# Marc Vlad  - DeFiScan :Transparency on Decentralization in DeFi

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2025-11-09
- Duration: 26:53
- Watch: https://streameth.org/watch/yt-6vbtQyHuJcQ
- YouTube: https://www.youtube.com/watch?v=6vbtQyHuJcQ

## Description

DeFiScan focuses on bringing transparency to Decentralized Finance (DeFi). The talk highlights the basics of DeFi, including Decentralized Exchanges (DEX), lending, yield, and liquid staking, and emphasizes the significant value and risks, such as the billions lost to hacks. It addresses the challenge of knowing who "operates" protocols and understanding potential dependencies and risks.

The talk cover DeFiScan's framework - with its criteria of autonomy, accessibility, exit-window, upgradeability, and chain decentralization -which is used to assess DeFi projects' decentralization levels. It categorizes projects into stages from "Not DeFi" to Stage 2, representing fully decentralized systems. The presentation encourages community/opensource participation in reviewing protocols and offers bounties of $1,000 to $3,000 for reviews. It outlines steps on how to get started, including using their permission scanner and other tools.

The talk also provides guidance on writing reviews, suggests protocols to examine, and highlights support available through the DeFi Collective Discord. It aims to give attendees insights into the decentralization aspects of DeFi and encourage active contribution to the DeFiScan project.

## Transcript

Thank you everyone. Um I'm Mark Deayo. Um I'm here to present you Defi Scan, an open-source uh framework and dashboard made by uh the DeFi collective, a Swiss NGO. And um our mission here is to to define what um and standardized the concept of decentralization in D5 and also to assess uh the current maturity level of decentralization uh in D5 protocol on EVM chains for now. So yeah, uh what is DeFi? It's um it's a pretty tough world uh to to to to navigate for me at least. And I I I believe most of DeFi enthusiasts and builders would agree at least with 99% of what is presented here. Um we believe DeFi is about transparency where everybody can verify the integrity of the the the ledger and um and see what's going on in the transaction. It's about resilience and anti-censorship mostly from state and corporate actor interference. It's about community where everything is open non-exclusive and everyone everybody can participate in some form of governance of financial protocols or community protocol accessibility. You don't need a KYC. You don't need an address to participate uh and access financial services. It's also about trustless um infrastructure that would go in resilience in a sense but um I think we need to to separate it and um yeah you don't need to rely on anybody to to have the best outcome for your protocol that that would be um a very important point and public utility which would be the most subjective point of this slide um and uh which I will defend uh harshly here but I think there is um a duty for defiers to really extend uh financial inclusion and uh give this kind of services to everybody as a public good. Unfortunately um even though this is the core values of defi I don't think we really have it and today it's mostly about um uh something else right we have a lot of obsuscation in protocols where um you see a lot of developers or or projects that um make very complex design for people to understand and uh there are a lot of names that comes to mind that I I I won't quote but recently there were like yesterday a big drama uh about the bridge across protocol uh where uh actually some of the the core team members were speaking about how the CEO and the DAO's were able to steal uh allegedly uh $23 million out of the treasury. So yeah, sometimes we have a lot of over complex designs and uh some people inside the protocol access uh information that you don't have and can exploit it uh against the users to to make profit. We also have a lot of ephemeral apps where uh people follow trends uh uh rather than really understand what they're using. And um these apps could easily be taken over uh if you had enough resources. Uh some protocol logics could be uh completely reversed if you have enough money to to unbalance pool and and you know act some critical um um parameter of the protocol. Communitywise, uh, we see a lot of VC driven, um, philosophy in crypto, which is not the baddest thing, but they're mostly focusing on profits rather than having this core community tools for everybody to use. And um, yeah, I think we can do bit better here. It's still gated. You might have been in some uh, website UI where you have to accept some pages state you're not from Iran or the US. there is still a lot of trusted setups uh regarding security consils um and uh yeah we we still trust a lot of humans to to hold the private keys of our favorite protocols and um yeah who when I say um public utility uh today it's mostly profit focused and uh help some very