Rubric v2.0 · effective 2026-08-22
How the Radar Score works
A rating is only worth the method behind it. Here is ours, in full, including what it cannot see.
The whole thing in one line
Radar Score = Σ ( pillar score × category weight ) − Σ penalties
clamped to 0–10 · one decimal place · recomputed on every save
There is no discretionary adjustment at the end, no editor's thumb on the scale, and no field anywhere in our system that lets a person type an overall score by hand. The judgement lives in the pillar findings, where it can be read and argued with. The arithmetic is arithmetic.
Where the findings come from
This is a documentary method. Every finding on this site rests on a public, dated source: an audit report, a regulatory register entry, on-chain data, a published fee schedule, a terms-of-service clause, an incident post-mortem. You are never asked to take our word for something — you are asked to check it.
We do not open accounts, place trades, file support tickets or time withdrawals, and no score here is derived from anything that would require us to. That is a real constraint and we would rather print it at the top of the methodology than let a reader assume otherwise — the limits section below sets out what it costs us.
What it buys, in exchange, is auditability. A rating built on one reviewer's afternoon with an app cannot be checked by anyone; a rating built on documents can be checked by everyone, including the company being rated. For the questions that actually decide whether you lose money — who holds the keys, what the terms permit, whether the reserves are attested or audited, how the last incident was handled — the record is the better instrument anyway.
The five pillars
Every service on the site is assessed against the same five pillars, whatever its category. That is what makes a wallet score and an exchange score comparable at all — the questions are constant, only their weighting moves.
Custody & Security
Who can move your money, and what happens when something breaks?
The pillar that decides whether everything else matters. We look at who holds the keys, what stands between an attacker and the balance, and — because every operator eventually has a bad day — what the record shows about how losses were actually handled.
What we check
- Key custody model as described in the operator's own documentation and terms
- Published third-party security audits, read in full rather than taken from a summary badge
- Proof-of-reserves or attestation reports, and whether balances are verifiable on-chain
- Incident history over 36 months from post-mortems, filings and contemporaneous reporting
- Insurance or backstop documents, including the exclusions
- Open-source status and reproducibility of the code that touches user funds
Cost & Fee Transparency
What does using this actually cost, including what isn't on the fee page?
Headline fees are marketing. We reconstruct the whole round trip from published schedules and on-chain or contract-level parameters — deposit, spread, execution, network pass-through, withdrawal — and treat a cost that is not discoverable before signing up as a transparency failure, not a footnote.
What we check
- Full published fee schedule, versioned and dated, or its absence
- Spread and pricing method as documented, and whether the real spread is disclosed at all
- Network fees passed through at cost or marked up, per the published terms
- Withdrawal, inactivity and conversion fees discoverable before signup
- Cost of exit, and any condition the terms place on getting everything out
Regulation & Legal Standing
Who authorises this, and what do the terms let them do to you?
Not a proxy for trustworthiness — plenty of unlicensed software is safer than licensed custody. It measures something narrower and checkable: which regulator can be complained to, what enforcement history exists, and what the terms of service quietly reserve the right to do.
What we check
- Named licences and the regulators that issued them, verified against public registers
- Enforcement actions, consent orders and ongoing restrictions
- Corporate structure: which entity actually holds the contract with the user
- Terms of service: unilateral freeze, rehypothecation and forced-arbitration clauses
- Segregation of user assets from operating funds
Performance & Reliability
Does it still work on the worst day of the year?
Judged on the record of stress events rather than on a quiet market: public depth and volume data, status-page and outage history during the sessions that made people want to trade, documented peg behaviour under redemption pressure, and whether an advertised yield has a source that survives a drawdown.
What we check
- Liquidity or total value locked from public data, and how concentrated it is
- Published status-page and outage history covering the highest-volatility sessions of the last year
- Documented execution or peg behaviour during past redemption and de-peg events
- Yield sustainability: where the return demonstrably comes from, per the protocol's own accounting
- Length of live track record and what it has actually been through
Access & Support
Can you actually use it, and is anyone there when it goes wrong?
Geography, onboarding requirements, documentation honesty and what the record shows about support. We read the published jurisdiction policy, the stated onboarding requirements and the documentation itself, and we weigh the pattern in public complaint channels rather than a single bad review.
