Blog

  • Why two market caps are not always comparable

    Why two market caps are not always comparable

    Market capitalisation is the default way assets get ranked, which encourages reading it as a standardised measure of size. It is price multiplied by circulating supply, and both of those inputs are less solid than the resulting number looks.

    The price is a last trade, not a valuation

    The price in a market cap calculation is whatever the most recent trades cleared at, usually aggregated across venues. It reflects the marginal buyer and seller — the small proportion of supply that changed hands — not what the whole supply could be sold for.

    This matters more as liquidity thins. For an asset where a large share of supply trades regularly, the last price is a reasonable estimate of what more of it would fetch. For one where a tiny fraction trades, the last price can be set by a small amount of money and the market cap extrapolates it across the entire supply.

    Two assets showing the same capitalisation can therefore represent very different amounts of capital actually committed.

    The supply figure is a convention

    The second input carries its own uncertainty. Circulating supply excludes tokens deemed unavailable, and what counts as unavailable is a judgement rather than a measurement — which is why providers publish different figures for the same asset.

    The largest disagreement concerns tokens held by a foundation or treasury under a stated but unenforceable commitment. Include them and the capitalisation rises; exclude them and it falls. Neither treatment is wrong, and the choice is rarely stated where the number is displayed. Our explainer on the three supply figures covers the definitions.

    What the number does not measure

    Several intuitions attach to market capitalisation that it does not support:

    • Money invested. Capitalisation is not the sum of what people paid. It is the current price applied to all units, most of which were never bought at that price.
    • Realisable value. Selling the supply would move the price long before the sale completed. The figure is what the supply is notionally worth, not what it could be exchanged for.
    • Adoption or usage. Price reflects what buyers will pay, which can diverge from any measure of use for extended periods.

    Comparing across designs

    Comparability degrades further between assets with different structures. An asset with fixed supply, one with ongoing issuance, and one with a large locked allocation are three different economic objects, and one number does not put them on a common footing.

    Comparing fully diluted valuations helps with the third case and introduces its own distortion, since it prices tokens that may not exist for years as though they existed now. Neither figure is complete, which argues for looking at both and at the gap between them.

    Where it is genuinely useful

    None of this makes market cap useless. Used carefully it does two jobs well.

    It gives a rough ordering. The distinction between an asset in the top ten and one in the top thousand is real and survives every caveat above. And it corrects the unit-price illusion, which is its most valuable function: it demonstrates why an asset priced at a fraction of a cent is not therefore cheap, because unit price is capitalisation divided by a supply that may be enormous. Our market cap what-if tool makes the arithmetic concrete.

    How to read a figure honestly

    Check which supply definition the source used, look at traded volume relative to capitalisation as a rough liquidity check, and look at the gap between circulating and fully diluted figures. Then treat the result as an approximate ordering rather than a measurement.

    That is a less satisfying position than a leaderboard implies, and it is the accurate one. We show the provider and timestamp beside every figure on this site for the same reason: a number without its provenance invites more confidence than it has earned.

    Volume relative to capitalisation as a rough check

    Since the reliability of a market cap depends heavily on how much of the supply actually trades, a crude ratio helps: daily traded volume divided by capitalisation.

    A high ratio suggests the price is set by meaningful activity. A very low one suggests the last price is doing a great deal of extrapolation across a supply that rarely moves. This does not produce a threshold — there is no line above which a figure becomes trustworthy — but comparing two assets on this ratio is more informative than comparing their capitalisations alone.

    The caveat is that reported volume is itself among the least reliable figures in the sector, aggregated across venues of very uneven quality. We pass through what the provider reports and name the provider rather than applying a silent correction, which is the same policy we apply to every other figure.

    Dominance shares inherit every problem

    Dominance — one asset’s capitalisation as a share of the total — is widely quoted and compounds the issues above rather than avoiding them.

    Both the numerator and the denominator depend on supply conventions, and the denominator depends additionally on which assets are included in “the total”. Providers differ on whether to include stablecoins, wrapped assets, and tokens whose supply is largely locked. Including wrapped versions of an asset alongside the asset itself double-counts the same underlying value.

    Dominance is therefore best read as a rough directional indicator over time from a single consistent source, and not as a precise figure comparable between providers.

    The practical position

    Market capitalisation is a useful ordering and a poor measurement. Treated as the former it corrects a genuine and widespread error about unit prices. Treated as the latter it invites conclusions its inputs cannot support.

    The distinction is not pedantry. Most of the confident claims about an asset being “bigger than” some conventional company rest on reading a rough ordering as a precise measurement — and the two inputs, a marginal price and a conventional supply figure, are exactly where that reading breaks.

  • Reading market breadth instead of the headline number

    Reading market breadth instead of the headline number

    Almost all market commentary reports one number — usually what the largest asset did — and treats it as a description of the market. It describes one asset. Whether the market moved with it is a separate question, and the two answers frequently disagree.

    What breadth measures

    Breadth counts participation: of the assets you are looking at, how many rose and how many fell over the period. It is deliberately indifferent to size.

    That indifference is the point. A capitalisation-weighted view tells you what happened to the money. Breadth tells you what happened to the assets. On a day when one very large asset rises and most others fall, those two measures point in opposite directions, and only one of them matches the headline.

    Computing it

    The calculation is deliberately simple, because complexity here buys nothing. Take a defined set — the top fifty by market capitalisation is a common choice — and count how many closed higher over the period.

    Report it as a fraction rather than a percentage of a percentage: twenty-six of fifty is clearer than fifty-two per cent, because it exposes the sample size. A breadth figure without its denominator is not checkable, which is why our markets page shows both.

    Two decisions shape the result and should be stated: which set of assets, and which period. Breadth across the top fifty and breadth across the top five hundred answer different questions, and neither is more correct.

    Magnitude is the second dimension

    Breadth counts direction and ignores size. On its own it can mislead in the opposite way: forty-nine assets up a fraction of a per cent and one down thirty per cent produces excellent breadth and a poor day for anyone holding the one.

