Skip to content

SYSTEM ONLINE

LIVE TAPE
BTC$85,517.00 4.8%·
ETH$2,734.56 2.8%·
USDT$0.999754 0.0%·
BNB$787.39 2.0%·
XRP$1.52 6.6%·
USDC$0.999848 0.0%·
SOL$116.76 4.4%·
TRX$0.34895 1.7%·
ZEC$1,496.25 0.5%·
FIGR_HELOC$1.01 1.3%·
HYPE$94.31 0.5%·
DOGE$0.100103 12.8%·
XMR$576.42 8.4%·
WBT$85.98 3.2%·
RAIN$0.013684 2.4%·
LINK$12.94 3.5%·
USDS$0.999981 0.0%·
ADA$0.245474 5.6%·
BTC$85,517.00 4.8%·
ETH$2,734.56 2.8%·
USDT$0.999754 0.0%·
BNB$787.39 2.0%·
XRP$1.52 6.6%·
USDC$0.999848 0.0%·
SOL$116.76 4.4%·
TRX$0.34895 1.7%·
ZEC$1,496.25 0.5%·
FIGR_HELOC$1.01 1.3%·
HYPE$94.31 0.5%·
DOGE$0.100103 12.8%·
XMR$576.42 8.4%·
WBT$85.98 3.2%·
RAIN$0.013684 2.4%·
LINK$12.94 3.5%·
USDS$0.999981 0.0%·
ADA$0.245474 5.6%·

DeFi · Incident ledger

DeFi risk managers, ranked by what went wrong and how they handled it

A DeFi risk manager is a firm that sets or recommends the parameters a lending protocol or vault runs on — loan-to-value ratios, supply and borrow caps, oracle choices and which collateral is accepted — under a public mandate. This ranking scores each firm on the documented incidents that happened on its watch.

◆ Incident ledger · rules v1.07 ranked9 scored incidentsSources checked How we score →

The ranking

start 10.0 · minus the record

Each score is computed from the ledger below. “Incident net” is what documented events cost after credits for the response; “Method / history” is the deduction for no public methodology or under a year of mandates.

DeFi risk managers ranked by incident-ledger score. Each score starts at 10.0; the columns show what the documented incidents and the firm-level checks took away.
#FirmScoreIncidentsscoredIncidentnetMethod /historyRecord from
01Steakhouse FinancialDepositors who want a curator whose stated policy is blue-chip collateral only10.0No net deductions00.00.02023
02GauntletDepositors in Compound v3 markets and in Gauntlet's larger Morpho vaults10.0No net deductions20.00.02021
03Chaos LabsProtocols and depositors that want parameters updated continuously rather than by periodic governance votes10.0No net deductions20.00.02022
04SentoraKraken DeFi Earn depositors and allocators who want a curator with a written risk framework9.0Minor deductions00.0−1.02025
05LlamaRiskAave depositors, and readers who want the reasoning behind a collateral listing before it goes live9.0Minor deductions1−1.00.02024
06Block AnaliticaProtocols that want long-horizon collateral analysis; vault depositors should weigh its 2025–26 Lazy Summer record7.0Material incidents2−3.00.02019
07Anthias LabsMoonwell users on Base who want to follow the parameter reasoning month by month6.5Serious record2−2.0−1.52025

We assessed 15 firms. 8 are not ranked: 6 fall outside the category as defined above, and 2 are held back until an incident reported on their markets is confirmed or dismissed by a primary source.

◆ How we score

Every firm starts at 10.0. It loses points for depositor losses or bad debt on markets it was responsible for, sized by the amount, and for public warnings it ignored; it wins part back for a post-mortem within 14 days and for confirmed payouts to depositors. Events older than 24 months count at half weight. Nothing is scored without a primary source, and nothing here is for sale: firms are neither asked nor able to pay to be listed or reordered.

Incident-ledger scoring rules
StepKeyRuleEvidence
Startbase10.0None
Depositor losses or bad debt on markets under managementloss−3.0 per event above $10M; −2.0 for $1–10M; −1.0 below $1MPost-mortems, governance forums, on-chain data
Public warnings ignored before the eventignored_warnings−1.0 per eventTimeline of publications and positions
No public risk methodologyno_methodology−1.5Website, documentation
Less than one year of operationshort_history−1.0Date of the first mandate or vault
Post-mortem within 14 dayspostmortem+1.0 per eventPublication date
Depositors compensatedcompensation+1.0 per eventConfirmed payouts
event_net  = min(0, −loss_tier − warnings + postmortem + compensation)
             × (0.5 if the event is older than 24 months, else 1)
score      = clamp(0, 10, 10 + Σ event_net − no_methodology − short_history)

loss_tier  = 3.0 above $10M · 2.0 for $1–10M · 1.0 below $1M or unquantified

The rules for amounts, attribution, ties and unverified entries are published in full on the methodology page.

