how they interact during settlement, and how they map to traditional fund structures.
</Callout>

## Introduction

In traditional finance, separation of duties is a regulatory and policy requirement. In an onchain vault, the separation of powers is enforced by code.

We built [Lagoon](https://lagoon.finance) to bring institutional-grade fund operations onchain, and with over 800 vaults deployed across 18+ EVM chains since inception, we have seen firsthand why governance design determines whether a vault earns trust or becomes a liability. The [curator model that emerged across DeFi in 2025 and 2026](https://defiprime.com/defi-vaults-guide) has professionalized vault operations, but the underlying question remains the same: who controls what, and how is that enforced?

Whether you are deploying your first vault or evaluating an existing one as an investor, understanding these roles is the foundation for assessing any onchain fund structure.

## Why governance separation matters

Traditional funds rely on legal agreements between service providers: the fund administrator calculates the net asset value (NAV), the transfer agent processes subscriptions, and the compliance officer verifies investor eligibility. These separations work, but they are enforced by contracts, audits, and regulatory oversight, not by the infrastructure itself.

Onchain vaults invert this model. Instead of trusting separate companies to follow their agreements, the smart contract defines what each role can and cannot do. A valuation provider can submit a NAV proposal but cannot settle requests. A curator can execute trades but cannot change fee parameters. These constraints are verifiable by anyone reading the contract.

This matters for two reasons:

1. **Security through scoping.** No single compromised key can drain a vault, manipulate pricing, and approve its own access. Each role is isolated, so a breach in one does not cascade to others.
2. **Institutional credibility.** Asset managers evaluating onchain infrastructure [consistently cite governance and risk management](https://www.coindesk.com/sponsored-content/accelerating-convergence-between-traditional-and-on-chain-finance-in-2026) as their primary concern. Smart contract enforcement provides a verifiable answer that policy documents cannot.

Lagoon's ERC-7540 implementation enforces this separation natively: the vault contract rejects any transaction from an address that does not hold the required role for that operation.

## The four governance roles

![The four governance roles in an onchain vault](https://storage.googleapis.com/lagoon-blog-media/blog/vault-governance-roles/fig1-four-roles-overview.webp?v=2)

### Vault administrator

**TradFi equivalent:** Board of Directors / General Partner

The vault administrator is the top-level configuration role. It sets the framework within which the vault operates, without directly touching investor capital.

**Responsibilities:**
- Configure vault parameters (settlement cadence, strategy constraints)
- Set fee structures
- Assign and reassign addresses for each governance role
- Manage allowlist settings and access policies

**Scope:** Configuration only. The vault administrator cannot move funds, settle requests, or submit valuations. Some parameters are immutable after deployment (such as the underlying asset), while others can be updated subject to a time-lock period.

**Typical setup:** A smart contract wallet (such as a Safe multisig) or an MPC wallet. Using a multisig ensures no single team member can unilaterally change vault parameters.

### Valuation provider

**TradFi equivalent:** Fund Administrator

The valuation provider determines the price at which deposits and redemptions settle. This is the role that answers the question: "What is the vault's portfolio actually worth?"

**Responsibilities:**
- Compute the total asset value of the portfolio
- Submit NAV proposals onchain
- Select and apply a consistent NAV methodology
- Ensure pricing accuracy across all positions (onchain and off-chain)

**Scope:** Propose only. The valuation provider submits a NAV figure, but it takes effect only after the curator accepts it. This role cannot settle requests, move funds, or modify any vault parameters.

**Typical setup:** An automated script that reads portfolio positions, an onchain oracle, or a third-party valuation service. For strategies with off-chain components (such as [real-world assets](/blog/erc-7540-explained)), a professional valuation agent may be required.

### Curator

**TradFi equivalent:** Portfolio Manager + Transfer Agent

The curator is the operational heart of the vault. It is the only role that can execute transactions on behalf of the vault, making it the most powerful and most closely watched.

**Responsibilities:**
- Review and accept (or reject) NAV proposals from the valuation provider
- Settle all pending deposit and redemption requests
- Execute the investment strategy: deploy capital, rebalance positions, bridge assets across chains
- Determine settlement timing and frequency

**Scope:** Operations and execution only. The curator cannot change fee structures, modify the allowlist, or reassign roles. Its authority is scoped to accepting valuations and moving capital within the strategy mandate.

**Typical setup:** A Safe multisig (e.g. 3-of-5) or an institutional MPC wallet through providers like [Fireblocks or Fordefi](/blog/onchain-fund-custody). The custody model for the curator wallet is one of the most consequential decisions in vault design, since this is the address that signs strategy transactions.

**Critical independence requirement:** The curator and the valuation provider must be separate entities. If the same address controls both, it can propose a favorable NAV and immediately settle against it, effectively manipulating the share price. Lagoon's contracts enforce this separation: the [two-step verification](/blog/erc-7540-explained) (propose, then accept) prevents unilateral price manipulation.

### Whitelist manager

**TradFi equivalent:** Compliance Officer

The whitelist manager controls who can interact with the vault. This role is optional: permissionless vaults leave it unassigned, while regulated products use it to enforce investor eligibility at the contract level.

**Responsibilities:**
- Maintain the allowlist of approved investor addresses
- Enforce KYC/AML and accreditation requirements programmatically
- Gate vault access before transactions execute (pre-trade enforcement)

**Scope:** Access control only. The whitelist manager cannot move funds, submit valuations, or change vault parameters. It operates as a binary gate: an address is either approved or it is not.

**Typical setup:** A KYC/KYB provider integration, an externally owned account (EOA) managed by the compliance team, or a smart contract connected to an identity verification service. For [DeFi-native strategies](/blog/building-yield-strategy) targeting open participation, this role is simply left unassigned.

## How the roles work together

The governance roles are not independent silos. They interact in a specific sequence during every settlement cycle, creating a chain of verification that no single participant can bypass.

![Settlement flow: how governance roles interact](https://storage.googleapis.com/lagoon-blog-media/blog/vault-governance-roles/fig2-settlement-flow.webp?v=2)

### The settlement cycle

**Step 1: Investor submits a request.** An investor calls `requestDeposit` or `requestRedeem` on the vault contract. If a whitelist manager is configured, the contract checks the caller's address against the allowlist before accepting the request. Assets transfer to the vault, and the request enters a pending queue. No shares are minted yet.

**Step 2: Valuation provider proposes the NAV.** The valuation provider computes the portfolio's total asset value and submits it onchain. This figure determines the exchange rate (share price) for all pending requests. Because the price is set after requests are submitted ([forward pricing](https://docs.lagoon.finance)), investors cannot front-run the settlement.

**Step 3: Curator reviews and settles.** The curator examines the proposed NAV. If it is accurate, the curator accepts it and settles all pending requests in a single transaction. Fees are computed, shares are minted (for deposits) or assets are released (for redemptions) at the settlement price. The curator then deploys the new capital according to the strategy.

This three-step process ensures that:
- The entity proposing the price (valuation provider) cannot settle the requests (curator)
- The entity settling requests (curator) cannot change who has access (whitelist manager)
- The entity configuring the vault (administrator) cannot execute trades (curator)

### Checks and balances

This separation mirrors the principle behind [traditional fund operations](/blog/onchain-vaults-fund-operations), but with one critical difference: onchain enforcement is continuous and verifiable, not periodic and trust-based. An investor can read the vault contract to confirm which addresses hold which roles, and verify that no single entity controls multiple functions.

## Configuring roles in practice

![Traditional fund governance vs. onchain vault governance](https://storage.googleapis.com/lagoon-blog-media/blog/vault-governance-roles/fig3-tradfi-vs-onchain.webp?v=2)

### Common configuration patterns

| Pattern | Vault Admin | Valuation Provider | Curator | Whitelist Manager |
|---|---|---|---|---|
| **DeFi-native (open)** | Team multisig | Automated script or third-party valuation provider | Smart contract wallet or MPC | Not assigned |
| **Institutional (gated)** | Team multisig | Third-party service | MPC wallet (Fireblocks) | KYC provider |
| **DAO-managed** | Governance contract | Oracle integration | Safe multisig | DAO vote |

### Mistakes to avoid

**Assigning all roles to the same address.** This eliminates every governance benefit. If one key is compromised, the attacker controls valuation, execution, configuration, and access simultaneously. Always use distinct addresses.

**Using the curator wallet as the valuation provider.** This is the most common governance mistake in vault design. It removes the two-step verification that prevents share price manipulation. Even if the same team manages both functions, use separate signing addresses.

**Skipping the whitelist manager for regulated products.** If your vault accepts capital from accredited or institutional investors, compliance must be enforced at the contract level, not as an off-chain process that can be bypassed. Onchain enforcement is auditable and pre-trade, which is what regulators expect.

**Using a single-key EOA for the curator.** The curator controls strategy execution. A single private key means a single point of failure. Use a multisig or MPC wallet to distribute signing authority across multiple parties.

<KeyTakeaways>
- **Four distinct roles** (vault admin, valuation provider, curator, whitelist manager) enforce separation of duties at the smart contract level
- **Two-step verification** prevents share price manipulation: the entity that proposes the NAV cannot settle requests
- **TradFi mapping** is direct: each onchain role corresponds to a traditional fund service provider, but enforcement moves from legal agreements to code
- **Custody choice for the curator** is the most consequential governance decision, since this address signs all strategy transactions
- **Permissionless or gated** access is a configuration choice: the whitelist manager is optional, enabling both open DeFi strategies and regulated institutional products
</KeyTakeaways>

<CTA href="https://app.lagoon.finance">Deploy a vault on Lagoon and configure governance roles across 18+ EVM chains.</CTA>

---

## Building a Yield Strategy: From Concept to Live Vault

> A practical framework for DeFi builders to design, configure, and deploy yield vault strategies on ERC-7540 infrastructure.

- URL: https://lagoon.finance/blog/building-yield-strategy
- Date: 2026-03-26
- Author: Lagoon
- Category: DeFi

<Callout>
Every yield vault starts with a strategy thesis. This guide walks DeFi builders through the four phases of launching one: defining your edge, mapping it to vault parameters, configuring governance roles, and going live with proper settlement design on ERC-7540 infrastructure.
</Callout>

## Introduction

Vaults have become the dominant capital allocation interface in DeFi. With total value locked (TVL) across vault protocols exceeding $15 billion and curated strategies managing billions in deposits, the infrastructure is mature. The gap is no longer "can I build a vault?" but "how do I build a good one?"

At Lagoon, we have deployed 120+ vaults across 18+ EVM chains, permissionlessly, with no approvals, no minimum TVL, and no delays. That scale gives us direct visibility into what separates strategies that attract capital from those that sit empty. The pattern is consistent: successful vaults are not just good strategies wrapped in a smart contract. They are well-designed products with clear risk parameters, appropriate settlement cadences, and properly scoped governance.

This guide covers the full lifecycle, from strategy thesis to live vault, using Lagoon's [ERC-7540 infrastructure](/blog/erc-7540-explained) as the reference implementation.

## Phase 1: define your strategy thesis

Before touching any vault configuration, answer one question: what is your edge?

A vault is a product. Like any product, it needs a reason to exist. "Yield farming" is not a thesis. "Earning 6-8% on stablecoins by lending across Aave and Morpho with automated rebalancing" is a thesis, because it specifies the source of return, the risk profile, and the mechanism.

