DeFi Tools
DeFi Protocol Risk Scorecard
Investment Education, Research & Tools for Smarter Decisions.
Document evidence and unknowns across nine DeFi risk dimensions before using a protocol. Critical unknowns remain visible as exposure constraints, not hidden in an aggregate score.
Direct Answer
The DeFi Protocol Risk Scorecard documents evidence and unknowns across nine risk dimensions before you use a protocol: deployment identity, contract security, privileged control, asset quality, oracle integrity, liquidity depth, economic sustainability, operational resilience, and user position policy. It deliberately assigns no aggregate "safe" label, because a single number can mask a critical unknown, and instead reports section-level evidence quality and triggers a hard stop whenever a critical question is answered Unknown or with weak evidence. A hard stop does not claim a protocol is fraudulent; it means evidence is insufficient for the deployment you reviewed, so the unknown stays visible as an exposure constraint.
Educational tool only. Results are scenarios based on user-entered assumptions, not investment advice, price forecasts, or safety ratings. DeFi positions can result in partial or total loss of principal.
Protocol Risk Scorecard
Complete each section based on your own research. Unknown answers stay unknown, they are never assigned neutral points. A critical unknown prevents any reassuring overall label.
Review Summary
| Section | Strong | Some | Weak | Unknown | N/A | Status |
|---|
About This Scorecard
This tool applies a structured evidence-documentation framework across nine risk dimensions common to DeFi protocols: deployment identity, contract security, privileged control, asset quality, oracle integrity, liquidity depth, economic sustainability, operational resilience, and user position policy.
No aggregate "safe" label is assigned. A single numerical score can mask a critical unknown. Instead, the tool surfaces section-level evidence quality and flags hard stops, conditions where evidence is insufficient for the reviewed deployment regardless of other scores.
Rating labels
| Label | Meaning |
|---|---|
| Evidence substantially documented | No hard stops triggered; every section has at least one answered question; no question anywhere was answered Weak or Unknown. |
| Evidence partially documented | No critical hard stops, but one or more sections have material unknowns or low confidence evidence. |
| Material unknowns | No critical hard stops triggered, but more than two Unknown answers or more than three Weak-evidence answers across non-critical questions. Position requires further research before entry. |
| Critical unknowns | One or more hard-stop conditions triggered. Evidence is insufficient. These unknowns must be resolved or treated as permanent exposure constraints. |
| Review incomplete | Fewer than three sections have any answers. Summary not generated. |
Hard-stop conditions
A hard stop is triggered when a critical question receives an Unknown or Weak evidence answer. Hard stops do not claim a protocol is fraudulent, they mean evidence is insufficient for the reviewed scope. Hard stops that remain unresolved prevent a reassuring overall label.
- Contract addresses cannot be verified on a block explorer
- Audit scope does not cover the exact deployment
- Upgrade or custody key identity is unknown
- Timelock is absent or its delay is unknown
- Exit route cannot be fully described
- Oracle source cannot be identified
- Yield source (who pays and why) cannot be identified
- Collateral or stablecoin design cannot be evaluated
- User's loss tolerance or maximum exposure is undefined
Supporting Lessons
References
- Ethereum.org: DeFi Overview: background on smart-contract, oracle, and protocol risk categories this scorecard's due-diligence sections evaluate.
- CFTC: Digital Assets Primer: regulatory context for digital-asset market structure and counterparty risk.
This scorecard is a manual due-diligence checklist based on your own research, not a verified safety rating or investment recommendation. It does not use live data and does not audit smart contracts.