What each score rests on

  1. 01
    10.0/10

    Steakhouse Financial

    No net deductions0 incidents scored

    Steakhouse Financial curates lending vaults on Morpho: for each vault it decides which markets the vault may lend into and how much it may place in each. It filed its first Morpho vault whitelisting request in November 2023. Its flagship Steakhouse series admits blue-chip crypto collateral and tokenised traditional assets only.

    On the record

    • No incident found for its vaults, including across the November 2025 xUSD, deUSD and USDX depegs that left bad debt in vaults run by other curators.
    • Publishes a full risk framework — collateral standards, asset and platform ratings, vault controls and a timelock on adding markets — so its decisions can be checked against its own rules.

    Against it

    • Its documented parameter responsibility is concentrated on Morpho vaults, so its ledger reflects a single venue.
    • Curation is set vault by vault: the markets and caps of one Steakhouse vault say nothing about another, so the record does not replace reading the vault itself.
  2. 02
    10.0/10

    Gauntlet

    No net deductions2 incidents scored

    Gauntlet sets risk parameters for Compound v3 — collateral factors, supply caps and interest-rate curves across its deployments — and curates vaults on Morpho. Its public parameter work on Compound dates to February 2021. It also curated Euler DAO's own vaults until the DAO wound them down in April 2026.

    On the record

    • Co-authored a recapitalisation plan for Aave's CRV bad debt the day after it appeared in November 2022, and paid its own insolvency fund toward covering it.
    • Published the markets it removed from each affected vault, with the liquidity involved, nine days after the Resolv exploit, and in June 2026 opened 4,379,827 USDC of recovery claims to depositors.
    • On Compound it acts before trouble: in April 2026 it proposed cutting unused supply-cap headroom across 16 L2 deployments, citing the rise in exploits aimed at long-tail collateral.

    Against it

    • Its USDC Core vault held about $7.6M in a wstUSR/USDC market when USR was exploited on 22 March 2026; independent on-chain analysis attributes 96% of the resulting Morpho bad debt to Gauntlet vaults.
    • The recovery it secured, 4,379,827 USDC across five vaults, is smaller than the allocation removed from USDC Core alone and arrived about ten weeks after the exploit.
  3. 03
    10.0/10

    Chaos Labs

    No net deductions2 incidents scored

    Chaos Labs builds risk oracles — systems that update lending and trading parameters automatically from market data. It was Aave's primary risk manager from November 2022 until it left in April 2026, and served as Venus Protocol's risk manager until early 2026. It works with GMX on market risk and runs USDC vaults in Kraken's DeFi Earn programme.

    On the record

    • Published its post-mortem on the Aave wstETH CAPO incident the same day, naming its own off-chain process as the source of the misconfiguration.
    • Both events on its ledger were explained within four days and followed by confirmed payouts to affected users.

    Against it

    • The CAPO misconfiguration of 10 March 2026 cost Aave users about 512 ETH (≈$1.02M) through erroneous liquidations.
    • The 10 October 2025 crash left about $1.38M of bad debt on Venus, largely from an oracle price deviation Chaos Labs attributed to Chainlink's CAKE feed — a reading Chainlink publicly disputed.
    • Delegates noted the Aave reimbursement came without a public per-user accounting, and one payment was reported about 20 WETH short.
  4. 04
    9.0/10

    Sentora

    Minor deductions0 incidents scored

    Sentora is the institutional DeFi firm formed in May 2025 from the merger of IntoTheBlock and Trident Digital. It designs strategies and manages risk for Kraken's DeFi Earn vaults, launched in January 2026, and curates its own lending vaults on Morpho.

    On the record

    • No incident on its ledger.
    • Publishes a layered risk framework and commits in its curator introduction to publishing incident notes and post-mortems if a risk materialises.