### The strategy spectrum

Not all strategies map equally well to vault structures. What matters most: risk, operational complexity, and settlement requirements.

![Yield strategy spectrum showing risk, complexity, and return profiles for five strategy categories](https://storage.googleapis.com/lagoon-blog-media/blog/building-yield-strategy/fig1-strategy-spectrum.webp)

**Stablecoin lending** is the most common vault strategy in 2026, offering 3-8% annual percentage yield (APY) with minimal directional risk. Protocols like Aave, Morpho, and Compound provide the underlying yield. The curator's edge comes from allocation optimization: choosing the right markets, rebalancing between protocols based on rate fluctuations, and managing utilization risk.

**Liquid staking with looping** combines ETH staking rewards (via wstETH, rETH, or similar liquid staking tokens) with recursive lending to amplify yield to 4-12%. The risk is moderate: smart contract exposure compounds with each loop, and liquidation risk increases with leverage.

**Delta-neutral arbitrage** neutralizes directional price exposure by holding offsetting long and short positions. Vault curators typically arbitrage funding rates across perpetual exchanges or basis spreads between spot and futures. APYs range from 6-15%, but operational complexity is high, often requiring cross-chain or centralized exchange (CEX) execution.

**Active yield farming** captures token incentive programs, liquidity mining rewards, and protocol emissions. Returns can exceed 25%, but they depend on incentive sustainability, and impermanent loss is a real cost. This category requires the most active management.

**RWA yield** (tokenized T-Bills, credit products) provides 3-6% with low DeFi-native risk, but introduces settlement latency (T+1 or longer) and compliance requirements. ERC-7540's async settlement model was [designed specifically for this use case](/blog/erc-7540-explained).

### Defining your risk bounds

Every strategy thesis should include explicit risk parameters:

- **Maximum drawdown tolerance**: the worst-case loss you are willing to accept in a single settlement period
- **Liquidity constraints**: how quickly can the vault unwind positions to meet redemptions?
- **Concentration limits**: maximum exposure to a single protocol, chain, or asset
- **Leverage ceiling**: for looping or leveraged strategies, the maximum loan-to-value ratio

These constraints directly inform your vault architecture in Phase 2.

## Phase 2: map strategy to vault architecture

Once the strategy thesis is clear, translate it into vault configuration decisions. Four choices define the architecture: custody model, settlement frequency, fee structure, and flow direction.

![Four phases from concept to live vault with key decisions and timeline](https://storage.googleapis.com/lagoon-blog-media/blog/building-yield-strategy/fig2-concept-to-live-vault.webp)

### Custody model

The curator's wallet is the vault's execution layer. Every trade, bridge, and protocol interaction happens through this address. Two primary options exist:

**Safe (multisig)** is the default for most DeFi-native teams. A 2-of-3 or 3-of-5 signer configuration provides security without operational friction. With [Zodiac Roles Modifier](https://docs.roles.gnosisguild.org/), you can scope permissions at the contract, function, and argument level, limiting what the curator can do with vault capital. For cross-chain strategies, Safe supports bridging across EVM chains.

**MPC wallets** (Fireblocks, Fordefi) suit teams that need institutional-grade signing workflows or high-frequency execution. MPC distributes key shards across multiple parties, eliminating single points of failure. Policy engines enforce transaction rules before signing, providing a different security model than onchain enforcement. For a deeper comparison, see our [custody guide](/blog/onchain-fund-custody).

### Settlement frequency

This is the most consequential architectural decision. Settlement frequency determines how often deposits and redemptions are processed, which directly impacts the depositor experience and your strategy's operational requirements.

The tradeoff: **frequent settlement** (daily or per block) provides better UX for depositors but constrains the curator to highly liquid strategies. **Infrequent settlement** (weekly or biweekly) gives the curator more flexibility to execute complex strategies but means depositors wait longer to enter or exit.

| Strategy Type | Typical Settlement | Why |
|---|---|---|
| Stablecoin lending | Daily | Positions are liquid, net asset value (NAV) is easy to compute |
| Liquid staking + looping | Daily to weekly | Unwinding leverage takes time |
| Delta-neutral arbitrage | Weekly | Cross-venue rebalancing needs time |
| Active yield farming | Weekly to custom | Position entry/exit may be illiquid |
| RWA yield | T+1 to weekly | Off-chain settlement cycles |

### Fee structure

Lagoon vaults support two fee types, both enforced by the smart contract:

- **Management fee**: a percentage of assets under management (AUM), accrued continuously. Typical range: 0.5-2% annually.
- **Performance fee**: a percentage of profits above a high-water mark. Typical range: 10-20%. The high-water mark prevents charging performance fees on recovery after a drawdown.

Design your fees to align incentives. A vault charging 2% management + 20% performance on a 5% APY stablecoin strategy takes nearly half the gross return. A vault charging 0% management + 10% performance on the same strategy leaves more value for depositors and still earns on outperformance.

Lagoon's protocol fee (10% of curator fees, taken at settlement) applies only to vaults that charge fees. Zero-fee vaults pay nothing.

### Settlement flexibility

Lagoon gives the curator full flexibility over when to accept deposits and settle redemptions. The curator controls the settlement cadence, choosing when to process queued requests based on the strategy's liquidity profile and operational rhythm.

## Phase 3: configure governance and roles

Lagoon's governance model separates concerns across [four distinct roles](/blog/deploy-permissionless-vault). No single party controls the entire vault, which is both a security feature and an operational requirement.

| Role | Responsibility | Who Typically Fills It |
|---|---|---|
| **Vault Admin** | Configures vault parameters, contract settings | Team multisig or DAO |
| **Valuation Provider** | Submits NAV updates (total asset valuations) | Internal script, oracle, or third-party service |
| **Curator** | Approves valuations, executes strategy, settles requests | Strategy team's custody wallet |
| **Whitelist Manager** | Controls investor access (KYC/AML gatekeeping) | Compliance team or open (no whitelist) |

### Scoping permissions

The most common governance mistake is assigning all roles to the same address. This creates a single point of failure and eliminates the checks and balances that the role separation is designed to provide.

The **valuation provider** should be independent from the **curator**. This two-step settlement process (valuation proposal, then curator approval) prevents either party from unilaterally manipulating the share price. The valuation provider proposes a NAV; the curator verifies it before calling settlement. Neither can act alone.

For DeFi-native teams without a formal compliance function, the whitelist manager role can be left open (permissionless deposits). For vaults targeting institutional capital, this role gates investor access based on KYC/KYB verification.

## Phase 4: deploy and operate

With the strategy thesis, architecture, and governance defined, deployment itself takes minutes.

### Deployment via Vault Factory

Lagoon's Vault Factory is a permissionless smart contract deployed across 18+ EVM chains. No approvals, no minimum TVL, no partnership required. You configure the vault parameters (name, underlying asset, fee structure, governance addresses) and deploy. The factory creates two contracts: the ERC-7540 vault and a silo contract that holds pending deposits and redemptions.

For a step-by-step walkthrough, see our [deployment guide](/blog/deploy-permissionless-vault).

### The first settlement cycle

After deployment, the vault's initial NAV is zero. The first operational cycle looks like this:

1. **Deposits arrive**: investors call `requestDeposit()`, and their assets move to the silo
2. **Curator deploys capital**: the curator executes the strategy using the custody wallet
3. **Valuation provider submits NAV**: the total value of managed positions is proposed onchain
4. **Curator settles**: the curator approves the NAV and calls `settleDeposit()`, minting shares for all queued depositors at the forward price

![Vault settlement cycle showing deposit and redemption flows with role responsibilities](https://storage.googleapis.com/lagoon-blog-media/blog/building-yield-strategy/fig3-settlement-cycle.webp)

This cycle repeats at the settlement frequency you configured. For redemptions, the process mirrors deposits: investors request, the curator unwinds positions as needed, the valuation provider updates the NAV, and the curator settles. One critical difference: for redemptions, only the investor can claim their assets (the curator cannot claim on their behalf), which protects against forced liquidations.

### Operational monitoring

Once live, monitor three things:

1. **NAV accuracy**: the valuation should reflect the true market value of all positions held by the curator. Discrepancies between onchain NAV and actual position values create arbitrage opportunities against your depositors.
2. **Settlement queue depth**: if deposit or redemption requests are accumulating faster than your settlement cadence can handle, either increase frequency or communicate expected wait times to depositors.
3. **Strategy performance vs. benchmark**: track your vault's returns against the relevant benchmark (stablecoin lending rate, ETH staking yield, etc.). Consistent underperformance relative to risk taken signals a thesis that needs revision.

<KeyTakeaways>
- **Start with the thesis, not the tool**: a vault is a product. Define your edge, risk bounds, and target return before configuring anything.
- **Settlement frequency is the critical design choice**: it determines depositor UX, strategy flexibility, and operational burden. Match it to your strategy's liquidity profile.
- **Separate governance roles**: independent valuation and curation prevent single-party manipulation and build depositor trust.
- **Fees should align incentives**: high management fees on low-yield strategies extract too much value. Performance fees with high-water marks reward genuine outperformance.
- **Deploy small, scale with data**: use Lagoon's permissionless Vault Factory to test with minimal capital before marketing to depositors.
</KeyTakeaways>

<CTA href="https://app.lagoon.finance/deploy">Deploy your first vault on Lagoon</CTA>

---

## How Onchain Vaults Cut Fund Operations from Weeks to Hours

> Learn how onchain vaults automate NAV settlement, fee management, and compliance reporting, replacing weeks of manual fund administration.

- URL: https://lagoon.finance/blog/onchain-vaults-fund-operations
- Date: 2026-03-24
- Author: Lagoon
- Category: Product

<Callout>
Traditional fund administration involves 6+ intermediaries, costs 10 to 25 basis points of AUM annually, and settles in days. Onchain vaults built on ERC-7540 compress these operations into smart contracts that automate NAV settlement, fee management, and reporting in a single cycle.
</Callout>

## Introduction

Every fund manager knows the rhythm: end of month, the administrator sends a preliminary NAV. A week later, the fee invoice follows. Somewhere in between, an investor requests a redemption that triggers a cascade of emails between the transfer agent, custodian, and compliance team. The strategy may be sophisticated, but the operations running it are manual, sequential, and slow.

We see this pattern repeatedly across the 120+ active vaults on Lagoon's infrastructure spanning 18+ EVM chains. The managers who move operations onchain are not chasing a technology trend; they are eliminating the coordination overhead that consumes 10 to 25 basis points of assets under management (AUM) every year. This article walks through five core operational functions, shows how each one works in an onchain vault, and explains what changes for fund managers considering the transition.

For a structural comparison of fund types, see [Onchain Vaults vs. Traditional Funds](/blog/onchain-vaults-vs-traditional-funds). This article focuses on the day-to-day operational workflow.

## The traditional fund operations stack

A traditional fund relies on a chain of service providers, each handling one piece of the operational puzzle:

1. **Fund administrator**: Calculates NAV, reconciles positions, produces reports. Typically charges 10 to 25 basis points of AUM annually, plus minimum subscription fees depending on mandate size.
2. **Transfer agent**: Processes investor subscriptions and redemptions. Manages the shareholder register.
3. **Custodian**: Holds fund assets. Provides safekeeping and settlement services.
4. **Auditor**: Reviews records quarterly or annually. Requests documentation from the administrator and the fund manager.
5. **Compliance officer**: Manages KYC/AML documentation, often handled internally or by the fund administrator. Tracks investor eligibility.
6. **Legal counsel**: Reviews subscription agreements, side letters, and regulatory filings.