specific people uh I think the one of the biggest use case of defy today um would be stable coin uh usage and um who benefits from stable coin today there is a lot of protocol but let's face it reality is we have uh most stable coins uh backed by US treasuries it's actually 80% of stable coin eight out of 10 protocols in stable coins are using US treasuries and represent more than 99.8% 8% of the stable coin market and volume. Um, more specifically in DeFi, here you can see like Tether and USDC completely obliterating the the share of of the stable coin market. Um, and USDC, if you didn't know, represent the biggest part part of stable coins in EVM DeFi. In this sense, uh we can say well play to the US Treasury uh bringing up this huge amount of loans uh that finance the US department uh the the US uh government uh thanks to um blockchain infrastructure and um and DeFi. We heard recently about the US Genius Act that should be enacted in the next six to seven weeks I think and uh they if you read it they um they really push forward uh this idea of the traditional banking model for stable coins. This is how they quote it uh and this is the model that tether and circle are using. So basically holding short-term US treasuries in banks and uh when you realize that your stable coin or the onchain cash is actually um the base of perpetual US loan. Uh you could actually question why is this the case in DeFi? I think it's wrong. So um yeah the main challenges here is to bring more transparency. We still have a lot of of folks that uh want to bring more lights into DeFi and uh want to dissecate how protocol really functioned how decentralized their collateral is. And so these are the questions we really want to to answer at uh at the collective and uh with DeFi scan. So who really operates a protocol? Uh what permissions affect my usage of the protocol? um what dependency do I have and all the risk associated with external control and is the protocol finished is it mature enough um so yeah the the main goal here uh and also u the the gra struggle we have uh right now at defi scan is to really build a community consensus about what decentralization is and when we see that stable coin is mostly based on real world assets or tokenized bonds there's a lot of work and thinking and peer reviewing to to to do. Um there are other uh spaces that I will speak a bit forward uh speak a bit more about in in um in in the next slides. It's also about teaching uh the people about uh state-of-the-art um protocols and how you can really decentralize your financial protocols and of course um have this kind of anti-fragility mindset where we help with liquidity with um marketing services highly decentralized protocol. So yeah, let let's go to the core of it. Uh how do we do it? how to assess how much decentralization is in my finance. I see some people love the the ants design. Uh please take as much picture as you want. Um so yeah, defy scan comes in in three. Um it's a framework um that we've been um uh developing for the last two years and still needs some work as I just said regarding real world assets uh maybe vault creators um and so everybody can participate. It's a it's a completely open source uh initiative and uh you're very welcome to comment anything we've written or write for yourself. Also it also come with tools and resources. We have a permission scanner completely open source uh that enables anyone uh that know how to use uh Python scripts or we have a various UI and you'll see better user experience regarding this in the close future but anyone could use this permission scanner to um to scan the centralized permission that your smart contract might have and we also have this public datab reviews and the template for anybody to start reviewing a protocol. Obviously, we have a public dashboard and uh a UI uh that is a bit changing that you can find at defiscan.info. We also are so proud to say that the EF uh gave us some funds. So, yes, uh it's just not just not us making our our world more decentralized. The EF trust us. We we're legit guys. Please contribute. And um and yes, so far so good. We we we have as an objective to cover 90% of the total TVL in EVM chains by the end of the year. Today we're at 58% with 15 protocol reviewed. You can see how you know uh concentrated the the TVL can be in some um in some um in some protocols. You just need to pull out Defy Lama to to see it. Actually, we have two full-time devs that are um postgrad engineers uh with a lot of experience in security or engineering and uh they work just to review. They are the core peer reviewers uh of um of um of Defi Scan and five other part-time contributors covering legal business marketing stuff and uh and even operation as we help various D5 protocols to to boost their quality. So let's get into it. Uh what are the centralization risk in our framework? First of all, we use uh the the L2-bit framework to assess uh how decentralized your chain. If you're building on Ethereum mainet, you're on