Unit 4 · Level 3 · The DeFi risk stack
The DYOR checklist
'Do your own research' usually means nothing; it's a hashtag people type before aping in. Let's make it a method. Five checks: what the protocol does and where its yield comes from; audits, age, and exploit history; who holds the admin keys; whether the TVL is real and spread out or two whales who can leave tonight; and finally, position size. Twenty minutes of this filters out most disasters before they can find you.
Free to play. No ads, no token, no account needed to start.
What you get asked
A protocol shows €500M TVL. What matters more than the headline number?
TVL can be rented (emissions), faked (protocol-owned deposits), or concentrated (a whale duo). Quality of the money beats quantity of the money.
Run the DYOR checklist in order:
Comprehension first, sizing last. If you can't pass step one in plain words, steps two through five don't matter.
Code that has secured billions for ___ is safer than a fork deployed last week.
Time-tested code has survived thousands of real attack attempts. A fresh fork has survived a copy-paste.
The team behind a protocol is anonymous. The honest read:
Some of DeFi's most battle-tested code was shipped by pseudonyms. But anonymity removes one safety net, so demand more from the other checks: audits, age, timelocks.
DeFi risks stack: contract, oracle, governance, market. What follows for position sizing?
Stacked risks multiply, and any layer can fail alone. Same spirit as the 1% rule from the Trading course: survive first, compound second. 🐜
The rest of this unit
Code, oracles, and admin keys: the risks stacked under every APY.