Each handoff introduces delay. A capital call that requires the administrator to calculate contributions, the transfer agent to send notices, and the custodian to receive wires typically takes two to three weeks from initiation to completion. NAV is published with a T+1 or T+2 lag. Fee disputes arise because performance calculations depend on methodology choices that are executed manually, often delayed, and subject to protracted negotiations.

![Fund operations: traditional vs. onchain vaults](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-vaults-fund-operations/fig1-traditional-vs-onchain-operations.webp)

The cost structure compounds with complexity. A fund operating across multiple jurisdictions, asset classes, or share classes multiplies the administrative burden at each layer.

## How onchain vaults automate each step

A Lagoon [ERC-7540](/blog/erc-7540-explained) vault encodes fund operations into a smart contract. Instead of coordinating six service providers through emails, spreadsheets, and wire transfers, the vault executes each function programmatically.

### NAV calculation

In a traditional fund, the administrator collects prices from data vendors, reconciles them against custodian records, and publishes NAV with a one to two day delay. In a Lagoon vault, the vault admin selects the valuation methodology and provider at inception; this can involve multiple parties, be automated, or be calculated natively onchain. This separation of roles (the valuation provider calculates, the curator accepts and settles) mirrors institutional standards for independent pricing, but eliminates the reconciliation step.

The result: NAV is available per settlement cycle, not per business day. And because it is recorded onchain, every historical NAV is permanently auditable.

### Settlement

Traditional settlement involves wire transfers, correspondent banking, and manual confirmation. Depending on the asset class, this takes T+1 to T+3.

ERC-7540 replaces this with a four-stage async flow: request, valuation, settlement, claim. The curator settles all pending deposit and redemption requests in a single onchain transaction. Forward pricing (the exchange rate is determined at settlement, not at request time) prevents the arbitrage that plagues same-block settlement in simpler vault designs.

![The onchain vault settlement cycle](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-vaults-fund-operations/fig2-settlement-cycle.webp)

### Fee computation

Traditional funds invoice fees quarterly. Performance fee calculations require agreeing on hurdle rate or high-water mark (HWM) methodology, which in turn involves reconciliation, manual lags, and disputes when managers and administrators use different reference points.

In an onchain vault, the smart contract computes management and performance fees automatically at every settlement. The HWM is tracked onchain, removing ambiguity. Investors can verify fee calculations independently by reading the contract state. This is one of the clearest operational advantages: a process that traditionally generates friction becomes transparent, automated, and deterministic.

### Access control

Investor onboarding in traditional funds involves legal documentation, email threads, and spreadsheet-based tracking. Adding a new investor to a fund can take weeks or months.

Onchain vaults use a dedicated whitelist manager role. Once an investor completes KYC/KYB verification, their wallet address is added to the whitelist. The smart contract enforces access permissions automatically: only whitelisted addresses can deposit. This is comparable to the transfer agent function, but enforced at the infrastructure level rather than through manual processes.

For more on how custody and access control work together, see [Onchain Fund Custody: MPC, Multisig, and Safeguards](/blog/onchain-fund-custody).

### Compliance and reporting

Traditional compliance reporting is reactive: auditors request records, administrators compile them, and the process repeats quarterly. Gaps between reporting periods create blind spots.

Every operation in an onchain vault (deposits, withdrawals, NAV updates, fee events) is immutably recorded on the blockchain. This audit trail is always available, always current, and exportable to match the regulatory requirements of each operator's jurisdiction. Lagoon also generates automated factsheets, replacing the manual report compilation that consumes administrator time.

## Operational roles: from intermediaries to smart contracts

The transition from traditional to onchain operations does not eliminate governance. It restructures it into four smart contract roles (for a deeper look at how custody integrates with these roles, see [Onchain Fund Custody](/blog/onchain-fund-custody)):

| Traditional Role | Vault Role | What Changes |
|---|---|---|
| Fund administrator | Valuation provider | NAV submitted onchain; no reconciliation needed |
| Transfer agent | Curator | Settles requests in one transaction; no wire coordination |
| Compliance officer | Whitelist manager | KYC/KYB enforced at contract level; no spreadsheet tracking |
| Board / GP | Vault administrator | Configures parameters onchain; verifiable by all parties |

Each role is scoped at the smart contract level, enforcing separation of duties natively. A curator cannot modify fee parameters. A whitelist manager cannot settle requests. This is institutional-grade segregation, but enforced, transparent, and auditable at the smart contract level rather than relying on policy documents.

These roles operate on a single shared ledger. There is no reconciliation between the administrator's books, the custodian's records, and the transfer agent's register because they are all the same onchain state.

## What this means for fund economics

The cost structure of onchain fund operations differs fundamentally from traditional administration. Instead of ongoing basis-point fees tied to AUM, onchain vaults minimize both the recurring costs and the operational friction of fund management. Lagoon's [Vault Factory](/blog/deploy-permissionless-vault) makes deployment permissionless across 18+ EVM chains.

This matters most at scale. A $100 million fund paying 15 basis points for administration spends $150,000 annually. That cost remains roughly fixed per vault in the onchain model. As tokenized fund AUM grows (BCG projects tokenized funds alone could exceed $600 billion by 2030, and [onchain vault TVL already surpassed $15 billion](/blog/state-of-onchain-vaults-2026) in 2025), the operational cost advantage compounds.

Deloitte's [2026 Investment Management Outlook](https://www.deloitte.com/us/en/insights/industry/financial-services/financial-services-industry-outlooks/investment-management-industry-outlook.html) anticipates "healthy growth in tokenized funds that invest in private assets," driven partly by the operational efficiency these structures provide. The firms moving first are not replacing their entire infrastructure overnight; they are running parallel structures and comparing unit economics.

<KeyTakeaways>
- **Administration costs drop**: Traditional fund admin costs 10 to 25 bps annually; onchain vaults minimize both costs and operational friction
- **Settlement compresses**: Multi-day wire-and-reconcile cycles become single-transaction settlements via ERC-7540
- **Fees become transparent**: Smart contracts compute management and performance fees automatically, with onchain HWM tracking
- **Compliance is continuous**: Immutable onchain records replace quarterly report compilation, providing always-available audit trails
- **Governance is enforced and auditable**: Four smart contract roles replace six intermediaries, with separation of duties at the contract level
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance">Explore Lagoon's documentation to understand how vault operations work at the smart contract level, or launch your first vault on any of 18+ supported chains.</CTA>

---

## The State of Onchain Vaults: TVL, Chains, and Trends in 2026

> Onchain vault TVL surpassed $15B in 2025. Here's where the market stands in 2026: growth drivers, chain distribution, and what's next.

- URL: https://lagoon.finance/blog/state-of-onchain-vaults-2026
- Date: 2026-03-19
- Author: Lagoon
- Category: DeFi

<Callout>
Tokenized real-world assets on public blockchains reached $23.6 billion in March 2026, up 66% year-to-date. Vault standards like ERC-4626 and ERC-7540 now underpin over $15 billion in total value locked (TVL), and institutions from BlackRock to Kraken are deploying capital through onchain vault infrastructure.
</Callout>

## Introduction

Real-world asset (RWA) protocols just overtook decentralized exchanges to become the [fifth-largest DeFi category by total value locked](https://cointelegraph.com/news/rwas-surpassed-dexs-defi-tvl). That milestone, reached in early 2026, marks a shift that has been building for three years: onchain vaults are no longer a niche DeFi primitive. They are becoming the default infrastructure for tokenized investment products.

At Lagoon, we build vault infrastructure across 18+ EVM chains and have deployed over 800 vaults to date, giving us direct visibility into how this market is evolving. Every data point below is sourced and timestamped.

## Market size: where onchain vaults stand today

The total value of tokenized RWAs on public blockchains reached [$23.6 billion in March 2026](https://cointelegraph.com/news/tokenized-rwas-rise-66-percent-2026-defillama) (data: [DefiLlama](https://defillama.com/protocols/RWA), [rwa.xyz](https://rwa.xyz)), up from $14.1 billion at the start of the year. That 66% growth in under three months outpaces the 2025 full-year trajectory, when onchain RWA value grew from roughly $6 billion to over $30 billion.

![Tokenized real-world assets by category](https://storage.googleapis.com/lagoon-blog-media/blog/state-of-onchain-vaults-2026/fig1-rwa-market-composition.webp)

### Composition by asset class

The $23.6 billion breaks down into four segments:

- **Tokenized funds** ($10.5 billion, 44.5%): U.S. Treasuries, money market funds, and bond products dominate. Tokenized U.S. Treasuries alone [hit a record $11 billion in March 2026](https://www.coindesk.com/markets/2026/03/13/circle-overtakes-blackrock-in-tokenized-treasuries-as-market-hits-record-usd11-billion), up 27% year-to-date.
- **Gold and commodities** ($6.5 billion, 27.5%): Tokenized gold products (PAXG, XAUT) and metals represent the second-largest category.
- **Tokenized equities** ($4.0 billion, 16.9%): Stocks, ETFs, and index fund tokens are growing as regulatory frameworks clarify.
- **Private credit and other** ($2.6 billion, 11.1%): Lending protocols, real estate tokens, and other RWA categories.

For context, total DeFi TVL across all chains sits at approximately [$95.4 billion as of March 2026](https://www.spotedcrypto.com/defi-tvl-95b-aave-1t-loans-staking-airdrop-guide-march-2026/), meaning tokenized RWAs now represent roughly one-quarter of all value locked in DeFi.

### Vault-specific TVL

ERC-4626 and its async extension ERC-7540 collectively account for over $15 billion in vault TVL, up from near-zero in early 2023. Over [1,300 ERC-4626-compliant stablecoin vaults](https://erc4626.info/) are tracked, with USDC vaults alone holding $3 billion.

## The vault stack: standards driving adoption

Two Ethereum standards form the technical foundation of the onchain vault ecosystem. Understanding their relationship explains why vault adoption accelerated so rapidly.

![The onchain vault standard stack](https://storage.googleapis.com/lagoon-blog-media/blog/state-of-onchain-vaults-2026/fig2-vault-standard-stack.webp?v=2)

### ERC-4626: the foundation

[ERC-4626](https://ethereum.org/developers/docs/standards/tokens/erc-4626/), finalized in 2022, standardized how tokenized vaults handle deposits, withdrawals, and share accounting. Before ERC-4626, every protocol implemented its own vault interface, making composability between protocols difficult. The standard solved this by defining a common API that any vault could implement.

The result: protocols like Yearn, Morpho, Euler, and hundreds of others adopted ERC-4626, creating an interoperable vault layer across DeFi. Aggregators and front-ends could integrate any ERC-4626 vault without custom code.

### ERC-7540: the async extension

ERC-4626 assumes synchronous settlement, where deposits and withdrawals complete in the same transaction. That works for liquid DeFi strategies but breaks down for assets that need processing time: real-world assets with T+1 or T+2 settlement, institutional funds requiring compliance checks, or strategies involving off-chain execution.

[ERC-7540](https://eips.ethereum.org/EIPS/eip-7540), finalized in June 2024 and [recognized on ethereum.org in January 2025](/blog/erc-7540-explained), extends ERC-4626 with asynchronous deposit and redemption flows. The request-then-claim pattern allows vaults to handle settlement delays, forward pricing (where the exchange rate is determined at settlement, not at request time), and role-based governance without breaking ERC-4626 compatibility.