    Pairing breadth with a magnitude measure — the median move rather than the mean, since the mean is dominated by outliers — gives a much more complete picture. The median says what a typical asset did; breadth says how many did it. Together they distinguish a broad small move from a narrow large one, which the headline cannot.

    When breadth and the headline disagree

    The disagreement is the useful signal, and it comes in two shapes.

    A large asset up, weak breadth reading describes concentration: money moving into one or two names while most of the market does not participate. A large asset flat or down, strong breadth reading describes the reverse.

    Neither is a prediction, and we do not present them as one. What they are is a correction to a headline that has compressed a market of hundreds of assets into a single number, and the correction is often the difference between two opposite situations that produce identical coverage.

    What the figures cannot tell you

    Being explicit about the limits, since this is a measurement rather than a forecast:

    • Breadth is entirely determined by the set you chose. Changing the sample changes the answer, and there is no neutral sample.
    • It says nothing about volume. Assets can rise on almost no trading, particularly the smaller ones.
    • It says nothing about tomorrow. A reading describes a period that has ended.
    • Reported volume across venues is among the least reliable widely quoted figures in this sector, so any measure weighted by it inherits that unreliability.

    Reading it honestly

    The discipline that makes this worth doing is stating the method alongside the number: which assets, which period, which provider, and when the data was read. A breadth figure without those is an assertion.

    Our approach to this is set out on the methodology page, and the worked version of the calculation is in how to read a crypto market day. The general principle is duller than most commentary and considerably harder to be wrong with: compute several things, say how, and let them disagree in public.

    Timeframe agreement is a third check

    A single period can mislead in a way that neither breadth nor magnitude catches. A strong day inside a weak month is a different situation from a strong day inside a strong month, and both produce the same daily figures.

    Computing breadth over several periods — a day, a week, a month — and noting whether they agree is a cheap addition. Where all three point the same way the reading is consistent. Where the short period diverges from the longer ones, the honest description is that they disagree, which is more informative than picking whichever supports a narrative.

    This is deliberately not a signal. It is a way of describing a market without implying that a single timeframe is the true one.

    Why the median rather than the mean

    Worth being explicit, because the choice does real work. Crypto returns are heavily skewed: a small number of assets post very large moves in either direction.

    The mean is dragged around by those outliers, so an average move can be strongly positive on a day when most assets fell. The median is the middle observation and is unaffected by how extreme the extremes are. For describing what a typical asset did, the median is the honest statistic and the mean is the one that produces better headlines.

    Where we publish an average we say which one it is, for exactly this reason.

    The set determines the answer

    One more caveat that deserves its own space, because it is the easiest way to produce a misleading breadth figure without stating anything false.

    Breadth across the top fifty by capitalisation is dominated by established assets. Breadth across a wider set includes many small, thinly traded ones whose prices move on very little volume. A publication can produce almost any breadth reading it likes by choosing the sample, and none of the resulting numbers is a lie.

    The only defence available to a reader is a stated method. Where a breadth figure appears without the set, the period and the source, it is not checkable, and an uncheckable statistic is an opinion with a number attached.

  • What a crypto licence actually obliges a platform to do

    What a crypto licence actually obliges a platform to do

    “Regulated” appears on nearly every crypto platform’s homepage. It is not a lie and it is not informative, because it covers arrangements ranging from being recorded on a public list to operating under capital, custody and reporting obligations. The word is identical; the substance is not.

    The registration end of the range

    The lightest common arrangement is registration for anti-money-laundering purposes. A firm demonstrates it has identification procedures, appoints someone responsible for compliance, and is entered on a register.

    This is a genuine obligation and it addresses a genuine problem. What it does not do is say anything about how customer assets are held, whether the firm holds capital against losses, whether customer funds are segregated, or what happens in insolvency. A firm can hold this registration, market itself as regulated, and be under no obligation whatsoever regarding your balance.

    The licensing end of the range

    At the other end, an authorisation to conduct regulated financial activity typically brings a substantially longer list: minimum capital, rules on holding client assets, requirements to segregate them from the firm’s own, periodic reporting, controls on outsourcing, fitness requirements for management, and complaint-handling procedures.

    Firms under this kind of regime are also usually subject to supervisory attention rather than merely a one-off registration — inspections, data returns, and the possibility of intervention.

    The distinction that matters most to a customer is in there: client asset rules. Whether assets must be segregated, and whether they sit outside the firm’s estate if it fails, is decided by the regime the firm operates under and not by anything the firm chooses.

    The questions that separate them

    Four questions distinguish a meaningful authorisation from a listing, and all four have published answers:

    • Does the regime require customer assets to be segregated from the firm’s own?
    • Does it impose capital requirements scaled to the business?
    • Does it include a compensation or protection scheme, and does that scheme cover crypto holdings or only cash?
    • Is the firm supervised on an ongoing basis, or was it assessed once at entry?

    Answering these takes a few minutes on the regulator’s own register, and it is the difference between reading a claim and checking one.

    Which entity holds the permission

    A subtlety that does real damage. Large platforms are corporate groups. A licence held by one entity does not extend to another, and the entity serving you may not be the licensed one.

    The check is to find the entity named in the terms you accepted, then look up that name on the regulator’s register — not the brand. Where they differ, the permission belongs to whichever entity is listed, and your relationship is with whichever entity is in the contract.

    What compensation schemes usually cover

    Where a protection scheme exists, its scope is narrower than the marketing implies. Schemes typically cover money held by a failed regulated firm in the course of a protected activity. Whether crypto assets qualify depends on whether holding them is itself a protected activity in that jurisdiction, and frequently it is not.

    A platform can therefore be a member of a compensation scheme, disclose that accurately, and have crypto balances entirely outside its scope. The scheme’s own documentation states what it covers, and reading it is more reliable than reading a badge.

