Skip to main content
Risk Modeling, Compliance Architecture & Regulation10 Min Read

Quantitative Due Diligence: A Risk-Scoring Framework for Crypto and Private-Market Platforms

Quantitative Due Diligence: A Risk-Scoring Framework for Crypto and Private-Market Platforms

Crypto and private-market due diligence is often reduced to qualitative signals such as team reputation, audit badges, and community activity. These signals may be relevant, but they are not sufficient unless they are tied to reproducible evidence and consistent risk criteria.

Chainalysis separately estimated that scams and fraud stole approximately $17 billion in 2025, while hacks accounted for approximately $3.4 billion over the same period (subject to ongoing revision as additional illicit addresses are identified). Observable warning signs preceded many failures, although public evidence cannot reveal every technical, operational, or fraudulent risk.

The question is whether that is really enough.

This page converts due diligence into something checkable: a multi-factor risk framework built from structured evidence rather than subjective impressions. A score improves consistency only when its definitions, thresholds, evidence sources, and limitations are transparent. The framework prioritizes primary evidence, such as on-chain records, audit reports, legal documents, and regulatory publications, and is supplemented, where necessary, by clearly identified industry research. The framework is designed so that findings can be independently reproduced.

Why Due Diligence Needs Consistent Risk Criteria

A qualitative impression cannot be reliably compared across projects. A structured risk assessment can, but a score improves consistency only when its definitions, thresholds, evidence sources, and limitations are transparent. If one token presents high concentration risk and low vesting risk while another presents the reverse, that comparison is meaningful only if both were measured against consistent thresholds and primary sources.

That also means being honest about what a scoring framework can and can't do. It can't predict price. It can't tell you whether a project will succeed. What it can do is flag the specific, documented patterns that have preceded real collapses again and again, so that the decision to invest is made with that information in hand rather than discovered after the fact.

Evidence Standards & Confidence Hierarchy

This framework breaks quantitative due diligence into six checkable pillars. Each one has its own dedicated deep-dive elsewhere in this cluster, with the full mechanics, scoring brackets, and worked examples. This page shows how they fit together into one composite view.

Not all evidence carries equal weight. Before evaluating individual risk factors, findings must be categorized by evidence confidence:

Level

Source Type

Examples

High

Direct Primary

Node queries, signed legal agreements, official regulator registers

Moderate

Verified Secondary

Published third-party audits, official filings, verified contract deployments

Limited

Aggregated / Vendor

Vendor research databases, corporate press releases, media reports

Unverified

Uncorroborated

Anonymous claims, undated screenshots, marketing collateral

Each pillar is assigned one of four ratings: Low Risk, Moderate Risk, High Risk, or Unverifiable. Missing or obscured information is never automatically treated as low risk; depending on materiality, incomplete data triggers either an Unverifiable status or an immediate risk escalation.

The Six Pillars of the Framework

Pillar 1: Tokenomics and Dilution

The first pillar evaluates token supply dynamics, unlock schedules, and economic inflation. A key metric is Fully Diluted Valuation (FDV), calculated as:

$\text{FDV} = \text{Current Token Price} \times \text{Maximum Supply}$

FDV does not predict the value of the project after all tokens unlock; it is a static comparison using the current token price. Evaluating tokenomics requires analyzing the circulating-to-total supply ratio, 30/90/365-day unlock schedules relative to daily trading volume, insider allocations, treasury control, vesting enforceability, and emission rates.

See the full Tokenomics Forensics methodology for granular unlock rubrics.

Pillar 2: Audit and Technical Security

The second pillar examines code security, historical exploits, and audit quality. In their 2024 Web3 Security Report, Hacken reported $4.0 billion in total crypto losses, with $512 million stemming from smart-contract vulnerabilities and $2.12 billion from access-control failures.

These categories reinforce the need to examine both code-level findings and operational access controls. A smart-contract audit alone may not cover private key custody, phishing, or organizational authorization processes. Due diligence must confirm whether audit findings were remediated, accepted as residual risk, disputed, or left unresolved, and verify the deployed bytecode match, audited commit hash, and upgrade governance. See Smart Contract Audit Breakdown for audit verification protocols.

Pillar 3: Ownership Concentration

The third pillar assesses entity-level supply control. For supported tokens, chain explorers and direct node queries can provide address-level balance data. That data must then be labeled and clustered before it can be interpreted as entity-level concentration.