    Against it

    • The earliest dated curation mandate we could source is 5 December 2025, which costs the one-point short-history deduction.
    • A short public record: the ledger has had less than a year of Sentora mandates to observe.
  5. 05
    9.0/10

    LlamaRisk

    Minor deductions1 incident scored

    LlamaRisk is a risk service provider that joined Aave as its second risk manager in 2024 and has carried Aave's risk-management functions since Chaos Labs left in April 2026. It publishes its asset-onboarding framework openly and co-authored Aave's report on the April 2026 rsETH exploit.

    On the record

    • Co-authored a detailed incident report on the rsETH exploit two days after it, with per-market bad-debt scenarios.
    • Its asset-onboarding framework is public, covering market, technological and counterparty risk before parameters are proposed.
    • Depositors on the affected Aave markets did not absorb the loss: the attacker positions were liquidated and the DeFi United coalition funded the remaining gap.

    Against it

    • rsETH and wrsETH were accepted as collateral at up to 95% loan-to-value on eleven Aave deployments while bridged copies depended on a LayerZero route secured by a single verifier; the attacker borrowed about $193M against it.
    • Under the incident report's uniform-loss scenario, bad debt on Aave's Ethereum WETH reserve alone would have been about $91.8M.
  6. 06
    7.0/10

    Block Analitica

    Material incidents2 incidents scored

    Block Analitica, established in 2019, describes itself as the risk team behind the Sky ecosystem (formerly MakerDAO) and builds risk tooling for Spark and other lenders. From 2025 until July 2026 it was risk curator for the Lazy Summer Protocol vaults, a role it gave up after the July 2026 exploit.

    On the record

    • Cut exposure to xUSD and deUSD to zero in late October 2025, before both depegged, which kept those losses out of Lazy Summer vaults.
    • Published a risk-curator retrospective two days after the July 2026 exploit.

    Against it

    • The Arbitrum USDC vault lost about $1.5M on a Silo sUSDX/USDC market in November 2025; the firm's retrospective came 25 days later and a reimbursement was proposed but not confirmed as paid.
    • On 6 July 2026 an attacker extracted about $6.04M from two Lazy Summer USDC vaults by donating overvalued tokens into a strategy the vaults still counted — one capped for offboarding but not yet removed.
  7. 07
    6.5/10

    Anthias Labs

    Serious record2 incidents scored

    Anthias Labs is a risk advisory firm founded in 2022. Since May 2025 it has been risk partner for Moonwell's Base markets, recommending collateral factors, caps and rate curves every 28 days, and it curates the Moonwell Ecosystem USDC vault on Morpho.

    On the record

    • Wrote both Moonwell post-mortems itself, within two days of each event, with full bad-debt tables.
    • Its monitoring caught the cbETH mispricing four minutes after the faulty proposal executed, and it cut the market caps immediately.

    Against it

    • Two losses on Moonwell's Base markets in 2026: about $2.68M of user losses from the cbETH oracle misconfiguration in February, and about $9.13M of residual debt from the MAMO market manipulation in August.
    • Neither event has a confirmed payout: the cbETH plan combined a partial repayment with a share of future revenue and remediation questions were still open in August 2026; the MAMO recovery plan is still under discussion.
    • No public document states the method behind its parameter recommendations, which costs 1.5 points.

The incident ledger

every scored entry, newest first

One entry per firm per event, each with its primary source. The figure in the corner is what the event does to that firm's score today.

  1. Anthias Labs−1.0

    MAMO market manipulation on Moonwell Base

    Role: Risk partner for Moonwell's Base markets; MAMO listed at a 50% collateral factor

    Loss or bad debt
    $9.13M−2.0About $9.131M of borrower obligations left after liquidation — Anthias' best estimate of residual and potential bad debt.
    Response
    Post-mortem in 1 day +1.0
    No confirmed payout
    — No ignored public warning documented

    An actor inflated the mMAMO exchange rate by transferring MAMO straight into the contract and pushed MAMO's price up through thin liquidity, then borrowed about $11.03M. Liquidations began 32 seconds after the last borrow; Anthias published the post-mortem the next day.

    A recovery plan for the affected USDC market was put to governance on 4 September 2026; no payout confirmed.

