RIADeFi
Foundations

DeFi for RIAs: the due-diligence guide to asset, protocol, chain, and custody

DeFi is not one asset class, and “the protocol” is not the whole risk. Every position has four layers: the asset held, the protocol holding it, the chain settling it, and the custody that signs for it. Each layer has failed on its own, at scale, in the last four years.

By 18 min read

Educational analysis for financial professionals. Not legal, tax, compliance, or investment advice. Regulatory statements are source-linked and time-stamped.

Reader objective

Diligence a DeFi position from the asset down to the signing key, and keep a file an examiner can follow.

What DeFi actually is

Decentralized finance is lending, borrowing, trading, and asset management performed by software deployed to a blockchain. A lending protocol can match suppliers of capital with overcollateralized borrowers without a bank operating the ledger. The rules are visible in code and transactions settle on-chain.

That description does not make the arrangement safe, decentralized in every respect, or appropriate for a client. It only names the mechanism. A USDC lending position, for example, combines an issuer-controlled dollar token, an upgradeable lending protocol, a price oracle, a settlement chain, and whatever wallet signs for the client. Each of those can fail in its own way.

The mechanics of the flagship case, overcollateralized lending, fit in a paragraph. A supplier deposits USDC into a pooled market contract and receives a receipt token that grows with interest. A borrower posts collateral worth more than the loan and pays a floating rate set by utilization: the more of the pool that is lent out, the higher the rate climbs, which draws new suppliers and pushes borrowers to repay. If the collateral’s value falls toward the loan’s value, any third party may repay the debt and take the collateral at a discount. That liquidation, not a credit officer, protects suppliers. Every step is a contract call recorded on the chain, which is why the diligence questions can be answered at all.

Why advisors are looking at this now

The clients arrived before the industry did. One in four American adults owns crypto, about 67 million people, according to the National Cryptocurrency Association’s 2026 State of Crypto Holders Report, run with The Harris Poll and published 2026-05-21.1 In the Bitwise/VettaFi 2026 Benchmark Survey, 32% of advisors said they allocated to crypto in client accounts in 2025, up from 22% in 2024, and advisors said 74% of their clients invested in crypto outside the advisory relationship, up from 71%.2

A held-away position is unadvised risk inside a household the advisor already serves: unknown wallets, unknown protocols, no diligence file, no position limit. The rest of this guide is how a fiduciary closes that gap without pretending the asset class is simpler than it is.

The four-layer test

Test every position at four layers. Each layer answers the same question, who can change or stop this, about a different part of the stack.

  1. Asset: What does the client legally and economically own? Who can freeze, redeem, dilute, or change it?
  2. Protocol: Which contracts hold the asset? Who can upgrade or pause them? Which oracles, bridges, curators, and governance votes can change the terms?
  3. Chain: Who orders transactions? Can the chain halt? Who controls upgrades, and the bridges in and out?
  4. Custody: Who holds the keys that sign for the position, how many must agree, and what do they check before they sign?
Working ruleA position is only as strong as its weakest layer. A non-custodial protocol does not remove the issuer’s freeze on the asset, and a sound protocol does not survive a signing key that can be tricked.

The layers fail independently, and each has a recent failure with a name and a number. The asset: in March 2023 USDC, a fully reserved dollar token, traded as low as 86 cents because $3.3 billion of its reserves sat in a failed bank over a weekend.3 The protocol: in March 2023 an attacker took about $197 million from Euler Finance through a function a governance upgrade had added the summer before.45 The chain: in August 2022 an upgrade to the Nomad bridge made every message look valid, and more than $190 million left.6 The custody: in February 2025 Bybit’s signers approved a transfer that looked routine and handed over about $1.5 billion.7 The sections below take each layer in turn.

The test, applied to one position

Take a client supplying USDC to a lending protocol on Ethereum from a wallet the client controls.

The asset. USDC is issuer-controlled. Circle administers the token contracts, can block addresses, and stands behind the redemption path the client’s dollar claim runs through. That is not a defect; it is a fact for the file, recorded in the USDC control profile.

The protocol. The lending market is a set of upgradeable contracts. Someone holds the upgrade key, someone sets collateral parameters, and an oracle feeds it prices. Each is a named dependency.

The chain. On Ethereum no single operator can halt settlement or reorder transactions by decision. The same position on Base reads differently: Coinbase, one regulated US company, runs the only sequencer, and admin keys can upgrade the bridge contracts within about seven days.