Rather than simply ignoring exchange and liquidity-pool addresses, holders must be categorized into distinct buckets: exchange custody, liquidity pools, bridge contracts, protocol treasuries, vesting contracts, burn addresses, team-controlled wallets, and unidentified holders. While metrics like the Gini coefficient measure statistical distribution, they can be skewed by exchange omnibus wallets, dust addresses, or multi-wallet entities unless entity resolution is performed first.

See Quantifying Concentration Risk for entity clustering methodologies.

Pillar 4: Compliance and Jurisdiction

The fourth pillar evaluates compliance infrastructure, licensing, and access controls. Compliance extends beyond basic KYC/AML checks to include securities registration exemptions, marketing rules, sanctions filtering, transaction monitoring, Travel Rule implementation, geographic blocking, and consumer protection controls.

Regulatory frameworks vary significantly by jurisdiction:

  • United States: The SEC’s March 17, 2026 interpretation identifies four categories of crypto assets that are not themselves securities: digital commodities, digital collectibles, digital tools, and qualifying payment stablecoins, while tokenized securities remain subject to federal securities law. The interpretation continues to apply Howey when analyzing whether a crypto-asset transaction or arrangement constitutes an investment contract.
  • United Kingdom: The expanded UK regime is expected to bring specified cryptoasset activities within the FCA authorization framework from October 25, 2027.
  • Global Baseline: Financial Action Task Force (FATF) standards dictate cross-border transaction monitoring and identity exchange requirements.

Due diligence must distinguish between statutory legal requirements, platform claims, and actual technical enforcement. See KYC/AML Architecture in Tokenized Platforms and Regulatory Arbitrage Mapping.

Pillar 5: Custody and Position Sizing: What Happens If It Fails

The fifth pillar addresses asset safety, legal ownership, and insolvency protection. Custody mechanisms determine whether assets are vulnerable to platform bankruptcy, commingling, or counterparty default. Platform Terms of Use are an important factor in determining customer legal ownership and creditor status, alongside applicable property law, account segregation, and the platform's actual operational custody practices. See Bankruptcy Remote Custody Models.

Pillar 6: Liquidity and Position Sizing

The sixth pillar evaluates market depth and exitability. Liquidity determines whether a risk assessment can be acted upon; if a position cannot be liquidated without severe price impact, risk scoring is purely theoretical. Basic Kelly-style position sizing does not automatically account for uncertain probability distributions, lockups, market impact, or constrained exit windows. See Liquidity Depth and Exit Sizing.

Scoring Thresholds, Red-Flag Overrides, & Worked Example

Risk Ratings and Red-Flag Overrides

To quantify risk across the six pillars, evaluate each against defined operational thresholds:

Pillar

Low Risk

Moderate Risk

High Risk

Unverifiable

Tokenomics

<15% 90-day unlock relative to volume; clear supply cap.

15%–40% scheduled unlock; moderate inflation.

>40% near-term cliff; unallocated treasury minting.

Missing emission schedule or unverified supply.

Audit Security

All Critical/High findings remediated; bytecode matches.

Medium findings accepted as residual risk; minor scope gaps.

Unresolved Critical/High findings; unverified deployed code.

No independent audit available for public review.

Concentration

Dispersed verified ownership; top 3 entities hold <20%.

Moderate concentration; top 3 entities hold 20%–50%.

>50% held by top 3 entities; team controls upgrade keys.

Wallet cluster identity and balance data untraceable.

Compliance

Fully licensed/registered; proactive geo-blocking & KYC.

Partial jurisdictional clarity; pending licensing filings.

Unlicensed operations in restricted markets; no AML/KYC.

Legal entity, registration, or jurisdiction undisclosed.

Custody

Bankruptcy-remote segregated accounts; clear title.

Commingled omnibus accounts; moderate counterparty risk.

Unclear asset ownership; unsegregated custody.

Undisclosed custodian or legal Terms of Use.

Liquidity

Exit size <2% of 24h volume at <1% slippage.

Exit size 2%–10% of 24h volume; moderate slippage.

Exit size >10% of 24h volume; severe illiquidity.

Non-executable secondary market or total lockup.

Red-Flag Mandatory Escalations

A high rating in one pillar cannot be "averaged away" by good scores in others. The presence of any of the following triggers an immediate High Risk / Non-Investment rating:

  • Unresolved Critical vulnerability in deployed production code.
  • Legal inability to establish clear asset ownership in bankruptcy.
  • Unrestricted admin mint function or unverified contract ownership.
  • Active enforcement actions, sanctions violations, or explicit regulatory prohibitions.

Worked Platform Example: "Protocol Alpha"

Pillar

Rating

Evidence Level

Primary Concern

Tokenomics

High Risk

High

42% of total supply unlocks in 60 days; exceeds 15 days of trading volume.