the most decentralized uh infrastructure that we have available, but you could also build on other layer tools and uh that wouldn't affect if you have an instance on on Ethereum. Um upgradability. So are your smart contract upgradeable? Which is pretty logical, right? You use something and the day after it's um it's something else. So how upgradeable are your contract is a big part of the problem in centralization defy. Autonomy. So how much do you rely on external factors such as USDC um such as one oracle? Do you have do you have fallback mechanism here? The exit window. So if you have upgradable uh contracts, how uh you let your users opt out if they're not agreeing with your vision and your road map. Uh so state of the art today is like 30 days exit window is discussable. I'm not um I'm not I'm just stating the facts as of today. It might change in a in a future. And of course uh accessibility uh which is more regarding front ends and uh how many UI can we use uh to access the protocol. You you might uh have been affected or heard about um hacks through front ends. So you you get your DNS act or maybe the Gnosis act could be one with the so sorry the Gnosis safe one with um uh with by bit was also a front end hack uh through uh through their Amazon services and um and the gnosis safe front end. So yeah how can we have more versatility in the front end is super important. Um so yeah then we got this beautiful pizza or some say pi I say pizza short chart uh that we that we use uh for assessing how high medium or low risk um you you you you rate into this um these five categories and then we give you a stage um so you're not defy if you don't have a blockchainbased financial technology if your assets are not um are in custody uh if you don't have a public documentation uh that outline uh the expected performance and the list of your contracts and obviously if you're not uh open source and also uh if you don't have verified contracts so you just go on block explorer and say yeah this matches the open source code that we we we published we have a big problem here with unis swap by the way who uh is one of the most decentralized protocol in define forever but I have an instance on um baze and arbitrum with unverified contract Right. So like we can do better here. Um yeah stage white requirement. Okay. So stage zero is full training wheel. So it's highly centralized. Um but we have met all the requirement before. Stage one um it's still centralized and you have like core permissions that could affect the performance of the protocol and stage two you pretty much know uh what's the output forever kind of. So we can go a bit more into to each requirement but I I'll go a bit uh faster here and uh yeah um I want to speak about security console. This is also a big uh debate in the space and in the framework. Uh what is a decentralized security console? Today uh we consider you need at least seven signers with 51% threshold of people voting for it obviously and at least 50% non insider signers uh which are obviously either publicly announced with their name or sudden name but we need to to have some accountability here. stage two requirements. You can you can pretty fast and understand that you just score low in all the the five risk. And let me fastly go on um on a practical example. So liquidity which we consider one of the most decentralized collateral debt uh protocol matches this beautiful stage two rating of D5 scan because they have imitable code um multiple frontends. I think they have at least 40 front ends. I I know five. I've been using five with them and uh they use chain link as their main oracle but they have a fallback called Telor and if both uh oracles become entrusted they actually use the last price. So um pretty well designed and well done to the engineers. Lately we we did uh five big reviews that unfortunately I don't have the time to go through all of it uh and the centralization risk but please come come to me and we'll discuss this a bit further. Uh we did a uh and lido that are the two biggest D5 protocols today and they both reach stage zero for relying either on uh highly upgradable contracts. This is really the case for lido when you withdraw and deposit contracts are actually upgradable and a mostly because they have problem regarding the security consils and um their dependency on chain link protocol. So yeah please come to me if you want to speak more. Uh this is a slide uh that is half uh true for the moment because we need to renew uh this bounty program that we have but uh in say anyone can participate and review a D5 protocol um as per this method. So you go on our GitHub, you can fork the repo. Uh we have a template that you can use and you start completing everything in the templates. Um you you create this PR on the GitHub and the peer reviewers will come and check uh uh if u it's correct. And we have bounties up to 3K paid in stable coin uh bold or LUSD stable coin. So the liquidity stable coin for for rewarding activity