Crypto Yield Due Diligence: 20 Questions to Ask Before Depositing
A new crypto savings product can present a simple choice between flexible and fixed returns.
The investor’s real decision is more complex: which crypto savings product receives the assets, who controls them, how yield is generated, what can delay withdrawal, and who bears loss.
Digital-asset yield can come from lending, staking, liquidity provision, market-making, arbitrage, token incentives, or promotional subsidy. None is automatically safe or unsafe. Each must be understood in context.
This guide provides an educational framework, not a recommendation. Digital assets can lose substantial value, and users may lose access to funds.
1. Which Legal Entity Contracts With Me?
Record the legal name, registration, address, jurisdiction, governing law, and dispute forum. A brand may use different entities for custody, exchange, cards, or yield.
Verify regulatory claims on official registers. Registration for one activity does not guarantee the product or insure balances.
2. Is the Product Available in My Jurisdiction?
Availability can depend on residence, investor type, verification level, and asset. Accessing a website does not prove eligibility.
Read restricted-country terms and do not provide false information to bypass controls. That can create problems during withdrawal.
3. What Asset Am I Depositing?
Identify the exact token and blockchain network. Similar tickers on different chains may not be interchangeable.
Confirm:
contract or official asset identifier;
supported network;
minimum amount;
required confirmations;
memo or tag;
withdrawal route.
A small test reduces address error but does not remove platform risk.
4. Who Controls the Private Keys?
Custody can be provided by the platform, a third party, a smart contract, or the user.
Ask whether assets are pooled, segregated, held offline, or moved to protocols and exchanges. Key security does not by itself define legal ownership.
5. Can My Assets Be Lent or Pledged?
Terms may permit the provider to lend, rehypothecate, pledge, or otherwise deploy user assets. This can create claims against a counterparty rather than a simple custodial relationship.
Users should know whether they retain title, receive a contractual claim, or accept another arrangement.
6. What Generates the Yield?
Source
Revenue
Main risks
Lending
Borrower interest
Default, collateral
Staking
Network rewards
Protocol, lock, slashing
Liquidity provision
Fees and incentives
Smart contract, price divergence
Market strategy
Trading or basis
Leverage, venue, execution
Token incentives
New tokens
Volatility, dilution
Promotion
Provider budget
Unsustainable rate
The provider should explain the strategy without revealing proprietary details. “Advanced algorithms” alone is not an economic explanation.
7. Is the Rate Fixed, Variable, or Promotional?
Check:
APY or APR definition.
Compounding frequency.
Balance tiers.
Caps.
Asset paid.
Lock requirement.
Change procedure.
Promotion end date.
An annualized number does not promise the same return over a short holding period.
8. Who Are the Borrowers or Counterparties?
For lending strategies, users need to understand borrower type, concentration, collateral, maturity, and affiliates.
Questions include:
Are loans secured?
What is the loan-to-value limit?
How is collateral valued?
What triggers liquidation?
Can collateral and borrower fail together?
What is the largest exposure?
Are related parties involved?
Average statistics can hide one material weak exposure.
9. What Happens After Default?
Collateral only protects users if it is liquid, sufficient, enforceable, and sold in time.
The provider should have a process for margin calls, liquidation, recovery, provisioning, and loss allocation. Markets can gap faster than systems can sell collateral.
Users should know whether the platform, reserve fund, or customers absorb a shortfall.
10. What Is the Liquidity Model?
Flexible withdrawals require liquid assets. If underlying positions are locked or long term, the provider may rely on reserves, repayments, or new liquidity.
Ask:
what portion is immediately available;
whether withdrawals depend on borrower repayment;
whether terms permit queues;
whether early redemption has a penalty;
which stress tests are used;
what happens during mass withdrawal.
“Anytime” should be read with its exceptions.
11. What Are the Withdrawal Rules?
Review:
supported asset and network;
minimum and maximum;
fee;
expected processing;
manual review;
security delay;
address allowlist;
compliance hold;
suspension rights.
Test a small withdrawal early. A successful withdrawal verifies mechanics but not long-term solvency.
12. How Are Stablecoin Risks Managed?
Stablecoins can lose their reference value. Risk depends on issuer, reserves, redemption rights, legal structure, exchange liquidity, and network.
A platform concentrated in one stablecoin can suffer even if its lending strategy performs normally. Review contingency plans for depegging and redemption restrictions.
13. Which Protocols and Bridges Are Used?
DeFi strategies can introduce:
smart-contract bugs;
admin-key risk;
oracle manipulation;
governance attacks;
bridge exploits;
liquidity loss;
network congestion.
Audits reduce some uncertainty but do not guarantee safety. Check date, scope, auditor, findings, and remediation.
14. What Does Proof of Reserves Prove?
A reserve snapshot can show some controlled assets. It may not prove all liabilities, ownership, encumbrances, affiliates, or future liquidity.
Review:
Covered legal entities.
Assets included.
Liability method.
Frequency.
Independent verifier.
Borrowed or pledged treatment.
Customer inclusion verification.
Proof of reserves and audited financial statements answer different questions.
15. What Security Controls Exist?
Platform controls may include:
cold and warm wallet design;
multi-party approval;
role separation;
penetration testing;
monitoring;
vendor controls;
incident response;
business continuity.
Customer features should include strong authentication, session review, withdrawal alerts, and address controls.
Security descriptions should be specific. “Military grade” is not a control.
16. Is There Insurance?
If insurance is mentioned, identify:
insurer;
insured entity;
covered events;
wallet or custodian scope;
aggregate limit;
deductible;
exclusions;
customer claim mechanism.