The custody. The client’s wallet signs every deposit and withdrawal. If a phishing page or a compromised device gets a signature, no layer above it helps.

The position’s effective control is the weakest of the four. Here it is the asset or the custody, depending on how the client signs. The same test disposes of harder cases at the first layer. Binance Staked ETH appears in DeFi dashboards next to non-custodial staking tokens. Ask the asset question and the answer is immediate: the token is a claim on a centralized exchange, wrapped so that it moves on-chain. Ketju rejected it on that finding alone.

Where the yield comes from

Yield is compensation paid by someone or created by some mechanism. Lending yield comes from borrowers. Staking yield comes from protocol issuance and transaction fees. Tokenized Treasury yield comes from the underlying government securities, less fees. Private-credit yield pays the lender for borrower and recovery risk. Reward-token yield is often a temporary subsidy paid in the protocol’s own token.

Naming the payer matters more than comparing the percentage. Two positions showing 5% may carry different duration, liquidity, credit, contract, and control risks. Ketju’s clearest published case: Maple Finance screened near 5%, a modest premium over collateralized lending, and the premium paid for undercollateralized institutional credit, a different risk entirely. The published rejection walks the whole case.

Protocol layer: smart-contract risk

“Audited” is not a research finding. It says one firm reviewed one version of some code, within a stated scope, on a stated date. The diligence question is whether the code that holds the client’s money was inside that scope.

Euler Finance is the case to learn. On 2023-03-13 an attacker used a donation function that a governance proposal, eIP-14, had added to the protocol. The function let an account give away its collateral without a health check, so the account’s debt stayed while the collateral behind it disappeared.5 About $197 million left the protocol.4 Euler had been audited. The firm that reviewed eIP-14, Omniscia, has said in writing that its audit covered only the upgrade’s Chainlink price integration, and that the donation function “was never in scope of any audit conducted by our team.” A second firm, Sherlock, had reviewed the function in July 2022.5 Euler recovered the funds after three weeks of talks with the attacker, an outcome its own account calls almost unheard of in crypto.4 No advisor could have found the bug. Any advisor could have asked which audit covered the code added last, and demanded a precise answer.

Start by recording the exact code path: the deployed contract addresses, the network, the implementation behind any proxy, the market or vault, and every contract the deposit and withdrawal touch. One protocol brand often holds several products with different code and different administrators. For each audit, record the firm, date, commit, scope, exclusions, findings, fixes, and whether the deployed code matches the code reviewed.

Then record who can change the code, and how fast:

  • the administrator of any upgradeable proxy;
  • pause and emergency powers, and who holds them;
  • the governance thresholds for proposing and executing a change;
  • timelocks and security councils, and how long a holder has to leave before a change takes effect;
  • whoever sets oracle sources and collateral parameters;
  • the configuration of any bridge the asset depends on;
  • the front end and API the client actually uses.

An immutable protocol trades repairability for predictability. An upgradeable one trades adaptability for administrative risk. Neither label decides suitability. The file must name who holds each power.

The failure worth studying from 2026 was a setting, not a bug. On 2026-04-18 a forged cross-chain message released 116,500 rsETH, worth about $292 million, from Kelp’s LayerZero adapter on Ethereum with no matching burn on the other chain.89 LayerZero’s final report found that the application owner had replaced a two-of-two verification setup with a single verifier; a compromise of LayerZero’s internal RPC infrastructure, plus a denial-of-service attack on a third-party one, was then enough.9 Kelp’s restaking contracts were never exploited. For any wrapped or bridged asset, the bridge and its configuration are part of the asset’s security, and they are usually the least examined part of the stack. The Kelp memo carries the full account.

Chain layer: who orders transactions, and the bridges

The chain decides whether a transaction happens at all, and in what order. On Ethereum a permissionless set of validators proposes blocks, and no single party can refuse a transaction for long. On most layer-two networks one company runs the sequencer that orders every transaction, and a small group of key holders can upgrade the bridge that holds deposits from Ethereum. The Atlas records these facts chain by chain: who runs the sequencer, whether users can force a transaction through if it stops, and who can upgrade what.

Bridges are where the chain layer has failed most. On 2022-08-01 an upgrade to the Nomad bridge set the value of trusted roots to 0x00. That value also matches an untrusted root, so every message was treated as proven.6 More than $190 million left, much of it through copycats who replayed the first attacker’s transaction with their own address; no technical skill was needed.6 The chains on either side never failed. The bridge between them did. A client holding a bridged token holds the bridge’s risk, whether or not the client ever used the bridge.

