Why we rate
Onyx exists because Web3 inherited a credibility problem from Web2 and made it worse. Most projects publishing a "verified" badge sold it; most directories rank by ad spend, listing fee, or token sponsorship1. Users — and increasingly regulators — have no neutral, evidence-based answer to the only question that matters: is this project the kind of thing a serious person should rely on?
We answer that question using a transparent framework, applied identically to every project, by a small team accountable to a public conflict-of-interest policy. We score 2,418 projects on the same 100-point scale and we publish every removal, downgrade, and dissent in full.
What we are not: a press shop, a paid listing service, a research consultancy, or a clearinghouse for investment advice. Nothing in this document constitutes a recommendation to buy, sell, hold, stake, lend against, or otherwise trade any asset.
Independence policy
The single most important property of our ratings is that they cannot be purchased. Five binding commitments make this concrete:
- Score independence. The score is determined by the methodology. No commercial relationship — listing fee, marketing package, sponsorship, employment agreement, or token holding — alters a score in either direction. The lead reviewer signs every score change on-chain2.
- Tier pricing decoupled. Projects pay for listing features (additional badges, promotional placement in non-ranking surfaces, application processing). They do not pay for tiers. A Free Provisional project is scored on the same rubric as an Enterprise project.
- No token holdings. Editorial staff disclose, and where required divest, holdings in any project under active review.
- Public dissent. When a reviewer dissents from a score, the dissent is published on the project's page with the reviewer's name.
- Public removals. Every removal, downgrade, and watchlist action is published with date, reason, and evidence sources, regardless of the project's commercial relationship with Onyx.
The 100-point framework
The framework allocates 100 points across five categories. Each category has between three and five sub-criteria. The point allocations have been stable since v2.0 (Q3 2024); the sub-criteria are revised quarterly. The current allocation is:
Legal & entity legitimacy
Whether a real, accountable entity stands behind the project — and whether that entity is operating in a jurisdiction with rule of law.
Security & audit posture
Code review coverage, auditor independence, active bug bounty, key management, and incident history.
Operational track record
Uptime, version cadence, governance activity, founder tenure, response quality during incidents.
Financial transparency
Treasury disclosure, token vesting visibility, revenue reporting, audited financials where applicable.
User outcomes
Verified-user reviews, fund safety, support quality, dispute resolution history.
Note: A project may also accrue at most +3 bonus points in any category where its performance materially exceeds expectations, capped at the category maximum. Bonus rationale is always published in the rating notes.
Legal & entity legitimacy
Worth 25 of 100 points. This category answers: is there an accountable entity operating in a jurisdiction we can reach if something goes wrong? It is the largest single category because, in 2026, no other property of a Web3 project predicts long-term user safety as reliably.
Sub-criteria
Evidence sources
- Corporate registries (Companies House, Delaware SOS, BVI Registry, etc.)
- FATF jurisdictional risk index
- OFAC SDN list cross-reference
- KYC documentation provided by the project under NDA
- Independent press reports and court filings
How anonymous teams are scored
A pseudonymous or anonymous team is not automatically disqualifying — many of the most important projects in Web3 history shipped under pseudonyms3. They are, however, capped at 14 points in this category. The scoring acknowledges that anonymity is sometimes principled (privacy, jurisdictional safety) and sometimes evasive (evasion of liability). We do not attempt to distinguish; we apply the same cap to both.
Security & audit posture
Worth 25 of 100 points. Smart-contract risk is the single most consequential failure mode of a Web3 product. We score audit depth and recency, auditor independence and diversity, the existence and budget of an active bug-bounty program, key-management practices, and any incident history.
Sub-criteria
What does not count
An "audit" performed by an entity with a financial interest in the protocol — equity, advisory, or token allocation — is excluded from auditor-diversity scoring. Self-audits, "internal review" attestations, and any audit not published in full are not counted toward audit recency.
Operational track record
Worth 20 of 100 points. Time-tested protocols accrue points here. Uptime, version cadence, governance throughput, founder tenure, and the quality of operational responses during stress events. A protocol that has run cleanly for three years in production is, all else equal, less risky than one launched eight weeks ago.
Sub-criteria
Financial transparency
Worth 15 of 100 points. Treasury disclosure (wallet addresses, balances, custody arrangements), token-vesting schedules with on-chain proofs, audited financials where the project operates a registered entity, and the level of detail in revenue reporting.
Sub-criteria
User outcomes
Worth 15 of 100 points. The only category where user-generated evidence is the primary input. We accept reviews only from wallets with verified on-chain interaction history with the project under review4. Average review score, fund-loss disclosures, support quality (measured via direct test interactions), and dispute resolution history.
