DeFi Tools

DeFi Protocol Risk Scorecard

Spot the edge. Swoop in.

Document evidence and unknowns across nine DeFi risk dimensions before using a protocol. Critical unknowns remain visible as exposure constraints, not hidden in an aggregate score.

Educational tool only. Results are scenarios based on user-entered assumptions, not investment advice, price forecasts, or safety ratings. DeFi positions can result in partial or total loss of principal.

Protocol Risk Scorecard

Complete each section based on your own research. Unknown answers stay unknown — they are never assigned neutral points. A critical unknown prevents any reassuring overall label.

0 of 9 sections answered
1 Exact Deployment Not started

Record the exact scope of this review. These details appear in the summary and any export.

Are contract addresses verified on a block explorer? Critical
Hard stop — contract verification unknown Unverified contracts cannot be independently reviewed. Treat this as a blocking exposure constraint.
Are official sources cross-checked against the deployment? Material
Are legacy or deprecated contracts excluded from scope? Material
Independent audits exist and cover the exact deployment? Critical
Hard stop — audit evidence unknown or absent Without a scoped audit covering this exact deployment, the contract attack surface cannot be assessed.
Bug bounty program active and in scope for this deployment? Material
On-chain monitoring and incident alerts documented? Material
Integrated protocols (composability dependencies) are identified? Material
Upgrade authority (proxy admin / owner) is known and documented? Critical
Hard stop — upgrade authority unknown An unknown upgrade key means the protocol can be modified without warning. Treat as a blocking exposure constraint.
Pause, freeze, or emergency powers are documented with constraints? Material
Governance participation is active and concentration is documented? Material
Timelock delay is sufficient for users to exit before changes apply? Critical
Hard stop — timelock unknown or absent Without a timelock, protocol changes can take effect immediately with no exit window for users.
Underlying asset issuer and reserve model are documented? Critical
Hard stop — collateral or stablecoin design cannot be evaluated If you cannot identify the reserve model and redemption path, the floor value of the position cannot be assessed.
Wrapper and bridge risks for any non-native assets are documented? Material
Collateral factors, caps, and concentration are documented? Material
Oracle provider, source markets, and manipulation resistance are documented? Critical
Hard stop — oracle source unknown Oracle manipulation is a top-5 DeFi exploit vector. An unknown oracle source is a critical unresolved risk.
Fallback oracle behavior on stale data or network outage is documented? Material
Exit route is fully described and can be completed without a front-end? Critical
Hard stop — exit route cannot be described If you cannot describe a complete exit path (including a direct contract call if the front-end is unavailable), this is a blocking exposure constraint.
TVL, available liquidity, and utilization are documented? Material
Stressed price impact for position size is calculated? Contextual
Yield source is identified — who pays and why? Critical
Hard stop — yield source cannot be identified If you cannot identify who pays the yield and why, the sustainability of returns and risk to principal cannot be assessed.
Token emissions schedule and unlock events are documented? Material
Bad-debt handling and loss socialization mechanism are documented? Material
Front-end and RPC dependencies are identified and fallbacks exist? Material
Postmortems for past incidents are published and accessible? Material
Emergency communication channels are known and monitored? Contextual

Document your personal exposure rules before entering. These are constraints you set, not protocol parameters.

Maximum exposure and shared dependency limits are defined? Critical
Hard stop — user cannot tolerate complete loss If no maximum exposure or loss tolerance has been defined, this scorecard cannot establish readiness to enter a position.
Gas reserve, emergency conditions, and action thresholds are defined? Material
Review cadence and re-review triggers are defined? Contextual

Review Summary

Section-by-section evidence summary
Section Strong Some Weak Unknown N/A Status
Disclaimer: This scorecard is for educational purposes only. It does not certify safety, predict outcomes, or constitute investment advice. Results reflect only the evidence you have documented. Reviewed: .

About This Scorecard

This tool applies a structured evidence-documentation framework across nine risk dimensions common to DeFi protocols: deployment identity, contract security, privileged control, asset quality, oracle integrity, liquidity depth, economic sustainability, operational resilience, and user position policy.

No aggregate "safe" label is assigned. A single numerical score can mask a critical unknown. Instead, the tool surfaces section-level evidence quality and flags hard stops — conditions where evidence is insufficient for the reviewed deployment regardless of other scores.

Rating labels

Scorecard overall rating labels and their meaning
LabelMeaning
Evidence substantially documentedAll critical questions answered with at least some evidence; no hard stops triggered; most questions at medium or high confidence.
Evidence partially documentedNo critical hard stops, but one or more sections have material unknowns or low confidence evidence.
Material unknownsMultiple unknowns across non-critical questions, or weak evidence on critical items. Position requires further research before entry.
Critical unknownsOne or more hard-stop conditions triggered. Evidence is insufficient. These unknowns must be resolved or treated as permanent exposure constraints.
Review incompleteFewer than three sections have any answers. Summary not generated.

Hard-stop conditions

A hard stop is triggered when a critical question receives an Unknown or Weak evidence answer. Hard stops do not claim a protocol is fraudulent — they mean evidence is insufficient for the reviewed scope. Hard stops that remain unresolved prevent a reassuring overall label.

Supporting Lessons