    What none of it guarantees

    Worth stating plainly: authorisation reduces certain risks and eliminates none. Regulated firms fail. Rules can be broken and are sometimes only discovered afterwards. Supervision is periodic rather than continuous.

    What authorisation genuinely provides is a set of obligations that exist independently of the firm’s goodwill, and a body with the power to act. That is meaningfully better than nothing and is not the same as a guarantee — a distinction the word “regulated”, used alone, is designed to blur. Our note on what happens when an exchange fails covers the insolvency side.

    Checking a register properly

    Regulators publish searchable registers, and using one takes a couple of minutes. Three things are worth extracting.

    The permissions granted, which are usually itemised. A firm may be authorised for one activity and not another, and offering a product outside its permissions is a compliance problem regardless of how it is marketed. The status and dates, since registrations lapse, get varied, or carry conditions imposed after entry. And any restrictions, which are recorded on the register and are rarely mentioned elsewhere.

    The register is also where you confirm the entity name matches the one in the terms of service, which is the check that catches the group-structure problem.

    Passporting and its limits

    In some regions an authorisation obtained in one member state permits operation across the bloc. Where that applies it genuinely reduces friction, and it is frequently invoked loosely by firms outside such arrangements.

    The limit worth knowing is that passporting operates within a defined legal framework and does not extend beyond it. A licence from a jurisdiction outside the bloc confers no rights inside it, however reputable the issuing regulator. Claims that a firm is “licensed in Europe” on the strength of an authorisation from a non-member state are a specific and recurring form of overstatement.

    What to do with all this

    The practical routine is short. Find the entity name in the terms. Look it up on the register of the regulator named. Read the permissions and any conditions. Check whether client asset rules apply to that permission, and check what any compensation scheme actually covers.

    That is perhaps ten minutes and it replaces a badge with a fact. It will not tell you whether a platform is well run — nothing available to a customer will — but it establishes what obligations exist independently of the firm’s intentions, which is the part that still holds when intentions change.

  • Why the same crypto activity is legal in one country and not the next

    Why the same crypto activity is legal in one country and not the next

    People discuss crypto regulation as though it were a single thing arriving in different places at different speeds. It is not. The substantive disagreement is upstream of any rule: countries differ on what an asset is, and everything downstream follows from that classification.

    Classification decides which rulebook applies

    Most jurisdictions did not write crypto law from nothing. They asked which existing category an asset falls into, and the categories carry entirely different regimes with them.

    Treated as a security, an asset attracts disclosure obligations, licensing for anyone facilitating trading, and restrictions on marketing. Treated as a commodity, a different regulator and a lighter set of conduct rules typically apply. Treated as property for tax but not as a financial instrument, much of the market-conduct apparatus does not attach at all. Treated as a payment instrument, the money-transmission and anti-money-laundering regime dominates.

    These are not gradations of strictness. They are different bodies of law with different regulators, different thresholds and different penalties, and a country can reasonably arrive at any of them.

    The same token can be several things at once

    This is where intuition fails most often. Classification frequently attaches to the transaction rather than the object.

    An asset sold to fund development, with the seller promising to build something that gives it value, has the structure of an investment contract in many legal systems. The same asset traded years later between strangers on a market, with no promoter making promises, may not. Nothing about the token changed; the circumstances did.

    This is why blanket statements that a given asset “is” or “is not” a security are usually too strong. The honest formulation is that a particular transaction, in a particular jurisdiction, at a particular time, was or was not treated as one.

    Where jurisdictions genuinely agree

    Amid the divergence, one area has converged substantially: anti-money-laundering obligations on intermediaries.

    Broadly, businesses that hold customer assets or exchange between crypto and conventional currency are expected to identify their customers, monitor for suspicious activity, and report it. The thresholds and documentation differ, but the principle is close to universal among jurisdictions with functioning financial regulation.

    This is why identity verification is near-inescapable on custodial services regardless of where they operate, and why the requirements feel similar even between countries that disagree about everything else. Our glossary covers KYC and AML as concepts.

    Which country’s rules apply to you

    Two answers matter and they are frequently different. A service is regulated where it is established and licensed. A user is generally subject to the rules of where they reside.

    A platform licensed in one jurisdiction and serving a customer in another may be operating lawfully at home while being unavailable, restricted, or unlawful to offer where the customer sits. This is why services geo-block, why terms of service list excluded territories, and why availability changes without the product changing.

    The practical consequence for a reader is that “is this legal?” has no general answer. It has an answer for you, in your country, which is not the one written on most websites.

    Registration is not endorsement

    A registration or licence tells you a firm met a defined set of conditions. It does not tell you the firm is well run, that its product is suitable, or that your assets are protected in insolvency.

    Registrations also vary enormously in what they require. Some involve capital adequacy, custody rules and regular reporting. Others amount to being recorded on a list for anti-money-laundering purposes and impose almost nothing about how customer assets are held. Both get described as “regulated” in marketing.

    The useful question is not whether a firm is registered but what its specific registration actually obliges it to do — which is published, and rarely quoted.

    Why this keeps moving

    Classification decisions get revisited as products change and as courts rule. A framework designed around exchanges fits awkwardly around software that no company operates. New instruments arrive that fit no existing category cleanly.

    Expecting a settled position is therefore the wrong frame. What is reasonably stable is the underlying logic: identify the classification, and the applicable regime follows. That approach survives changes in the specific answer, which a memorised list of country positions does not.

    What we do and do not cover

    We write about regulatory structure — what a category means, what an obligation entails, what a registration covers. We do not report enforcement actions we cannot source, and we do not offer legal advice, which is what a definitive answer about your circumstances would be. Where a rule matters to a decision you are making, the applicable regulator’s own guidance is the primary source, and it is usually published in plain language.

    Why decentralisation complicates enforcement rather than removing it

    A common assumption is that software with no operating company sits outside regulation entirely. The more accurate position is that regulators apply existing law to whoever they can identify, and the absence of a company redirects attention rather than removing it.