What we check
- Jurisdictions served, and how clearly exclusions are stated before signup
- Onboarding requirements as published: documents, thresholds and stated timeframes
- Documentation quality, especially how honestly failure modes are described
- Sustained pattern in public support complaints, weighted by volume rather than anecdote
- Accessibility, language coverage and interface clarity for non-experts
Weights, fixed in advance
Weights are set for a category before any service in it is looked at, and they are published on the category page. A service cannot be helped by moving the goalposts after the fact, because the goalposts were printed first.
| Category | Custody | Cost | Regulation | Performance | Access |
|---|---|---|---|---|---|
| Crypto Exchanges | 30 | 20 | 20 | 20 | 10 |
| Decentralised Exchanges | 30 | 20 | 5 | 30 | 15 |
| Perpetual DEXs | 25 | 25 | 5 | 35 | 10 |
| Instant Exchangers | 25 | 30 | 15 | 15 | 15 |
| Trading Tools | 25 | 20 | 10 | 30 | 15 |
| Hardware Wallets | 45 | 15 | 5 | 15 | 20 |
| Crypto Wallets | 40 | 10 | 5 | 20 | 25 |
| Staking Platforms | 30 | 25 | 15 | 20 | 10 |
| Liquid Staking | 30 | 20 | 10 | 30 | 10 |
| Liquid Restaking | 35 | 15 | 5 | 35 | 10 |
| Yield Aggregators | 35 | 20 | 5 | 30 | 10 |
| Lending Platforms | 35 | 20 | 10 | 25 | 10 |
| DeFi Protocols | 35 | 15 | 5 | 35 | 10 |
| Crypto Bridges | 45 | 15 | 5 | 25 | 10 |
| Stablecoins | 35 | 10 | 20 | 30 | 5 |
| NFT Marketplaces | 25 | 25 | 5 | 25 | 20 |
| NFT & AI Tools | 20 | 25 | 5 | 30 | 20 |
| Crypto Cards | 25 | 25 | 20 | 15 | 15 |
Figures are percentages and total 100 for every row. Highlighted values are the pillar that dominates that category.
Penalties
A weighted average is a generous instrument: strength in four pillars will quietly absorb a disaster in the fifth. These deductions exist so it cannot. They are applied after the average, from a fixed list, and shown on the review with the reason attached.
Unrecovered user-fund loss
Users lost funds in the last 24 months and were not made whole. Applies once, regardless of cause.
Withdrawals halted
Withdrawals were suspended in the last 12 months outside a pre-announced maintenance window.
Live enforcement action
A regulator currently restricts the service, its market access or its users' ability to withdraw.
Undisclosed cost
A material cost of using the service is documented somewhere other than the fee schedule — in the terms, in a help article, or in a condition attached to a reward — where a user pricing the product would not find it.
No current audit
Custody or contract code that holds user funds has no third-party audit against the deployed version.
Material fact undisclosed
The operator publishes nothing at all on a question this rubric asks — no fee schedule, no reserve or audit disclosure, no named operating entity. Silence is a finding, and it is scored as one.
What the numbers mean
Best in its category on evidence, not reputation. Rare by design.
Does the job well with no material unresolved concerns.
Dependable, with trade-offs a reader should know about first.
Works, but something here costs you — money, control or certainty.
Real weaknesses. Suitable only for a narrow, informed use case.
We would not put our own funds here on the current evidence.
We do not grade on a curve. If nothing in a category clears 8.0, the table tops out below 8.0 and says so — a category where the best available option is merely adequate is useful information, and inflating it to look decisive would be the opposite of a rating.
Rules v1.0 · effective 2026-09-21
DeFi risk managers: the incident ledger
The five pillars score a service you use. A risk manager is not one: it is the firm deciding the parameters of the markets you deposit into, and what a reader can check about it is its record. So the DeFi risk managers ranking does not use the pillars at all. Every firm starts at 10.0, loses points for documented events on markets it was responsible for, and wins part of them back for how it responded.
In scope: Organisations that, by public mandate or through a protocol's own interface, are responsible for risk parameters: limits, loan-to-value ratios, oracles and the composition of accepted collateral. Out of scope: Code auditors, insurance protocols, and security-monitoring or rating services with no role in setting parameters.
The rules, verbatim
| Step | Key | Rule | Evidence |
|---|---|---|---|
| Start | base | 10.0 | None |
| Depositor losses or bad debt on markets under management | loss | −3.0 per event above $10M; −2.0 for $1–10M; −1.0 below $1M | Post-mortems, governance forums, on-chain data |
| Public warnings ignored before the event | ignored_warnings | −1.0 per event | Timeline of publications and positions |
| No public risk methodology | no_methodology | −1.5 | Website, documentation |
| Less than one year of operation | short_history | −1.0 | Date of the first mandate or vault |
| Post-mortem within 14 days | postmortem | +1.0 per event | Publication date |
| Depositors compensated | compensation | +1.0 per event | Confirmed payouts |
The formula
event_net = min(0, −loss_tier − warnings + postmortem + compensation)
× (0.5 if the event is older than 24 months, else 1)
score = clamp(0, 10, 10 + Σ event_net − no_methodology − short_history)
loss_tier = 3.0 above $10M · 2.0 for $1–10M · 1.0 below $1M or unquantifiedEvents are stored in a separate ledger, one entry per firm per event, each with a primary source. Adding or editing an entry recomputes that firm's score automatically; the page also recomputes on every render, so the half-life and the one-year threshold apply on the day you read it rather than the day the entry was written.