    Primary sourcePost-Mortem: MAMO Market Incident on Base — Anthias LabsPayout record

  2. Block Analitica−1.0

    Donation attack drains two Lazy Summer USDC vaults

    Role: Risk curator for the Lazy Summer USDC vaults

    Loss or bad debt
    $6.04M−2.0Net losses of about $5.64M in the lower-risk vault and $0.40M in the higher-risk vault, per the Summer.fi post-mortem.
    Response
    Post-mortem in 2 days +1.0
    No confirmed payout
    — No ignored public warning documented

    Vaults were paused by the Guardian multisig; the exploited strategy held stale Silo vault tokens and had been capped for offboarding but was still counted in the share price. BA Labs published a curator retrospective two days later and stepped down as risk curator.

    Recovered USDC left in the vaults was distributed to affected users via Merkl after the loss was socialised; we found no payout toward the loss itself.

    Primary sourceLazy Summer USDC Vault Exploit Post-Mortem — Summer.fiPost-mortemPayout record

  3. LlamaRisk−1.0

    Kelp rsETH bridge exploit leaves bad debt on Aave

    Role: Aave risk service provider holding the parameter controls through the Risk Steward

    Loss or bad debt
    $91.8M−3.0Bad debt modelled for Aave's Ethereum Core WETH reserve alone under the incident report's uniform-loss scenario; Mantle, Arbitrum and Base add about $26.8M more. The attacker borrowed about $193M against 89,567 rsETH on Aave. Every scenario is far above the $10M threshold.
    Response
    Post-mortem in 2 days +1.0
    Depositors paid +1.0
    — No ignored public warning documented

    rsETH and wrsETH were frozen across all Aave V3 deployments within about 90 minutes, WETH rate curves were flattened and WETH frozen on affected markets; a co-authored incident report with bad-debt scenarios followed two days later.

    The attacker positions were liquidated on 6 May 2026, recovering 106,993 rsETH across Aave and Compound, and the DeFi United coalition — to which the Aave DAO contributed — committed ETH to cover the remaining bad debt in all affected Aave markets.

    Primary sourcersETH Incident Report (20 April 2026) — co-authored by Aave service providersPayout record

  4. Gauntlet0.0

    Resolv USR exploit hits Gauntlet-curated vaults

    Role: Curator of Gauntlet USDC Core, USDC Frontier, Resolv USDC, Seamless USDC and Extrafi XLend USDC on Morpho

    Loss or bad debt
    $7.60M−2.0Gauntlet removed the wstUSR/USDC market from USDC Core with $7.6M of liquidity allocated to it (and markets holding $4.3M from USDC Frontier, which later reopened). Gauntlet gives no loss figure; independent on-chain analysis put Morpho bad debt from the exploit at $6.2M, 96% of it in Gauntlet vaults. Every figure sits in the $1–10M tier.
    Response
    Post-mortem in 9 days +1.0
    Depositors paid +1.0
    — No ignored public warning documented

    Reported the exploit and its limited scope within three hours, removed the affected markets after their timelocks, deprecated three vaults, and pursued recovery from Resolv.

    On 3 June 2026 Gauntlet announced an agreement with Resolv under which 4,379,827 USDC of recovery proceeds became claimable by depositors of the five affected vaults through Merkl.

    Primary sourceGauntlet — market removal update, 31 March 2026Payout record

  5. Chaos Labs0.0

    wstETH CAPO oracle misconfiguration on Aave

    Role: Primary risk manager for Aave; operated the CAPO risk oracle

    Loss or bad debt
    $1.02M−2.0512.48 ETH of losses to users (382.76 ETH oracle profit captured by liquidators + 129.72 ETH liquidation bonus) per the Aave reimbursement proposal, converted at the CoinGecko ETH/USD price of $1,992.98 on 10 March 2026. The protocol took no bad debt.
    Response
    Post-mortem the same day +1.0
    Depositors paid +1.0
    — No ignored public warning documented

    Posted a post-mortem the same day: a snapshot ratio and timestamp set out of step pushed the wstETH exchange-rate cap about 2.85% below market, triggering 10,938 wstETH of E-Mode liquidations across 34 accounts. Borrows were capped and the ratios resynchronised through the Risk Steward.

    The Aave DAO refunded affected users from its treasury after recovering part of the liquidators' gains; the AIP was executed and funds distributed by 1 April 2026. Delegates noted there was no public per-user accounting and one payment was reported about 20 WETH short.