    Attention tends to land on the points where the system touches conventional finance: the interfaces people actually use, the developers who published and maintain the code, the entities that market it, and the on- and off-ramps converting to conventional currency. Those are identifiable and located somewhere.

    This is why front-ends restrict access by territory while the underlying contracts remain reachable by anyone able to interact with them directly. The protocol and the interface are not the same thing, and only one of them has an address.

    Reading a consultation is more useful than reading coverage

    Most substantial regulatory change is preceded by a published consultation setting out what a regulator is considering and inviting responses. These documents are long, plainly written, and read by almost nobody outside the industry.

    They are considerably more informative than reporting about them, for a specific reason: coverage compresses a proposal into a verdict, and the proposal usually contains the reasoning, the scope, the thresholds, and the questions the regulator is genuinely uncertain about. The final rules are frequently visible in outline months before they arrive.

    Where a rule matters to a decision, the consultation and the resulting policy statement are primary sources, freely available, and specific about who is caught.

  • What happens to your assets when an exchange fails

    What happens to your assets when an exchange fails

    Whether you get your assets back after a custodian fails is determined almost entirely by arrangements made before anything went wrong. It is a legal question, not a technical one, and the answers are usually available in advance to anyone who reads for them.

    Deposit and you become a creditor

    The starting point people find most surprising. When you deposit into a custodial exchange, in most arrangements you no longer own specific assets. You hold a claim against the company for a balance, and the company holds the assets.

    The practical difference appears only at insolvency. An owner of segregated property can generally claim that property back. A creditor joins a queue and receives a proportion of whatever remains after those ranking above them are paid. The same balance on the same screen can mean either, depending on terms you agreed at sign-up.

    Segregation, and whether it is real

    Segregation means customer assets are held separately from the company’s own and are not used to fund its operations. Where it is genuine and legally effective, customer assets may sit outside the insolvency estate entirely.

    Two things undermine it in practice. The first is commingling: assets nominally segregated but operationally pooled, so no individual holding can be identified. The second is rehypothecation — terms permitting the custodian to lend or pledge customer assets, which converts your property into someone else’s collateral with your consent.

    Both are addressed in terms of service, generally in a section about the use of digital assets. It is not compelling reading and it is the section that decides the outcome.

    Which entity actually owes you

    Large exchanges are corporate groups, not single companies. The entity named in the terms you accepted may be different from the one holding the assets, and different again from the one that markets the service.

    This determines which insolvency regime applies, which court, and which creditor hierarchy. Customers of different entities within the same brand can experience very different outcomes from the same collapse. The name at the top of the terms of service is the one that matters, and it is frequently registered somewhere other than where you live.

    Where a claim ranks

    Assuming you are a creditor rather than an owner, ranking decides everything. Secured creditors are paid first, then various preferential classes depending on jurisdiction, then unsecured creditors — which is usually where customers sit.

    Two consequences follow. Recovery is a proportion rather than all-or-nothing, and it takes years. Claims are also commonly valued in fiat at the date proceedings opened, so subsequent price movement in the asset does not accrue to you. Recovering a percentage of a valuation fixed at the worst moment is a materially different outcome from recovering your coins.

    What insurance usually covers

    Exchanges advertise insurance, and it is worth knowing what these policies typically address. They generally cover theft from the custodian’s own hot or cold storage — a security event.

    They typically do not cover insolvency, mismanagement, fraud by the operator, unauthorised access to your individual account through your own credentials, or losses arising from the custodian’s business failing. Deposit insurance of the kind attached to bank accounts in many jurisdictions generally does not extend to crypto balances, even where the same institution offers both.

    What to check, and what it costs

    Four things, all findable before you deposit: which legal entity is named in the terms; whether assets are segregated and whether the terms permit lending or pledging them; what regulatory registration the entity holds and what that registration actually requires; and what any advertised insurance covers.

    None of this makes an exchange unusable, and holding assets on one is a reasonable choice for many purposes. The point is that the choice carries a specific, knowable exposure that is settled by paperwork rather than by technology — and that the alternative, self-custody, replaces it with a different exposure rather than removing risk. Our comparison of who actually holds your crypto sets both sides out.

    Warning signs that appear before a failure

    Collapses are usually sudden in public and gradual in fact. Several signs tend to precede them and are visible without inside information.

    Withdrawal friction is the clearest: delays described as upgrades, new limits, additional verification imposed on withdrawal but not deposit. A custodian short of assets slows the outflow before it stops it.

    Others are structural. Yields materially above what the market offers have to come from somewhere, and the usual somewhere is lending customer assets or paying from capital. Ownership or corporate structure that is hard to establish, an auditor that resigns, an unexplained departure of a finance officer, or a sudden marketing push funding growth during a downturn all belong on the list.

    None is conclusive alone. Several together have preceded enough failures to be worth treating as a prompt to reduce exposure rather than a puzzle to solve.

    Proof of reserves does not answer this

    Worth connecting explicitly, because the two topics are frequently conflated. A proof of reserves demonstrates assets at a moment. Solvency depends on assets against liabilities, and recovery depends on legal structure.

    A custodian can publish a clean proof and still fail, and its customers can still rank as unsecured creditors afterwards. The proof was never addressed to that question. Our note on what proof of reserves demonstrates covers the boundary in detail.

    Reducing exposure without abandoning exchanges

    The practical position for most people is not to avoid custodians but to be deliberate about how much sits with them and for how long.

    Balances needed for trading are a working requirement. Balances sitting idle for months are a decision, and one worth making explicitly rather than by inertia. Spreading across more than one custodian reduces single-entity exposure at the cost of more accounts to secure. Moving longer-term holdings to self-custody removes the counterparty entirely and substitutes the risks covered in our note on what hardware wallets protect against.

    There is no arrangement without exposure. What there is, is a choice about which kind you hold — and that choice is better made while everything is working than during a withdrawal queue.

