The method
The score is a rubric, not a verdict
Every venue we would put capital into carries a 0–100 risk score, where higher is riskier. It is a weighted rubric with published dimensions and published weights, computed from stored observations.
Hold the same observations and you get the same number we did. That is the whole claim, and it is the reason this is worth licensing rather than just running.
The scale
Three bands, and what each means for an allocation
- Low 0–29allocate freely, within the cap
- Elevated 30–59allocate, capped tighter
- High 60–100not whitelisted
Calibration profiles as a table
| Score | Band | Profile |
|---|---|---|
| 13 | Low | Mature lending market: immutable, 72h timelock, deeply liquid, no incidents |
| 38 | Elevated | Mid-tier market: upgradeable behind a 3-of-5 multisig, 24h timelock, two audits |
| 46 | Elevated | The same mid-tier market, with an uncompensated critical incident six months ago |
| 89 | High | Fresh fork: 14 days old, unaudited, single-key admin, TWAP oracle, thin liquidity |
The dimensions
Six things we look at, weighted in the open
Weights sum to one. They are judgement written down so it can be argued with, which is the honest form for this kind of number to take.
| Dimension | Weight | What it reads |
|---|---|---|
| Contract maturity | 0.22 | How long the code has been live, how much capital has survived in it, how many audits cover it and how recent they are, and whether the deployed bytecode can still be changed. |
| Governance | 0.22 | Who can change the rules and how fast: the admin type, how many signatures it takes, how long the timelock is, and how much surface an upgrade could touch. |
| Exit liquidity | 0.18 | Whether a position our size could actually leave — absolute withdrawable depth as well as the withdrawable share, plus how much headroom is left before withdrawals start failing. |
| Oracle | 0.15 | Where prices come from, how far they may drift before an update is due, how often they update, and what happens when the source stops answering. |
| Collateral | 0.13 | What backs the borrowing, how concentrated it is in one asset, and whether it falls at the same time as the asset we are owed. |
| Incident history | 0.10 | What has already gone wrong there, how recently, how severe, and whether the team made users whole afterwards. |
The division of labour
Where the model helps, and where it would be a liability
The model does this
- Reads audit reports, governance threads, incident write-ups and admin configurations, and turns them into the structured facts the rubric needs. Doing that by hand does not scale past a handful of markets.
- Projects forward yield out of its parts — a base rate that mean-reverts, emissions that stop on a date, points that may be worth nothing.
The model never does this
- Choose the weights, or produce the score itself.
- Decide which venues are eligible. That list is human-approved and enforced on chain.
- Widen any limit. The score changes what the optimiser wants; it can never change what the contracts permit.
A worked example
The first thing the rubric got wrong
We would rather show a correction than a testimonial. A scoring method nobody has ever found a fault in is a method nobody has checked.
Exit liquidity was first scored on the withdrawable share of a market. That structurally punishes lending markets, which exist in order to lend most of their deposits out. A market with $800m supplied and $300m withdrawable is trivially exitable for any position we would hold — and it scored 69 out of 100, which would have pushed capital away from exactly the venues we intend to use.
It now takes the better of withdrawable share and absolute withdrawable depth, and adds utilisation as the stress signal. That market moved to 10, while a thin fork stayed at 100.
Eighteen passing tests did not catch it. Printing the actual numbers and looking at them did — which is why the calibration profiles above are published rather than kept internal.
Licensing it
What you would actually be buying
The rubric, the observation pipeline that feeds it, and the venue history behind it. For protocols deciding which markets to integrate, funds allocating across venues, and treasuries doing what we do.
The argument is not that the model is clever. It is that we run our own balance sheet on these numbers, and that you can recompute every score we publish from the observations we stored. A scoring product that cannot be checked is an opinion with a price on it.
Still open, and we would rather ask than guess: whether this ships as an API, a periodic report or a dashboard, and whether the rubric is published openly with the data sold, or the reverse. Tell us which would be useful.
Limits
What the score is not
Not fitted to loss data
There is not enough public data on DeFi losses to fit a model to, and a rubric claiming to be fitted would be a more confident lie than one that admits to judgement.
Not a prediction
A low score means a venue has the properties that have historically preceded surviving, not that it will survive. Nothing here forecasts an exploit.
Not a substitute for a cap
Scores steer allocation. Caps constrain it. A venue with a perfect score still cannot hold more than a human set, because a score is an opinion and a cap is a limit.