    Primary sourcePost-Mortem: Exchange Rate Misalignment on wstETH Core and Prime Instances — Chaos LabsPayout record

  6. Anthias Labs−1.0

    cbETH oracle misconfiguration on Moonwell Base

    Role: Risk partner for Moonwell's Base markets

    Loss or bad debt
    $2.68M−2.0About $2.68M of net losses across roughly 181 borrowers per Moonwell's recovery plan; protocol bad debt was $1,779,044.83 per Anthias' post-mortem.
    Response
    Post-mortem in 2 days +1.0
    No confirmed payout
    — No ignored public warning documented

    Its monitoring flagged the mispricing at 18:05 UTC, four minutes after governance proposal MIP-X43 executed with an oracle reading only the cbETH/ETH ratio; it cut the cbETH supply and borrow caps to 0.01, but liquidations continued until the oracle could be fixed through the five-day governance process.

    A recovery plan combined a partial repayment from a treasury with a share of future protocol revenue, claimable over 12 months; we found no confirmation of payouts, and remediation questions were still open on the forum in August 2026.

    Primary sourceMIP-X43 cbETH Oracle Incident Summary — Anthias LabsPayout record

  7. Block Analitica−2.0

    sUSDX market loss in the Lazy Summer Arbitrum USDC vault

    Role: Risk curator for the Lazy Summer Protocol vaults

    Loss or bad debt
    $1.50M−2.0About $1.5M of depositor losses in the Arbitrum USDC Lower Risk vault from the Silo sUSDX/USDC (127) market, per the reimbursement RFC.
    Response
    Account after 25 days — outside the 14-day window
    No confirmed payout
    — No ignored public warning documented

    Set the market cap to zero on 4 November 2025, two days before USDX depegged, but the vault could not exit because Stables Labs withdrew its liquidity and utilisation hit 100%.

    A one-time reimbursement in SUMR tokens was proposed in December 2025; we found no confirmation that it was paid.

    Primary source[RFC] Arbitrum User Reimbursement, Insurance Fund, and Other ImprovementsPost-mortem

  8. Chaos Labs0.0

    Oracle deviations on Venus during the 10 October 2025 crash

    Role: Risk manager for Venus Protocol

    Loss or bad debt
    $1.38M−2.0About $1.38M of bad debt in Chaos Labs' own analysis (Venus later put it at ~$1.17M at 31 October balances). Separately, borrowers liquidated during the WBETH depeg window were compensated.
    Response
    Post-mortem in 4 days +1.0
    Depositors paid +1.0
    — No ignored public warning documented

    Published a market-volatility update four days after the crash with liquidation volumes, the bad debt and the CAKE oracle deviation it identified (Chainlink disputed that reading in the same thread), then a per-user repayment analysis for WBETH holders.

    The first wave of compensation to users liquidated during the WBETH depeg was executed on 27 October 2025, priced on Chaos Labs' analysis of the depeg window, and a second wave followed. Repayment of the remaining bad debt from the Venus Risk Fund was proposed on 6 November 2025.

    Primary sourceChaos Labs — Market Volatility Risk Update, 14 October 2025Payout record

  9. Gauntlet0.0

    CRV short squeeze leaves bad debt on Aave V2 Ethereum

    Role: Risk manager for Aave V2 Ethereum

    Loss or bad debt
    $1.60M−2.0About $1.6M of excess debt in the CRV market at the CRV price of 23 November 2022, per the recapitalisation proposal Gauntlet co-authored (2,651,906 CRV).
    Response
    Post-mortem in 1 day +1.0
    Depositors paid +1.0
    — No ignored public warning documented
    × 0.5 — older than 24 months

    Co-authored, the day after, a proposal explaining the position that caused the debt and how to repay it, and transferred its insolvency fund to Aave.

    The Aave DAO covered the shortfall rather than socialise it to CRV suppliers; Gauntlet's insolvency fund was transferred to the Aave Ecosystem Reserve.

    Primary source[ARC] Repay excess debt in CRV market for Aave V2 ETH — Llama and GauntletPayout record

What a risk manager decides, and why depositors carry the result

When you deposit into a lending market or a curated vault, the yield on the screen is the output of choices someone else made: which assets may be posted as collateral, how much can be borrowed against each, how large any one position may grow, and which price feed decides when a borrower is liquidated. On Aave and Compound those choices come from a risk manager paid by the DAO. On Morpho and Euler they come from the curator named on the vault. Either way, the depositor carries the outcome and the firm carries the reputation.

That split is why this table reads records rather than promises. A methodology describes how a firm intends to decide. The ledger shows what happened when one of its decisions met a market that did not cooperate, and what the firm did next.