How the rules are applied
- Bounds and half-life
- The score is held between 0 and 10. Every penalty and credit belonging to an event more than 24 months old is multiplied by 0.5, so an old incident still counts, at half weight.
- A response cannot turn an incident into a gain
- Credits for a post-mortem and for compensation can offset an event's penalties in full, but not beyond them: an event's net effect is never positive. Without this, a small loss handled well would raise a firm above a firm that never had one.
- Tier boundaries
- An event of exactly $10M sits in the $1–10M tier; exactly $1M does too. A loss stated in a token is converted at that token's USD price on the day of the event, and the conversion is shown in the entry.
- What counts as the amount
- Depositor losses or bad debt as a primary source states them — the firm, the protocol's governance forum, or the protocol's own post-mortem. Where the primary record gives only a lower bound, the tier follows that bound. A confirmed loss whose size no primary source states is scored at the lowest tier and marked as unquantified.
- What counts as a post-mortem
- A public account, by the firm or co-authored by it, that names the cause, the affected markets with amounts, and the actions taken. The 14 days run from the event to that account's publication date. A status update that says only that the team is investigating does not count.
- What counts as compensation
- Payouts that have happened, not payouts that were proposed. New money paid toward depositors' loss counts whoever paid it — the firm, the protocol treasury, the counterparty or a recovery coalition — and the entry states how much was paid against how much was lost. A proposal still under discussion does not count, and neither does handing depositors whatever assets were left in the vault.
- Attribution
- An event is recorded against the firm that held the parameter mandate for that market on the day it happened. When a mandate was being handed over, the firm that controlled the parameters that day carries the event, and the other firm's review says so.
- What counts as a public methodology
- A document published by the firm that states how it decides the parameters it is responsible for: the inputs it reads, the thresholds or models it applies, and when it changes a parameter. A scope of work, a list of services or a series of recommendations does not qualify on its own.
- Unverifiable track records
- Less than a year is measured from the earliest dated mandate or vault we can source. A record we cannot date is treated as a short one; a firm that shows us an earlier dated mandate has the deduction removed.
- Unverified incidents hold a firm back
- An event reported in secondary sources but not yet confirmed by a primary one is kept as a draft entry and does not score. A firm with such an open entry is held out of the ranking entirely until it is confirmed or dismissed, so an unverified incident can neither sink a score nor be quietly left out of one.
- Ties
- Firms with the same score are ordered by fewer scored incidents, then by the earlier first documented mandate, then alphabetically.
Coverage · For every mandate listed in a firm's review we searched that protocol's governance forum and the firm's own publications for bad-debt, post-mortem, reimbursement and incident threads, from the start of the mandate to the check date, and cross-checked against independent incident reporting. An incident we missed is a correction, not a matter of opinion: send it with a primary source and it is assessed under the same rules and dated in the change log.
Reading a ledger score
Nothing on the ledger costs this firm points. That is an absence of documented failures, not proof of skill.
A limited or well-handled record, or a short or undocumented method.
At least one incident with real depositor cost that the response did not fully offset.
Repeated or large incidents with incomplete responses.
These readings are not the Radar Score bands above. On the ledger 10.0 is where every firm starts, so it means the record holds nothing against the firm — not that the firm is exceptional.
Independence
This section is the reason the rest of the page is worth reading. Any site can publish a rubric; what matters is what the rubric is not allowed to be overruled by.
There is nothing here to buy
CoinRadar Daily is a non-commercial project. No advertising, no affiliate or referral links, no sponsored placements, no commercial relationship of any kind with anything we rate. A rating cannot be bought because none is for sale, which is a stronger guarantee than a policy against selling one.
Rank cannot be bought, and non-partners are ranked anyway
Ordering is by computed score, full stop. Every service in a category is scored on the same terms, and none of them has any relationship with us that could make it otherwise.
Outbound links earn us nothing
Links to a rated service point at its own site for reference. None carries a referral parameter, none is tracked, and following one transfers nothing to us.
Reviewers hold no position in what they rate
Anyone contributing findings on a service declares holdings in it or its token first, and is reassigned if there are any.
Every finding cites something you can open yourself
A finding rests on a public, dated source — an audit report, a regulatory register entry, on-chain data, a fee schedule, a terms-of-service clause, an incident post-mortem. You are not asked to take our word for anything; you are asked to check.
Corrections are made on evidence, from anyone, including the operator
There is no pre-publication approval process and we do not pretend to run one. Instead the channel is open permanently and in both directions: show us a source that contradicts a finding and we change the finding, recompute the score and date the change on the review. Disagreement with our judgement is noted; disagreement with our facts is settled by the facts.
