NEWMethodology v3.3 is open for public comment.Read the draft →
About Press Ratings Partners Compare Watchlist Advertise
Public document · binding

The Onyx scoring methodology.

A 100-point framework applied uniformly to every Web3 project we rate. Independent, signed, and unsellable. This document is the single source of truth for what we score, how we score it, what disqualifies a project, and what we change when we change it.

Version
v3.2 · Q2 2026
Effective from
2026-04-01
Last revised
2026-05-14
Maintained by
Editorial Board
Signed
0xA4E1…c8d2
01

Why we rate

Onyx exists because Web3 inherited a credibility problem from Web2 and made it worse. Most projects publishing a "verified" badge sold it; most directories rank by ad spend, listing fee, or token sponsorship1. Users — and increasingly regulators — have no neutral, evidence-based answer to the only question that matters: is this project the kind of thing a serious person should rely on?

We answer that question using a transparent framework, applied identically to every project, by a small team accountable to a public conflict-of-interest policy. We score 2,418 projects on the same 100-point scale and we publish every removal, downgrade, and dissent in full.

What we are not: a press shop, a paid listing service, a research consultancy, or a clearinghouse for investment advice. Nothing in this document constitutes a recommendation to buy, sell, hold, stake, lend against, or otherwise trade any asset.

02

Independence policy

The single most important property of our ratings is that they cannot be purchased. Five binding commitments make this concrete:

  1. Score independence. The score is determined by the methodology. No commercial relationship — listing fee, marketing package, sponsorship, employment agreement, or token holding — alters a score in either direction. The lead reviewer signs every score change on-chain2.
  2. Tier pricing decoupled. Projects pay for listing features (additional badges, promotional placement in non-ranking surfaces, application processing). They do not pay for tiers. A Free Provisional project is scored on the same rubric as an Enterprise project.
  3. No token holdings. Editorial staff disclose, and where required divest, holdings in any project under active review.
  4. Public dissent. When a reviewer dissents from a score, the dissent is published on the project's page with the reviewer's name.
  5. Public removals. Every removal, downgrade, and watchlist action is published with date, reason, and evidence sources, regardless of the project's commercial relationship with Onyx.
Binding
Violation of any of these commitments by a member of the editorial board is grounds for immediate removal from the board and a public correction notice on every score that member signed.
03

The 100-point framework

The framework allocates 100 points across five categories. Each category has between three and five sub-criteria. The point allocations have been stable since v2.0 (Q3 2024); the sub-criteria are revised quarterly. The current allocation is:

Legal & entity legitimacy

Whether a real, accountable entity stands behind the project — and whether that entity is operating in a jurisdiction with rule of law.

25 / 100

Security & audit posture

Code review coverage, auditor independence, active bug bounty, key management, and incident history.

25 / 100

Operational track record

Uptime, version cadence, governance activity, founder tenure, response quality during incidents.

20 / 100

Financial transparency

Treasury disclosure, token vesting visibility, revenue reporting, audited financials where applicable.

15 / 100

User outcomes

Verified-user reviews, fund safety, support quality, dispute resolution history.

15 / 100

Note: A project may also accrue at most +3 bonus points in any category where its performance materially exceeds expectations, capped at the category maximum. Bonus rationale is always published in the rating notes.

05

Security & audit posture

Worth 25 of 100 points. Smart-contract risk is the single most consequential failure mode of a Web3 product. We score audit depth and recency, auditor independence and diversity, the existence and budget of an active bug-bounty program, key-management practices, and any incident history.

Sub-criteria

25 points total
Audit recency & coverage
Most recent audit ≤ 12 months · covers all production contracts
8 / 8
Auditor independence & diversity
≥ 2 independent firms · no firm-protocol financial ties
5 / 5
Active bug bounty
Immunefi · Hats · ImmuneFi-tier program · paid disclosures
4 / 4
Multi-sig & key management
≥ 5 signers · public registry · hardware wallets · timelocked
4 / 4
Incident history
Contract-level exploits · response time · user reimbursement
4 / 4

What does not count

An "audit" performed by an entity with a financial interest in the protocol — equity, advisory, or token allocation — is excluded from auditor-diversity scoring. Self-audits, "internal review" attestations, and any audit not published in full are not counted toward audit recency.

06

Operational track record

Worth 20 of 100 points. Time-tested protocols accrue points here. Uptime, version cadence, governance throughput, founder tenure, and the quality of operational responses during stress events. A protocol that has run cleanly for three years in production is, all else equal, less risky than one launched eight weeks ago.