Audit Security

Moderate Risk

High

Code audited; 1 High-severity access-control finding accepted as operational risk.

Concentration

High Risk

High

Entity clustering reveals top 3 identified wallets control 58% of circulating supply.

Compliance

Unverifiable

Limited

Platform claims local exemptions but provides no legal opinion or registration details.

Custody

Moderate Risk

Moderate

Commingled omnibus custodial structure; asset segregation unverified.

Liquidity

High Risk

High

Target position liquidation represents 12 days of average daily DEX liquidity.

Framework Governance and Re-Scoring

To maintain analytical rigor, each evaluation must document the methodology version, assigned analyst, evidence cutoff date, and an archived change log. Risk assessments require dual-review sign-off and follow a two-tier review cadence:

  • Scheduled Periodic Monitoring: Quarterly re-evaluations for active holdings; monthly re-evaluations for elevated-risk platforms.
  • Immediate Event-Driven Re-Scoring: Mandatory re-assessment triggered by smart contract upgrades, key rotations, major unlocks, regulatory actions, or changes in custodian Terms of Use.

Pre-Launch Assessment FAQ

Can pre-launch projects be scored using this framework?

Yes. While live operational history and market liquidity cannot be observed before launch, key aspects can still be evaluated: planned concentration can be estimated from vesting contracts and token allocation schedules, while custody architecture can be assessed via multisig parameters, custodian agreements, and Terms of Use. Pre-launch evaluations must be explicitly tagged as Provisional.

What This Framework Does Not Do

This framework does not predict price movement, constitute investment advice, or guarantee that a platform rated low risk across all pillars is immune to loss. It also cannot substitute for direct legal review of contractual terms; evaluating custody risk requires reading platform Terms of Use directly rather than relying on marketing claims.

What it provides is a repeatable, verifiable starting point: consistent risk criteria evaluated against primary sources across six core pillars. That consistency is what turns due diligence from a subjective impression into a structured process.

Bottom Line

Every collapse examined across this cluster, whether a presale rug pull, a custodial bankruptcy, or a vesting-cliff-driven crash, left visible evidence beforehand. The evidence was on-chain, in a published audit, or in a contract's own Terms of Use. None of it required insider access to find. This framework exists to make sure that evidence gets checked before capital moves, not after.

Frequently Asked Questions

How often should a platform be re-scored after the initial due diligence pass?

Treat the initial score as a snapshot, not a permanent rating. The inputs behind several pillars shift on their own timeline: token concentration and vesting unlocks move with on-chain activity, audit status can change if a project ships new, unaudited code after the original report, and jurisdictional access can shift when a regulator updates its guidance, as happened with the SEC's own framework in March 2026.

A practical rhythm is to re-score around any major event specific to that platform, a new funding round, a contract upgrade, a scheduled unlock, or a regulatory announcement affecting its jurisdiction, rather than on a fixed calendar interval that might miss the moment the risk profile actually changed.

Can this framework be applied to a platform that hasn't launched yet?

Only partially, and it's worth being direct about which pillars simply don't have data yet. Concentration and custody-in-practice can't be scored before a token exists on a live chain, since there's no Holders tab or bankruptcy history to check.

What can be scored pre-launch: the audit, if one has been completed and published before deployment, the vesting schedule as disclosed in funding documents, and the team's identity verification status. The retail-focused checklist covered elsewhere in this cluster is built specifically for this earlier stage, since a presale by definition doesn't have on-chain trading history to evaluate yet.

Does a platform need to score well on every pillar to be worth considering?

No, and treating the framework that way misreads its purpose. The six pillars aren't a pass or fail gate; they're a way to see where the risk in a specific platform actually concentrates, so that decision can be made with eyes open rather than avoided altogether.

A platform might carry a wide FDV gap because it's genuinely early-stage, while scoring cleanly on custody and compliance; that's a very different profile from a platform flagged across three or more pillars simultaneously, even though neither one scores a perfect result. The framework is built to help direct scrutiny, not to produce an automatic accept-or-reject verdict.

Disclaimer: This article is for educational purposes only and is not financial, legal, investment, or tax advice. Crypto and private-market assets carry risks including loss, limited liquidity, custody issues, and regulatory changes. Review all primary sources and seek professional advice before investing.

Get Pre-IPO Insights Weekly

Join 5,000+ investors getting exclusive deal alerts.

Key Terms to Know

New to investing? Explore our glossary for more terms.

Related Articles

More from IPO Genie

Buy Now