Paper: Toward a Risk Assessment Framework for Institutional DeFi: A Nine-Dimension Approach
Authors: Eva Oberholzer, Valeriy Zamaraiev
Date: April 2026
Estimated Reading Time: 45 minutes
The paper proposes a nine-dimension framework for institutional DeFi risk assessment, extending the six-dimension Moody’s and Gauntlet taxonomy with composability risk, comprehension debt, and temporal risk dynamics. It argues that institutional DeFi exposure cannot be assessed through protocol-specific scoring alone because stablecoins, tokenized collateral, bridges, governance systems, and infrastructure providers create cross-protocol dependencies. The framework models DeFi as a directed, typed multigraph in which protocols, tokens, oracles, bridges, governance mechanisms, and administrative keys form risk transmission paths. The paper uses 12 incidents from 2024 to 2026, representing about USD 2.5 billion in direct losses, as illustrative evidence rather than validation. Five of the 12 incidents require at least one of the three new dimensions for complete root-cause characterization. The authors also introduce a transparency modifier that measures assessment reliability separately from risk severity. The paper concludes that the framework is a foundation for future prospective validation, larger incident mapping, and empirical testing of dimensional independence.
Core insights
- Nine risk dimensions. The framework retains smart contract, market, oracle, governance, regulatory, and counterparty risk while adding composability risk, comprehension debt, and temporal risk dynamics. These additions are intended to capture risks that the paper says are not derivable from the original six dimensions.
- Composability as contagion. Composability risk covers multi-hop dependency chains that are invisible in bilateral counterparty analysis. The paper uses Kelp DAO and Resolv to show how tokenized assets and stablecoins can transmit losses through downstream lending and collateral systems.
- Complexity as risk. Comprehension debt measures the gap between protocol complexity and the ability of auditors, governors, and users to reason about the system. The Cetus case is used to distinguish this from normal smart contract audit quality.
- Risk changes over time. Temporal risk dynamics focus on changes in governance state, timelocks, multisig thresholds, and attacker staging patterns. The paper argues that static snapshots miss risks created by the rate and sequence of these changes.
- Validation remains incomplete. The authors state that the 12-incident study is illustrative rather than a backtest. Future work requires prospective validation, mapping to the 181-incident Zhou et al. dataset, and testing across at least 50 independently assessed protocols.
The paper’s tokenomics relevance comes from its treatment of stablecoins, tokenized assets, collateral markets, and governance tokens as risk-bearing instruments within a shared protocol graph. Supply and demand for these assets are not modeled through issuance schedules or reward rates, but through collateral acceptance, liquidity depth, regulatory exposure, and dependency pathways. Collateral utility becomes a source of systemic exposure when an asset used in one protocol depends on upstream infrastructure that another protocol does not directly assess. The framework implies that token demand can be distorted by incomplete risk information. A token accepted as collateral may appear usable based on direct counterparty and market risk, while bridge, oracle, or governance dependencies create latent exposure outside that bilateral view. A practical question follows from the paper’s model: should token collateral demand be treated as lower quality when the asset’s upstream dependency graph cannot be traced? The paper also links governance token concentration to protocol risk. Governance token distribution affects multisig control, timelock settings, upgrade authority, and emergency response capacity. Governance concentration therefore has tokenomics consequences because token ownership can influence both protocol control and the security assumptions behind collateral markets. Rewards are not a central object of the paper, but the framework affects how reward opportunities should be interpreted. Yield from lending, liquidity provision, or tokenized collateral deployment may compensate users for market risk while leaving composability or temporal risk unpriced. This raises a second question: when DeFi yields exceed comparable off-chain returns, how much of the spread reflects unmeasured dependency risk rather than productive protocol activity? The transparency modifier is important for institutional allocation. A known unresolved weakness should produce high risk with high reliability, not a lower risk score because the issue is visible. This distinction matters for token markets because disclosed but unresolved vulnerabilities may still support trading activity until an incident converts known technical risk into realized collateral, liquidity, or governance loss. The paper’s main limitation is that it does not provide probabilistic scoring, production weights, or full ontology artifacts. Its claims are best read as a proposed assessment architecture rather than an empirical model of DeFi failure probabilities. An explicit assumption is that the 12 selected incidents are sufficient to motivate the three new dimensions, while the paper itself states that broader prospective validation is still required.