  • Phishing patterns that target crypto users specifically

    Phishing patterns that target crypto users specifically

    Standard phishing advice — check the URL, look for the padlock — was written for a world where the worst case was a stolen password you could change. Crypto attacks are built for an audience whose mistakes are irreversible, and they are shaped accordingly. The patterns repeat, and recognising the shape is more reliable than inspecting every link.

    The fake support agent

    You post a problem publicly — a forum, a chat, a social platform — and someone helpful appears in your direct messages within minutes, presenting as support for whatever you mentioned.

    The tell is the direction of contact. Legitimate support does not initiate a private conversation because you complained publicly. Everything that follows, whether a “validation” site, a “sync” tool, or a screen-share, exists to reach your seed phrase or get you to sign something.

    The habit that defeats it is absolute: nobody who contacts you first is support. Not if the display name matches, not if the avatar is right, not if they know details from your public post.

    The approval that is not a transfer

    The most effective attacks do not ask you to send anything. They ask you to sign an approval that grants a contract permission to move a token on your behalf, often without limit and without expiry.

    It works because the prompt does not look like a payment. No amount leaves your wallet at the moment of signing, the wallet may show a small or zero value, and the funds move later. People who would never send funds to a stranger will approve a contract to claim an airdrop or connect to a site.

    The defence is to read the device or wallet screen rather than the website, and to be suspicious of any unlimited allowance. Periodically reviewing and revoking standing approvals is maintenance that most people never perform.

    The address that looks right

    Two variants, both exploiting the fact that nobody reads a full address.

    Clipboard malware replaces a copied address with the attacker’s at the moment you paste. Address poisoning sends you a tiny transaction from an address whose first and last characters match one you use, so that when you later copy from your history you take the wrong one.

    Both defeat the habit of checking the first four and last four characters, which is the habit almost everyone has. Verifying the middle, using a saved address book, and sending a small test first are the countermeasures — and the test transaction is worth its fee on anything substantial.

    Urgency about your own security

    “Your wallet is compromised, migrate immediately.” “Suspicious activity detected, verify now.” The message is engineered so that the emotion it produces — fear about security — pushes you toward the action that destroys it.

    Nothing in crypto genuinely requires action within minutes. There is no migration a real wallet provider will demand, no validation step involving your phrase, and no legitimate reason for anyone to need it. Time pressure applied to a security decision is itself the signal.

    The search result and the paid ad

    Searching for a wallet or exchange returns paid placements above the real result, and those placements are periodically bought by attackers pointing at a convincing clone. The site is pixel-accurate and the domain is a near-miss.

    Bookmarks solve this completely and cost nothing. Reach anything holding value through a bookmark you created, never through a search result, and the entire category stops applying.

    Why intelligence is not the defence

    Worth saying because the shame of falling for one of these keeps people from reporting them. These attacks succeed against experienced, careful people, because they are designed to be caught during ordinary moments of distraction rather than during careful inspection.

    What actually protects you is a small number of habits that do not depend on judgement in the moment: bookmarks rather than search, nobody who messages first is support, read the device screen not the website, a test transaction on anything large, and periodic approval review. Each removes a whole category regardless of how convincing an individual attempt is. Our note on what each security measure protects against covers the tooling side.

    The fake airdrop and the token you did not buy

    Unexpected tokens appearing in a wallet are a standing pattern rather than an occasional nuisance. The token is created by an attacker, distributed widely, and named to suggest value and a claim process.

    Interacting with it is the trap. Attempting to sell or claim routes you to a site that requests an approval, and the approval is the attack. Holding the token costs nothing; touching it is what carries risk.

    The correct response to an unexpected token is to ignore it. Most wallets allow hiding it from view. There is no version of this where a token you did not expect turns out to be a windfall, and the emotional pull of the possibility is exactly what the pattern is built on.

    Compromised official channels

    The hardest variant, because the usual advice fails. A project’s own social account, community server, or occasionally its website is taken over, and the malicious link is posted from the genuine source.

    Every heuristic based on checking the sender breaks here. What still works is not depending on any single channel: confirming an announcement across the project’s other channels before acting, treating anything time-limited with additional suspicion, and reaching sites through bookmarks so a compromised post cannot route you anywhere.

    It also argues for a habit that feels excessive until it isn’t — never connecting a wallet holding significant value to a site you reached from a link, whatever posted it.

    Separate wallets do most of the work

    The highest-leverage structural defence is not vigilance, which fails eventually, but separation. A wallet holding long-term assets that never connects to any site, and a separate wallet with a small balance used for everything interactive.

    This converts a category of catastrophic outcomes into an annoyance. An approval signed from the interaction wallet exposes what is in it, which by design is little. The holdings wallet is unreachable because it has no relationship with any application.

    It costs some inconvenience and removes the requirement that you never make a mistake — which is a better foundation than any amount of care, because care is a resource that runs out on a bad day and structure is not.

  • What a smart contract audit does and does not tell you

    What a smart contract audit does and does not tell you

    “Audited” appears on landing pages as though it were a certification with a defined meaning. It is not. It is a professional service with variable scope, and the difference between a thorough review and a cursory one is invisible from the badge.

    What an audit actually is

    A firm is engaged to review a specified set of contracts at a specified commit, over a specified period, looking for defects against a specified threat model. They produce a report listing findings by severity, the project responds, and a final report usually records what was fixed.

    Every word of “specified” there is doing work. The scope is negotiated, and a report on three contracts says nothing about the fourth that holds the funds.

    Read the scope section first

    The scope tells you which files were reviewed and at which commit hash. Two questions follow, and both are answerable in a few minutes.

    Does the scope include the contracts that actually hold or move value, or only peripheral ones? And does the reviewed commit match what is deployed? Code changes after an audit, and a report against a commit from before several upgrades describes software that no longer exists. Verifying deployed bytecode against the audited source is the check that closes this gap, and it is rarely done by anyone reading the badge.

    Findings and their resolution

    Reports classify findings by severity. What matters more than the counts is the resolution: fixed, acknowledged, or disputed.

