Cointime

Download App
iOS & Android

How to Stay Safe in DeFi: A Simple Guide to Evaluate Project Safety

The collapse of FTX proved the importance of self-custody and risk management.

But it’s so easy to lose money in DeFi if you are not careful with many exploits, rug pulls, contract bugs around.

In this blog I’d like to share how to evaluate safety of DeFi protocols to protect your assets.

It’s great if you’re an experienced smart contract developer and can verify the code yourself. But most of us aren’t.

It leaves us with no other choice, but to evaluate projects based on other data, that involves some degree of trust.

Total Value Lock, ultimate proof of security?

It’s no secret that the majority evaluate DeFi projects by how much value is deposited to the smart contracts. So, TVL is the ultimate proof of trust.

The higher the Total Value Locked, the higher the implied security of a protocol. If a lot of money is deposited, it means ‘someone’ did due diligence, and that protocol is secure.

Unfortunately, it gives a false sense of security. And high TVL protocols are actively targeted by hackers. At the same time, low TVL doesn’t mean a protocol is not secure.

Take a look at the top DeFi protocols by TVL.

  • Do you think that the TVL represents the level of security/safety?
  • Is there any protocol you wouldn’t trust with your money? Why?

There might be biases in you based on what you read online.

Trust, but verify?

‘Don’t trust, verify’ is the reason we have smart contract audits.

If that wasn’t the case, we might not need audits, because code is open source and community could find all the issues in the code. Yet the community might not have the right motivation, incentives or expertise to verify code.

Auditors are supposed to have the right technical expertise, but at the end of the day, we also have to trust them to do the right job.

Remember Twitter backlash against Certik because a few of their audited protocols ended up hacked?

Audit companies are building their reputation too. If the protocols they audit (and evaluated as safe) are exploited, then it shows lack of expertise. In fact, Certik has audited 3,422 projects, so no wonder some of them got hacked or had a bug.

Just having an audit doesn’t mean the protocol is safe. I’ve seen projects proudly announcing ‘Completed audit’, but when you read the audit the safety score is actually low.

The lesson is not to trust the announcements blindly, but verify the result by reading the actual audit.

What if you don’t read the audits?

The majority doesn’t read the audits anyway.

Knowing that Certik has a dashboard with all their audited projects. You can check the ‘Trust Score’ with higher number implying safety.

https://www.certik.com/

Other auditors like Hacken has a similar dashboard, or you could simply read the audit summary. Check the example, of Trader Joe’s audit done by Paladin.

You can see here that Trader Joe fixed high and medium severity issues, but not all low severity issues has been resolved.

https://paladinsec.co/projects/trader-joe-launchpeg/

Audit is just a start.

A lot more is needed to evaluate safety:

  • Adequate testing
  • Bounty campaigns
  • Documentation clarity
  • Admin controls
  • Oracle documentation

and much more… It’s a nightmare to verify it all yourself.

I really like what DefiSafety is doing. Its Process Quality Review verifies protocols and gives them a safety score.

https://www.defisafety.com/app?orderBy=finalScore

According to the PQR results, Liquity Protocol, Synthetix and Angle Protocol are the safest of all verified DeFi protocols.

On DefiSafety you can then check every element and see where the protocol scores the best/worst.

For example, Liquidy still needs Formal Verification.

Additionally, you can start by rating your portfolio safety on Exponential DeFi.

Its ‘Rate my wallet’ feature provides you with a custom risk analysis of your current investments. For example, $4.5M of Tetranode’s assets are deposited into riskier (C rank) protocols.

Elemental DeFi gives a score based on the project evaluation.Assessment takes into account asset risk, code quality and blockchain security to which the assets are deposited.

I like their easy to understand explanation of risks.

For example, take a look at Abracadabra’s MIM. It warns of SPELL being used as collateral which could result in bad debt.

If in doubt, ask!

Finally, I recommend joining the project community groups and ask:

Do they have an insurance fund?

Do they avoid questions?

What are they doing to increase security?

I asked Stargate team if they had an insurance fund in case they get hacked, but it sometimes more difficult to get an answer than I thought, which poses red flags.

But whatever happens, DeFi is still young, so better not to put all your assets into one protocol.

Do you have more useful tips how to evaluate projects and protect your assets?

Comments

All Comments

Recommended for you

  • BTC breaks through $85,000

    the market shows that BTC has broken through $85,000, now trading at $85,032, with a 24-hour increase of 0.38%. The market is volatile, please manage your risks carefully.

