Review Methodology: How DifiCalc Grades DeFi Protocol Risk

By DifiCalc Research Team · Published Sep 10, 2026 · Reviewed Sep 10, 2026

TL;DR. Every protocol receives a 0–100 weighted risk score from TVL depth (25), independent audits (25), operating years (15), chain diversification (10) and category/adjustment factors. The score maps to an A+–D letter grade, and the published grade maps to a 1–5 editorial rating. The exact weights, thresholds and data sources are published on this page; grades cannot be bought and affiliate revenue never changes them.

1. What the score measures

The score estimates structural protocol risk — how resilient a protocol is to smart-contract, liquidity and operational failure. It does not estimate token price direction, tax treatment or regulatory status. Factors and maximum points:

FactorHow it is scoredMax
Total value lockedLog-scaled from $10k (0) to $10B (25); deeper liquidity resists shocks and exit slippage.25
Independent audits5 points per public audit from recognized firms, capped at 25. Audit names are listed on each review.25
Years in production3 points per full year since launch, capped at 15. Survived market cycles count.15
Chain diversification2 points per supported chain, capped at 10. Multi-chain deployment reduces single-chain dependency.10
Category baselineLending and stablecoin protocols +5, aggregators +3, prediction markets 0, perpetual DEXs −5 (leverage and liquidation risk).±5
Affiliate-risk signal−5 when a protocol pays unusually high (30%+) referral commissions, a common unsustainable-user-acquisition signal.−5
Impermanent-loss exposure−5 when flagship strategies carry volatile-asset LP exposure that can erase headline yield.−5

The same formula runs openly in the Yield Risk Grader, where the complete point breakdown is displayed for every protocol.

2. Score to letter grade

ScoreGradeInterpretation
90–100A+Very low structural risk; suitable for core positions
80–89ALow risk
70–79B+ / A- bandModerate-low; smaller or newer but well-audited
60–69BModerate risk; position-size carefully
45–59CElevated risk; speculative allocation only
Below 45DHigh risk; conservative users should avoid

3. Letter grade to 5-star editorial rating

Published reviews show the grade both as a letter and as a 1–5 rating (worst 1, best 5) inside the page's Review structured data, using this fixed mapping:

GradeEditorial rating
A+4.8 / 5
A4.3 / 5
A-4.1 / 5
B+3.8 / 5
B3.3 / 5
C+2.8 / 5
C2.3 / 5
D1.5 / 5

4. Editorial overrides

The algorithmic score is an input, not the final verdict. Human analysts can set the published grade when the formula misses qualitative context — for example, a protocol with strong raw metrics but a recent exploit, or a newer protocol with unusually rigorous audits. Every override uses the same grade bands, the factor breakdown remains visible on the review, and the override rationale appears in the review text. Overrides are never sold.

5. Data sources and verification cadence

6. Independence and limits

Frequently asked questions

How often are DifiCalc protocol reviews updated?

Every protocol review shows a published date and a last-verified date. Reviews are re-verified at least quarterly and immediately after material events such as a major exploit, an audit publication, a large TVL change or a protocol upgrade.

Can a protocol pay DifiCalc for a better grade?

No. There are no paid placements and no pay-to-rank arrangements. Where DifiCalc earns an affiliate commission, an affiliate disclosure appears on the review and the commission never changes the risk grade or editorial rating.

Does an A+ grade mean my funds are safe?

No grade eliminates risk. A+ means the protocol scores highest on the structural factors DifiCalc can measure — TVL depth, audits, operating history and diversification. It cannot predict a future exploit, governance attack, stablecoin depeg or market crash, and it is not financial advice.

Where do TVL and APY figures come from?

Live and historical TVL and yield data come from the DeFiLlama Yields and Coins APIs. Audit lists, founding years and supported chains are cross-checked against official protocol documentation and public audit reports.

Why can the editorial grade differ from the calculator score?

The Yield Risk Grader tool computes a purely algorithmic score from the same weighted factors. Published reviews use that score as input, but human analysts can apply an editorial override when the formula misses qualitative context; the override is recorded in the review and the factor breakdown remains visible.

See the methodology applied

Browse all 11 protocol reviews with grades, ratings and full score breakdowns.

View Protocol Reviews →