How to read a DeFi protocol’s risk disclosures
You can read DeFi risk disclosures by checking docs, audits, app UI, and governance forum, then audit dates, liquidation rules, admin keys, terms.

On this page
- Risk disclosures sit in docs, audits, the app, and governance forums.
- Audits show what was reviewed, when, and what stayed open.
- Lending markets list collateral factors, liquidation rules, and oracles.
- Admin keys, bridges, and terms carry risks beyond the app.
The words in the app often hide the details that matter. You do not need to be a programmer, but you do need to read slowly and compare the app with the documents.
Where are the risk disclosures?
Start with the protocol's materials. The documentation explains how it works, while audit reports sit in a security folder. The app shows warnings and parameters, and the governance forum holds proposals that can change the rules.
How do you read them step by step?
Reading risk disclosures takes patience. Compare each document with the current app and the latest governance votes.
- 1Check each audit's date and scopeCompare the report date with the latest code upgrade. Read which contracts the auditors reviewed, and treat unresolved findings as open risks.
- 2Read lending market rulesLook for collateral factors, liquidation thresholds, and oracle price sources. These rules decide when your collateral can be sold.
- 3Find who controls admin keysCheck who can upgrade contracts, pause the protocol, or move user funds. Look for a multisig, timelock, or governance vote.
- 4Follow assets across chainsIf you use a bridge or a stablecoin on another chain, read the bridge contract risks and the stablecoin's peg history. Stablecoins have traded below their peg, as USDC did in March 2023.
What should you do after reading?
After reading, review the legal terms and your records. DeFi can feel anonymous, but tax and legal duties usually remain. The IRS treats crypto as property, so income and trades may need to be reported.
Frequently asked questions
Treat the missing page as a warning sign. Look for audits from a parent company or a fork. If basic disclosures are missing, you have little basis to judge the risks.
No. An audit is a review at one point in time by one firm. It can miss bugs, and later code changes can create new risks.
Usually no. The CFTC has warned that government agencies do not regulate or supervise most virtual currency cash markets. You also cannot be sure of getting your virtual currency back if it is stolen.
They can change with every upgrade, parameter vote, or new audit. Read them again before you add funds or change your position.





