USDA
Bu tür bir varlık için geçerli olan riskler; her birinin arkasındaki mekanizma ve bir araştırmacının fiilen inceleyebileceği kanıtlarla birlikte. Bunlar, nelerin yanlış gidebileceğine ilişkin açıklamalardır — değerlendirme değil, tahmin değil, herhangi bir eylem için neden de değil.
Counterparty
Customer assets are pooled and reused, lent, posted as collateral, or traded, so the same units back more than one obligation at once.
Neye bakılmalı: Read the custody and yield terms for language granting the venue the right to use, lend, or pledge assets. Ask whether balances are held in named or omnibus wallets and whether any regulator requires segregation for that entity. On-chain, look for regular movement between exchange-labeled addresses and affiliate or lender addresses, and check whether any proof-of-reserves exercise covers liabilities and was performed by an independent party.
One custodian, one signing arrangement, or one operations team stands between holders and their assets, so a single failure can be terminal.
Neye bakılmalı: Establish who can sign, in what quorum, under what recovery procedure, and whether any independent party has tested the key ceremony and the disaster recovery plan. Check whether the custodian is a regulated trust company or similar, what its financial statements show, and whether it discloses subcustodians. Read the insurance policy's scope rather than the headline figure, since cause and wallet type limitations do most of the work.
A venue holding customer assets fails, and the balance shown in the account becomes a claim in a bankruptcy rather than an asset the customer controls.
Neye bakılmalı: Read the terms of service on title, segregation, and what happens in insolvency, since the language is usually explicit once found. Check whether the venue publishes proof of reserves, whether that exercise includes liabilities, and who performed it. Withdrawal processing times during past stress, published financial statements if any, and the licensing regime that governs client money are all observable before the fact.
Self-custody puts the holder in charge of a secret that cannot be reset, so losing it or destroying the only backup is permanent.
Neye bakılmalı: On-chain dormancy metrics show how much supply has not moved in many years, part of which is generally understood to be permanently inaccessible. For an individual arrangement, the testable facts are whether a restore has actually been performed from the backup, whether backups are geographically separated, whether any passphrase is recorded separately, and whether an inheritance procedure exists in writing. Wallet software support for the specific token standard and chain is also checkable in advance.
Attackers take assets by persuading holders to sign a transaction or reveal a secret, without breaking any cryptography or contract.
Neye bakılmalı: Review outstanding token approvals with an allowance viewer, since standing approvals are the main mechanism and are visible on-chain. Check whether the wallet decodes calldata into a plain-language action and whether the project pins its front end to a content hash or serves it from a decentralized host. Domain hijacks, dependency compromises, and support-impersonation waves are usually documented publicly by the projects affected.
Data
Historical series are recomputed, backfilled, and corrected over time, so a chart today may not match the same chart pulled last month.
Neye bakılmalı: Check whether the provider publishes a changelog, versions its methodology, or timestamps revisions, since most do not. Snapshot any series you rely on, store it, and re-pull it later to measure whether history moved. Step changes that align with a methodology note or a code commit rather than an on-chain event are the clearest sign that a revision, not an activity change, produced the shape.
Burada neden listelendiği: We hold 365 daily observations for this asset, so long-horizon statistics are unavailable and short ones are drawn from a thin record.
The same value or activity can be counted on more than one chain or assigned to the wrong one, inflating totals when figures from different sources are added.
Neye bakılmalı: Check whether the provider deduplicates double counting and whether it publishes the rule it applies, and compare a protocol's reported total against the underlying assets it actually custodies. Where wrapped versions exist, check whether chain-level totals exclude them. Reconciling a chain total against the sum of its top protocols usually surfaces the largest attribution differences quickly.
Circulating supply is often a number supplied by the project, computed under rules that differ between data providers and can change without notice.
Neye bakılmalı: Reconstruct supply from the token contract itself, subtracting balances in vesting contracts, identified treasury addresses, and burn addresses, then compare that with the provider's published figure. Read the provider's methodology document and its revision history, and check whether bridged or wrapped versions are double counted. Where a project publishes its own supply dashboard, compare it with the on-chain reconstruction rather than accepting it.