Lagoon's entire vault infrastructure is built on ERC-7540, enabling asset managers to run [tokenized fund structures](/blog/what-is-onchain-asset-management) with async settlement, independent net asset value (NAV) computation, and four distinct governance roles.

### Protocol landscape

The vault standard stack has enabled a diverse protocol layer:

| Protocol | Focus | TVL / Scale |
|---|---|---|
| [Morpho](https://morpho.org) | Curated lending vaults | $5.8B TVL |
| [Pendle](https://pendle.finance) | Yield tokenization | $3.5B across 11 chains |
| [Kamino](https://kamino.finance) | Solana lending vaults | $2.4B TVL |
| [**Lagoon**](https://lagoon.finance) | Asset management infra | 18+ chains, 120+ active vaults |
| [Euler v2](https://euler.finance) | Modular lending | Vault Kit for custom markets |

Risk curation is what sets the top protocols apart. Professional curators like [Gauntlet ($1.41B managed)](https://www.gauntlet.xyz/resources/under-the-hood-unpacking-our-morpho-vault-curation-methodology) and Steakhouse ($1.28B managed) allocate depositor capital across isolated lending markets, earning 3 to 8% APY on conservative stablecoin strategies.

Lagoon occupies a different position in the stack: rather than a single strategy vertical, it provides general-purpose vault infrastructure — any strategy type, any custody model, any EVM chain — enabling managers and institutions to launch tokenized products without building custom smart contracts.

## Chains, curators, and capital flows

### Institutional entrants

The distinction between "DeFi protocols" and "financial institutions" is blurring. Several developments in late 2025 and early 2026 illustrate this convergence:

- **BlackRock BUIDL on Uniswap** (February 2026): BlackRock's [tokenized Treasury fund](https://www.ccn.com/education/crypto/blackrock-buidl-fund-tokenized-money-markets-explained/) became [tradable on Uniswap](https://blockeden.xyz/blog/2026/02/24/blackrock-buidl-uniswap-defi-integration/) for pre-qualified investors. This is a $10 trillion asset manager using DeFi rails for fund distribution.
- **Circle overtakes BUIDL**: Circle's USYC token [surpassed BUIDL](https://www.coindesk.com/markets/2026/03/13/circle-overtakes-blackrock-in-tokenized-treasuries-as-market-hits-record-usd11-billion) as the largest single tokenized U.S. Treasury product in early 2026, as the total tokenized treasury market expanded to $11 billion. BUIDL's share of that market fell from a 46% peak to roughly 18%, not because it shrank, but because new entrants grew faster.
- **Kraken DeFi Earn** (January 2026): Kraken launched a product routing centralized exchange deposits into onchain lending vaults managed by professional risk teams. Tens of millions flowed in within weeks.
- **Bitwise onchain vaults**: Bitwise [launched a non-custodial stablecoin vault](https://bitwiseinvestments.com/newsroom/bitwise-expands-onchain-solutions-with-introduction-of-non-custodial-vault) on Ethereum targeting yields up to 6%, built on top of Morpho markets.

![Institutional adoption of onchain vaults timeline](https://storage.googleapis.com/lagoon-blog-media/blog/state-of-onchain-vaults-2026/fig3-institutional-adoption-timeline.webp?v=2)

### Capital concentration

One pattern stands out in the data: capital is concentrated among large depositors. According to [Keyrock's onchain asset management report](https://keyrock.com/onchain-asset-management-report/), whales (over $1M) and dolphins ($100K to $1M) account for 70 to 99% of vault AUM across most protocols, while retail depositors (under $10K) contribute less than 1% of capital despite representing the majority of unique addresses.

This concentration has implications for vault design. Institutional depositors require [custody infrastructure](/blog/onchain-fund-custody) (MPC wallets, multisig, role-based permissions), compliance tooling (whitelisting, KYC gates), and professional reporting. Protocols that serve only retail are leaving the largest capital pools unaddressed.

This is why Lagoon's vault architecture separates governance into four distinct roles — vault admin, valuation manager, curator, and whitelist manager — each with independent permissions. Combined with flexible custody (multisig, MPC, or hybrid), KYC/KYB whitelisting, and automated reporting, the infrastructure is designed for the capital profile the data reveals: institutional depositors who require operational controls before committing capital.

### Multi-chain expansion

Onchain vaults are no longer Ethereum-only. Pendle operates across 11 chains. Kamino dominates on Solana with a [$2.36 billion TVL](https://defiprime.com/defi-vaults-guide). Lagoon supports [18+ EVM chains](/blog/deploy-permissionless-vault) with identical vault contracts on each, enabling managers to deploy the same strategy across networks without custom integration work.

The multi-chain trend is driven by a practical reality: institutional capital does not sit on one chain. A manager running a treasury strategy may want Ethereum for liquidity depth, Arbitrum for lower gas costs, and Base for access to Coinbase's distribution. Vault infrastructure that supports permissionless multi-chain deployment, like Lagoon's [Vault Factory](/blog/deploy-permissionless-vault), removes the friction of cross-chain expansion.

## What's next: projections and catalysts

### Market projections

Three data points frame the forward outlook:

1. **$64 billion** (base case) in onchain vault AUM by end of 2026, per [Keyrock Research](https://keyrock.com/onchain-asset-management-report/). The bull case is $85 billion; the bear case is $41.6 billion.
2. **$100 billion+** in tokenized RWAs by end of 2026, with more than half of the world's top 20 asset managers expected to launch tokenized products ([CoinDesk](https://www.coindesk.com/news-analysis/2026/01/17/why-tokenized-stocks-funds-and-gold-will-have-a-breakout-year-in-2026)).
3. **$16 trillion** in tokenized assets by 2030, projected by [Boston Consulting Group](https://coinlaw.io/asset-tokenization-statistics/). McKinsey's estimate is $2 trillion, while Citi projects $4 to $5 trillion in tokenized securities alone.

### Key catalysts

Several forces could accelerate adoption through 2026:

- **Regulatory clarity**: As tokenized fund frameworks mature in the EU (MiCA), Singapore (MAS guidelines), and the U.S. (SEC engagement with tokenized securities), institutional allocators gain the legal certainty they need to deploy capital.
- **Institutional onramps**: Products like Kraken DeFi Earn and BlackRock BUIDL on Uniswap lower the barrier between traditional finance and onchain vaults. Each new onramp expands the addressable depositor base.
- **Vault composability**: ERC-4626 compatibility means vault shares can be used as collateral, traded on secondary markets, or composed into structured products. This programmability creates network effects that traditional fund structures cannot replicate.
- **Performance premium**: Onchain vault strategies outperform traditional equivalents by [230 to 380 basis points](https://keyrock.com/onchain-asset-management-report/) after fees across most categories, according to Keyrock. As awareness of this performance gap grows, capital rotation from traditional to onchain accelerates.

Each of these catalysts maps to infrastructure requirements Lagoon already addresses: ERC-7540 for institutional compliance flows, permissionless multi-chain deployment for geographic and chain expansion, custody integrations (Safe, Fireblocks, Fordefi) for institutional onramps, and full ERC-4626 backward compatibility for vault composability. As the market scales from $15B toward $64B+, the infrastructure layer becomes the critical enabler — and the opportunity.

<KeyTakeaways>
- **$23.6B in tokenized RWAs** on public blockchains as of March 2026, up 66% year-to-date, with tokenized U.S. Treasuries alone hitting a record $11B+ (Sources: DefiLlama, CoinDesk).
- **$15B+ in ERC-4626/7540 vault TVL**, powering over 1,300 tracked stablecoin vaults across Morpho, Pendle, Kamino, Lagoon, and hundreds of other protocols.
- **Institutional convergence is accelerating**: BlackRock BUIDL traded on Uniswap, Kraken routing deposits to onchain vaults, Bitwise launching non-custodial vault products.
- **$64B base-case projection** for onchain vault AUM by end of 2026 (Keyrock Research), with the broader RWA market targeting $100B+.
- **Multi-chain is the default**: leading protocols operate across 11 to 18+ chains, and permissionless deployment (like Lagoon's Vault Factory) removes cross-chain friction.
- **Infrastructure is the bottleneck**: as vault AUM scales 4x, demand for general-purpose, multi-chain, institutional-grade vault infrastructure grows with it — the layer Lagoon provides.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance">Explore Lagoon's vault documentation to understand how ERC-7540 powers institutional-grade onchain fund infrastructure across 18+ chains.</CTA>

---

## Onchain Fund Custody: MPC, Multisig, and Safeguards

> MPC wallets, multisig, and role-based permissions for institutional onchain funds. Compare custody models, trade-offs, and how Lagoon integrates each.

- URL: https://lagoon.finance/blog/onchain-fund-custody
- Date: 2026-03-17
- Author: Lagoon
- Category: Product

<Callout>
Custody is the primary institutional concern when moving fund operations onchain. Three models dominate: MPC wallets (Fireblocks, Fordefi) for operational speed, multisig (Safe) for transparent governance, and hybrid setups combining both with role-based permissions. Lagoon supports all three natively as the vault's curation wallet.
</Callout>

## Introduction

86% of institutional investors either hold digital assets or plan to allocate within the next two years, according to a 2025 EY survey. Yet when these institutions evaluate onchain fund structures, one question dominates every due diligence conversation: who controls the keys?

In traditional finance, custody is straightforward. A regulated third-party custodian (State Street, BNY, Northern Trust) holds the assets, maintains the books, and provides insurance coverage. The fund manager gives instructions; the custodian executes. The roles are distinct, the liability is clear, and the model has worked for decades.

Onchain funds work differently. There is no single custodian holding assets in an omnibus account. Instead, assets sit in a smart contract vault, and a designated curation wallet executes the investment strategy. That wallet can be an MPC wallet, a multisig, or a hybrid of both, and the choice directly affects the fund's security model, operational speed, and regulatory posture.

Below we compare the three dominant custody models for onchain funds, explain their trade-offs in terms institutional managers already understand, and show how [Lagoon](https://lagoon.finance)'s infrastructure supports all three.

## What custody means for onchain funds

In a traditional fund, custody means physical or legal control of assets by a regulated entity. The custodian is a separate counterparty from the fund manager, the administrator, and the transfer agent. This separation of duties is a cornerstone of institutional fund governance.

In an onchain fund built on the ERC-7540 standard, the vault smart contract handles deposits, net asset value (NAV) calculation, fee computation, and share token issuance. But the vault itself does not execute the investment strategy. That responsibility belongs to the curation wallet: the address authorized to deploy the vault's settled assets into protocols, lending markets, or other yield-generating positions.

### The curation wallet is your custody layer

The curation wallet is the onchain equivalent of the custodian role. It controls where settled assets go and how they are deployed. Unlike a traditional custodian, the curation wallet is not a separate legal entity; it is a blockchain address, and the security model depends entirely on what kind of address it is.

This is where the custody decision matters. The curation wallet can be:

- **An MPC wallet** (Fireblocks, Fordefi), where key shards are distributed across multiple parties and no single person ever holds a complete private key.
- **A multisig wallet** (Safe), where N-of-M independent signers must approve every transaction onchain.
- **A hybrid setup** (Safe + Zodiac Roles Modifier), where a multisig provides the base security layer and a permissions module delegates scoped execution rights to specific addresses.

