Methodology for DeFi Protocol Rating
In the rapidly evolving landscape of Decentralized Finance (DeFi), assessing the safety and quality of a protocol is a complex challenge. Users and automated agents alike need a standardized, quantitative framework to evaluate risks objectively. We have developed a comprehensive DeFi Protocol Rating Framework that evaluates protocols across 5 main fields, generating a final score out of 100.
This methodology is designed to be rigorous, transparent, and uniform, ensuring that everyone—from individual investors to AI agents—can arrive at the same conclusion when verifying a protocol.
The final protocol score is calculated using weighted factors across five dimensions:
-
S1 - Smart Contract & Technical Risk (30%): Code security, audits, and technical maturity
-
S2 - Economic Design & Market Risk (25%): Economic model soundness and liquidity health
-
S3 - Governance & Centralization Risk (20%): Decentralization and control mechanisms
-
S4 - Sustainability & Competitive Position (15%): Longevity and business viability
-
S5 - Reputation & Social Trust (10%): Team credibility and community trust
-
Total Score = (S1 × 30%) + (S2 × 25%) + (S3 × 20%) + (S4 × 15%) + (S5 × 10%)
Below is the detailed breakdown of our 5-field rating system, including the exact source of information and point calculations, illustrated with real-world examples from protocols like Aave, Morpho, Ethena, Pendle, and Uniswap.
Rating Weight Distribution

Quick Reference Table
| Field | Sub-Field | Max Points | Weight |
|---|
| 1. Smart Contract & Technical Risk | | 100 | 30% |
| 1.1 Audit Coverage | 60 | |
| 1.2 Code Maturity & Openness | 20 | |
| 1.3 Upgradeability & Admin Control | 10 | |
| 1.4 Bug Bounty & Incident History | 10 | |
| 2. Economic Design & Market Risk | | 100 | 25% |
| 2.1 Core Mechanism Soundness | 10 | |
| 2.2 Capital Quality & Stickiness | 25 | |
| 2.3 Liquidity Stress Behavior | 15 | |
| 2.4 Liquidity & Exit Accessibility | 40 | |
| 2.5 Market Dependency | 10 | |
| 3. Governance & Centralization Risk | | 100 | 20% |
| 3.1 Governance Structure | 30 | |
| 3.2 Governance Token Distribution | 10 | |
| 3.3 Admin & Emergency Powers | 30 | |
| 3.4 Treasury & Transparency | 30 | |
| 4. Sustainability & Competitive Position | | 100 | 15% |
| 4.1 Protocol Age & Survival | 30 | |
| 4.2 Innovation vs Imitation | 30 | |
| 4.3 Revenue & Self-Sufficiency | 40 | |
| 5. Reputation & Social Trust Risk | | 100 | 10% |
| 5.1 Team & Founder Reputation | 40 | |
| 5.2 Investors & Backers | 30 | |
| 5.3 Community & Communication | 30 | |
Final Score Formula: (S1 × 30%) + (S2 × 25%) + (S3 × 20%) + (S4 × 15%) + (S5 × 10%)
1. Smart Contract & Technical Risk (Weight: 30%)
Max Score: 100
This section evaluates the code quality, security practices, and technical maturity of the protocol.
1.1 Audit Coverage (60 Points)
We prioritize quality over quantity. A single audit from a Tier-1 firm carries more weight than multiple audits from lesser-known firms.
- Criteria:
- Tier 1 Audit (e.g., OpenZeppelin, Spearbit, Trail of Bits): +60 Points (Max Cap).
- Tier 2 Audit + Others combined: +40 Points (Max Cap).
- Other / Independent Auditor: +20 Points.
- Multiple Audits Bonus: +5 Points per additional audit (Subject to max caps).
- You can check the Audit company list at this link: Smart Contract Auditor Rankings 2026
- Reasoning: Prevents "audit spamming" where multiple low-quality audits could mathematically overtake a single rigorous Tier-1 audit.
- Source: DefiLlama 'Audits' section, Vendor Public Githubs, or Protocol Docs.
- Example: Morpho scores 60/60. It has secured multiple Tier 1 audits (OpenZeppelin, Trail of Bits), hitting the Max Cap immediately.

1.2 Code Maturity & Openness (20 Points)
Time is the best tester ("Lindy Effect"). We look for open-source code.