Liquidity: can the client get out at size?

Total value locked says how much is in a protocol. It does not say how much a client can withdraw, redeem, or sell at a fair price.

MeasureWhat it answersWhat it misses
Total value lockedHow much value the protocol reportsBorrowed, locked, or unavailable capital
Available liquidityWhat can be withdrawn from a lending pool nowWhat borrowers and depositors do next
Market depthWhat can be sold near the quoted priceIssuer redemption and market stress
Redemption capacityWhat the issuer will redeem, and whenSecondary-market execution

In a pooled lending market the rate a supplier earns follows utilization, the share of the pool lent out. Aave v3 sets rates on two slopes around an optimal utilization point: below it, borrow rates rise gently; above it, they rise much faster, and suppliers are paid from that borrower interest.10 The steep slope exists to draw new deposits and push borrowers to repay when the pool runs low. It also means a very high rate is often the sign of a pool that is nearly empty, and a supplier cannot withdraw from an empty pool until borrowers repay or new money arrives. Record the rate and the withdrawable balance together, and test an exit larger than one client’s position.

Size the client against the exit, not the protocol. A venue can be large in total while the particular asset, chain, vault, or maturity is too small for the intended position. Then walk the paths out, in order: a normal withdrawal at today’s utilization; a withdrawal after utilization rises; a market sale with measured slippage; issuer redemption with its gates and cutoffs; and the exit during a chain halt, a pause, an oracle failure, or a depeg. Mark which path is contractual, which is technical, and which depends on someone else showing up to buy.

The price of an exit depends on where it happens. On 2025-10-10, in a market fall that took about $850 billion off total crypto value, USDe traded as low as 0.65 USDT on Binance and 0.92 on Bybit, while pools on Curve, Uniswap, and Fluid held near 0.99 and Ethena settled about $1.9 billion of redemptions, around 13% of supply, over two days.11 Binance’s price came from an internal oracle that read only its own order book. A client who sold on the wrong venue that hour lost about a third of a position in a token that never broke.

Some exit terms fail on paper before any market does. Convex locks CRV permanently when it mints cvxCRV, and there is no redemption back; the only exit is a market sale at whatever discount prevails, which is worst when everyone wants out.12 Rejected. USD.AI pays sUSDai holders out through 30-day redemption windows; in a rush, every holder waits in the same queue.13 Rejected, memo published. Concrete’s vaults add asynchronous withdrawals on top of whatever the underlying strategies impose; its rejection is on file. Each of these terms was in the documents before any client could have been harmed. Reading the exit path costs an afternoon; testing it costs the client.

Watch the warning signs after the position is on: available liquidity, utilization, market depth, redemption queues, depeg size and duration, bridge inventory, withdrawal fees, and governance changes. A rising yield paired with falling liquidity is a risk signal, not automatically an opportunity.

Custody layer: control is more than key possession

A key authorizes transactions, but control is spread across parties and contracts. Record who can sign, recover, rotate, delegate, upgrade, pause, freeze, or redeem. Do not fold those powers into the one word “custody.”

For a registered adviser the legal floor is the custody rule, Rule 206(4)-2 under the Advisers Act. An adviser with custody of client funds or securities must keep them with a qualified custodian: a bank or savings association, a registered broker-dealer, a futures commission merchant in limited cases, or a qualifying foreign institution, in an account under the client’s name or under the adviser’s name as agent or trustee.14 On 2025-09-30 SEC staff said they would not recommend enforcement against an adviser that treats a state-chartered trust company as a “bank” for crypto assets, if the adviser does annual diligence on it, holds a written agreement that bars lending or rehypothecating the assets without the client’s consent, discloses the material risks, and finds the arrangement in the client’s best interest.15 That letter is staff relief, not a rule. On 2026-09-14 Chairman Atkins said he had asked staff for a proposal that would allow adviser self-custody under conditions, “because for too many assets a qualified third-party custodian simply does not exist yet.”16 No proposal had been published when this guide was reviewed; the regulatory ledger will record it when one is.

ModelControl questionFailure to plan for
Qualified custodianWhich assets and protocols does it support?Asset not supported; transfer delay
Client self-custodyWho can start and approve a transaction?Loss, coercion, recovery
MultisignatureWho are the signers, and what threshold?Signers who are not independent
Embedded walletWhere are the key shares and the policies?Provider dependency and recovery

A signing threshold is only as independent as the people behind the keys. Ronin’s bridge needed five of nine validator signatures. On 2022-03-23 an attacker held five: four run by Sky Mavis, and one run by Axie DAO, which had allowlisted Sky Mavis to sign on its behalf in November 2021 to handle a surge of free transactions. That arrangement ended in December 2021, but the allowlist was never revoked. The attacker drained 173,600 ETH and 25.5 million USDC, and nobody noticed for six days, until a user could not withdraw 5,000 ETH.17 Nine keys; one operator.

