Skip to content

The method

The score is a rubric, not a verdict

Every venue we would put capital into carries a 0–100 risk score, where higher is riskier. It is a weighted rubric with published dimensions and published weights, computed from stored observations.

Hold the same observations and you get the same number we did. That is the whole claim, and it is the reason this is worth licensing rather than just running.

The scale

Three bands, and what each means for an allocation

13 mature market38 mid-tier46 after an incident89 fresh fork0255075100higher = riskier
  • Low 0–29allocate freely, within the cap
  • Elevated 30–59allocate, capped tighter
  • High 60–100not whitelisted
Calibration profiles as a table
Reference profiles the risk rubric was calibrated against
ScoreBandProfile
13LowMature lending market: immutable, 72h timelock, deeply liquid, no incidents
38ElevatedMid-tier market: upgradeable behind a 3-of-5 multisig, 24h timelock, two audits
46ElevatedThe same mid-tier market, with an uncompensated critical incident six months ago
89HighFresh fork: 14 days old, unaudited, single-key admin, TWAP oracle, thin liquidity
The rubric is calibrated, not fitted — there is not enough public loss data to fit it, and claiming otherwise would be worse than saying so. These four profiles are the reference points its thresholds were set against.

The dimensions

Six things we look at, weighted in the open

Weights sum to one. They are judgement written down so it can be argued with, which is the honest form for this kind of number to take.

The six risk dimensions, their weights, and what each one reads
DimensionWeightWhat it reads
Contract maturity0.22How long the code has been live, how much capital has survived in it, how many audits cover it and how recent they are, and whether the deployed bytecode can still be changed.
Governance0.22Who can change the rules and how fast: the admin type, how many signatures it takes, how long the timelock is, and how much surface an upgrade could touch.
Exit liquidity0.18Whether a position our size could actually leave — absolute withdrawable depth as well as the withdrawable share, plus how much headroom is left before withdrawals start failing.
Oracle0.15Where prices come from, how far they may drift before an update is due, how often they update, and what happens when the source stops answering.
Collateral0.13What backs the borrowing, how concentrated it is in one asset, and whether it falls at the same time as the asset we are owed.
Incident history0.10What has already gone wrong there, how recently, how severe, and whether the team made users whole afterwards.

The division of labour

Where the model helps, and where it would be a liability

The model does this

  • Reads audit reports, governance threads, incident write-ups and admin configurations, and turns them into the structured facts the rubric needs. Doing that by hand does not scale past a handful of markets.
  • Projects forward yield out of its parts — a base rate that mean-reverts, emissions that stop on a date, points that may be worth nothing.

The model never does this

  • Choose the weights, or produce the score itself.
  • Decide which venues are eligible. That list is human-approved and enforced on chain.
  • Widen any limit. The score changes what the optimiser wants; it can never change what the contracts permit.

A worked example

The first thing the rubric got wrong

We would rather show a correction than a testimonial. A scoring method nobody has ever found a fault in is a method nobody has checked.

Exit liquidity was first scored on the withdrawable share of a market. That structurally punishes lending markets, which exist in order to lend most of their deposits out. A market with $800m supplied and $300m withdrawable is trivially exitable for any position we would hold — and it scored 69 out of 100, which would have pushed capital away from exactly the venues we intend to use.

It now takes the better of withdrawable share and absolute withdrawable depth, and adds utilisation as the stress signal. That market moved to 10, while a thin fork stayed at 100.

Eighteen passing tests did not catch it. Printing the actual numbers and looking at them did — which is why the calibration profiles above are published rather than kept internal.

Licensing it

What you would actually be buying

The rubric, the observation pipeline that feeds it, and the venue history behind it. For protocols deciding which markets to integrate, funds allocating across venues, and treasuries doing what we do.

The argument is not that the model is clever. It is that we run our own balance sheet on these numbers, and that you can recompute every score we publish from the observations we stored. A scoring product that cannot be checked is an opinion with a price on it.

Still open, and we would rather ask than guess: whether this ships as an API, a periodic report or a dashboard, and whether the rubric is published openly with the data sold, or the reverse. Tell us which would be useful.

Limits

What the score is not

Not fitted to loss data

There is not enough public data on DeFi losses to fit a model to, and a rubric claiming to be fitted would be a more confident lie than one that admits to judgement.

Not a prediction

A low score means a venue has the properties that have historically preceded surviving, not that it will survive. Nothing here forecasts an exploit.

Not a substitute for a cap

Scores steer allocation. Caps constrain it. A venue with a perfect score still cannot hold more than a human set, because a score is an opinion and a cap is a limit.