- Criteria — three independent components, summed:
- Open Source: +5 Points. The deployed contract source is publicly readable — verified on a block explorer or published in a repo. Source-available counts; a program publishing only an ABI scores 0.
- Contract Age (from the first mainnet deployment of the core contract):
- 1.5 years or more: +10 Points.
- 1 – 1.5 years: +7.5 Points.
- 0.5 – 1 year: +5 Points.
- < 0.5 year: +0 Points.
- GitHub Activity — a date test, not a judgement of how impressive the project looks:
- Last commit within 90 days, public repo carrying the deployed source: +5 Points.
- Last commit between 90 days and 12 months: +2.5 Points.
- No public repo, or last commit older than 12 months: +0 Points.
- One clock for the whole board. Age and activity are measured at a single date shared by every protocol we rate, not at the date each individual rating happened to be written. Otherwise two identical protocols land in different age tiers purely because one was reviewed in April and the other in June.
- Source: Etherscan (Contract Verification), GitHub Repo (Commits/Activity), DefiLlama, Rootdata.
- Example: Aave scores 20/20. It is Open Source (+5), has been on mainnet > 1.5 years (+10), and has very active GitHub maintenance (+5).
1.3 Upgradeability & Admin Control (10 Points)
We assess "Rug Pull" risk here — who can change the code holding your money, and how much warning you get.
Step 1 — is there anything to govern? If no admin can change the fund-holding code or move, mint or freeze user funds, the protocol scores 10/10 and we stop. Contracts like these are immutable. Governance-controlled parameters — interest curves, collateral ratios, fee tiers, which assets are listed — are intended by design and do not count as an upgrade path.
Step 2 — otherwise, we score whoever controls the critical path on two axes:
| Axis | The bar |
|---|
| Multisig | At least 3 signatures required to act — the threshold, not the number of keys that exist. A 2-of-3 wallet fails, because two people acting together are enough. |
| Timelock | A contract-enforced delay of at least 24 hours before an upgrade takes effect, so depositors have a window to leave. |
-
Both axes satisfied: 10 Points.
-
Exactly one: 5 Points.
-
Neither — a single key, or a small multisig with no delay: 0 Points.
-
Two hard zeros, whatever else is in place: an admin who can mint the token without posting collateral, and a single externally-owned account sitting anywhere on the critical path with upgrade or fund-movement power.
-
We do not score signer identity. Establishing who actually holds the keys behind a multisig is slow and rarely conclusive, and asking raters to judge whether signers are "reputable" produced more disagreement than signal. We count the threshold and read the delay — two facts anyone can verify against the chain themselves.
-
Source: Etherscan (Read Contract/Owner), L2Beat (ZK/Optimistic Rollups), Protocol Docs.
-
Example: Morpho Blue scores 10/10 because the core lending contracts are Immutable — Step 1 ends it.
1.4 Bug Bounty & Incident History (10 Points)
Active bug bounties incentivize whitehat hackers. Past incidents are charged against that credit.
- Bounty credit — the verified maximum payout for a critical finding, on a programme that is live today:
- $500,000 or more: +10 Points.
- $100,000 – $499,999: +7.5 Points.
- $1 – $99,999: +5 Points.
- No programme: 0 Points.
- There is no default credit. A protocol without a bug bounty starts at zero and can only go down from there. It does not start at ten and lose a couple of points for the omission.
- Past Exploit Penalty — subtracted from the bounty credit:
- Major exploit where users were not made whole (more than 10% of TVL; for bridges, more than $10M): -20 Points.
- Major exploit where users were made whole — funds recovered, reimbursed from treasury, or compensated by governance vote: -10 Points.
- Minor resolved incident — contained, root cause fixed, between 1% and 10% of TVL: -5 Points.
- De-minimis incident — contained, root cause fixed, under 1% of TVL: -2.5 Points.
- Downstream exposure — the protocol's own code never failed, the loss arrived through an integrated protocol, and users were made whole: -2 Points.
- Non-exploit operational events — a depeg that recovered, a hijacked frontend with full reimbursement, a compromised social account: 0. We note these; we don't charge them.
- This subfield can go negative. A protocol that lost user money has earned a charge larger than a ten-point field can hold, and we let the excess carry into the category total rather than quietly capping it at zero.