here. And um if you are highly qualified here, we might hire you full-time, which is a beautiful job to be honest. Here I share more um decentralized acceleration links. So people who are really aligned with this mission of assessing the maturity of decentralization of protocols. Uh blue chip focused on um on stable coins. Defy safety maybe miss a bit the point because they also integrate a lot of um security audits and uh you know basic cyber security stuff. device scan, of course, L2 bit for layer 2 decentralization and anti capture with a very new um website u and framework that assesses the DAO decentralization how decentralizes DAO very interesting things happening here and highly recommend you can see more of a link you want you wanted the um and so you can find us here if you if you're interested in working with us please join the discord make a little presentation ask for a bounty, put pressure on us. Um I I've I've been putting pressure in my core team as well here. And um yeah, that's uh that's pretty much it. Um if you if you have any question, I'll be happy to to take otherwise I can go back and and speak a bit more about the centralization risk of um of the protocol that we lastly reviewed before. Thank you very much. Please give a hand for Mark. Amazing presentation. Thank you. you actually do have a little time to do uh talk a little you have like two minutes left on your time. &gt;&gt; Sure. &gt;&gt; So go a little bit deeper in and we go to the questions after. &gt;&gt; Let's go. Let's go. So um I I told you about the the Leo risk and the a risk. Um I could go deeper in each of them but I I wanted to speak also about morpho which is very interesting. It's like a stage one here. Um and I'm a bit surprised personally because I I would have given it a stage zero subjectively but they have a very beautifully designed protocol. It's only that I would have given stage zero in a in a mistakenly uh mindset because um anyone is very permissionless. You can create vaults and uh and and it's like um completely be immutable for the the the old vault, but you have creators responsible of the the the some permissions inside the strategies. And so yeah, how do we assess the centralization of creators and here we have some uh some gossip already with the various uh labs uh and risk managers, let's say. Uh otherwise they're pretty good. uh they have they have they have scored um uh really well on all our metrics but we lack a great framework regarding these creators. They also have issues regarding their token. Um so it's not really affecting Moro users if you're not depending on the the Moro extra yield uh and you just like doing some stable coin lending strategies on Moro, it won't affect you much. But their core token, the governance token is also upgradable and uh have have some issues there. Um they also need to extend their exit window for changing uh some um some permissions regarding this uh this token and the governance. Um and yeah I I think I I used the two minutes uh and and we'll go for the question. &gt;&gt; Mark you used it perfectly. So as we go to the questions coming again a big hand for going through everything. It was amazing listening to D5. I am a Gen at heart myself. So we do have like two questions that came in. I'm going to give you the most funny one. How much D is in D5 scan? &gt;&gt; That's a good question. That's a good question. I I I think we're we're pretty we're pretty decentralized in the sense that uh we don't depend on it like most of DeFi scan contributors beyond the two reviewers. The two reviewer have full-time contracts um at Defy Scan. uh but the rest of us the core contributors and the people who funded the NGO at the beginning were all cryptonatives and uh don't rely on the collective to to sustain our lifestyle. So we're pretty independent in this regard. Now geographic geographically speaking um we have someone in Australia, we have someone in Romania, in Serbia, in Switzerland, in France. So we're pretty much um Europe based but um I say we we're stage two decentralized at defi scan I would say. &gt;&gt; So that's the wonderful thing they even said oh this is a joke but actually you had a proper answer to it because even though it's a joke there's always a question proper in it. &gt;&gt; So we have the next one here. How do you evaluate chain decentralization? Do le choose like optimize automation score or lower? &gt;&gt; Yeah. So here we we got a bit lazy and and and learn from the best by just taking the authoritative arguments from L2BIT um and and which is a widely recognized uh actor in the space and so if they their framework is um is our core thing. So yeah, optimism which I believe is stage one uh rollups right now is um will score less. You you'll get a medium score if your instance of D5 protocol is only on optimism but you could easily fix this by just uploading it on Ethereum even though most of your volume and activities on optimism. So um yeah it's we we might have to to to think about