How the data flags are derived
For every pool shown, seven factors are evaluated over fields publicly available through the DeFiLlama API. Every branch that awards points appears as a named data flag; the sum is the flag-point figure. Since 2026-09-21 no class (“low”, “medium”, “high”) is derived from it. This is not a security or smart-contract audit, not a rating and not a statement about a pool's safety.
Methodology version 2.7, as of Sep 30, 2026.
Flag-point factors
Total Value Locked (TVL)
≥ $50M: 0 points · $10M to under $50M: +1 · $1M to under $10M: +2 · under $1M: +3
Chain maturity
Established chain (Ethereum, Arbitrum, Optimism, Base, Polygon, BSC, Avalanche, Solana, OP Mainnet): 0 points · other chain: +2
Asset, exposure & impermanent-loss risk
Stablecoin, single exposure, no IL risk: 0 points · stablecoin with multi-exposure or IL risk: +1 · non-stablecoin, single exposure, no IL risk: +1 · non-stablecoin with multi-exposure or IL risk: +2
Reward dependency
Reward share of APY < 20%: 0 points · 20–50%: +1 · > 50%: +2
Protocol track record
Protocol on the allowlist of established protocols: 0 points · unknown track record: +1 · RWA issuer (list below): suspended, 0 points
Data anomaly
DeFiLlama flags the pool as a statistical outlier: +2 points
Data completeness
Base APY or 30-day trend missing: +1 point
Flag points
The flag points are the sum of the points listed above. They do not order pools and support no ranking; they state which of the seven factors reported something and add up their points — the figure is a sum of points, not a count of factors. The Strategy Intelligence Report only shows pools with at most two points (curated universe) — a filter threshold, not a classification.
The scale runs from 0 to at most 13 points: each factor contributes its highest-scoring branch. For the RWA issuers listed below the maximum is 12, because factor 5 is suspended for them. There is no division into classes.
In detail, the curated universe requires: TVL of at least $10M, no outlier flag, a reported APY and at most 2 flag points. Crypto pools additionally need an established chain, a protocol on the allowlist and one of 25 core assets (USDC, USDT, DAI, USDS, ETH, STETH, WBTC, BTC, AVAX, MATIC, LINK, SOL, USDE, USDG, PYUSD, RLUSD, GHO, CRVUSD, WEETH, RETH, JITOSOL, CBETH, METH, OSETH, MSOL).
How flags become points
Each triggered flag adds points; the sum is the flag-point figure — not a classification and not an audit.
The curated universe of the Strategy Intelligence Report contains only pools with at most 2 flag points — alongside TVL, data-quality and allowlist criteria. That is a filter threshold, not a classification.
An internal heuristic over public data — not an audit, not a rating and not a guarantee.
The lists behind the factors
Factors 2 and 5 compare a pool against fixed lists. They are published here in full so every point awarded can be checked. Listed means “known and in use for years”, not “audited” and not “safe”.
Established chains (factor 2, 9)
- Arbitrum
- Avalanche
- Base
- BSC
- Ethereum
- OP Mainnet
- Optimism
- Polygon
- Solana
Allowlist of established protocols (factor 5, 36)
- Aave
- Aave V2
- Aave V3
- Aave V4
- Aerodrome V1
- Balancer
- Balancer V2
- Coinbase Wrapped Staked ETH
- Compound
- Compound V2
- Compound V3
- Convex Finance
- Curve
- Curve DEX
- Curve LlamaLend
- ether.fi Stake
- Jito Liquid Staking
- Kamino Lend
- Lido
- MakerDAO
- Maple Finance
- Marinade Liquid Staking
- mETH Protocol
- Morpho
- Morpho Blue
- Orca DEX
- Rocket Pool
- Sky Lending
- Spark Savings
- SparkLend
- StakeWise V3
- Uniswap
- Uniswap V2
- Uniswap V3
- Uniswap V4
- Yearn Finance
RWA issuers for which factor 5 is suspended (15)
- Apollo Diversified Credit Securitize Fund
- BlackRock BUIDL
- Centrifuge
- Circle USYC
- Flux Finance
- Franklin Templeton
- Goldfinch
- Invesco USTB
- Maple Finance
- Matrixdock
- Ondo Finance
- OpenEden TBILL
- RealT
- Sky (sDAI)
- VanEck Treasury Fund
The allowlist measures how long DeFi protocols have been in use. For issuers of tokenized securities it measures nothing: none of them could meet it, and until version 2.0 each received a flat point. Since version 2.1 the factor is suspended for these issuers — zero points, shown as “suspended”, not as “established”. What would have to be checked for an issuer instead — counterparty, custody, regulation — is not assessed by this platform. The issuers were deliberately not added to the allowlist: that would have required a statement about their regulatory status that nobody here has substantiated.