### Non-custodial infrastructure

A critical distinction: Lagoon is non-custodial infrastructure. The protocol never holds private keys, never takes custody of assets, and never controls the curation wallet. Custody remains entirely with the fund and its chosen wallet provider. Lagoon provides the vault smart contracts (audited [8+ times by NethermindSec and Trail of Bits](https://docs.lagoon.finance)), the governance roles, and the settlement logic, but the custody model is the fund's decision.

## Three custody models compared

Each custody model represents a different set of trade-offs across security, operational speed, transparency, and regulatory alignment. The right choice depends on the fund's strategy, compliance requirements, and operational maturity.

### MPC wallets: speed and flexibility

Multi-party computation (MPC) wallets distribute the private key into multiple cryptographic shards held by different parties. To sign a transaction, the parties participate in a distributed signing protocol without ever assembling the complete key. The result is a standard blockchain signature, indistinguishable from any other, with no onchain footprint of the multi-party process.

Providers like [Fireblocks](https://www.fireblocks.com) (protecting over $10 trillion in cumulative assets) and [Fordefi](https://fordefi.com) (recently acquired by Paxos, safeguarding $120 billion in monthly transaction volume) have become the dominant MPC platforms for institutional digital asset management.

MPC wallets are chain-agnostic (they work on any EVM network without requiring chain-specific smart contracts), produce single-signature transactions (lower gas costs), and allow flexible signer rotation without onchain transactions. They also include built-in policy engines that can restrict transactions by protocol, amount, destination, and time of day.

The trade-off: MPC signing happens off-chain. The approval process is not publicly verifiable on the blockchain, and the fund depends on the MPC provider's infrastructure for availability and security. For institutions accustomed to relying on regulated custodians, this maps closely to the traditional model: you trust a service provider rather than a smart contract.

### Multisig: transparency and decentralization

Multisig wallets, most commonly implemented through [Safe](https://safe.global) (managing over $50 billion in assets), require multiple independent private keys to sign every transaction. A 3-of-5 Safe, for example, needs three out of five designated signers to approve before any assets can move.

Every approval is recorded onchain. Anyone can verify who signed, when, and what was executed. This makes multisig the most transparent custody model, and the most auditable. Regulators, investors, and compliance teams can independently verify every transaction without relying on provider reports.

The trade-off: higher gas costs (each signer's approval is an onchain transaction), slower execution (coordinating multiple signers takes time), and less flexibility for signer changes (adding or removing a signer requires an onchain transaction approved by the existing threshold).

### Hybrid: multisig with scoped permissions

The hybrid model combines a multisig base layer (Safe) with a permissions module (Zodiac Roles Modifier) that delegates specific, scoped execution rights to designated addresses. This gives the fund the security of multi-party approval for high-risk operations while enabling faster execution for pre-approved, constrained actions.

The [Zodiac Roles Modifier](https://docs.roles.gnosisguild.org) is an onchain permissions module that controls access at three levels: which smart contracts can be called, which functions within those contracts, and what argument values are acceptable. For example, a fund could allow its portfolio manager to execute swaps on Uniswap up to a specific dollar amount without requiring a full multisig vote, while still requiring multisig approval for any other action.

Organizations like ENS DAO, GnosisDAO, and Balancer already use this pattern for treasury management. [Karpatkey's DeFi-Kit](https://github.com/karpatkey/defi-kit) provides pre-built permission sets for common DeFi protocols, accelerating setup.

![Three custody models for onchain funds: MPC, multisig, and hybrid, with trade-offs for institutional managers](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-fund-custody/fig1-three-custody-models-compared.webp)

### Side-by-side comparison

| Dimension | MPC Wallet | Multisig (Safe) | Hybrid (Safe + Zodiac) |
|---|---|---|---|
| **Key management** | Distributed shards, never assembled | Independent keys, onchain threshold | Multisig base + scoped delegation |
| **Transparency** | Off-chain signing | Fully onchain, publicly verifiable | Onchain approvals + scoped actions |
| **Gas cost** | Low (single signature) | Higher (N onchain signatures) | Variable (depends on action type) |
| **Signer changes** | Off-chain, no gas | Onchain tx required | Onchain tx for signers, offchain for roles |
| **Policy engine** | Built-in (Fordefi, Fireblocks) | Via modules (Zodiac) | Native Zodiac permissions |
| **Chain support** | Any chain (chain-agnostic) | EVM chains (requires deployment) | EVM chains (Safe + module) |
| **Vendor dependency** | Yes (MPC provider) | No (open-source contracts) | Partial (open-source + optional tooling) |
| **Best for** | High-frequency, multi-chain | DAO treasury, audit-first | Institutional funds, delegated mgmt |

## Role-based permissions: the missing layer

Choosing between MPC and multisig addresses only half of the custody question. The other half is permissions: what is the curation wallet allowed to do with the vault's assets?

In a traditional fund, the investment management agreement (IMA) defines what the portfolio manager can and cannot do: asset class restrictions, concentration limits, counterparty exposure caps. Violations are caught by the compliance team after the fact, through periodic reviews.

Onchain, these constraints can be enforced before the fact, at the smart contract level. The curation wallet does not just need to be secure; it needs to be constrained.

### Three levels of onchain permissions

The Zodiac Roles Modifier enforces permissions at three levels:

- **Contract-level:** Which smart contracts can the role interact with? (e.g., only Aave, Compound, and Uniswap)
- **Function-level:** Which functions within those contracts? (e.g., supply and withdraw, but not borrow)
- **Argument-level:** What parameter values are acceptable? (e.g., maximum 50 ETH per swap, only USDC as collateral)

This creates an onchain equivalent of the investment management agreement. The rules are encoded in the smart contract, publicly verifiable, and enforced automatically: no compliance officer needed for real-time monitoring.

### MPC policy engines

MPC providers offer their own permission systems. Fordefi's policy engine allows role-based approvals with thresholds based on protocol, action type, amount, and time windows. Fireblocks provides a transaction authorization policy (TAP) that can enforce approval workflows, whitelisted destinations, and spending limits.

These operate off-chain within the MPC provider's infrastructure, offering similar functional outcomes (constrained execution) but without onchain verifiability. For institutions that already trust their MPC provider for key management, this may be an acceptable trade-off. For those requiring full onchain auditability, the Zodiac approach provides a stronger transparency guarantee.

![Custody architecture in a Lagoon vault: from investor deposits to strategy execution, with layered safeguards](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-fund-custody/fig2-custody-architecture-lagoon-vault.webp)

## How Lagoon integrates custody

Lagoon's vault architecture separates custody from fund operations by design. The ERC-7540 vault contract handles all investor-facing logic (deposits, redemptions, NAV, fees, share minting), while the curation wallet handles strategy execution. This separation means the custody model is a configuration choice, not a protocol constraint.

### Any address as curation wallet

During vault deployment via the [Lagoon Vault Factory](https://app.lagoon.finance/deploy), the manager specifies a curation wallet address. This can be:

- **A Fireblocks vault address** (MPC, for high-frequency, multi-chain strategies)
- **A Fordefi wallet address** (MPC, with built-in DeFi policy controls)
- **A Safe multisig address** (for DAO treasuries and transparent governance)
- **A Safe + Zodiac Roles Modifier address** (for institutional funds requiring delegated management with constraints)
- **Any other Ethereum-compatible address** (including hardware wallets for simpler setups)

### Governance separation enforced onchain

Regardless of the custody model, every Lagoon vault enforces role-based governance at the smart contract level. The vault administrator configures contract parameters. The valuation provider submits NAV updates. The curator (curation wallet) accepts valuations and executes strategy. The whitelist manager controls investor access. These roles cannot be bypassed; they are enforced by the ERC-7540 contract, not by the custody wallet.

This means the custody model protects *how* the strategy is executed, while the vault's governance roles protect *what* can happen within the fund's lifecycle. Together, they create a layered security model that maps to institutional internal controls.

For a step-by-step guide to deploying a vault with your chosen custody wallet, see [How to Deploy a Permissionless Vault on Lagoon](/blog/deploy-permissionless-vault).

<KeyTakeaways>
- **Custody in onchain funds is a configuration choice, not a protocol constraint.** The curation wallet (MPC, multisig, or hybrid) determines the fund's security model, operational speed, and auditability.
- **MPC wallets (Fireblocks, Fordefi) offer speed and chain-agnostic flexibility,** but signing happens off-chain. Best for high-frequency trading and multi-chain strategies.
- **Multisig wallets (Safe) provide full onchain transparency and no vendor dependency,** at the cost of higher gas and slower execution. Best for DAO treasuries and audit-first mandates.
- **Hybrid setups (Safe + Zodiac Roles Modifier) combine both models,** enabling scoped delegation with onchain constraints. Best for institutional funds with delegated management.
- **Lagoon is non-custodial infrastructure.** The protocol never holds keys or controls curation wallets. Custody remains entirely with the fund, enforced by 8+ audited smart contracts across 18+ EVM chains.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance/curation-solutions/safe-and-zodiac-roles-modifier">
Ready to evaluate custody options for your onchain fund? Explore Lagoon's curation wallet documentation to review Safe, Zodiac, and MPC integration guides, or deploy your first vault at [app.lagoon.finance](https://app.lagoon.finance/deploy).
</CTA>

## Going further

- [How to Deploy a Permissionless Vault on Lagoon](/blog/deploy-permissionless-vault) — Step-by-step guide to configuring your curation wallet during vault deployment.
- [Onchain Vaults vs. Traditional Funds: What Changes](/blog/onchain-vaults-vs-traditional-funds) — Broader comparison of onchain and traditional fund operations, including the custody dimension.

---

## Onchain Vaults vs. Traditional Funds: What Changes

> Onchain vaults replace manual fund administration with smart contracts. Compare settlement, fees, transparency, and governance side by side.

- URL: https://lagoon.finance/blog/onchain-vaults-vs-traditional-funds
- Date: 2026-03-12
- Author: Lagoon
- Category: DeFi

<Callout>
Onchain vaults encode the same fund operations (deposits, net asset value calculation, fee collection, redemptions) into smart contracts instead of manual processes. The result: settlement in hours instead of days, fees computed automatically instead of quarterly, and a fully auditable record that replaces periodic reports.
</Callout>

## Introduction

A $500 million fund pays $250,000 to $750,000 per year for administration services: net asset value (NAV) calculation, investor communications, fee reconciliation, and regulatory reporting. Most of this cost is driven not by the complexity of the work, but by the manual coordination required between four or five separate counterparties. Launching the fund in the first place takes 4 to 12 weeks of legal setup, admin onboarding, and service agreements before a single dollar is deployed.

Onchain vaults change this. By encoding fund operations into smart contracts, they compress settlement from days to hours, automate fee computation at every cycle, and produce a fully auditable record that replaces quarterly reports. JPMorgan's MONY fund, BlackRock's BUIDL ($2.9 billion across seven blockchains), and State Street's SWEEP on Solana are already running production capital through this infrastructure.

Here is what specifically changes when fund administration moves from manual processes to smart contracts, for institutional managers evaluating the shift.

## How traditional funds actually operate

To understand what onchain vaults change, it helps to map the traditional fund lifecycle clearly. A typical investment fund relies on a chain of intermediaries, each handling a specific piece of the process.