An issuer states that assets back what it has issued, but the claim may be unverified, point-in-time, or cover only one side of the ledger.
Neye bakılmalı: Check who signed the report, under what standard, as of what date, at what frequency, and whether liabilities are in scope, since these five facts separate an audit from a marketing document. Where wallet addresses are published, examine flows immediately before and after each snapshot for large temporary inflows. For off-chain backing, look for the custodian's name, the legal structure holding the assets, and whether any independent party inspects them.
Economic
An asset designed to track a reference value stops doing so because its backing, its redemption path, or its arbitrage loop fails under stress.
Neye bakılmalı: Establish who may redeem at par, on what schedule, with what minimum size, and what the reserve is actually invested in, then read the attestation's date and scope. On-chain, look at the depth of the primary trading pair, the collateralization ratio where applicable, and the historical distribution of deviation from the reference rather than only the current price. Past deviations and how quickly they closed are the most informative record a peg has.
Burada neden listelendiği: The token is currently 494 basis points below its reference value.
New units are created faster than demand to hold them grows, so each existing unit represents a smaller share of the same network.
Neye bakılmalı: The emission schedule is in code and documentation and can be checked against realized issuance on-chain, and net issuance, burn rate, and the staking ratio are standard metrics. Compare issuance against fees actually paid by users to see how much of validator or provider income is subsidy rather than demand. Check whether emissions are fixed by protocol or adjustable by a governance vote, and whether any past vote changed them.
Burada neden listelendiği: No maximum supply is written into this asset's protocol, so new units can keep being created indefinitely.
A token is used as collateral to borrow against itself or a sibling asset, so a price decline forces sales that push the price down further.
Neye bakılmalı: Measure what share of a lending market's collateral is the protocol's own token or a token issued by an affiliated project, and examine treasury composition against any obligations denominated elsewhere. On-chain positions reveal recursive borrowing, since the same address appears as depositor and borrower across successive loops. Compare the value that would be liquidated at defined price thresholds against actual order-book depth for that asset.
Governance
A small set of keys can pause, upgrade, mint, or move assets, so the system's safety depends on those keyholders and their operational security.
Neye bakılmalı: Enumerate the privileged roles in the deployed contracts and resolve each to an address, then check whether that address is an externally owned account, a multisig, or a timelock, and what the multisig threshold and signer count are. Check whether signers are publicly identified, whether they are independent of one another, and whether they use separate hardware and jurisdictions. Read what the pause and mint functions can actually do, since a pause that also blocks withdrawals is a different instrument from one that only stops deposits.
The contract that holds funds can be pointed at new code, so the audited behavior of today is not necessarily the behavior of tomorrow.
Neye bakılmalı: Check whether the address is a proxy by reading the standard implementation and admin storage slots, then identify who holds the upgrade right and whether upgrades pass a timelock. Count how many times the implementation has changed and compare the currently deployed implementation against the specific commit that was audited. Where a timelock exists, its queue of pending changes is public and can be monitored.
Market
Digital asset markets trade without pause, so a move that equities would spread across sessions and halts can complete in minutes with nothing interrupting it.
Neye bakılmalı: Compare depth and spread during weekend and overnight hours against weekday peaks on the same venue, and look at the largest observed short-interval ranges rather than at daily candles. Cross-venue price divergence during past stress windows is observable and shows where arbitrage stopped functioning. Read each venue's published policy on halts and on cancelling trades, since practice varies and some venues have unwound executions after the fact.
Most trading, price discovery, and often custody for an asset sit at one or two venues, so a venue's problem immediately becomes the asset's problem.
Neye bakılmalı: Look at volume share by venue after filtering, at which venues feed the relevant index or oracle, and at whether the asset trades meaningfully in more than one regulatory jurisdiction. On-chain balances at exchange-labeled addresses show how much supply is custodied where, though labeling is heuristic and should be treated as approximate. Historical outages, withdrawal pauses, and maintenance windows at the dominant venue are documented in its own announcements.