    “Acknowledged” means the project read the finding and chose not to change anything. That can be entirely reasonable — the finding may describe an accepted trade-off — but it means a known issue is live, and it will not appear in a summary that only reports the badge.

    A report with no findings at all is not a triumph. It usually means a narrow scope or a shallow review. Competent reviews of non-trivial systems find things.

    What audits are structurally poor at

    Certain categories are hard to catch by reviewing code:

    • Economic design flaws. Code that behaves exactly as written, where the incentives it creates are exploitable. This requires modelling the system’s economics, which is a different discipline and frequently out of scope.
    • Composability. A contract can be sound alone and unsafe when combined with another protocol nobody anticipated.
    • Oracle assumptions. Contracts relying on external price data inherit the reliability of that data, and the oracle is usually outside scope.
    • Governance and keys. An upgradeable contract controlled by a small multisig has a risk that no code review addresses, because the code permits the upgrade by design.

    That last one deserves emphasis. If a contract can be upgraded, the audit describes the current implementation and the holders of the upgrade keys can replace it. What matters then is who those holders are and what process governs them — a governance question wearing a technical badge.

    What a good report looks like

    Published in full rather than summarised. Scope stated with commit hashes. Findings with severity, description and resolution. A methodology section describing what was and was not examined. And a date, so you can compare it against the deployment history.

    A project publishing all of that is doing something meaningfully different from one displaying a logo. The logo is the part that costs least.

    How to use one

    Treat an audit as evidence that a project spent money on scrutiny and was willing to publish the result, which is a real signal about how it operates. Do not treat it as a guarantee of safety, because the report does not claim to be one — the disclaimer in it usually says so explicitly, in the section nobody quotes.

    The practical questions remain: what proportion of your holdings is exposed to this contract, could you tolerate losing it, and is the yield being offered plausibly compensation for that risk? Those are unchanged by the presence of a report, which is exactly why the badge is used the way it is.

    Not all reviews are the same depth

    “Audit” covers a range of activity with very different cost and rigour, and the report does not always make the distinction obvious.

    A manual review by experienced engineers reading the code is the expensive end. Automated analysis catches known patterns cheaply and misses anything novel. Formal verification proves mathematically that code satisfies a specification, which is powerful and only as good as the specification. Competitive audit platforms crowdsource review, which finds a wide range of issues but produces less consistent coverage.

    Each has a role. What matters is knowing which you are looking at, and the methodology section says so. A report that does not describe its method is asking to be taken on the strength of the logo.

    Bug bounties tell you something a report cannot

    An audit is a snapshot; a bug bounty is continuous. A project running a substantial, well-scoped bounty with a public payout history is exposed to ongoing scrutiny in a way that a one-off review does not provide.

    The size matters. A maximum payout far below what an exploit would yield is not an incentive, it is a gesture — a researcher who finds a critical flaw in a contract holding a large sum faces an obvious arithmetic problem if the bounty is trivial by comparison. Bounties scaled to the value at risk are a genuine signal about how seriously a project takes the possibility that it is wrong.

    Time in production is evidence too

    Contracts that have held significant value for a long period without incident have been subjected to the most rigorous review available: sustained attention from people financially motivated to break them.

    This is not proof — dormant flaws exist and several long-lived protocols have failed late. But a recently deployed contract with a report and no operating history has been reviewed by one firm for a few weeks. An older one with the same report has additionally survived years of adversarial interest, and that is a different quality of evidence.

    Combining the two is the practical approach: read the report for what was examined, and weigh the deployment history for what the report could not cover.

  • Liquid staking: what the derivative token actually represents

    Liquid staking: what the derivative token actually represents

    Liquid staking solves a genuine problem: staked assets are locked and unproductive elsewhere. You deposit, receive a token representing the position, and can use that token while the original stays staked. The mechanism works. What it also does is stack several distinct risks into one instrument, and they are worth separating.

    What the token is a claim on

    The derivative token is a claim against a pool of staked assets plus accumulated rewards, redeemable through the issuing protocol. Two designs are common and behave differently.

    In a rebasing design your balance increases over time while each unit stays pegged to one unit of the underlying. In a value-accruing design your balance stays fixed and each unit represents a growing quantity of the underlying, so the token trades above the underlying by design.

    Neither is better, but confusing them produces real errors — particularly in tax records and in any calculation where you assume one token equals one underlying unit.

    Why it can trade below what it represents

    The token’s redemption value is set by the protocol. Its market price is set by whoever is trading it, and the two need not agree.

    Redemption is usually not instant: unstaking involves a queue whose length is set by the network. Anyone wanting out faster must sell on the market instead, and if many want out at once the market price falls below redemption value. The discount is the price of immediacy.

    This is not a failure of the peg in the stablecoin sense — the claim is still good, and arbitrage should close the gap for anyone willing to wait out the queue. But the gap can be wide precisely when you would most like it not to be, which is the pattern with any instrument offering liquidity against something illiquid.

    The risks stack rather than replace

    Holding a liquid staking token exposes you to several things at once, and they are frequently discussed as if they were one:

    • The underlying asset’s price. Unchanged by staking. A yield on an asset that halves is still a loss.
    • Validator performance. Rewards depend on validators doing their job, and misbehaviour can be penalised by slashing, which reduces the pool backing your claim.
    • Smart contract risk. The protocol issuing the token is code holding a large pool of assets.
    • Queue and discount risk. Exiting quickly may mean accepting the market discount described above.
    • Concentration. If one protocol controls a large share of a network’s stake, that is a governance and security concern for the network and a correlated risk for holders.

    Where the yield actually comes from

    Worth stating plainly, because it is often obscured: the yield is the network’s issuance and fee revenue for validating, minus the operator’s commission, minus the protocol’s fee. It is payment for a service and it is denominated in the staked asset.

    That last point does most of the damage to intuition. A yield quoted as a percentage of the asset is a percentage of something whose price moves. Our staking yield calculator converts an advertised APR into the APY it actually produces, and the framing to keep is that neither figure says anything about the asset’s price.