Sub-criteria
Tier definitions
The total score determines tier placement. Tiers correspond to credibility levels, not investment recommendations. Below 40, projects are rejected and not listed.
Comprehensive evidence across all five categories. Multiple independent audits, identified leadership, multi-year operating history, treasury fully disclosed.
Strong evidence in most categories with one or two material gaps. Often: identified team but limited audit history, or strong audits but shorter operating window.
Meets baseline credibility threshold but with notable risk markers. Suitable for informed users who understand the methodology.
Recently rated, insufficient evidence, or unresolved questions. Re-rated within 90 days. Below 40 = rejection.
Re-rating schedule
Ratings expire. Every project is re-rated on a cadence determined by tier, with additional triggers for material events. A score that has not been refreshed within its cadence is flagged stale and excluded from rankings.
| Tier | Cadence | Event triggers | Stale after |
|---|---|---|---|
| ★ Certified | Quarterly | New audit · exploit · governance event · 50%+ TVL move | 120 d |
| ◆ Verified | Quarterly | New audit · exploit · ownership change | 120 d |
| ● Listed | Semi-annually | Exploit · ownership change · regulatory action | 210 d |
| ○ Provisional | ≤ 90 days | Always re-rated within 90 days | 100 d |
Appeal process
Any rated project may appeal a score. Appeals must cite the specific sub-criterion in dispute, provide new evidence, and be filed within 30 days of the score's publication.
- Filing. Appeals are filed through the project's account on Onyx. A wallet signature from a treasury or multi-sig signer is required.
- Triage. The lead reviewer assigns the appeal to a second reviewer who did not score the original rating.
- Review window. 14 business days. The second reviewer's findings are published with rationale, regardless of outcome.
- Board escalation. A project may escalate to the full Editorial Board within 7 days of the second-reviewer decision. Board decisions are final, signed, and published.
In 24 months of operation, appeals have moved scores by an average of +1.2 points. We publish that average to be transparent about the fact that appeals are real but not transformative.
Conflict of interest
Every editorial staff member files a quarterly disclosure of all token holdings, advisory positions, equity in Web3 entities, and personal relationships with founders or executives of any rated project. Disclosures are public.
- Tokens of any rated project under active review must be divested before review begins, or the staff member is recused.
- Advisory relationships, paid or unpaid, with any rated project disqualify the staff member from reviewing that project — permanently, not for a cooling-off period.
- Personal relationships (family, romantic, financial) with anyone serving as a founder, executive, board member, or counsel of a rated project trigger automatic recusal.
- The lead reviewer may not own > $10k of any single token, regardless of whether the project is rated.
Rejection & removal
A project may be rejected before listing, downgraded after listing, watchlisted, or removed for cause. The four states are distinct and visually distinct on the platform.
Rejection (pre-listing)
Score below 40, identified fraud risk, sanctioned-entity association, or refusal to engage with the application process. Rejection is not public unless the project chooses to disclose.
Downgrade
Material change in the evidence: a new exploit, founder departure, regulatory action, audit-finding non-resolution past 90 days. Downgrades are always published with reasons.
Watchlist
An open question that has not yet resolved into a downgrade or removal. The project remains rated, but the watchlist badge appears on every surface.
Removal
Reserved for projects whose continued rating would itself be misleading. Examples: team identity falsification, sustained unresponsive treasury after exploit, sanctioned-entity confirmation, or evidence of deliberate fraud5.
Editorial team
The editorial board is named, signs every score on-chain, and is accountable to this methodology and the conflict-of-interest policy. Backgrounds across former regulators, on-chain analysts, and security researchers.
Version history
Every change to this document is published as a signed diff. The diff is binding from the effective date forward; ratings issued under earlier methodology versions are explicitly tagged with their version6.
Five revisions establishing the current category weights and the appeal process. Full v2 archive · on request
Footnotes
- Sources: 2024 Onyx Editorial Review of Web3 Directory Practices; 2025 SEC Crypto Asset Trading Platform Study; conversations with 14 founders who paid for listings on at least three competing platforms. Available on request.
- On-chain signatures are recorded against a public registry at onyx.dev/registry. Each signed score is independently verifiable via block explorer.
- The principle was established by Satoshi Nakamoto in 2009. We are aware of the irony of citing precedent here.
- Interaction proof requires ≥ 5 transactions with the target protocol over ≥ 30 days from a wallet not flagged for sybil patterns. Full anti-sybil methodology is published separately.
- "Deliberate fraud" is the highest bar in this document. It requires evidence that would survive a civil burden of proof. We have applied this standard 14 times. Two are subject to ongoing litigation.
- A v2.4 rating remains valid until the project's next scheduled review under v3.x. We do not retroactively reapply newer methodologies because we believe ratings should be stable signals, not moving goalposts.