- Incidents fade, and after five years they are gone. An incident more than three years old whose root cause has been retired — the contract replaced, the dependency dropped — carries half its penalty, and an incident more than five years old stops counting altogether. If the code that failed is still running, the penalty neither fades nor expires: a bug living on in an immutable contract that still holds the money is a present risk, not history.
- Attribution: oracle-enabled exploits, where manipulating a price feed drained a lending protocol, are attributed to the protocol that was drained, not the oracle. Where a collateral issuer's failure creates bad debt in a lender that integrated it, the charge belongs to the issuer.
- Source: Immunefi, Cantina, HackenProof, DefiLlama 'Hacks', Rekt.news.
- Example: Pendle scores 10/10 for maintaining an Active Bug Bounty on Immunefi with payouts > $1,000,000.
2. Economic Design & Market Risk (Weight: 25%)
Max Score: 100
This section assesses the soundness of the economic model and liquidity health.
2.1 Core Mechanism Soundness (10 Points)
Is the protocol built on a battle-tested model?
- Criteria:
- Standard Fork (e.g., Uniswap V2, Aave V2): +10 Points (Battle-tested).
- Novel but Audited Economic Model: +7.5 Points.
- Experimental/Complex Mechanism: +5 Points.
- Source: DefiLlama 'Forked From', Whitepaper, Web Search reviews.
- Example: Aave scores 10/10 as a "Standard Fork" base (though it is the original) and Category Definer.
2.2 Capital Quality & Stickiness (25 Points)
Replaces raw TVL size with a measure of durability.
- Criteria:
- High Organic Growth & Stickiness: +25 Points.
- Mixed Incentives / Solid TVL Base: +15 Points.
- Highly Incentivized / Mercenary Capital: +5 Points.
- Low/Trace TVL: 0 Points.
- Source: DefiLlama (TVL vs Token Price Correlation, Yield Composition).
- Example: Morpho scores 25/25 for "High Organic Growth" due to its P2P efficiency model that doesn't rely solely on token incentives.
2.3 Liquidity Stress Behavior (15 Points)
Measures resilience during volatility.
- Criteria:
- High Resilience (Low Slippage during stress): +15 Points.
- Moderate Resilience: +10 Points.
- Fragile (High Slippage/Depegs): 0 Points.
- Source: DEXScreener (Depth/Peg History), Coingecko.
- Example: Uniswap scores 15/15 for proven High Resilience during market crashes.
2.4 Liquidity & Exit Accessibility (40 Points)
Combines Liquidity Depth and Withdrawal/Lockup Risk.
We score depth, not slippage at an arbitrary trade size. A fixed $1M probe is 0.007% of a
$13.8B protocol and 50% of a $2M one — banding on it punishes small protocols for being small
rather than for being hard to exit.
We score the best route a user could actually take. Some protocols are exited through a
DEX, some through a redemption that is cheaper and faster than any DEX, and some hold no user
capital at all.
-
Step 0 — is there an exit to score? No user capital deposited (aggregators, routers,
services) → 40/40. Position self-resolves by design (option expiry, market resolution,
liquidation, insurance claim) → N/A, points redistributed.
-
Step 1 — list the routes a regular user can execute permissionlessly: native
redemption/withdrawal, and sale on a secondary market. A route needing KYC, an allowlist, an
operator signature or a support ticket is not a route.
-
Step 2 — cost each on value (slippage + fees + discount to NAV) and time (cooldown,
queue, epoch).
-
Step 3 — score the best one. A deep market rescues a slow queue; a par-value redemption
beats a thin market. Where both are bad, score the better of two bad options.
-
Step 4 — depth@2% on the winning route: the USD notional that exits within 2% of fair
value.
| Depth tier | depth@2% |
|---|
| Deep | ≥ $5M |
| Reasonable | $1M – $5M |
| Thin | $250K – $1M |
| Illiquid | < $250K |
-
Step 5 — relative modifier (depth@2% ÷ TVL): ≥ 10% promotes one tier, < 1%
demotes one tier. Never above Deep, never below Illiquid.