The failures the ledger keeps recording

Three patterns account for most of the entries. The first is collateral whose value depended on something outside the lending market: a synthetic stablecoin whose issuer pulled its liquidity, a restaking token whose bridged copies relied on a single verifier, a yield-bearing stablecoin that an attacker could mint without backing. When that outside dependency broke, markets that still priced the asset near face value were left holding loans against collateral worth a fraction of it. Our analysis of what a vault depositor actually underwrites walks through each layer of that exposure.

The second is the oracle. Several entries trace to a feed that reported the wrong number for minutes or hours: an exchange-rate cap set out of step with its own timestamp, a staked-ETH feed that returned a ratio instead of a dollar price, a thinly traded token pushed up long enough for its feed to accept the new level. Oracle configuration is squarely a risk manager's parameter, which is why these events score — and why the gap between a staking token's redemption value and its market price matters to anyone borrowing against one.

The third is accounting that let an attacker inflate a position without passing through a supply cap, by sending tokens straight to a market contract instead of depositing them. The same mechanism has hit more than one Compound-derived market. Where a ranked firm set the parameters of the market that was drained, the loss sits on its line; where the firm had already handed the mandate on, its review says so.

Reading the response, not only the loss

A loss tells you a parameter was wrong. The response tells you what kind of firm made it. The ledger credits two things: a post-mortem within 14 days that names the cause, the markets and the amounts, and money actually paid back to depositors. Post-mortems are the common part — most incidents here were explained within days, one within hours. Confirmed payouts are rarer, and they are the credit a depositor actually feels.

It is also why two firms can sit on the same score for different reasons. A 10.0 can be a long record with nothing on it, or a record whose incidents were each explained quickly and followed by payouts. The Incidents scored and Record from columns in the table tell the two apart.

How to use this table before you deposit

  • Find out who sets the parameters. The vault page or the protocol's governance forum names the curator or risk manager; if neither does, that is already an answer.
  • Open the firm's ledger entries, not just its score, and check whether the incidents happened on the kind of market you are about to use.
  • Look for the collateral types that recur above in the vault's own list: yield-bearing stablecoins, bridged restaking tokens, thinly traded governance tokens. None disqualifies a vault on its own; each has failed on someone's watch.
  • Read the firm's published methodology and compare it with what the vault holds. A written rule the portfolio visibly breaks tells you more than no rule at all.
  • Size the position to the withdrawal you might need. Lending pools can lock up in exactly the events recorded here — see how utilisation limits withdrawals and how liquidation cascades build.

What this ranking does not tell you

It does not measure yield, and it does not predict. A firm with no entries may simply not have met its test yet, and a firm with several may have run larger and more exposed markets than its peers. The score is a documented record — sized, dated and sourced — to set beside a vault's own collateral list and your own tolerance for the failures described above. It is not investment advice, and no firm on this page has paid to appear on it.

Frequently asked questions

What does a DeFi risk manager actually do?+

It sets or recommends the parameters a lending market runs on: how much can be borrowed against each collateral, how large a position the market will accept, which price feed values the collateral, and which assets are accepted at all. On Aave and Compound the role is a paid mandate from the DAO; on Morpho and Euler the curator of a vault plays the same part for that vault.

Why does every firm start at 10?+

Because the ranking measures a record, not a reputation. Firms lose points only for documented events — losses or bad debt on markets they ran, warnings they ignored — and for two checkable gaps: no published method, or less than a year of mandates. A 10.0 means nothing on the ledger costs the firm points. It is not a claim that the firm is the best at its job.

Can a good response make up for an incident?+

Fully, but never more than fully. A post-mortem within 14 days and confirmed payouts to depositors each win back a point for that event, and an event's net effect is capped at zero. A small loss handled perfectly leaves a firm where it started; it cannot lift it above a firm that never had a loss.

Why is a firm I expected not in the table?+

Some firms sit outside the category as defined — rating services, monitoring platforms, and protocols that hand their parameters to others. Others are held back because an incident on their markets is reported but not yet confirmed by a primary source. Ranking them without the entry would flatter them; ranking them on an unconfirmed figure would not be fair either.

How do I report an incident you missed?+

Send it through the contact page with a primary source: the firm's own statement, the protocol's governance forum or its post-mortem. It is assessed under the same published rules, and any change to a score moves the check date shown on this page.

Last checked · compiled by the CoinRadar Daily ratings desk