### The intermediary chain

When an investor subscribes to a traditional fund, their capital passes through multiple entities before being deployed:

- **The investor** submits a subscription document, typically via paper or email, along with KYC documentation.
- **A transfer agent** records the allocation, maintaining the fund's shareholder registry.
- **The fund administrator** calculates the net asset value, reconciling positions across databases and pricing sources.
- **A custodian** holds the underlying assets and processes settlement via wire transfer.
- **The portfolio manager** finally deploys the capital into the investment strategy.

A single deposit can touch four or five separate entities before it is reflected in the investor's position. Each handoff introduces latency, cost, and reconciliation risk.

![Traditional fund lifecycle showing five entities and multiple handoffs from investor to portfolio manager, with operational pain points](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-vaults-vs-traditional-funds/fig1-traditional-fund-lifecycle.webp)

*Figure 1: The traditional fund lifecycle, five entities, multiple handoffs, and 2-3 days to confirm a single deposit.*

### The cost of manual administration

Traditional fund administrators charge 10 to 25 basis points of AUM annually for services that include NAV calculation, investor communications, regulatory reporting, and fee processing. For a $500 million fund, that translates to $500,000 to $1,250,000 per year in administration costs alone.

These costs are not driven by complexity of the calculations; they are driven by the manual nature of the processes: reconciling data across fragmented systems, generating reports from siloed databases, and coordinating between multiple counterparties on different timelines.

## What onchain vaults replace

An onchain vault does not eliminate the need for fund management. Someone still makes investment decisions, someone still provides valuations, and investors still need to be onboarded. What changes is the execution layer. The roles persist, but the manual processes become programmable.

### The smart contract as operations hub

In an onchain vault built on the ERC-7540 standard (the async extension of ERC-4626), the vault smart contract handles:

- **Deposit and redemption processing.** Investors submit requests onchain. Assets are locked until settlement, then shares are minted at the forward price (the NAV calculated at settlement, not at the time of the deposit request).
- **NAV and valuation.** A designated valuation provider submits updated total asset values. The curator accepts valuations and triggers settlement.
- **Fee computation.** Management and performance fees are calculated automatically at every settlement, with high-water mark tracking built into the contract.
- **Governance enforcement.** Role-based permissions (vault administrator, curator, valuation provider, whitelist manager) are enforced onchain, creating separation of powers equivalent to institutional internal controls.

Lagoon's Vault Factory implements this architecture out of the box — managers deploy a production-ready ERC-7540 vault with all four governance roles configured, without writing contract code or negotiating service agreements.

![Onchain vault lifecycle showing ERC-7540 smart contract handling deposits, NAV, fees, and governance with benefits for institutional managers](https://storage.googleapis.com/lagoon-blog-media/blog/onchain-vaults-vs-traditional-funds/fig2-onchain-vault-lifecycle.webp)

*Figure 2: The onchain vault lifecycle, same fund operations, executed by auditable smart contracts instead of manual processes.*

### Mapping TradFi roles to onchain equivalents

| Traditional Role | Onchain Equivalent | What Changes |
|---|---|---|
| **Fund Administrator** | Valuation Provider | NAV submitted via oracle, verified onchain |
| **Transfer Agent** | Vault Smart Contract | Share registry is the ERC-20 token ledger |
| **Custodian** | Multisig / MPC Wallet | Flexible custody: Safe, Fireblocks, Fordefi |
| **Portfolio Manager** | Curator | Executes strategy, accepts valuations, settles |
| **Compliance Officer** | Whitelist Manager | KYC gatekeeping via onchain access control |

Onchain vaults do not remove the roles; they change how the roles are executed. A curator still makes investment decisions. A valuation provider still submits prices. But the coordination between them happens through a smart contract rather than through emails, spreadsheets, and wire transfers.

## What changes in practice

With these roles mapped, the next question is: what changes operationally across the dimensions that matter most to institutional managers? The differences are not cosmetic. They affect the speed, cost, transparency, and operational model of running a fund.

| Dimension | Traditional Fund | Onchain Vault |
|---|---|---|
| **Launch Time** | 4-12 weeks: legal setup, admin onboarding, service agreements, compliance review | Minutes: deploy via Vault Factory, no approvals, no minimum TVL |
| **NAV Calculation** | Daily, by fund administrator using spreadsheets and manual reconciliation | Per settlement cycle, by designated valuation provider with onchain verification |
| **Settlement** | T+1 to T+3: wire transfers, custodian processing, transfer agent recording | Near-instant once valuation is accepted; async flow handles real-world delays |
| **Fee Collection** | Quarterly invoicing, manual calculation, reconciliation between fund and admin | Automated at contract level, computed every settlement with HWM tracking |
| **Reporting** | Monthly or quarterly statements, periodic external audits | Real-time onchain data, publicly verifiable transaction history |
| **Custody** | Third-party custodian (single entity), limited operational flexibility | Multisig, MPC, or smart contract custody: choose based on compliance needs |
| **Audit Trail** | Internal records, annual external audits, trust-based verification | Complete onchain transaction history, independently verifiable by anyone |

### Launch time

Traditional funds require 4 to 12 weeks for legal setup, administrator onboarding, and service agreements. With platforms like Lagoon, deploying a vault takes minutes via a permissionless Vault Factory, with no team approvals, no minimum TVL, and no partnership agreements. This does not eliminate the legal work for regulated products, but it removes the infrastructure bottleneck.

### Settlement

Traditional settlement runs on T+1 to T+3 timelines, involving wire transfers between banks, custodian processing, and transfer agent recording. Onchain vaults using the ERC-7540 async pattern process settlement in hours: requests are submitted, the valuation provider proposes a NAV update, the curator accepts and settles, and investors claim their shares. The async design accommodates real-world delays (off-chain assets, compliance checks) without the manual overhead.

### Transparency and audit

In traditional structures, investors rely on administrator reports that arrive monthly or quarterly. Portfolio breakdowns, fee calculations, and transaction histories are internal, verified only through periodic external audits. In an onchain vault, every transaction, fee, and allocation is recorded on a public ledger. Investors do not need to trust the report; they can verify it independently, in real time.

<KeyTakeaways>
- **Onchain vaults encode the same fund operations into smart contracts:** deposits, NAV, fees, redemptions, and governance all execute programmatically instead of manually.
- **Settlement compresses from days to hours:** ERC-7540's async pattern handles real-world delays while eliminating manual intermediary handoffs.
- **Transparency is structural, not periodic:** every transaction, fee, and allocation is recorded on a public ledger and independently verifiable.
- **TradFi roles map directly to onchain equivalents:** fund administrators become valuation providers, transfer agents become token registries, and custodians become flexible (multisig, MPC, or smart contract).
- **Major institutions are already in production:** JPMorgan, BlackRock, State Street, and Franklin Templeton all operate live tokenized funds onchain.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance">
Want to see how onchain fund infrastructure works in practice? Explore the Lagoon documentation to review vault architecture, governance roles, and fee structures.
</CTA>

## Going further

- [ERC-7540 Explained: Async Vaults for Real-World Assets](/blog/erc-7540-explained) — A deeper technical dive into the async settlement standard behind these vaults.
- [What Is Onchain Asset Management? A Practical Guide](/blog/what-is-onchain-asset-management) — The broader context for understanding onchain fund infrastructure.

---

## ERC-7540 Explained: Async Vaults for Real-World Assets

> ERC-7540 extends ERC-4626 with async deposit and redemption flows, enabling onchain vaults to handle real-world assets with T+1/T+2 settlement.

- URL: https://lagoon.finance/blog/erc-7540-explained
- Date: 2026-03-10
- Author: Lagoon
- Category: Technical

<Callout>
ERC-7540 is an Ethereum standard that extends ERC-4626 with asynchronous deposit and redemption flows. Instead of requiring instant, atomic settlement, it introduces a request-then-claim pattern: investors submit a request, a valuation provider updates the NAV, the curator settles, and investors claim their shares. This design is essential for vaults holding real-world assets, private credit, or any strategy requiring off-chain settlement. Lagoon builds its entire vault infrastructure on ERC-7540.
</Callout>

## Introduction

DeFi vaults were designed for a world where everything settles in the same block. You deposit USDC, shares are minted, and the transaction is complete before the next block is produced. For highly liquid strategies this works. ERC-4626, the tokenized vault standard, codified this pattern and became the backbone of DeFi's vault ecosystem.

But as onchain asset management moves beyond liquid DeFi strategies into tokenized treasuries, private credit, and institutional fund structures, that assumption breaks. Real-world assets don't settle in 12 seconds. They settle in days. Wire transfers take T+1 or T+2. NAV calculations depend on off-chain valuations. KYC checks happen outside the blockchain. Forcing these workflows into a synchronous vault creates architectural failures: unbacked share issuance, settlement reverts, and compliance deadlocks.

**ERC-7540** solves this. Finalized in June 2024 and now recognized on ethereum.org, it extends ERC-4626 with asynchronous deposit and redemption flows. The standard introduces a request-then-claim pattern that decouples user intent from execution, enabling vaults to handle settlement delays, batch processing, and external valuation without breaking the onchain interface.

Lagoon builds its entire vault infrastructure on ERC-7540.

## Why ERC-4626 is not enough

ERC-4626 standardized how tokenized vaults work on Ethereum. It defined a common interface for deposits, withdrawals, share minting, and share burning, and it did this well for synchronous, liquid strategies. Protocols like Yearn, Morpho, and Aave adopted it widely.

The problem is the atomicity assumption. ERC-4626 requires that every deposit and withdrawal completes within a single transaction. When you call `deposit()`, the vault must immediately accept your assets and mint shares. When you call `redeem()`, shares are burned and assets are returned, all in the same block.

This breaks down for three categories of assets and strategies:

- **Real-world assets with T+1 or T+2 settlement.** Tokenized treasuries, private credit, and structured products depend on bank wires and custodial transfers that take days, not seconds. Minting shares before settlement confirms leaves the vault under-collateralized.

- **Strategies requiring external valuation.** Any vault that depends on off-chain NAV inputs (a third-party valuation provider, an audited price feed, or a manual appraisal) cannot determine the correct share price at the moment of deposit. The price needs to be calculated after the request, not during it.

- **Institutional compliance requirements.** KYC/AML checks, investor eligibility verification, and regulatory reporting cannot execute within the gas limit of a single Ethereum transaction. These processes need a window between request submission and settlement.

![Three ERC-4626 limitations and how ERC-7540 solves each: unbacked issuance, settlement reverts, and compliance deadlocks](https://storage.googleapis.com/lagoon-blog-media/blog/erc-7540-explained/why-erc4626-breaks.webp)

*Figure 1: Why ERC-4626 breaks for real-world assets, and how ERC-7540 addresses each limitation*

ERC-7540 was developed to address exactly these constraints. Co-authored by teams from Centrifuge, Superform, and Maple Finance, it went through over nine months of community review before being finalized as an Ethereum standard in June 2024.

## How ERC-7540 works: the request-claim pattern

The core innovation of ERC-7540 is simple: it separates the request from the fulfillment. Instead of a single atomic transaction, every deposit and redemption goes through a two-step lifecycle.

### The three states

Every request in an ERC-7540 vault moves through three states:

- **Pending.** The user submits a deposit or redemption request. Assets (for deposits) or shares (for redemptions) are locked in the vault, but no shares are minted or assets returned yet. The request is waiting for processing.

