Reading a risk assessment — and this platform's flag points
What this platform's flag points actually compute, which seven factors they know, why they no longer assign a bucket, and which risks they explicitly do not see.
This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.
Learning objectives
- You can name the seven factors behind the flag points and explain the point thresholds.
- You can explain why a low flag-point total — even zero — is not proof of safety.
Check your prior knowledge
Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.
- What separates a heuristic from an audit?
- Which data does an aggregator have about a protocol?
- What can a score built only from that data never capture?
Core concept
Seven factors, additive, disclosed
The evaluation adds points across seven factors: deposited capital, chain maturity, the asset's type together with its exposure and IL risk, dependence on reward emissions, the protocol's track record, the statistical outlier marking, and data completeness. Every branch that fires appears as a named data flag, and the total as flag points — at most 13, because only one branch per factor can fire. Since 2026-09-21 no class (“low”/“medium”/“high”) is derived from it — the example further down says why.
Two factors are lists, not measurements
Chain maturity and protocol track record rest on maintained allowlists — currently 9 chains and 36 protocols. That is an assumption, not a measurement: a new, carefully built protocol is not on the list and takes a point; a listed protocol keeps its status after an incident until someone edits the list. Using the score means adopting that assumption.
What the score does not see
No code review, no admin rights, no upgrade paths, no oracle design, no governance concentration, no legal classification. A protocol with unlimited admin rights and a manipulable oracle can be unremarkable in all seven factors and come out with zero flag points. The score is a pre-sort by observable market data — not a substitute for dimensions 4, 8 and 11 of the analysis framework.
Definitions
- Heuristic
- An approximation that yields a usable pre-sort without examining the underlying facts.
- Flag points in the glossary
- Here: this platform's internal, disclosed heuristic — data flags and their total. Explicitly not a risk rating, not an audit and not a guarantee.
- Allowlist
- A maintained list standing in for a property that cannot be measured.
Model
Deposited capital (TVL)
Chain maturity — allowlist
Asset, exposure and IL risk
Dependence on reward emissions
Protocol track record — allowlist
Statistical outlier marking
Data completeness
Formulas
Flag points
Flag points = sum of the points of all triggered flags (0–13) | filter threshold of the narrow selection: <= 2- Flag points
- sum across the seven factors
Limit: The total adds up the factors with fixed point values per factor (at most 3, 2, 2, 2, 1, 2 and 1), without that weighting having been empirically grounded or calibrated. It does not order pools and supports no ranking.
TVL factor
>= USD 50m: 0 | >= 10m: +1 | >= 1m: +2 | below: +3- TVL
- the pool's deposited capital in USD
Limit: The factor measures size, not quality — and TVL itself has two drivers, quantity and price (see the lesson “Reading TVL”).
Worked example
Why the bucket was dropped
- Pool A
- 0 points: large TVL, established chain and protocol, stablecoin, barely any rewards
- Pool B
- 2 points: two flags triggered
- Former display
- both “Niedrig” (low)
Both sat at or below the 2-point threshold and received the same bucket, although two flags had triggered for pool B and none for pool A.
The same bucket, different flags — and different reasons behind them.
Reading: That is exactly why this platform has shown the flags instead of a bucket since 2026-09-21. A word like “low” over a named product is a verdict; the list of triggered flags is an observation anyone can recompute.
Retrieval
Exercise on real data
Compare the factors described there with the seven above and record which limits the methodology page names itself.
Read the methodology in the original →Open a market and read the individual flags, not just the total. Find two markets with the same flag points where different flags fired.
Look at a market's factor list →Application
Your organization wants to use this platform's flag points as a filter in an internal process, say “at most 2 points”. What do you advise?
Related case studies
Institutional reading
- Bank
- Which internal requirements for a risk model does a disclosed heuristic meet — and which not?
- Advisory
- How is a client told that a low flag-point total is a pre-sort and not an assurance?
Metrics in this lesson
Key takeaways
- The assessment is a disclosed, recomputable sum of seven observable factors — with no bucket, because a bucket hides different flags behind one word.
- Two of those factors are maintained lists — assumptions, not measurements.
- Code, admin rights, oracle, governance and law are not included. Even zero points are not proof of safety.
Evidence
- EVD-2026-0005
Review of Accounting Studies (Springer) — Decentralized Finance (DeFi) assurance: early evidence
- EVD-2026-0008
DeFiLlama — DeFiLlama yields endpoint (/pools)