A large market capitalization can rest on a small amount of genuine order-book depth, so modest selling moves the price much further than the headline implies.
Neye bakılmalı: Measure bid and ask depth within one and two percent of the mid price on the venues that actually matter, and estimate realized slippage for a defined order size rather than reading a volume number. Compare market capitalization against genuine daily volume, and check how much supply has never moved, since dormant supply is neither pressure nor depth. Watch whether depth persists at night and on weekends or is posted only during active hours.
Burada neden listelendiği: Average daily volume over the last 30 days is 0.56% of market capitalization, so the capitalization rests on relatively few trades.
Regulatory
A venue can remove an asset for regulatory, compliance, or commercial reasons, cutting its liquidity and its fiat gateway in that market.
Neye bakılmalı: Track listing status by venue and region over time, and read the venues' own delisting notices, which usually state a reason and a timetable. After a removal, look at the share of remaining filtered volume and at whether depth actually migrated or simply disappeared. Check whether regulated custodians still support the asset, since custody support often precedes and outlasts trading support.
Action against one critical intermediary, such as an issuer, custodian, bridge operator, or staking service, can disable a function the asset depends on.
Neye bakılmalı: Map the intermediaries standing between the protocol and an ordinary user, including the issuer, the custodian, the fiat rails, the oracle operator, the sequencer, and the front-end host, then note where each is incorporated and what license it holds. For each, check whether a substitute exists and how quickly users could switch. Enforcement filings, consent orders, and company announcements are public and usually state precisely what activity must cease.
Rules on what may back a payment stablecoin, who may issue one, and how redemption works can force changes to reserves, availability, or the product itself.
Neye bakılmalı: Read the issuer's attestation, noting who signed it, under what standard, as of what date, and what instruments the reserves hold. Establish who may redeem at par, in what minimum size, and within what period, and identify the issuing entity's jurisdiction and license. Availability on regulated venues in a given region is a direct observable, as are supervisory orders directed at the issuer.
How staking rewards, forks, airdrops, wrapping, and lending are taxed varies by jurisdiction and is unsettled in places, creating liabilities that surprise holders.
Neye bakılmalı: Read the specific published guidance for the relevant jurisdiction and note exactly which events it addresses and which it leaves open. Check whether venues and custodians issue tax statements and what basis method they apply, and whether the protocol produces per-epoch records adequate to reconstruct reward timing. On-chain data will usually support reconstruction, but only if reward accrual and claims are separately observable.
A trading venue may operate without licenses that would apply to a comparable regulated market, so customer protections differ from what the interface implies.
Neye bakılmalı: Read which licenses the venue actually names, in which jurisdiction, and for which activity, then check whether client assets are segregated by rule or only by promise in the terms. Look for an independent auditor, a published market-surveillance policy, and whether the terms permit the venue or its affiliates to trade against customers. Enforcement actions and regulator warning lists are public and specific.
Technical
A protocol reads a price from an external feed, and someone moves that price cheaply in order to trigger borrowing, liquidations, or settlement in their favor.
Neye bakılmalı: Read the oracle configuration: how many independent sources feed it, whether it is a spot read or a time-weighted average and over what window, what deviation and heartbeat thresholds trigger an update, and what the contract does when the feed goes stale. Compare the depth of the underlying market for a collateral asset against the maximum amount borrowable against it, since manipulation cost scales with that depth. Governance records often show when a market was listed with parameters set before its liquidity existed.
A flaw in deployed contract code lets funds be moved, locked, or destroyed in ways the designers never intended.
Neye bakılmalı: Check whether the deployed bytecode matches published verified source, when the implementation last changed, and how much value the contract has held without incident, since value held multiplied by time live is a cruder but harder-to-fake signal than an audit badge. Look at how many independent audits exist, whether findings were fixed or formally accepted, and whether a funded bug bounty with a published scope and payout history is in place. An immutable contract and an upgradeable one carry different failure modes, so establish which you are looking at before reading anything else.