Where an issuer also appears on the allowlist (today: Maple Finance), the RWA rule applies to the points: factor 5 is suspended and the allowlist entry has no effect there.
Validation status
Every point rule of this assessment is written out above. Disclosed, however, is not the same as checked. The five steps below separate a heuristic from a validated risk model — none of them has been taken so far.
Current status: heuristic, not validated.
Calibration of the thresholds
open- Status
- The thresholds — 50M, 10M and 1M USD, plus the two-point filter threshold — are set by judgment, not derived from an observed distribution.
- What it would require
- A traceable derivation of each threshold from the distribution of real pools rather than from an assessment.
Weighting of the factors
open- Status
- All factors enter with fixed point values. Why chain maturity weighs as much as reward dependency, at up to +2 each, has not been justified.
- What it would require
- A reasoned or empirically estimated weighting of the factors relative to one another.
Empirical study
open- Status
- It has never been examined whether pools with many flag points actually experienced exploits, depegs, lasting APY collapses or bad debt more often than pools with no flags triggered.
- What it would require
- A dataset of historical pools with outcome labels defined in advance, and a measured association between score and outcome.
Backtesting
open- Status
- No comparison of the score at time T against events at T+30, T+90 and T+180 days. Of the time-dependent inputs, only TVL could be reconstructed from the history endpoint already in use; this site knows the others only as they stand today. The outcome side does not exist here as a dataset and would first have to be defined and collected.
- What it would require
- Scores computed as of T against events observed at T+30, T+90 and T+180, reported with discrimination and calibration figures.
Out-of-sample check
open- Status
- Presupposes the preceding steps and is therefore open as well.
- What it would require
- The same measurement on a period or pool universe not used while the thresholds were chosen.
What follows from this: the assessment describes pools by named, disclosed data flags. It states no probability of loss, and how well it separates later loss events from unremarkable pools has not been measured.
Known limitations of this methodology
- No real audit data: DeFiLlama has no reliable field indicating whether a protocol has been audited. Being on the allowlist of established protocols means “known and long-running”, not “audited and therefore safe”.
- TVL and chain maturity are proxies, not causes: a large TVL doesn't prevent a smart-contract exploit — it only shows how much capital other market participants have invested there.
- The flags never appear next to unqualified safety promises or yield guarantees — such wording is deliberately avoided on this site. An empty flag list is not such a promise; it states that none of the seven factors triggered.
- This assessment covers only a subset of institutionally relevant risk dimensions: it accounts for TVL, chain maturity, asset/exposure classification, reward dependency, protocol track record, and data completeness/anomalies. It does not assess smart contract risk, oracle risk, governance risk, bridge risk, counterparty risk, custody risk, or regulatory status.
- Since 28.09.2026 the market pages show evidence from public sources for several of these dimensions — such as oracle providers, audit references, event markers, L2BEAT criteria and, for tokenized RWA, register data. Evidence awards no flag points. How it relates to the dimensions is described in the metrics framework and the dimension mapping.
Data source
The figures for crypto pools come from the public DeFiLlama API (/pools). They are cached and refreshed on the next page request once the cache has expired — fifteen minutes, for the pool data as well as for the Navigator and the Explorer. There is no fixed refresh interval: nothing is fetched without a page request. RWA pools come from a separate retrieval — mostly DeFiLlama as well, a few from on-chain data and a price service — and are cached for up to twelve hours. The retrieval time in the report header applies to the crypto pools; the report states the RWA pools' own retrieval time below the market table and in each RWA market's details. Sample data never enters a figure.
For the evidence on the market pages the site has additionally retrieved, since 28.09.2026: DeFiLlama (protocols, chains, stablecoins), L2BEAT, GLEIF and SEC EDGAR (register data for tokenized RWA), and public chain endpoints (name and supply of tokenized-RWA token contracts). Individual deposit rates are cross-checked against the protocol's public interface (currently Aave). None of these sources changes flag points.
DeFiLlama supplies the raw data. SKN3X.COM shows it split into base and incentives, gives every metric a definition and its limits, and marks what is not assessed.