Sub-criteria

20 points total
Operating duration
Production deployment age · gradual unlock to full credit at 36 mo
6 / 6
Uptime & reliability
Frontend & contract-level · last 12 months
4 / 4
Governance throughput
Active proposal count · participation rate · execution discipline
4 / 4
Founder & team tenure
Original team retention · vesting completion · key-person risk
3 / 3
Incident response quality
Mean time to disclosure · post-mortem depth · remediation
3 / 3
07

Financial transparency

Worth 15 of 100 points. Treasury disclosure (wallet addresses, balances, custody arrangements), token-vesting schedules with on-chain proofs, audited financials where the project operates a registered entity, and the level of detail in revenue reporting.

Sub-criteria

15 points total
Treasury wallet disclosure
All major wallets · public addresses · custody attestation
5 / 5
Token vesting visibility
On-chain vesting · public schedule · enforced via contract
4 / 4
Revenue reporting
Quarterly disclosures · revenue source breakdown
3 / 3
Audited financials
Where entity is registered · Big-4 or equivalent
3 / 3
08

User outcomes

Worth 15 of 100 points. The only category where user-generated evidence is the primary input. We accept reviews only from wallets with verified on-chain interaction history with the project under review4. Average review score, fund-loss disclosures, support quality (measured via direct test interactions), and dispute resolution history.

Sub-criteria

15 points total
Verified-review aggregate score
Mean rating · ≥ 50 verified reviews · weighted by interaction depth
5 / 5
Fund safety record
User-fund losses from protocol vs. user error · reimbursement record
4 / 4
Support quality
First-response time · resolution rate · direct test interactions
3 / 3
Dispute resolution history
Open disputes · resolution outcomes · pattern flags
3 / 3
09

Tier definitions

The total score determines tier placement. Tiers correspond to credibility levels, not investment recommendations. Below 40, projects are rejected and not listed.

★ Certified 85 – 100

Comprehensive evidence across all five categories. Multiple independent audits, identified leadership, multi-year operating history, treasury fully disclosed.

Min audit: 2 firms · < 12mo · Min track record: 24 mo
◆ Verified 70 – 84

Strong evidence in most categories with one or two material gaps. Often: identified team but limited audit history, or strong audits but shorter operating window.

Min audit: 1 firm · < 12mo · Min track record: 12 mo
● Listed 55 – 69

Meets baseline credibility threshold but with notable risk markers. Suitable for informed users who understand the methodology.

Min audit: 1 audit ever · Public disclosure required
○ Provisional 40 – 54

Recently rated, insufficient evidence, or unresolved questions. Re-rated within 90 days. Below 40 = rejection.

Re-rated: ≤ 90 days · Below 40 = rejected
10

Re-rating schedule

Ratings expire. Every project is re-rated on a cadence determined by tier, with additional triggers for material events. A score that has not been refreshed within its cadence is flagged stale and excluded from rankings.

Tier Cadence Event triggers Stale after
★ Certified Quarterly New audit · exploit · governance event · 50%+ TVL move 120 d
◆ Verified Quarterly New audit · exploit · ownership change 120 d
● Listed Semi-annually Exploit · ownership change · regulatory action 210 d
○ Provisional ≤ 90 days Always re-rated within 90 days 100 d
11

Appeal process

Any rated project may appeal a score. Appeals must cite the specific sub-criterion in dispute, provide new evidence, and be filed within 30 days of the score's publication.

  1. Filing. Appeals are filed through the project's account on Onyx. A wallet signature from a treasury or multi-sig signer is required.
  2. Triage. The lead reviewer assigns the appeal to a second reviewer who did not score the original rating.
  3. Review window. 14 business days. The second reviewer's findings are published with rationale, regardless of outcome.
  4. Board escalation. A project may escalate to the full Editorial Board within 7 days of the second-reviewer decision. Board decisions are final, signed, and published.

In 24 months of operation, appeals have moved scores by an average of +1.2 points. We publish that average to be transparent about the fact that appeals are real but not transformative.

12

Conflict of interest

Every editorial staff member files a quarterly disclosure of all token holdings, advisory positions, equity in Web3 entities, and personal relationships with founders or executives of any rated project. Disclosures are public.

  • Tokens of any rated project under active review must be divested before review begins, or the staff member is recused.
  • Advisory relationships, paid or unpaid, with any rated project disqualify the staff member from reviewing that project — permanently, not for a cooling-off period.
  • Personal relationships (family, romantic, financial) with anyone serving as a founder, executive, board member, or counsel of a rated project trigger automatic recusal.
  • The lead reviewer may not own > $10k of any single token, regardless of whether the project is rated.
2026-Q1 disclosure summary
11 editorial staff · 14 active recusals across 9 reviewers · 0 violations · 0 corrections issued. Full disclosure registry at onyx.dev/disclosures.
13

Rejection & removal

A project may be rejected before listing, downgraded after listing, watchlisted, or removed for cause. The four states are distinct and visually distinct on the platform.

