Risk Framework
Due diligence methodology for evaluating tokens listed in Kamino markets
1Oracle Pricing
3 subtopics
Reliability and redundancy of the asset's price feeds. Every lending decision depends on oracle prices. Failure modes include inaccurate feeds, stale data, and manipulable pricing mechanisms.
Price Source Coverage
textNumber and type of oracle providers. Major assets (SOL, USDC) use feeds from Chainlink, Pyth, Switchboard, and Redstone. Fewer sources = higher risk. Decentralized networks > on-chain feeds > centralized sources. Fallback eliminates single-provider dependency.
Uptime & Freshness
textUpdate frequency (sub-second pull-based vs heartbeat-based), historical uptime, and accuracy. Cross-provider deviation patterns reveal systematic issues.
Validation & Manipulation Resistance
textHeuristic anomaly checks, TWAP/EWMA smoothing, configured price bands for pegged assets, multi-provider cross-referencing.
2Smart Contract
4 subtopics
Robustness of the token's underlying code. Tokens derive value from smart contracts — exploits cause total, immediate loss. Accepting tokens as collateral implicitly trusts the backing contract.
Audit History
textIndependent audit coverage — different auditors catch different bug classes. Multiple reputable audits = highest confidence; no audit = elevated risk. Track resolution of critical/high findings.
Code Quality & Maturity
textVerifiability and battle-testing. Open-source with reproducible builds benefits from community review. A contract holding $500M for two years > one deployed last month.
Upgrade Authority
textWho can modify the program. Immutable = secure but unfixable. Multisig + timelock substantially lowers risk vs single-key with no delay.
Bug Bounty Program
textIncentives for responsible disclosure. $1M bounty attracts more research than $10K. Note program maturity and scope coverage.
3De-peg
3 subtopics
Probability and impact of a pegged asset's price detaching from its peg. Critical because E-Mode permits high LTV for pegged pairs — a 5% depeg on a 95%-LTV E-Mode position triggers liquidation.
Reserve Backing Quality
textWhat backs the token and how verifiable. Stablecoins: cash/treasuries vs commercial paper. LSTs: stake-pool structure, validator count. Composition determines stress resilience.
Historical Stability
textTrack record under stress: max historical deviation, recovery time, depeg event frequency. e.g. USDC dropped to $0.90 post-SVB and recovered in ~48h.
Peg & Redemption Mechanism
textDirect redemption (e.g. USDC at $1) provides hard floor. LST unstaking enables arbitrage but has delay (Solana ~2-day epoch). Note peg-restoration incentives.
4Counterparty
3 subtopics
Qualitative governance evaluation — how much trust the protocol requires in controlling entities, and what happens if that trust breaks down. Spectrum: fully decentralized → single-company.
Degree of Decentralization
textDecentralized → DAO-governed → multisig → single-entity. Note signer independence (5 signers at one company ≈ single-entity) and admin-key capabilities.
Token Holder Distribution
textTop-holder concentration, vesting & unlock schedules, team/investor allocations. Top-10 holding 80% has fundamentally different risk than top-10 at 15%.
Entity Track Record
textOperating history, transparency, regulatory standing. Prompt incident transparency builds confidence; relevant licenses (money transmitter, MiCA) signal compliance posture.
5Market
3 subtopics
Can liquidators profitably liquidate when needed? When price moves outpace liquidators or collateral lacks liquidity, unprofitable positions become bad debt socialized among lenders. Two axes: volatility and liquidity.
Volatility
textDetermines buffer between Max LTV and Liquidation LTV. Higher volatility → lower Max LTV. Trend (stable/increasing/declining) — spikes trigger Max LTV reductions.
Liquidity & Price Impact
textWhether collateral can be sold without excessive market impact. Critical failure: when price impact exceeds liquidation bonus, liquidations stop being profitable.
Market Capitalization
textContext for other risk metrics. Low-cap → conservative parameters. Watch FDV/circulating-cap ratio — 98% locked supply means future unlocks create selling pressure.
6Correlations & Systemic
3 subtopics
Individual asset analysis is insufficient for multi-asset lending. Correlations determine whether downturns cause isolated or cascading liquidations. Systemic risk emerges when aggregate correlated exposure exceeds market absorption.
Token Correlation
textPrice linkage between listed assets — correlated assets compound liquidation demand (e.g. SOL LSTs all fall with SOL). Stress correlations trend toward 1.0 in downturns.
Protocol Concentration
textAggregate exposure analysis. SOL+LSTs combined exposure under -30% shock. If one stablecoin is 60% of debt, its depeg affects 60% of loans.
Stress Scenarios
textModeled scenarios for protocol resilience — KRAF Dashboard models -10/-20/-30/-40/-60% shocks plus idiosyncratic single-asset events.
7Safeguards
4 subtopics
Defense-in-depth mechanisms that limit exposure and contain failures. No single risk check is relied upon alone — layers stack to protect against insolvency and illiquidity.
Caps & Limits
textSupply cap bounds losses if exploited; borrow cap is constrained by debt-token liquidity; daily caps prevent rapid buildup; E-Mode caps limit high-LTV pegged-pair exposure.
Isolation & Tiering
textAsset classification: General (cross-margin, higher LTV) vs Isolated Collateral (ring-fenced) vs Isolated Debt (borrow-only, strict caps). Isolation prevents cascade.
Interest Rate & Liquidation Design
textRates spike at high utilization to incentivize repayment. Liquidation bonus must exceed expected price impact at max position size. Auto-deleverage for anomalies.
Continuous Monitoring
textReal-time KRAF Dashboard: per-reserve utilization, LTV-distribution clustering near liquidation thresholds, oracle staleness/deviation, liquidation-at-risk percentages.
8Issuance
4 subtopics
Where the token comes from and who controls supply: chain-of-origin (native vs bridged), the bridge if any, the minting process, and the issuing entity.
Native/Bridged
enumWhether this token is issued natively on Solana or is a bridged representation of an asset that lives on another chain. Bridged tokens inherit risk from the bridge in addition to the underlying asset.
Bridge Info
enumWhich bridge protocol the token uses, if it is bridged. Bridge security and design (lock-and-mint vs burn-and-mint, custody model, validator set) is a major risk vector.
Issuer
linkThe entity issuing the token. Use the name + link to the issuer's primary website. Affects counterparty exposure, regulatory standing, and recourse in failure scenarios.
Minting Process
enum-linkHow new units are created. Native = SPL/Token-2022 mint authority (e.g. multisig issuing directly). Smart contract = a program controls minting (staking vault, wrapping program, etc). For Smart contract include both a URL (e.g. Solscan program account) and the GitHub source repo.