- **Claimable.** The vault's settlement process completes: a valuation is accepted, NAV is updated, pending requests are processed at the settlement price. The request is now ready to be claimed.

- **Claimed.** The user calls the standard ERC-4626 claim function (`deposit`/`mint` for deposits, `redeem`/`withdraw` for redemptions) to receive their shares or assets. The transaction is complete.

![State machine showing Pending to Claimable to Claimed with deposit and redemption flows](https://storage.googleapis.com/lagoon-blog-media/blog/erc-7540-explained/request-claim-lifecycle.webp)

*Figure 2: The ERC-7540 request-claim lifecycle, both deposits and redemptions follow the same three-state pattern*

### Forward pricing

A critical difference from ERC-4626: the exchange rate between assets and shares is determined at fulfillment time, not at request time. When you call `requestDeposit()`, you don't know exactly how many shares you'll receive. The price is calculated when the vault's NAV updates, typically at the next settlement window.

This is called forward pricing, and it's how traditional funds operate. Subscriptions are submitted before the NAV strike, and allocations happen at the next published price. ERC-7540 encodes this into a standard smart contract interface, preventing arbitrage attacks where users could exploit stale pricing data during off-chain settlement windows.

### Delegated management

ERC-7540 introduces a controller parameter that enables institutional custody workflows. A regulated custodian or fund administrator can act as the controller to manage deposit and redemption flows on behalf of investors, handling KYC verification and compliance checks without needing full custody of the underlying tokens. This is essential for regulated entities operating under fiduciary obligations.

## ERC-4626 vs. ERC-7540: side-by-side comparison

The two standards are not competitors. ERC-7540 extends ERC-4626: it is a superset, not a replacement. The choice depends on your vault's underlying assets and settlement requirements.

| Dimension | ERC-4626 (Synchronous) | ERC-7540 (Asynchronous) |
|---|---|---|
| **Deposit flow** | Atomic: `deposit()` mints shares instantly | Two-step: `requestDeposit()` then claim after settlement |
| **Redemption flow** | Atomic: `redeem()` burns shares instantly | Two-step: `requestRedeem()` then claim after settlement |
| **Pricing** | Exchange rate known at transaction time | Forward pricing: rate set at fulfillment, not request |
| **Settlement** | Same-block, same-transaction | Supports T+1, T+2, or custom settlement cycles |
| **Off-chain assets** | Not supported (requires instant liquidity) | Native support via async processing window |
| **KYC / compliance** | Must complete within single transaction | Off-chain checks between request and claim phases |
| **Use cases** | Liquid DeFi strategies (yield farming, staking) | RWAs, private credit, cross-chain, institutional funds |

![Side-by-side comparison of ERC-4626 synchronous single-transaction flow versus ERC-7540 four-step asynchronous flow](https://storage.googleapis.com/lagoon-blog-media/blog/erc-7540-explained/erc4626-vs-erc7540.webp)

*Figure 3: Synchronous vs. asynchronous vault flows: ERC-4626's single-transaction model versus ERC-7540's multi-step request-claim pattern*

Vaults can also implement hybrid models: synchronous deposits with asynchronous redemptions, or vice versa. This flexibility lets protocols match their vault mechanics to the actual liquidity profile of their underlying assets.

## How Lagoon implements ERC-7540

Lagoon builds its entire vault infrastructure on ERC-7540. Every vault deployed through Lagoon's permissionless Vault Factory is an ERC-7540 contract with built-in governance roles, fee logic, and settlement mechanics.

### The Lagoon deposit workflow

Here is how a deposit flows through a Lagoon vault:

- **Step 1: Request deposit.** The investor transfers assets (e.g., USDC) to the vault via `requestDeposit()`. Funds enter the Pending state, waiting for settlement.

- **Step 2: Propose valuation.** A designated price oracle submits an updated total asset valuation for the vault. This can be an automated feed or a third-party valuation provider.

- **Step 3: Accept valuation and settle.** The vault curator reviews and accepts the proposed valuation. This triggers settlement: fees are computed, pending deposit requests are processed, and shares are minted at the settlement price.

- **Step 4: Claim shares (optional).** Investors claim their newly minted share tokens. If they don't claim, shares remain in the vault and continue to accrue yield.

### The Lagoon redemption workflow

Redemptions follow the same pattern in reverse. An investor requests redemption by transferring share tokens to the vault. After the next valuation cycle, the curator accepts the updated NAV and settles. If the vault has sufficient underlying assets available, redemption requests are processed and the investor can withdraw their assets.

This design mirrors traditional fund subscription and redemption cycles. Capital calls are submitted, processed at a cut-off, and allocated at a NAV strike. The difference is that the entire workflow is onchain, auditable, and governed by smart contract rules rather than manual administration.

### Governance separation

Lagoon enforces role-based permissions across every ERC-7540 vault. The vault administrator configures the contract. A designated valuation provider submits NAV updates. The curator accepts valuations and executes investment strategy. A whitelist manager controls investor access. These roles are enforced onchain, creating a separation of powers equivalent to institutional internal controls in traditional finance.

This separation is a structural requirement of the ERC-7540 pattern, not an optional feature. The async settlement window only works when there's a trusted valuation step between request and claim, and when the entity settling requests is distinct from the entity submitting valuations.

## Why ERC-7540 matters for the future of onchain funds

The tokenized asset market is growing rapidly. BlackRock's BUIDL fund has surpassed $2.9 billion in AUM across seven blockchains. Tokenized U.S. Treasuries alone represent over $8.7 billion. The broader RWA tokenization market has reached approximately $24-36 billion in early 2026, with analysts projecting growth toward $100 billion by year-end. Boston Consulting Group projects the total tokenized asset market could reach $16 trillion by 2030.

Every one of these products needs a vault standard that can handle real-world settlement timelines. ERC-4626 cannot do this. ERC-7540 can.

Lagoon's ERC-7540 foundation supports batch settlement at a single valuation point, delayed settlement and external valuation logic, capital calls and subscription cycles that mirror traditional fund operations, and compliance workflows that happen off-chain between the request and claim phases.

As Ethereum's official recognition of ERC-7540 in January 2025 confirmed, this standard is becoming foundational infrastructure for the next generation of onchain finance.

<KeyTakeaways>
- **ERC-7540 extends ERC-4626 with asynchronous deposit and redemption flows,** introducing a request-then-claim pattern that decouples user intent from settlement execution.
- **ERC-4626 breaks for real-world assets:** synchronous settlement cannot handle T+1/T+2 cycles, external valuation, or compliance checks that happen off-chain.
- **Forward pricing prevents arbitrage:** exchange rates are determined at settlement, not at request time, mirroring how traditional funds price subscriptions.
- **Lagoon builds entirely on ERC-7540:** every vault uses async settlement with role-based governance, valuation providers, and institutional fee logic.
- **The RWA market demands this standard:** $24-36B in tokenized assets today, projected to reach $100B+ by end of 2026, all requiring async settlement infrastructure.
</KeyTakeaways>

<CTA href="https://app.lagoon.finance">
Want to understand Lagoon's ERC-7540 implementation in detail? Explore the [Lagoon documentation](https://docs.lagoon.finance) to review vault architecture, deposit and withdrawal flows, and governance roles, or deploy your first ERC-7540 vault at [app.lagoon.finance](https://app.lagoon.finance).
</CTA>

---

## What Is Onchain Asset Management? A Practical Guide

> Onchain asset management uses smart contract vaults to handle deposits, NAV, fees, and reporting, replacing manual fund ops with programmable infrastructure.

- URL: https://lagoon.finance/blog/what-is-onchain-asset-management
- Date: 2026-03-05
- Author: Lagoon
- Category: Product

<Callout>
Onchain asset management moves fund operations (deposits, redemptions, NAV calculation, fee collection, and reporting) onto blockchain-based smart contracts called vaults. Instead of relying on manual fund administration, spreadsheets, and T+2 settlement, managers use programmable infrastructure that runs 24/7 with full onchain transparency. This guide explains what it is, why it matters for institutional managers, and how the technology works in practice.
</Callout>

## Introduction

The asset management industry runs on infrastructure built decades ago. Launching a fund still takes weeks of legal setup, manual administrator onboarding, and bespoke integrations. Net asset value calculation is often messy and fragmented, based on spreadsheets and reconciliation between different parties. Redemptions take days to settle. Reporting is quarterly, at best. For an industry managing over $140 trillion globally, the operational stack has barely changed since the 1990s.

But that is starting to shift. In 2025, JPMorgan launched its first tokenized money market fund on Ethereum. BlackRock's BUIDL fund surpassed $2.9 billion. State Street and Galaxy Digital announced their SWEEP fund to bring tokenized liquidity onchain. These are not experiments; they are production systems processing real capital through smart contracts.

Onchain asset management is the infrastructure layer that makes this possible. It replaces manual fund administration with programmable vaults: smart contracts that handle deposits, redemptions, NAV updates, fee calculations, and governance roles. All onchain, all auditable, all in real time.

## What onchain asset management actually means

Onchain asset management is not just about putting a fund's token on a blockchain. It means moving the core operational machinery of a fund, the parts traditionally handled by administrators, custodians, and transfer agents, into smart contracts that execute automatically.

In a traditional fund, an investor submits a subscription, an administrator processes it, a transfer agent records the allocation, and a custodian settles the assets. Each step involves separate systems, separate counterparties, and separate timelines. A single deposit can touch four or five entities before it's reflected in the investor's position.

In an onchain fund, this entire workflow is compressed into a vault: a smart contract that accepts deposits, mints share tokens representing ownership, tracks the net asset value, and processes redemptions according to pre-defined rules. The roles still exist (someone still manages the strategy, someone still provides valuations), but the operational layer is code rather than manual process.

### The core components

Every onchain vault consists of a few building blocks. Deposits and redemptions are the investor-facing flows. An investor sends an underlying asset (like USDC) to the vault and receives share tokens in return. To exit, they return their shares and receive the underlying asset back, proportional to their ownership of the vault.

NAV and settlement govern how the vault prices its shares. A valuation provider, either an automated feed or a designated third party, submits updated total asset values. The vault uses these to calculate a price per share and settle pending deposit and redemption requests.

Fee logic is embedded in the contract. Management fees accrue over time based on assets under management. Performance fees are calculated against a high-water mark, ensuring the manager only earns on net new gains. All of this happens at the smart contract level: no invoices, no manual calculations, no quarterly fee reconciliations.

Governance and roles separate who can do what. A vault administrator configures the contract. A curator executes the investment strategy. A valuation provider submits NAV updates. A whitelist manager controls investor access. These roles are enforced onchain, creating a separation of powers that mirrors institutional compliance requirements.