-
Step 6 — cross depth with the winning route's lockup. A liquid secondary market substitutes for the exit
queue, so lockup only dominates when the market is thin.
| Deep | Reasonable | Thin | Illiquid |
|---|
| No lockup / instant | 40 | 40 | 35 | 25 |
| Short lockup (≤ 7d) | 35 | 30 | 20 | 15 |
| Long lockup (> 7d) | 30 | 25 | 15 | 10 |
-
Predatory Exit Tax (> 5%): 0 Points, regardless of depth or lockup.
Depth is measured on the actual exit path: for a lending protocol that is withdrawing your
supplied assets, not selling the governance token.
- Source: Protocol Docs, Staking Contract UI, Coingecko (-2% Depth), Honeypot.is.
- Example: Spark scores 35/40 — sDAI depth is Deep, but D3M conditions mean exit is not unconditionally instant, so it sits on the short-lockup row. Uniswap, with no lockup at all, scores 40.

2.5 Market Dependency (10 Points)
Exposure to volatile assets and market-dependent revenue increases risk.
- Criteria:
- Low Market Dependency (Revenue independent of asset price movement): +10 Points.
- Mixed Volatile Assets / Partial Market Dependency: +5 Points.
- Highly Volatile/Degen Assets / Fully Market-Dependent Revenue: +0 Points.
- Source: DefiLlama 'Composition', Protocol Asset List, Revenue Model Analysis.
- Example: Ethena scores 10/10. While its collateral consists of BTC and ETH, its yield derives from perpetual funding rates, not asset price appreciation. The delta-neutral strategy (spot long + perp short) neutralizes price exposure. Historically, negative funding rate periods are infrequent and short-lived—extended negative funding scenarios are rare in crypto markets due to the structural long bias of participants.
3. Governance & Centralization Risk (Weight: 20%)
Max Score: 100
Evaluates who controls the protocol.
3.1 Governance Structure (30 Points)
Decentralized governance is key to long-term trust.
- Criteria:
- Immutable / Governance Minimized (No DAO needed): +30 Points.
- Fully On-Chain DAO (e.g., Compound Governor): +30 Points.
- Snapshot + Veto (Off-chain signaling, On-chain execution): +25 Points.
- Multisig Council Decisions: +15 Points.
- Centralized Team Control: 0 Points.
- Source: Tally.xyz, Snapshot.org, Protocol Governance Docs.
- Example: Aave scores 30/30 for its Fully On-Chain DAO.

3.2 Governance Token Distribution (10 Points)
- Criteria:
- Highly Distributed + Quorum Rules: +10 Points (High Capture Resistance).
- VC/Whale Dominated Voting: +5 Points.
- Single Whale/Team Control: 0 Points.
- Source: Etherscan 'Holders', BubbleMaps.
- Example: Morpho scores 10/10 for "Highly Distributed" governance token holdings.
3.3 Admin & Emergency Powers (30 Points)
The risk here is concentrated single-actor control, not the existence of emergency mechanisms. A multisig or timelock distributes authority; a single EOA concentrates it. Immutable protocols are trustless by design. All three non-EOA patterns are equally acceptable and score full marks.
- Criteria:
- No Pause/Blacklist Functions (Immutable): +30 Points. No actor can halt operations.
- Pause with Timelock: +30 Points. Emergency capability exists, but the community has advance notice.
- Pause by Multisig (≥ 2-of-N threshold): +30 Points. Distributed emergency response; no single actor controls the halt.
- Pause by Single EOA: 0 Points. One key can freeze all user funds instantly — and the same key can lift the pause unilaterally, or holds powers beyond pausing.
- Key clarification — a fast pause with a supermajority-gated unpause still scores 30/30. A broad 1-of-N pauser set qualifies provided (1) the resume path is gated behind a ≥ 2-of-N multisig, a timelock or a governance vote, and (2) the pauser role can only halt — not upgrade, mint, move funds, or change the unpause threshold. What 3.3 measures is whether a single actor can seize or permanently trap user funds; a pause alone cannot move them, and scoring a broad fast-pause set at 0 would penalise a protocol for having better exploit response than one with a slow multisig pause.
- Source: Etherscan (Write Contract: pause/blacklist), automated admin-chain resolution.
- Example: Pendle scores 30/30 — pause is gated by a 3/5 Gnosis Safe, confirmed on-chain.
3.4 Treasury & Transparency (30 Points)
- Criteria:
- On-chain Treasury with periodic reports: +30 Points.
- On-chain Treasury (Silent/No reports): +15 Points.