Audit report
On Sep 26, 2026 this methodology was checked against the code, the copy in all five languages and the learning content. The report lists every criterion with its finding, location, severity and correction — including the points that remain open. It is written in German. It refers to the methodology as it stood that day (version 2.2); later changes are listed in the changelog.
Change log
This log begins on the day it was introduced. What changed in the methodology before that is not listed here — a list assembled after the fact would be a claim about the past that nobody has checked.
Version 2.7 · Sep 30, 2026
Data flags: DeFiLlama now lists the Optimism chain as “OP Mainnet”. The list of established chains only knew the old name, so markets on OP Mainnet received +2 points for a non-established chain and dropped out of the curated universe, although the methodology names Optimism as established. “OP Mainnet” is now on the list. On 30.09.2026 this affected 193 markets in the Explorer; their flag points fall by 2. All other factors, thresholds and points are unchanged.
Version 2.6 · Sep 28, 2026
Data characteristics: the field “predictions” (DeFiLlama’s own forecast) no longer counts toward data completeness. A missing forecast is optional context, not a gap in the data describing a market. Measured on 28 Sep 2026: none of the 17,023 DeFiLlama pools lacked this field, so no score changes. The chain and protocol characteristics now name the list explicitly as the “SKN3X reference list”: they say something is not on that list, not that no track record exists.
Version 2.5 · Sep 28, 2026
DeFi Finder: pools of two different assets (e.g. USDC-WETH, WETH-cbBTC, WSOL-USDC) are no longer listed under Ether, Bitcoin or Solana but in the new “Pair pools” choice, with their own answers, market average and plausibility threshold. Holding one asset is not enough to enter such a pool. Same-class pairs (e.g. ETH-stETH, WBTC-cbBTC) stay with their asset. In addition, DeFiLlama lending data with “borrowable: null” is no longer discarded; utilization and available liquidity were missing for 163 markets because of it.
Version 2.4 · Sep 28, 2026
DeFi Finder: a 30-day mean above the median + 10 × MAD of the markets for the same asset counts as unusually high. Such markets no longer count for answer 1 (“Longest history”), answer 2 (“More yield”) or the market average; they stay in the list and can be answer 3, with a visible note. Reason: a stablecoin pool with around 120% base APY for more than a year at an unchanged TVL, not flagged as an outlier by DeFiLlama. In addition, answer 2 now appears only if its 30-day mean is above answer 1's. Flags, factors, thresholds and points are unchanged.
Version 2.3 · Sep 27, 2026
Below an APY of 0.05%, a pool counts as a collateral market in the report, as does a pool without rewards whose base APY is below that. Until version 2.2 only an APY of exactly 0 separated them; markets at 0.004% counted as “pools with a yield” and entered medians, the TVL-weighted APY and the assets' representatives. The threshold is a convention, not a measurement: it sits where a display with two decimals stops showing a difference. The pools are not removed; they are listed in the collateral section below the table.
Version 2.2 · Sep 26, 2026
Liquid staking tokens on lending protocols count as collateral markets. For such a deposit (wstETH on Aave V3, for example) DeFiLlama reports the market's supply rate, not the token's staking yield; up to version 2.1 these pools belonged to the Liquid Staking segment and pulled its median below 0.01%. The assignment reads DeFiLlama's protocol category — the same one the Explorer uses to form “Lend & Borrow” — and does not guess where it is missing. The pools now sit in the collateral-markets section and no longer enter any median “over pools with a yield”. Factors, thresholds, points and the curated universe are unchanged.
Version 2.1 · Sep 25, 2026
Factor 5 (“protocol track record”) is suspended for RWA issuers. The allowlist measures how long DeFi protocols have been in use and could not be met by issuers of tokenized securities, so each received a flat point. The issuers now have their own list, published in full on this page, and the factor is shown as “suspended” for them. All other factors, thresholds and points are unchanged. New on this page: the highest possible score (13) and the complete lists behind factors 2 and 5.
Version 2.0 · Sep 21, 2026
Switched from the risk class to data flags. The classes “low”, “medium” and “high” were dropped without replacement, as was the per-pool “counterparty risk” figure. The triggered flags are now named individually, with what is not assessed stated alongside throughout. The seven factors, their thresholds and their points are unchanged; the default sort moved from the class to TVL, and the filter by class was replaced by filters on individual flags.