    Using the token as collateral compounds everything

    The common next step is borrowing against the derivative token. This is where the risks multiply rather than add.

    You now hold a position exposed to the underlying price, the discount between the token and the underlying, the lending protocol’s contract risk, and its liquidation mechanism. A widening discount can trigger liquidation without the underlying asset moving at all — the collateral fell in market terms while its redemption claim was unchanged.

    That is a specific and non-obvious failure mode, and it is the one worth understanding before the position is opened rather than after.

    What to check before depositing

    Which design the token uses and therefore what a unit represents. How the exit queue works and what the historical discount has looked like under stress. Who runs the validators and how concentrated they are. What the protocol’s fee is and whether it can change. And whether the contracts have been examined by anyone whose work you can read.

    None of those questions is exotic, and each has a published answer for the larger protocols. The instrument is reasonable; what makes it risky is holding it without having separated the risks it contains.

    Exchange rate is not the same as peg

    Language borrowed from stablecoins causes real confusion here. A stablecoin aims to hold a fixed value against an external reference. A value-accruing liquid staking token is designed to diverge from one-to-one, because each unit represents a growing quantity of the underlying.

    So a token trading above one unit of the underlying is not evidence of anything unusual; it is the design working. What is worth watching is the relationship between market price and the protocol’s own stated redemption rate. A persistent discount to redemption value is the signal, and it is a different measurement from the raw ratio against the underlying.

    Getting this wrong in either direction is common: alarm at a normal premium, or complacency about a genuine discount because the headline ratio still looks above one.

    Where the queue length comes from

    Exit queues are not set by the protocol issuing the token. They are a property of the underlying network, which limits how quickly validators can leave in order to protect its own security.

    This has a consequence worth internalising: the queue lengthens precisely when many people want out, because that is what the limit exists to manage. The liquidity that liquid staking provides is therefore most reliable when least needed and least reliable during stress, which is the general shape of liquidity everywhere and no less true here.

    Checking the current queue length before depositing gives you a baseline. Assuming it will be similar when you want to exit is the assumption to avoid.

    Concentration is a network-level concern

    One further point, because it is usually framed as somebody else’s problem. If a single liquid staking protocol controls a large share of a network’s total stake, that concentration affects the network’s security assumptions and its governance.

    For an individual holder this shows up as correlation: a problem at the dominant protocol is simultaneously a problem for the network your assets are staked on. Spreading across protocols reduces the individual exposure and, marginally, the systemic one. It is one of the few cases where the diversification argument and the civic argument point the same way.

  • Reading a token unlock schedule

    Reading a token unlock schedule

    For most tokens the majority of eventual supply does not exist yet, and the plan for creating it is public. That plan is more informative about the next several months than a great deal of what passes for analysis, and reading it costs nothing.

    The three things a schedule tells you

    A schedule answers when tokens unlock, how many, and to whom. All three matter and the third is the one most often skipped.

    Timing is usually expressed relative to a launch date, with a cliff followed by a vesting period. Size is expressed as a proportion of total supply. Recipients are grouped: team, early investors, treasury, ecosystem incentives, public sale. Those groups behave differently and the differences are not subtle.

    Cliffs concentrate what vesting spreads

    A cliff releases nothing until a date and then releases a tranche at once. Vesting releases gradually, often monthly, over a period after that.

    The shape matters more than the total. Two projects issuing the same proportion over the same period present very different situations if one drips it evenly and the other releases it in three large steps. Clustered cliffs create dates where a large quantity becomes transferable simultaneously, and everyone holding a calendar can see them coming.

    Cost basis is why recipients differ

    The reason to care who receives an allocation is that different holders acquired it at different prices, and that shapes what they do next.

    An early investor whose allocation was priced at a small fraction of the current market faces a straightforward decision at unlock. A team allocation is subject to the same arithmetic plus reputational and often contractual constraints. A treasury allocation is typically spent over years to fund work rather than sold as a position. Ecosystem incentives are designed to be distributed and are usually sold quickly by whoever receives them, because that is what an incentive is for.

    None of this is an accusation. It is the observation that a schedule listing recipients is describing a set of distinct incentives, and treating the total as one undifferentiated number discards the useful part.

    Proportion beats absolute size

    An unlock is meaningful relative to what already trades, not in isolation. A tranche equal to a small fraction of circulating supply is one thing; a tranche comparable to circulating supply is another entirely.

    The second comparison worth making is against traded volume. Supply arriving that is large relative to the daily volume of the market it arrives into has a different character from supply that could be absorbed in an hour. Both figures are available and the ratio is the interesting one.

    Our explainer on the three supply figures covers the denominators.

    What a schedule does not tell you

    Being honest about the limits: an unlock makes tokens transferable. It does not mean they are sold, and assuming a mechanical price effect on each unlock date is a stronger claim than the schedule supports. Markets anticipate published events, and an unlock everyone has known about for two years is not news on the day it happens.

    Schedules are also revisable. Teams have extended vesting, renegotiated investor terms and altered emissions. A schedule is a stated intention with a governance process attached, not a physical constraint — the only genuinely fixed supply parameters are the ones enforced by the protocol itself.

    Where to find it, and what its absence means

    Schedules are normally published in project documentation, a tokenomics section, or the original sale terms. Several data providers aggregate them, with the usual caveat that aggregation introduces transcription errors — prefer the primary source where a figure matters.

    If no schedule is published, that is itself the finding. A project that will not say how much supply is coming, when, or to whom has made a decision about how much scrutiny it wants, and the reasonable response is to treat unspecified future supply as unbounded rather than as zero.

    Emissions are a schedule too

    Unlocks release tokens that already exist. Emissions create new ones, typically as rewards to validators or liquidity providers, and they arrive continuously rather than on cliff dates.

    The distinction matters because emissions are frequently omitted from unlock discussions while being the larger source of new supply. A project with a modest unlock schedule and aggressive emissions is issuing more than one with the reverse, and only one of those appears on an unlock calendar.