- Opaque/No Treasury Disclosure: 0 Points.
- Source: DeepDAO, DefiLlama 'Treasury', Annual Reports.
- Example: Ethena scores 30/30 for excellent transparency and proof of reserves dashboards.
4. Sustainability & Competitive Position (Weight: 15%)
Max Score: 100
Assesses the protocol's longevity and business model.
4.1 Protocol Age & Survival (30 Points)
Surviving a bear market demonstrates resilience.
- Criteria:
- Launched before 2024 (Survived 2022/2023 Bear Market): +30 Points.
- > 1.5 Years: +25 Points.
- > 1 Year: +20 Points.
- 6 – 12 Months: +15 Points.
- < 6 Months: +10 Points.
- Source: DefiLlama TVL Chart (All-time start date), Rootdata.
- Example: Pendle scores 30/30, having launched in 2021.
4.2 Innovation vs Imitation (30 Points)
Innovators capture more value than generic forks.
- Criteria:
- Market Leader / Category Definer: +30 Points.
- Strong Challenger / Improved Fork: +20 Points.
- Generic Fork: +10 Points.
- Source: DefiLlama Categories/Rankings, Rootdata.
- Example: Morpho scores 30/30 as a "Category Definer" for lending optimization.
4.3 Revenue & Self-Sufficiency (40 Points)
- Criteria:
- Profitable (Fees > Emissions): +40 Points.
- Improving Revenue/Emission Ratio (Trend): +25 Points.
- Revenue Generating (Subsidized): +15 Points.
- Declining Revenue/Emission Ratio: -10 Points (Penalty).
- Zero Profit / Pure Emission Model: 0 Points.
- If "Information Not Found": 0 points.
- Source: DefiLlama 'Fees & Revenue', TokenTerminal.
- Example: Aave scores 40/40 as it is highly Profitable.
5. Reputation & Social Trust Risk (Weight: 10%)
Max Score: 100
5.1 Team & Founder Reputation (40 Points)
- Criteria:
- Base Score: 20 Points.
- Public Team (> 1.5 Years): +20 Points.
- Public Team (1 – 1.5 Years): +15 Points.
- Anon Team (> 2 Years): +20 Points.
- Infamous Founder (Past Scams/Rug): Score sets to -40 Points.
- Source: Rootdata, LinkedIn, Crunchbase, Web Search.
- Example: Morpho scores 40/40 — a public team with a >1.5-year operating record led by Paul Frambot: the 20-point base plus the +20 public-team bonus.
5.2 Investors & Backers (30 Points)
- Criteria:
- Top Tier VCs (Paradigm, a16z) + Clean History: +30 Points.
- Long-term Community Owned (No VC needed): +25 Points.
- Tier 2 VCs / Known Angels: +20 Points.
- VC-Backed with History of Governance Abuse: Cap at 15.
- No Backers / Unknown: +10 Points.
- Predatory Tokenomics: 0 Points.
- Source: CryptoRank.io, Crunchbase, CypherHunter, Rootdata.
- Example: Ethena scores 30/30 with Top Tier backing from Dragonfly and Binance Labs.
5.3 Community & Communication (30 Points)
- Criteria:
- High responsiveness & Regular Updates: +30 Points.
- Average activity: +15 Points.
- Ghost town / Deleted comments: 0 Points.
- Source: Twitter (X), Discord, Community Forums, Rootdata on specific protocol.
- Example: Spark scores 30/30 for regular substantive updates across its live channels.
Summary
By breaking down protocol risk into these 19 distinct sub-fields across 5 categories, we eliminate ambiguity. Whether you are a human analyst or an AI agent, following this DeFi Protocol Rating Framework ensures a consistent, data-driven assessment.
Special Cases:
- Not Applicable (N/A): Redistribute points to remaining criteria in the same field.
- Information Not Found: Default to 0 Points (Conservative Approach).
Example: Protocol Score Visualization
Below is an example of how a well-established protocol like Aave might score across all five dimensions:
Aave Example Calculation:
- Smart Contract (98/100) × 30% = 29.4
- Economic Design (100/100) × 25% = 25
- Governance (85/100) × 20% = 17
- Sustainability (100/100) × 15% = 15
- Reputation (100/100) × 10% = 10
- Total Score: 96 / 100