Weights are fixed before scoring and versioned in public
Category weights are set in advance and published. This page is rubric v2.0, effective 2026-08-22; when weights change, the version changes and previously published scores are recomputed, not quietly left in place.
Scores expire
A rating is a claim about the record on a particular date. Past 90 days it is flagged for re-check; past 180 days the sources are treated as stale and the entry drops out of the ranking until someone reads them again.
What this method cannot see
Every method has blind spots. A rating that does not publish its own is asking to be trusted rather than checked, which is the opposite of the point. Here are ours.
We are reading the record, not using the product
A public-evidence method sees what an operator has published and what the world has written down about it. It does not see what the tenth support ticket is like, whether a withdrawal actually clears on a Sunday, or how the interface behaves under load. Where a pillar depends on that kind of experience, our finding is weaker and we say so on the review rather than rounding it up.
Good disclosure and good behaviour are not the same thing
This method rewards operators who publish. A well-run business that documents little will score below a mediocre one with an excellent transparency team, and that is a genuine distortion rather than a subtlety. It is also why silence carries a penalty: if disclosure is what we can see, then refusing to disclose has to cost something.
The record is thinner for newer and smaller services
Audits, post-mortems, register entries and outage histories accumulate over time. A young protocol has less of everything, which shows up as a lower score even where nothing is wrong. We treat a short track record as the material fact it is, but readers should not confuse it with evidence of a problem.
Nothing here is verified for the day you read it
Every finding is anchored to a source with a date. Fee schedules change, licences lapse, audits go stale. That is why a rating carries its check date on the page and expires out of the ranking rather than sitting there implying it is current.
Absence of evidence is scored honestly, in both directions
No public record of an incident is not proof there was none, and we do not treat it as one. Equally, an operator with a documented failure is not automatically worse than one whose failures never reached the public record. The scores describe the evidence, and the evidence is not the whole world.
What we deliberately do not do
- ✕No sponsored placements, no paid reviews, no advertising, no affiliate links, and no 'featured' slots — sold or otherwise.
- ✕No scores where the public record is too thin to support one. A missing pillar is left missing rather than guessed at, and a service with almost nothing on the record does not get rated at all.
- ✕No claims of hands-on testing. We do not open accounts, place trades, run support tickets or time withdrawals, and nothing on this site will tell you we did.
- ✕No price predictions, and no rating of a token as an investment — we rate services, not bets.
- ✕No aggregate user-review scores: unverifiable ratings are trivially farmed and we will not launder them through ours.
Getting it wrong
We will. Every finding here is a reading of a document, and documents get misread. When a finding turns out to be wrong we change it, recompute the score, and date the change on the review rather than editing the page silently. If you can show us a source that contradicts anything on these pages, tell us — including if you work for the company concerned.
Frequently asked questions
Can a company pay for a better score or a higher position?+
No, and not because we decline the offers — because there is nothing to buy. CoinRadar Daily is a non-commercial project with no advertising, no affiliate links and no commercial relationship with anything it rates. Position is a sort on the computed score and nothing else.
Why does the same pillar count for more in one category than another?+
Because the risk is not the same. Custody carries 45% for hardware wallets and bridges, where a failure means the money is gone, and 20% for tools that never touch your funds. The weights for each category are set before anything in it is scored, and they are printed on that category's page.
What happens when a rated service has an incident?+
Penalties are applied from a published list rather than absorbed into a vague downgrade. An unrecovered loss of user funds in the last 24 months costs 2.0 points; halted withdrawals cost 1.5; publishing nothing at all on a question this rubric asks costs 0.5, because silence is a finding too. The deduction appears on the review with the reason attached.
How current is a score?+
Every rating carries the date its sources were last checked. After 90 days it is flagged for re-check; after 180 days the sources are treated as stale and the entry drops out of the ranking until someone reads them again. We would rather show a gap than a stale number.
Do you actually use the services you rate?+
No, and we will not pretend otherwise. This is a documentary method: we read audit reports, regulatory registers, on-chain data, fee schedules, terms of service and incident post-mortems, and every finding rests on a public source you can open yourself. We do not open accounts, place trades, file support tickets or time withdrawals — so nothing on this site claims a number that would require us to.
Is a rating based on public documents worth anything?+
For the questions that decide whether you lose money, it is the stronger instrument. Whether a bridge is secured by a five-key multisig, whether a stablecoin's reserves are attested or audited, what a lending platform's terms permit it to do with your deposit — these are matters of record, and reading the record carefully beats one person's afternoon with the app. What it cannot tell you is what the service feels like to use, and we have a section above saying exactly that.
What if a company disagrees with a finding?+
Send us the source. We do not run a pre-publication approval process and do not claim to; instead the correction channel is open permanently, to operators and readers alike. A document that contradicts a finding changes the finding, the score is recomputed, and the change is dated on the review. Disagreement with our judgement is noted and the score stands.