  • Major European stock indices opened higher and ended higher, with the UK FTSE 100 index rising by 2%.

    main stock indexes in Europe opened higher and continued to rise, with the UK's FTSE 100 index up 2%, Germany's DAX index, France's CAC40 index, Italy's FTSE index, and the Euro Stoxx 50 index all up by about 2.4%. 

  • AI Big Model Empowers Cryptocurrency Market, BitradeX Leads Industry Transformation with Forward looking Layout

    The latest industry analysis from BitradeX points out that the explosion of AI big model technology is bringing revolutionary changes to the 24/7 uninterrupted operation of the cryptocurrency market. The all-weather trading characteristics and high market volatility provide unique advantages for AI enabled quantitative trading. BitradeX has been the first to launch an AI Bot product by deeply integrating cutting-edge big model technology with high concurrency quantization systems, achieving millisecond level market analysis and intelligent decision-making. The platform believes that the combination of AI and encryption will reshape the industry landscape, and in the future, the competition core of exchanges will shift from simple trading to intelligent investment services. BitradeX has taken the lead in laying out and leading this wave of change. Official website address: bitradex.com

  • DWF Labs Partners: Hold USD1 to get Falcon Finance closed beta test qualification

    On April 12th, DWF Labs managing partner Andrei Grachev posted on social media that as long as users have the stablecoin USD1 in their on-chain wallet, they can directly access the closed beta testing of the stablecoin protocol Falcon Finance and enjoy its profits earlier than others. Falcon Finance is a synthetic USD stablecoin protocol launched by DWF Labs. Today, DWF Labs has started adding USD1 liquidity on-chain.

  • DWF Labs has deployed USD1 liquidity on ETH and BSC, and USD1 will be officially launched

    according to @EmberCN monitoring, DWF Labs has begun deploying the USD1 liquidity of the DeFi project WLFI supported by the Trump family on the chain, marking that the stablecoin now supports on-chain circulation and trading. Data shows that in the past 8 days, the DWF Labs address has received 11 million USD1 tokens from WLFI on both the Ethereum and BSC chains.

  • 🚀NEXUS 2140 KOREA

    🌍AI· WEB3· ECOMGLOBAL EXPO📍 Goyang, South Korea📅 2025.6.21-22✅ Convergence of 🌟 top-level resources🇰🇷 Supported by the Korean government | 🤝 500 Global Enterprises 🌐 | 150 Investment Institutions 💰 | 3000 KOL 📢✅ Frontier field coverage 🚀AI 🤖 | Web3 🌐 | ECOM's 🛒 three tracks, detonating future business opportunities! 💥✅ High-spec exposure 📡100M media traffic 🎥 | 30K Social Buzz 💬 | The world's top media cooperation 🌎✅ Celebrity event blessing 🎉Summit Forum 💼 | Project Roadshow 🏆 | 15,000 people concert 🎤🌟 | Community dinner 🥂 for 1,000 peopleStrong support from the government, international recognition and praiseConvergence of cutting-edge fields|Industry elites gathered———————————————🚀 Infinite innovation, unlimited 🔥 business opportunities

  • EU Trade Commissioner proposes zero-to-zero tariffs on goods to US

    European Commission Trade Commissioner Dombrovskis: We propose zero tariffs on goods to the United States, and if no trade agreement is reached, we are also prepared to respond. If necessary, we are prepared to take retaliatory measures.

  • BTC breaks through $82,000

    market shows BTC breaking through $82,000, now reported at $82,025.05, with a 24-hour increase of 0.19%. The market fluctuates greatly, please be prepared for risk control.

  • The State Council Tariff Commission: Adjustment of tariffs on imported goods originating from the United States

    on April 10, 2025, the U.S. government announced that the tariff rate for Chinese goods imported into the U.S. will be further increased to 125%. The U.S. imposing excessively high tariffs on China seriously violates international economic and trade rules, as well as basic economic laws and common sense, and is completely unilateral bullying and coercion. In accordance with the "Customs Law of the People's Republic of China," the "Customs Law of the People's Republic of China," the "Foreign Trade Law of the People's Republic of China," and other laws and regulations, as well as basic principles of international law, with the approval of the State Council, the measures of imposing tariffs on imported goods originating in the U.S. will be adjusted starting from April 12, 2025. The relevant matters are as follows:

  • DeFi TVL exceeds $95 billion again

    According to defillama data, as of May 18, 2024, the total value locked (TVL) in DeFi has once again surpassed $95 billion. It is currently reported at $95.069 billion, an increase of nearly $12 billion from the low point of $83.04 billion 35 days ago. Among the top five protocols in terms of TVL, Eigenlayer has the highest 30-day increase, with TVL rising by 19.67% to a total of $15.455 billion.