Rejection (pre-listing)

Score below 40, identified fraud risk, sanctioned-entity association, or refusal to engage with the application process. Rejection is not public unless the project chooses to disclose.

Downgrade

Material change in the evidence: a new exploit, founder departure, regulatory action, audit-finding non-resolution past 90 days. Downgrades are always published with reasons.

Watchlist

An open question that has not yet resolved into a downgrade or removal. The project remains rated, but the watchlist badge appears on every surface.

Removal

Reserved for projects whose continued rating would itself be misleading. Examples: team identity falsification, sustained unresponsive treasury after exploit, sanctioned-entity confirmation, or evidence of deliberate fraud5.

Public record
All four states — rejection (where the project consented to disclosure), downgrade, watchlist, removal — appear in our public watchlist registry with full evidence trails. 41 projects removed for cause in the platform's history. None have been quietly delisted.
14

Editorial team

The editorial board is named, signs every score on-chain, and is accountable to this methodology and the conflict-of-interest policy. Backgrounds across former regulators, on-chain analysts, and security researchers.

MC
Marisol Chen
Lead Reviewer · DeFi
Former senior counsel, SEC Office of the Chief Accountant. 8 years in crypto regulation. JD/MBA, Columbia.
TR
Tomás Reyes
Lead Reviewer · Infra & AI
Co-founder, Chainsigh. Previously senior researcher at Trail of Bits. PhD Computer Science, Stanford.
AO
Amara Okonkwo
Lead Reviewer · GameFi & NFT
Former product lead, OpenSea. 6 years operating consumer Web3 products. MA, Royal College of Art.
DB
Daniel Bjornsen
Methodology · Editorial Board
Former Director of Ratings Policy, S&P. 24 years in credit ratings before joining Onyx in 2023.
RP
Riya Patel
Investigations · Editorial Board
Former investigative journalist, The Block. Six exploit reconstructions cited in court filings.
JK
Jakob Kowalski
Editorial Board · Chair
Co-founder, Onyx. Former DG, Bank for International Settlements (Innovation Hub). MSc, ETH Zürich.
15

Version history

Every change to this document is published as a signed diff. The diff is binding from the effective date forward; ratings issued under earlier methodology versions are explicitly tagged with their version6.

v3.2
2026-04-01 · current
Signed · 0xA4E1…c8d2
+Added "Audit recency & coverage" sub-criterion for AI Agent projects: requires reproducibility attestation of agent execution.
+Added 2-point bonus for Telegram mini-apps with verified TON Foundation integration.
~Multi-sig sub-criterion now requires minimum 5 signers (was 3) for full credit at Certified tier.
Removed "Twitter following" as evidence input under user outcomes.
v3.1
2026-01-15
Superseded
+Pseudonymous team cap raised from 12 to 14 points (Legal category).
~Bug bounty minimum threshold updated: $50k for Listed, $250k for Verified, $1M for Certified.
v3.0
2025-10-01
Superseded
+Added Restaking sub-rubric within Security category (slashing semantics, AVS dependency depth).
+Added 90-day re-rating requirement for Provisional tier.
Removed "Team is doxxed" as a binary input; replaced with the graduated KYC sub-criterion.
v2.0 — v2.4
2024 – 2025
Archive

Five revisions establishing the current category weights and the appeal process. Full v2 archive · on request

Footnotes

  1. Sources: 2024 Onyx Editorial Review of Web3 Directory Practices; 2025 SEC Crypto Asset Trading Platform Study; conversations with 14 founders who paid for listings on at least three competing platforms. Available on request.
  2. On-chain signatures are recorded against a public registry at onyx.dev/registry. Each signed score is independently verifiable via block explorer.
  3. The principle was established by Satoshi Nakamoto in 2009. We are aware of the irony of citing precedent here.
  4. Interaction proof requires ≥ 5 transactions with the target protocol over ≥ 30 days from a wallet not flagged for sybil patterns. Full anti-sybil methodology is published separately.
  5. "Deliberate fraud" is the highest bar in this document. It requires evidence that would survive a civil burden of proof. We have applied this standard 14 times. Two are subject to ongoing litigation.
  6. A v2.4 rating remains valid until the project's next scheduled review under v3.x. We do not retroactively reapply newer methodologies because we believe ratings should be stable signals, not moving goalposts.
This methodology has been ratified by the Onyx Editorial Board and signed on-chain as of the date of publication. The signing key is held in a 4-of-7 multi-sig administered by the board.
Signed · Onyx Editorial Board · v3.2 · 0xA4E1…c8d2