The approval workflow is part of the control. On 2025-02-21 Bybit moved funds from an Ethereum multisig cold wallet to a warm wallet, a routine transfer.18 Its forensic review found that the credentials of a developer at Safe, the wallet software provider, had been compromised, which let the attacker “deceive signers into approving a malicious transaction.”19 The transaction changed the cold wallet’s contract logic, and 401,347 ETH plus staked ETH, $1.46 billion in Bybit’s own count, left the wallet.18 The FBI attributed the theft to North Korea and put it at about $1.5 billion.7 The keys were never stolen. The signers used them as designed, on a screen that lied. Record how a transaction is checked before signing: whether signers decode the raw transaction on a separate device, whether it is simulated, address allowlists, dollar limits, who can stop a transfer in progress, and who is called when something looks wrong.

For wrapped assets, custody sits one step away from the client, with whoever holds the underlying. The market sells three tokens as Bitcoin, and the custody answer separates them. WBTC is one custodian’s IOU: only approved merchants mint or redeem it. In August 2024 BitGo announced that WBTC custody would move to a joint venture with BiT Global, a custody firm registered in Hong Kong as a trust and company service provider, with BitGo as a minority shareholder and operations spread to Hong Kong and Singapore within 60 days.20 The client’s wallet did not change and neither did the token contract; the party holding the Bitcoin did. Ketju’s WBTC file records the finished structure. cbBTC is one issuer: Coinbase holds the Bitcoin and can freeze the token. Lombard’s LBTC spreads authority across a 14-member consortium that must reach a two-thirds threshold to authorize deposits, mints, burns, and payouts.21 That is more distributed, and it is still a set of named institutions, with Babylon slashing as a further loss path. Ketju’s research records those paths separately from the reward rate. The Atlas profiles record who controls each wrapper.

The checklist, and what each step has decided

A protocol audit is one input. The checklist below connects the client’s legal and economic exposure to every technical and operational dependency. Each step has decided a published case.

1. Define the position.

  • Name the exact token, contract, chain, protocol, market, and strategy.
  • State the economic exposure and who pays the return.
  • Identify the legal claim, the issuer or counterparty, or the lack of one.
  • Record who may hold it and where.

Defining the position decided USD.AI. Write down what the instrument is and the synthetic dollar becomes non-recourse lending against depreciating GPU hardware, with a 30-day exit queue. Rejected.

2. List every party that can change the position.

  • Asset issuer, collateral, redemption, and freeze authority
  • Protocol contracts, upgrades, pauses, governance, and audits
  • Oracles, bridges, curators, keepers, relayers, and front ends
  • Chain liveness, transaction ordering, validators, and upgrade control
  • Wallet, custodian, signers, recovery, and the transaction-approval workflow

Listing the parties decided Kelp’s rsETH. The staking logic was sound; the cross-chain bridge, set to trust one verifier, was the real security model, and it released about 116,500 unbacked tokens in April 2026. Rejected.

3. Test loss and exit.

  • Past exploits, bad debt, depegs, halts, and governance failures
  • Withdrawable liquidity at client size, not total value locked
  • Redemption gates, queues, market depth, fees, and settlement delay
  • What happens if the oracle, bridge, collateral, issuer, or keys fail
  • The recovery path, and who is responsible for it

Testing the exit decided Convex. Converting CRV to cvxCRV is one-way, and the only exit is a market sale at whatever discount prevails. Rejected.

4. Make the decision something a monitor can check.

  • The research finding and its reasons, kept apart from the client decision
  • Whether this household and this account type may hold it
  • The client’s position limit and the amount the advisor chose
  • Observable events that reopen the file, with a data source for each
  • A named owner, a next review date, and an evidence archive
  • A risk statement in the client’s language, and the suitability rationale
  • A version history for corrections and changed decisions
Evidence standardIf a fact can revoke the recommendation, record its source and how it will be watched when the position is approved.

Step four is why every Ketju memo, including every rejection, ships with the observable events that would reopen it and a scheduled next review.