um ponderating volume by chain to to really understand how decentralized the core activity of a protocol is. But if you have an instance on mainet well this you cannot uh think uh then you don't rely on the centralized dependencies of a layer 2. &gt;&gt; That's beautiful. So the thing is also many times uh you talked about uh verified contracts especially on chain. I know a lot of devs sometimes they do want to create their own but they don't want to share it. So they try to hide snippets of the contract on the chain while some is still open to to see. Yeah, I I wouldn't recommend that, you know, like it's it's it's it's fair to build in the in the shadows for a moment, but if you want to hit uh the the whole world with your product, uh I I I mean it's it's very it's it's it's it's the conflict of two paradigm here. uh you have uh this kind of fully profit maxi things that we have at the the beginning of my slides where I say it's VC backed and you know we we focus mostly on on on profit rather than a public good mindset and this is what we see I think with with protocols like um uh Hyperliquid uh where we don't have a full idea of who's the team behind even though like we have like five signers behind the multi-billion dollar protocol and they could just rug and and leave and And yeah, who knows what's uh what's behind it in regarding smart contracts. There's a lot of um protocol depending on the IPL liquid um uh infrastructure that are building on IP liquid infrastructure that don't realize this and it's a bit like the same you you you don't you don't know how sustainable and open uh the the infra you're using is. Um, so yeah, if you build in the dark, it's good, but at some point you got to you got to upload your contracts and we'll find it out. We we we'll see your contract somewhere. If it's not verified, we cannot be 100% sure it's yours and maybe it's a it's a fishing link or something, but uh then the volume will speak and if everybody start using your UI and we see the volume interacting with this smart contract, then uh we'll know uh your core source, your core code. Now, you not verifying it is just bad uh development methods in my opinion. &gt;&gt; Oh, don't we all just love a good fishing link to empty your wallets, &gt;&gt; right? &gt;&gt; So, yeah, there we have a question right down here. Perfect. So I was wondering if uh after doing the reviews on the protocols, do you ever like uh challenge the protocols publicly uh trying to like point uh some things out like findings so that you get a response from them like if they have those things in mind? &gt;&gt; Yeah. Yeah. It's um this is where the all the politics uh comes in and um you have different reactions from each protocols but um what can I say some people are really angry of the ratings they get and some are just surprised uh and say oh we can do so much better thank you so it's um it's a double-edged sword but um but yeah um obviously there is some social tenants here as well like if you have we have some reviewers or core team members that worked uh at big D5 protocols and clashed as they were working as you know executive or core contributors and uh well they left because of big dispute and now we we we come back to these protocols stating giving them a rating and they're obviously like oh you're so biased you're so uh you have some um some remorse or how can you say yeah you have some sense of revenge against us this is why you're rating us this And so you have this weird social dynamics, but at the end of the day, we we have this academic academic method and scientific rigor in our framework and reviewing process. Uh that's um I I don't think it really matters. Um we could obviously discuss and this is happening every day uh now at Defcan and with various people we're reviewing uh regarding security consil requirements and how the framework could be enhanced. Uh but this is a different question, right? like it is how you you redefine the framework. The method is the method and if we apply it and we see you have a multisig with admin rights and it's full of insiders. I mean you want us we're trusting you. We're trusting you to behave and um and and so yeah this is a lot of why don't you trust us kind of situation and uh some some weird gossip and social situation we have here. But fortunately we also have very interesting team. Lido is pushing some new governance and I'm pretty sure they they learned from uh the review and we spoke with them actively. Um Moro was extremely proactive in this sense. Uh they started to review themselves. Um so so yeah it's um it's it's a double-edged sword where you have very aggressive reactions and people like oh my god this is needed. Thank you. You you're enhancing the the developer operation uh in in in the core protocol. You can never make everybody happy. If you have more questions for Mark, please catch him outside. I'm sure he will be willing to answer everyone and love all the deep questions. Thank you so much and thank you for Mark.