Policies may exclude market losses, token failure, protocol exploits, or user phishing.
17. What Are the Full Costs?
The investor’s result can include:
subscription;
trading spread;
conversion fee;
deposit fee;
withdrawal fee;
network fee;
early redemption;
tax;
reward-token value change.
Calculate a complete round trip from deposit to withdrawal.
Net result = rewards − costs ± asset price change
18. How Transparent Is Reporting?
Statements should show:
opening balance;
deposits and withdrawals;
reward amount and asset;
accrual time;
fees;
locked or pending status;
closing balance;
valuation source.
Downloadable records support tax reporting and independent reconciliation. A portfolio chart alone is insufficient.
19. How Does Governance Control Conflicts?
Potential conflicts arise when the platform:
lends to affiliates;
promotes its own token;
values illiquid collateral;
earns more from higher-risk strategies;
rewards teams for deposit growth.
Independent risk approval, exposure limits, related-party disclosure, and board reporting help control those conflicts.
Users should be cautious when the provider’s own token is both collateral and reward.
20. What Is the Wind-Down Plan?
A responsible provider should know how to stop new deposits, unwind positions, return assets, preserve records, and communicate if it closes a product.
The plan should consider illiquid positions, disputed claims, unsupported networks, and customers who do not respond.
An exit plan does not predict failure; it reduces disorder.
Additional Question: Who Are the Hidden Dependencies?
One platform may depend on a custodian, exchange, market maker, stablecoin issuer, bank, cloud provider, blockchain node, and screening vendor.
Map the dependencies. Several products can share one underlying point of failure. Diversification by interface does not help if assets are held by the same custodian.
Additional Question: How Does the Provider Communicate Incidents?
A useful incident process defines:
Official status channel.
Update frequency.
Scope and affected product.
Customer actions.
Protection against impersonation.
Post-incident review.
Silence encourages phishing and speculation. Premature certainty can be equally damaging.
Additional Question: How Is Valuation Determined?
A dashboard may convert every asset into dollars using one price, even when the position is illiquid or locked. Users should know the price source, timestamp, and treatment of assets that cannot be sold at the displayed value.
For collateral and liquidation, valuation is critical. An oracle delay or thin market can make protection appear sufficient until it is too late.
Look for independent sources, a fallback method, stale-price thresholds, exchange-outage treatment, haircuts for illiquid assets, and frequent collateral checks. Displayed value is an estimate, not necessarily the amount realizable during stress.
Additional Question: Are Returns Paid From Revenue or Reserves?
A provider can smooth a variable strategy by paying from reserves. That may improve predictability, but users should understand the mechanism and its limits.
If rewards are paid in a newly issued token, the provider may have low cash cost while users bear price risk. If rewards come from new deposits without sustainable external revenue, the model may be fragile or fraudulent.
A transparent product distinguishes realized strategy revenue, promotional subsidy, and discretionary bonuses.
Additional Question: What Happens When Terms Change?
Check the notice period, delivery channel, effective date, and whether existing fixed commitments are protected.
Material changes can include a new rate, custodian, borrower, protocol, withdrawal limit, fee, contracting entity, or automatic asset conversion. Users should be able to retrieve the prior version of terms. Continued use should not be treated as informed consent when notice is obscure.
Additional Question: Can I Export My Records?
Transaction-level exports should show deposits, withdrawals, rewards, fees, conversions, and timestamps. These records support tax, disputes, and independent accounting.
Users should download them periodically rather than wait until closure or an outage. The platform’s retention period and access after closure should be stated.
Additional Question: What Is the Customer-Support Boundary?
Support can explain status and policy; it should not ask for secrets or direct users to send a “verification deposit.”
Before placing meaningful funds, test support with a factual question. A credible response is specific, references official terms, creates a case record, and remains in an official channel.
After a public complaint, impersonators may offer help through direct messages. Users should return to the official site independently.
Red Flags
guaranteed return;
secret legal entity;
yield without an economic source;
unusually high rate without explanation;
withdrawal requiring a new payment;
support requesting credentials;
pressure or countdown;
reserve claim without liabilities;
no risk disclosure;
referral rewards dominating activity;
related-party exposure not disclosed.
One issue may be explainable. Several unresolved issues should stop the deposit.
A Safe First-Use Process
Verify the official domain.
Identify the legal entity.
Read terms, fees, and risk disclosure.
Secure the account and email.
Confirm token and network.
Deposit a small amount.
Observe reporting and accrual.
Test support.
Withdraw part of the balance.
Reconcile the result.
Only then should the user reconsider the exposure limit.
Set Exposure Limits
Limits can apply by:
platform;
stablecoin;
custodian;
protocol;
borrower;
locked term;
percentage of liquid savings.
Money required for essential obligations should remain in an appropriate low-risk and accessible form. Borrowing to chase yield amplifies losses.
Monitor Continuously
Reassess after:
withdrawal delay;
rate increase;
stablecoin depeg;
security incident;
legal-entity change;
new custodian;
modified terms;
reserve-report change;
regulatory restriction.
Save copies of terms accepted at deposit. The current website may not reflect an older agreement.
Conclusion
Crypto yield is not a single risk category. It is a chain of legal, custody, credit, market, liquidity, technology, and operational exposures.
Investors should be able to explain where the asset goes, who pays the return, what protects repayment, and how they exit. If those answers are coherent, a small test can provide practical evidence. If they remain vague, waiting is a rational risk decision.
The best comparison starts after the headline APY. It measures transparency, liquidity, loss allocation, and the ability to withdraw under understandable rules.