    Emission rates are usually set by protocol parameters and are often adjustable by governance, which makes them a moving figure rather than a fixed one. Where an emission rate is scheduled to decline, that schedule is worth reading with the same attention as an unlock.

    Reading the accompanying language carefully

    Schedules come with prose, and the prose is where imprecision lives. “Locked” can mean enforced by a contract that nobody can override, or it can mean subject to a commitment the holder has made and could break. Those are very different, and both get the same word.

    The check is whether the lock is on-chain and verifiable. A contract holding tokens until a block height is a constraint. A statement of intent in a blog post is a preference. Where documentation does not distinguish, assume the weaker version until shown otherwise.

    How to use the schedule without over-reading it

    The reasonable use is contextual rather than predictive. Knowing that a large tranche unlocks to early investors next quarter does not tell you what price does; it tells you that a specific, foreseeable increase in potential supply is arriving and that anyone claiming surprise afterwards was not looking.

    It is also a useful honesty test of a project’s own communication. A team that publishes its schedule clearly, notes upcoming unlocks in its updates, and explains changes when they occur is behaving differently from one that publishes a schedule once and never mentions it again. That difference is observable and costs nothing to check.

  • Where a disclosure has to sit to actually do its job

    Where a disclosure has to sit to actually do its job

    Most affiliate disclosures satisfy the letter of an obligation and none of its purpose. They exist, they are findable, and essentially nobody reads them — because of where they are, which is after the point at which the reader has already made up their mind.

    Placement is the whole mechanism

    A disclosure works by changing how the reader weighs what follows. That means it has to arrive before what follows, not after it.

    A footer disclosure is met after the article, after the comparison table, and usually after the click. A disclosure that appears once the reader reaches the bottom has informed them of nothing they could still act on. The same sentence placed above the recommendation does actual work: it tells the reader what to discount while they are still deciding.

    This is why we place the Partner Declaration above the body on any page carrying a commercial link rather than at the end. The position is not a stylistic choice; it is the difference between disclosure and paperwork.

    Prominence is not the same as presence

    The second failure is a disclosure that is technically above the content and visually designed to be skipped: small grey type, low contrast, collapsed behind a toggle, or phrased as boilerplate the eye has learned to ignore.

    The test is simple and uncomfortable. Show the page to somebody who has not seen it, ask them afterwards whether the publisher is paid, and see whether they know. A disclosure that fails that test is decorative regardless of where it sits in the markup.

    Specificity beats generality

    “This site may earn commission from some links” is close to meaningless. It does not say whether this page has such a link, which one, or whether the ranking was affected.

    A specific statement is harder to write and considerably more useful: what the relationship is on this page, which of the things being compared pay, and whether payment influenced the order. If the answer is that everything on the page pays, saying so is more honest than a generic hedge. If the answer is that nothing on this page pays, saying that is worth more than silence, because it distinguishes the page from the ones where money is involved.

    The ordering question is the one that matters

    Readers assume a ranked list is ranked on merit. If commercial terms influenced the order, disclosing that you earn commission does not disclose the thing that actually affects them.

    The two claims are separable and should be stated separately: whether you are paid, and whether being paid changed the order. A publication that ranks on stated criteria and can point to those criteria has something concrete to say here. One that cannot describe its ranking method has answered the question by omission.

    Language people actually parse

    Legalistic phrasing degrades comprehension even when the content is complete. “We may receive remuneration from certain third-party providers referenced herein” is accurate and communicates less than “we get paid if you sign up through these links”.

    Plain phrasing has a secondary benefit: it is harder to write plainly about an arrangement you would rather the reader did not think about. If the honest sentence is uncomfortable to write, that discomfort is information about the arrangement rather than about the sentence.

    What good looks like

    Above the content, in the same type size as the content, in the first person, naming the specific relationship on this specific page, and stating separately whether ranking was affected. Repeated near any prominent call to action, because readers arrive at those from search without reading top-down.

    None of this is expensive. It costs a paragraph and some willingness to be plain, and it is the difference between a disclosure that protects the reader and one that protects only the publisher. Our affiliate disclosure and editorial guidelines set out how we apply this.

    The failure mode nobody admits

    The strongest test of a disclosure regime is what happens when the best product does not pay. A publication whose comparisons only ever feature paying partners has not disclosed its way out of the problem; it has described a catalogue while presenting it as an assessment.

    Including options that pay nothing, and saying which ones those are, is the part that costs money and the part that makes the rest credible. Everything else is placement.

    Search traffic breaks top-down assumptions

    Disclosure design usually assumes a reader who starts at the top and works down. Most readers do not. They arrive from search directly onto a section heading, read one part of the page, and leave.

    That reader never passes the disclosure at the top, however well placed it is relative to the article as a whole. The fix is repetition at the points where a commercial decision is actually made — beside a prominent link, above a comparison table, adjacent to a call to action — rather than a single placement that assumes a reading path most people do not take.

    Repetition feels redundant to whoever wrote the page and is invisible to the person who landed halfway down it.

    Disclosure does not neutralise a conflict

    A quiet assumption underlies a lot of practice: that disclosing a conflict discharges the obligation created by it. It does not. It informs the reader of a bias that still exists and that they now have to correct for, using information they do not have.

    There is research suggesting disclosure can even increase the influence of a conflict, by making the discloser feel licensed and the reader reluctant to appear distrustful. Whether or not that effect holds in any particular setting, the safer assumption is that disclosure informs rather than absolves — and that structural choices about what gets covered and how it is ranked matter more than the sentence explaining them.

    What the reader is entitled to

    Reduced to essentials, a reader looking at a recommendation is entitled to know three things before they act on it: whether the publisher is paid, whether payment affected what they are seeing, and what was excluded.

    The third is the one almost nobody addresses. A comparison covering only paying partners can be entirely accurate about each entry while being misleading about the market. Saying what is not on the list, and why, is the part that turns a disclosure from a legal formality into something a reader can actually use.