Automated Strategies
How to Evaluate a DeFi Protocol Before Depositing Funds
A practical checklist for assessing a DeFi protocol's audit history, TVL concentration, admin controls, and yield source before depositing, and why even audited protocols still get exploited.
Why this checklist exists
Depositing funds into a DeFi protocol means trusting its smart-contract code with your money, with no company, support line, or deposit insurance standing behind it if something goes wrong, a distinction covered generally in What DeFi and a DEX Actually Are. That doesn’t mean every protocol is equally risky; it means the due diligence that a bank or a regulated exchange effectively does for you has to be done yourself, or at least understood well enough to make an informed decision. The following isn’t a guarantee of safety for anything that passes; it’s a way to systematically catch the most common reasons DeFi deposits actually go wrong.
Has it been audited, and by whom
A smart-contract audit is an independent security review of a protocol’s code, looking for bugs, logic errors, and exploitable vulnerabilities before (or after) the protocol goes live. Reputable auditing firms have real reputations at stake and publish their findings, which is worth checking directly rather than trusting a protocol’s own summary of “we passed our audit.” A few things worth confirming specifically: which firm conducted the audit (established, well-known firms carry more weight than an obscure or first-time auditor), whether the audit covers the current version of the code actually deployed (a protocol that’s been updated since its last audit has, in effect, unaudited changes), and whether any findings were left unresolved.
It’s just as important to understand what an audit doesn’t guarantee. An audit is a review of the code as written against known categories of vulnerabilities within a limited time frame; it isn’t a proof of correctness, and it doesn’t cover risks like a poorly designed economic incentive that’s technically bug-free but exploitable in practice, or a completely new kind of attack not yet known to the security research community at the time of the review. Audited protocols have still been exploited, sometimes for large sums, which is a fact worth taking at face value rather than treating “audited” as a synonym for “safe.”
How long has it been live and battle-tested
A protocol that’s held meaningful deposits for a long stretch of time, across different market conditions, without incident, has a track record that a brand-new protocol simply cannot have yet, no matter how good its code looks on paper. This isn’t a guarantee either (a long-running protocol can still be exploited for the first time on any given day), but time in production under real economic conditions, with real attackers actively looking for flaws and finding none, is meaningful evidence in a way that code review alone isn’t. A protocol launched days or weeks ago, however well-marketed, hasn’t yet had the chance to prove anything.
Is TVL concentrated or distributed
TVL (Total Value Locked) is the total value of assets deposited in a protocol. Two things are worth checking beyond the headline number: how TVL is distributed across depositors, and how it’s distributed across the specific pools or markets within the protocol. A protocol whose TVL is dominated by a handful of very large wallets carries a different risk than one with broadly distributed deposits, since a small number of large holders withdrawing at once can behave very differently from a protocol with many smaller, independent depositors, particularly for anything relying on deep liquidity to function normally (like an AMM pool, described in What DeFi and a DEX Actually Are). A sudden, unexplained spike in TVL, especially alongside aggressive marketing or unusually high advertised yields, is also worth treating with extra scrutiny rather than as pure reassurance.
Is there a multisig or timelock on admin functions
Most DeFi protocols retain some administrative capability even after launch: the ability to upgrade contracts, adjust parameters, or in some designs, withdraw or redirect funds. Who controls that capability, and how, matters enormously. A protocol where a single private key can unilaterally change core contract behavior or move funds is a centralization risk dressed up as decentralized infrastructure, and it’s the exact mechanism behind a meaningful share of rug pulls, described in Common Crypto Scams: a team that retains sole control over admin functions can, in the worst case, simply use that control to drain the protocol.
Two mitigations to look for specifically: a multisig requiring several independent parties to approve any admin action (reducing the risk of a single compromised or malicious key), and a timelock, which forces a delay between an admin action being proposed and it actually taking effect, giving depositors time to notice and withdraw before a change goes live. Neither eliminates the risk entirely, but a protocol with no multisig and no timelock on meaningful admin functions is trusting a single point of failure with your deposit, whatever else about its code looks solid.
What’s the actual yield source
This is one of the most important, and most commonly skipped, questions: where does an advertised yield actually come from. There are two broad categories, and they’re not equally sustainable.
- Real fee revenue: yield paid out of genuine economic activity the protocol facilitates, like trading fees from an AMM pool or interest paid by actual borrowers in a lending market. This kind of yield scales with real usage and tends to be more durable, though it also fluctuates with that usage rather than staying fixed.
- Token emissions: yield paid in a protocol’s own newly minted token, funded by inflation rather than by any underlying economic activity. This can produce eye-catching advertised percentages, but it’s effectively the protocol paying you with a token it can print more of, and if the token’s price falls (which added selling pressure from yield farmers claiming and selling rewards often accelerates), the real, dollar-denominated yield can be far lower than advertised, or negative. This dynamic and its connection to impermanent loss is covered further in Exchange Staking vs. On-Chain Staking vs. Yield Farming.
An unusually high yield relative to comparable protocols is a specific, checkable prompt to ask which of these two categories it’s actually coming from, not a reason for immediate excitement.
Smart-contract risk generally
Even a protocol that clears every item above, audited by a reputable firm, battle-tested for years, broadly distributed TVL, a real multisig and timelock, and sustainable fee-based yield, still carries residual smart-contract risk. Some of the largest DeFi exploits in the industry’s history have hit protocols that had passed multiple audits and operated successfully for a long time beforehand; code review and track record reduce risk, they don’t remove it. Treating any DeFi deposit as entirely risk-free because it checks every box on a list like this one would be a mistake; the honest framing is that this checklist helps you avoid the more obviously avoidable failures, not that it certifies safety.
Frequently asked questions
Is a higher TVL always a sign of a safer protocol? Generally correlated but not guaranteed. High TVL often reflects accumulated trust and time in production, both genuinely useful signals, but a protocol can also accumulate large TVL quickly through aggressive incentives shortly before a problem surfaces. TVL is one data point among several, not a safety score on its own.
Should I avoid any protocol that isn’t fully immutable, meaning it has no admin controls at all? Not necessarily; some legitimate reasons exist for a protocol to retain limited upgrade capability, such as fixing a genuine bug quickly. The more important question is how that capability is controlled (multisig, timelock, transparency) rather than whether it exists at all, since a poorly governed immutable protocol with an undiscovered bug can be just as risky as a well-governed upgradeable one.
How do I actually check who holds the multisig keys? Reputable protocols typically publish this information, often on their documentation site or through a blockchain explorer showing the multisig contract’s signers. If a protocol doesn’t make this information easy to find, that itself is worth treating as a red flag rather than assuming it’s simply an oversight.
Does using an audited protocol mean I don’t need to think about custody or wallet risk separately? No; protocol-level risk and your own wallet security are entirely separate categories, covered in Wallets and Custody. A perfectly secure protocol doesn’t protect you from a phishing site or a compromised seed phrase, and vice versa.
Risk
Nothing on this page is financial advice, and it is not a complete or current statement of any specific protocol’s security, audit status, or yield sustainability. Even audited, long-running, well-governed DeFi protocols have been exploited, and a smart-contract failure can result in a total, unrecoverable loss of deposited funds. Do your own research before making any decisions based on this page.