← Blog

How-to seriesSeptember 28, 2026

How to research a DeFi protocol before using it

Build a read-only DeFi research brief from protocol documents and dated data. Separate TVL, token metrics, yield claims and contract controls.

A DeFi research brief should let you distinguish what a protocol holds, what its token represents and what a depositor is being promised. Combining those into one bullish or bearish score hides the assumptions you need to inspect.

Use this workflow to assemble a dated evidence packet for one protocol on one chain. It stops before wallet connection, token approval or deposit. The deliverable is a research worksheet with original links and clearly stated gaps.

1. Resolve the protocol and contracts

Begin with the protocol's official website and the exact product you are researching. A lending market, a staking product and a token can share a brand while exposing users to different contracts and terms.

Connect an agent using Vaaya's setup instructions, then paste a scoped request:

Research [protocol and product] on [chain] as of [date].
Confirm official documentation and contract addresses from primary sources.
Collect dated TVL evidence, relevant token facts, yield descriptions,
withdrawal conditions, audits and disclosed admin/upgrade controls.
Use Vaaya with a total research budget of [amount].
No wallet connection, signature, token approval, deposit or swap.
Separate observations, provider assessments and unresolved questions.
Return links and timestamps; do not label a protocol safe from a score.

If the official domain or contract identity is uncertain, stop that part of the task. A detailed report about an impersonating site is worse than a short unresolved identity check.

2. Retrieve only the metrics the question needs

Vaaya's catalog includes the kadec0/fetch route /v1/defi-tvl, yield-pool data, Heurist security-analysis routes and a Strale DeFi risk check. These sources answer different questions. A token-security response should not be presented as a full audit of a lending product.

Ask consult to select the current endpoint and required parameters. Verify whether the route accepts a protocol slug, chain, contract address or another identifier. Some catalog rows provide only a thin endpoint description; inspect the detailed instructions before paying rather than guessing a payload.

Keep the raw response. Mark a metric unavailable if the provider cannot cover the requested product or chain. Do not substitute the protocol's aggregate total for a particular pool without labeling the change in scope.

3. Keep the financial measures separate

TVL is sensitive to the values of the deposited assets as well as the quantities held. A dollar-value change alone cannot show how much new capital arrived. DefiLlama's data definitions also distinguish user-paid fees from the subset retained as protocol revenue.

Record the metric's unit, time and coverage next to the value. A chain-wide observation, a protocol total and one pool's value should occupy different rows. If two providers disagree, retain their definitions before comparing the numbers.

For yield, record where the displayed rate comes from, the period it represents and whether rewards require another token. Keep an advertised annualized figure separate from an achieved return. Do not infer that a displayed rate will remain available after the research time.

4. Read the operational conditions

Open the protocol's own documents for withdrawal conditions, supported assets and contract controls. Identify any described administrator, upgrade mechanism, pause authority or external dependency relevant to the product. Quote only the short language necessary to support a specific claim and link the complete source.

When an audit is listed, record the auditor, report date and contracts or version it covers. The presence of an audit logo does not establish that the currently deployed contract is the version reviewed. If that mapping cannot be established, put it in the unresolved column.

Use this worksheet as a template, not as a scored recommendation:

Question Evidence to attach
Which product? Official domain, chain and contract addresses
Which metric? Definition, scope, unit and observation time
Where does yield come from? Product documentation and reward conditions
Who can change behavior? Documented controls and relevant addresses
What remains unknown? Missing evidence and the next source to inspect

5. Deliver questions that can be answered

Write a short summary tied to the worksheet. Separate facts retrieved from primary documents, values reported by data providers and the agent's interpretations. A failed lookup or missing report should remain visible.

End with the specific questions that would change your understanding of the product. Save the sources and the data timestamps so the next review can focus on changed contracts, changed conditions or fresh observations rather than rebuilding the same packet.

Questions

Does a large TVL prove a protocol is safe?

No. TVL describes value under a particular methodology. It does not establish contract safety, reliable withdrawals, sustainable yield or the absence of concentrated control.

Should the agent approve a token to complete this research?

No. This tutorial only reads public evidence. Token approvals, deposits, swaps and signatures are outside its scope.

Can a risk score replace the protocol documentation?

No. A score depends on the provider’s coverage and methodology. Keep its timestamp and supporting evidence, then investigate the specific controls and unresolved risks.

Try Vaaya with your agent.

Connect your agent, choose a service, and try your first call with Vaaya.

npx @vaaya/mcp install