![Lagoon protocol architecture: vault roles, data flows, and governance separation](https://storage.googleapis.com/lagoon-blog-media/blog/what-is-onchain-asset-management/lagoon-protocol-architecture.webp)

## How onchain funds differ from traditional structures

The differences between onchain and traditional fund operations are not cosmetic. They change the speed, transparency, and cost structure of running a fund.

| Dimension | Traditional Fund | Onchain Vault |
|---|---|---|
| **Launch time** | 4–12 weeks (legal setup, admin onboarding) | Minutes (smart contract deployment) |
| **NAV calculation** | Daily, by fund administrator | Per settlement cycle, by valuation provider |
| **Settlement** | T+1 to T+3 (wire transfers, custodian processing) | Near-instant once valuation is accepted |
| **Fee collection** | Quarterly invoicing, manual reconciliation | Automated at contract level, every settlement |
| **Reporting** | Monthly or quarterly statements | Real-time onchain data, publicly verifiable |
| **Investor access** | Paper subscriptions, KYC packets | Onchain whitelisting, tokenized share ownership |
| **Custody** | Third-party custodian (single entity) | Multisig, MPC, or smart contract custody |
| **Audit trail** | Internal records, periodic external audits | Complete onchain transaction history |

![Traditional vs. onchain fund lifecycle: four-step comparison of launch, administration, reporting, and settlement](https://storage.googleapis.com/lagoon-blog-media/blog/what-is-onchain-asset-management/traditional-vs-onchain-fund-lifecycle-v3.webp)

The most significant shift is in transparency. In a traditional structure, investors rely on the administrator's reports to know what the fund is doing. NAV figures arrive on a schedule set by the administrator — daily, monthly, or less often — and portfolio breakdowns once a quarter at best. In an onchain vault, every allocation, every fee, every settlement is recorded on a public ledger. Investors don't need to trust the report; they can verify it.

This does not mean onchain funds are fully automated. Discretionary strategies still require a human curator making investment decisions. Off-chain assets still require oracles and external valuation. But the administrative layer, the plumbing that connects all the parts, is programmable and transparent in a way that traditional infrastructure simply is not.

## Why institutional managers are paying attention now

Onchain asset management has existed in various forms since the early days of DeFi yield vaults. What's different in 2026 is the institutional signal.

JPMorgan's MONY fund (My OnChain Net Yield) launched on Ethereum in December 2025 with a $100 million initial investment, investing exclusively in U.S. Treasuries. BlackRock's BUIDL fund surpassed $2.9 billion in assets under management. State Street and Galaxy Digital announced their SWEEP fund, a tokenized liquidity vehicle on Solana using PYUSD for subscriptions and redemptions. Franklin Templeton's onchain money market fund operates across Ethereum and Solana with over $800 million in assets.

These are not crypto-native experiments. These are the largest financial institutions in the world choosing to run real capital through onchain infrastructure.

The Keyrock Onchain Asset Management Report estimates the market at $35 billion in AUM as of 2025, with a base-case projection of $64 billion by end of 2026. Discretionary strategies, the category closest to traditional hedge fund management, grew 738% year-to-date in 2025, signaling that active managers are finding product-market fit onchain.

![Onchain asset management market growth, 2023–2026E (Source: Keyrock)](https://storage.googleapis.com/lagoon-blog-media/blog/what-is-onchain-asset-management/onchain-asset-management-market-growth.webp)

Three macro factors are driving this acceleration. First, regulatory clarity: Singapore's MAS framework accommodates tokenized yield products, and the UK's FCA positions tokenization as a critical efficiency gain for its £14 trillion asset management industry. Second, infrastructure maturity: standards like ERC-7540 provide the technical primitives for institutional-grade deposit and withdrawal flows. Third, cost pressure: traditional fund administrators charge 10–25 basis points of AUM for services that smart contracts can perform more efficiently and more transparently.

## The role of ERC-7540 in institutional vaults

Not all vault standards are created equal. Early DeFi vaults used ERC-4626, a standard designed for synchronous, atomic deposits and withdrawals. That works for simple yield strategies where assets are always liquid. But it breaks down for institutional use cases.

When a fund needs to process capital calls, apply KYC checks, calculate NAV with off-chain inputs, or handle assets with multi-day settlement cycles, synchronous deposits are not viable. The vault needs to separate the request from the fulfillment: an investor requests a deposit, the manager processes it at the next settlement window, and shares are minted based on the NAV at that point.

This is exactly what ERC-7540 provides. It extends ERC-4626 with asynchronous deposit and redemption flows. The standard introduces a request-then-claim pattern: an investor submits a deposit request, a valuation provider proposes an updated NAV, the curator accepts the valuation and settles pending requests, and the investor claims their newly minted shares.

This maps directly to how traditional funds operate. Subscriptions are submitted, processed at a cut-off, and allocated at a NAV strike. ERC-7540 encodes this workflow into a standard interface that any smart contract can implement, making it the technical foundation for institutional-grade onchain funds.

The standard also supports delegated management: a custodian or fund administrator can act on behalf of investors, handling compliance checks and settlement workflows without needing full custody of the underlying tokens. This is essential for regulated entities operating under fiduciary obligations.

<KeyTakeaways>
- **Onchain asset management replaces manual fund operations with smart contract vaults** that handle deposits, NAV, fees, and reporting programmatically.
- **Transparency is structural, not optional:** every transaction, fee, and allocation is recorded on a public ledger and independently verifiable.
- **Major institutions are moving to production:** JPMorgan, BlackRock, State Street, and Franklin Templeton all have live tokenized funds onchain.
- **ERC-7540 provides the institutional-grade standard:** asynchronous deposit/redemption flows that mirror traditional subscription and redemption cycles.
- **The market is reaching scale:** $35B AUM in 2025, projected to reach $64B by end of 2026, with discretionary strategies growing fastest.
</KeyTakeaways>

<CTA href="https://docs.lagoon.finance">
Want to see how it works in practice? Explore the Lagoon documentation to understand vault architecture, governance roles, and fee structures.
</CTA>

---

## How to Deploy a Permissionless Vault on Lagoon in Minutes

> Deploy an onchain vault across 18+ EVM chains with no approvals, no minimum TVL, and no operational overhead. Here's how Lagoon's Vault Factory works.

- URL: https://lagoon.finance/blog/deploy-permissionless-vault
- Date: 2026-03-04
- Author: Lagoon
- Category: Product

<Callout>
Lagoon's Vault Factory lets anyone deploy a fully onchain vault in minutes, across 18+ EVM networks, with no team approvals or minimum TVL. You choose a chain, pick an asset, assign governance roles, set fees, and deploy. The contracts are backed by 8+ audits from NethermindSec and Trail of Bits. This guide walks through each step.
</Callout>

## Introduction

Launching an onchain vault has historically meant navigating protocol-specific integrations, waiting on team approvals, and committing capital before you could even test your strategy. For curators and asset managers, this friction slowed experimentation and made multi-chain deployment impractical.

Lagoon's Vault Factory changes this. It enables fully permissionless vault deployment: anyone can spin up a production-ready vault across 18+ EVM chains in a single session. No gatekeepers, no operational overhead, no minimum TVL required.

This article walks through the six-step deployment process and explains what each configuration choice means for your vault.

<VideoPlayer src="https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/vault-deployment-walkthrough.mp4" />

## Why permissionless deployment matters

Traditional vault platforms require curators to commit before they can prove anything. You need a minimum TVL, a partnership agreement, or protocol approval just to get started. That model penalizes experimentation and testing.

With Lagoon, curators can launch empty vaults in production or staging environments, test multi-chain strategies freely, and scale on their own terms when they're ready. The barrier is gone: if you have a wallet and a strategy, you can deploy.

**Important:** Once deployed, some contract parameters are immutable, while others can only be changed after a time-lock period. Review your configuration carefully before confirming.

## Six steps to deploy your vault

### Step 1: select your network

Choose from 18+ supported EVM chains including Ethereum Mainnet, Arbitrum, Base, and more. If you need a specific chain that isn't listed, the Lagoon team can add it on request.

![Lagoon Vault Factory network selector showing Ethereum, Arbitrum, Base, and 15+ more EVM chains](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/select-network-chains.webp)

| Supported Networks | Status |
| --- | --- |
| Ethereum Mainnet | Live |
| Arbitrum | Live |
| Base | Live |
| + 15 additional EVM chains | Live |
| Custom chain requests | On request |

### Step 2: define asset & symbol

Pick an underlying asset from the preset list or add any custom ERC-20 token address. Then assign a ticker symbol for your vault share token (e.g., lagUSDC). This symbol is how LPs will identify your vault onchain.

![Lagoon Vault Factory asset selector showing ETH, BTC, USDC, USDT, and custom ERC-20 token option](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/define-asset-tokens.webp)

### Step 3: add your curation wallet

Connect the address that will manage vault assets. This can be a multisig (Safe, Squads), an MPC wallet (Fireblocks, Fordefi), or any other curation address. The curation wallet has execution authority over the vault's assets.

![Lagoon Vault Factory curation wallet options: Safe multisig, Fireblocks, Fordefi, MetaMask, and more](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/curation-wallet-options.webp)

### Step 4: configure governance

Assign roles and distribute permissions across your team. Lagoon's governance model separates concerns into distinct roles:

| Role | Responsibility |
| --- | --- |
| Vault Administrator | Top-level admin with full configuration control |
| Valuation Provider | Responsible for NAV calculations and asset pricing |
| Delay Proxy Admin | Authority over contract upgrades (time-locked) |
| Whitelist Manager | Controls investor access (if whitelisting is enabled) |
| Security Council | Emergency safety role (coming Q1) |

![Lagoon vault governance roles: Administrator, Valuation Provider, Delay Proxy Admin, Whitelist Manager, Security Council](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/governance-roles.webp)

### Step 5: set your fee structure

Define performance fees and management fees, and designate the address that receives fee payouts. Lagoon supports high-water mark tracking to ensure performance fees are only charged on new gains.

*Coming soon:* entry and exit fee types will be available in the next protocol iteration.

![Lagoon vault fee configuration: performance fees, management fees, and upcoming entry/exit fees](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/fee-structure-types.webp)

### Step 6: review and deploy

Review your full configuration. If anything needs adjustment, you can reset with a single click. Once confirmed, your vault is deployed onchain and immediately accessible.

![Lagoon vault deployment architecture: one asset, one vault, one share token, with governance and fee structure layers](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/deployment-review-diagram.webp)

Each deployed vault gets a lightweight UI and a unique shareable link for LP onboarding:

`app.lagoon.finance/vault/[CHAIN_ID]/[VAULT_ADDRESS]`

## After deployment: what you can configure

![Lagoon vault user interface showing live vault with TVL, APR, chain, and curator details](https://storage.googleapis.com/lagoon-blog-media/blog/deploy-permissionless-vault/vault-user-interface.webp)

Currently, contract parameter changes (fees, roles, whitelist updates, sync deposit module, vault closure) require proxy verification and block explorer interaction. A dedicated configuration UI is in development.

Vaults deployed through the factory automatically receive access to new protocol upgrades on an opt-in basis; no redeployment required.

## Security

Lagoon's smart contracts have undergone 8+ audits by **NethermindSec** and **Trail of Bits**. The vault architecture is built on the ERC-7540 standard, which provides asynchronous deposit and withdrawal flows designed for real-world asset management use cases.

<KeyTakeaways>
- **Permissionless:** Anyone can deploy a vault: no approvals, no partnerships, no minimum TVL.
- **Multi-chain:** 18+ EVM networks supported out of the box, with custom chain requests available.
- **Production-ready in minutes:** Six-step configuration, from chain selection to live deployment.
- **Audited:** 8+ security audits by NethermindSec and Trail of Bits on the underlying smart contracts.
- **Upgradeable:** Opt-in protocol upgrades without redeployment.
</KeyTakeaways>

<CTA href="https://app.lagoon.finance/deploy">
Ready to deploy? Launch your first vault. The factory is live across all supported chains.
</CTA>