What belongs in the diligence file

The goal is not a long memo. It is a decision someone else can reproduce: the evidence, the limits, the owner, and the conditions that would reverse it, still visible after the market changes. Rejections deserve the same record as approvals; they show the universe was examined rather than merely ranked.

The decision header names the exact instrument, token, contract, protocol, market, and chain; the research finding and the verdict; whether this household and account may hold it; what the advisor chose and how much; and the reviewer, approval date, next review, and version.

The evidence body covers the economic exposure and who pays the return; the legal claim, issuer, redemption, and eligibility; the asset, protocol, chain, oracle, bridge, and custody dependencies; fees, liquidity, valuation, tax, and the operating workflow; and the incidents, counterevidence, open questions, and source archive.

Review conditions are observable facts that reopen the file: an exploit above a stated size, an admin change, a new collateral type, liquidity under a floor for a stated number of hours, a depeg past a stated depth and duration, a shortened timelock, a regulatory restriction, an issuer change, or a missed disclosure. Define the threshold, the layer it touches, and the data source when the condition is adopted. The useful conditions are the ones a monitor can actually watch.

Corrections are part of the record. Never rewrite the prior decision in place. State what the earlier version claimed, why it was incomplete or wrong, what evidence changed, and what changed in the finding, the eligibility, the selection, or the limit. A visible correction shows process rather than hindsight.

Every element exists in public, filled in. The BUIDL memo records a favorable research finding with conditions and, separately, that the model client may not hold it: BUIDL is a private fund offered to qualified purchasers under Rule 506(c) and the Investment Company Act §3(c)(7) exemption, with a $5 million initial minimum and transfers only between whitelisted wallets.22 It carries a version number, a review date, a next review, and the reopen condition written down at decision time: look again if a retail or accredited share class ships. A regulator, a client, or a colleague reading it two years from now can see what was decided, on what facts, and what would change it. Every rejection in the research files follows the same format, and so does every other current assessment in the Ketju Register.

The last duty is monitoring, because a position does not hold still after it is approved. Code upgrades, oracle changes, and new collateral types happen without asking the holder. Kelp’s rsETH had audits behind it when the forged bridge message arrived in April 2026; diligence written a quarter earlier described a system that no longer existed. A written review date and a named owner are the difference between a decision and an opinion.

Primary and reference sources

  1. What the 2026 State of Crypto Holders Report reveals (2026-05-21) · National Cryptocurrency Association
  2. The Bitwise/VettaFi 2026 Benchmark Survey of Financial Advisor Attitudes Toward Crypto Assets · Bitwise Asset Management and VettaFi
  3. In the Shadow of Bank Runs: Lessons from the Silicon Valley Bank Failure and Its Impact on Stablecoins (FEDS Notes, 2025-12-17) · Board of Governors of the Federal Reserve System
  4. War & Peace: behind the scenes of Euler’s $240M exploit recovery · Euler Labs
  5. Euler Finance incident post-mortem (archived copy) · Omniscia
  6. Dissecting the Nomad bridge hack (2022-11-29) · Mandiant, Google Cloud
  7. North Korea responsible for $1.5 billion Bybit hack (PSA250226, 2025-02-26) · Federal Bureau of Investigation
  8. Kelp DAO incident response (2026-04-19) · Kelp DAO
  9. KelpDAO incident report · LayerZero Labs
  10. Aave V3 overview: interest rates · Aave
  11. Ethena’s October 2025 governance update · Ethena Foundation
  12. Understanding cvxCRV · Convex Finance
  13. USDai and sUSDai 101 · USD.AI
  14. 17 CFR 275.206(4)-2: custody of funds or securities of clients by investment advisers · Electronic Code of Federal Regulations
  15. Simpson Thacher & Bartlett LLP, staff no-action letter (2025-09-30) · U.S. Securities and Exchange Commission, Division of Investment Management
  16. Remarks at the Solana Policy Institute Summit (2026-09-14) · U.S. Securities and Exchange Commission, Chairman Paul S. Atkins
  17. Community alert: Ronin validators compromised (2022-03-29, archived copy) · Sky Mavis, Ronin Network
  18. Bybit security incident: timeline of events and FAQs · Bybit
  19. Bybit confirms security integrity amid Safe{Wallet} incident · Bybit
  20. BitGo to move WBTC to multi-jurisdictional custody · BitGo
  21. Lombard protocol architecture · Lombard
  22. BlackRock launches its first tokenized fund, BUIDL, on the Ethereum network (2024-03-20) · Securitize
  23. Crypto Assets · Investor.gov