DeFi (Decentralized Finance) protocols do specific things mechanically. Understanding what each protocol category actually does — without the token shilling that dominates most coverage — helps cut through promotional hype and provides substantive foundation for evaluating any specific protocol or token.
This cheat sheet covers what specific DeFi categories actually do, what risks they involve, and what to evaluate when considering any specific protocol within each category.
Decentralized Exchanges (DEXs)
What they actually do:
Allow users to swap one cryptocurrency for another without intermediaries.
Use smart contracts that hold liquidity provided by users.
Calculate exchange rates using mathematical formulas (constant product formula in Uniswap-style AMMs).
Charge specific fees on trades distributed to liquidity providers.
Major examples: Uniswap, Curve, SushiSwap, PancakeSwap, dYdX, others.
What they don't do: function as fully traditional exchanges with order books (most don't), provide regulatory protection, eliminate counterparty risk (smart contract risk replaces traditional counterparty risk).
What to evaluate: liquidity depth for tokens you want to trade, fee structures, smart contract audit history, governance structure, specific risks of impermanent loss for liquidity providers.
Lending Protocols
What they actually do:
Allow users to lend crypto and earn interest.
Allow users to borrow crypto by posting collateral exceeding loan value.
Match supply and demand through algorithmic interest rates.
Liquidate positions when collateral value falls below threshold.
Major examples: Aave, Compound, MakerDAO, others.
What they don't do: function as banks with deposit insurance, provide unsecured lending (most don't), eliminate liquidation risk, eliminate smart contract risk.
What to evaluate: liquidation thresholds, interest rate models, governance, smart contract audit history, oracle dependencies, specific token-listing risks.
Yield Aggregators
What they actually do:
Automatically move user deposits between different DeFi protocols seeking optimal yields.
Compound earnings automatically.
Extract yield from underlying protocols (lending, AMM fees, etc.).
Charge specific management fees on returns.
Major examples: Yearn Finance, Beefy, others.
What they don't do: produce yield from nothing — they extract from underlying protocols, eliminate underlying protocol risks, guarantee specific returns.
What to evaluate: underlying protocols used, fee structures, smart contract audits, strategy transparency, governance.
Stablecoin Protocols
What they actually do:
Maintain price stability against reference currency (typically USD) through specific mechanisms.
Different stablecoin types use different mechanisms — fiat-backed, crypto-collateralized, algorithmic.
Provide stable medium of exchange and store of value within crypto ecosystem.
Major examples: USDC, USDT, DAI, others.
What they don't do: maintain perfect peg in all conditions (specific de-pegs have occurred), provide same protections as bank deposits, eliminate counterparty risks specific to stablecoin type.
What to evaluate: backing transparency (audit reports for fiat-backed), specific collateral mechanisms (for crypto-collateralized), historical peg performance under stress.
Liquid Staking Protocols
What they actually do:
Allow users to stake proof-of-stake assets while receiving liquid tokens representing their staked position.
Liquid tokens can be used in other DeFi protocols.
Validators handle actual staking work.
Major examples: Lido, Rocket Pool, others.
What they don't do: eliminate staking risks (slashing, downtime), eliminate smart contract risks, maintain perfect peg between staked and liquid token in all conditions.
What to evaluate: validator decentralization, governance, smart contract audits, specific peg dynamics under stress, fee structures.
Prediction Markets
What they actually do:
Allow users to bet on outcomes of specific real-world events.
Aggregate predictions through market mechanisms.
Resolve outcomes through specific oracle mechanisms.
Major examples: Polymarket, Augur, others.
What they don't do: eliminate manipulation risks, provide regulatory protection in all jurisdictions, function in jurisdictions where prediction markets are restricted.
What to evaluate: oracle reliability, dispute resolution mechanisms, jurisdictional regulatory status, specific event resolution policies.
Insurance Protocols
What they actually do:
Provide coverage against specific DeFi-related risks (smart contract failures, oracle failures, others).
Pool premiums to fund claims.
Resolve claims through specific governance mechanisms.
Major examples: Nexus Mutual, others.
What they don't do: provide same coverage as traditional insurance, cover all possible risks, guarantee claim payment.
What to evaluate: covered risks specifically, claim resolution history, capital adequacy, governance, specific exclusions.
Cross-Chain Bridges
What they actually do:
Allow asset transfer between different blockchains.
Use various mechanisms — locking on source chain and minting on destination, or other techniques.
Enable cross-chain DeFi participation.
Major examples: various bridges associated with specific blockchain ecosystems.
What they don't do: eliminate bridge-specific risks (substantial bridge hacks have occurred), provide same security as native chain transactions, function instantly without specific delays.
What to evaluate: security model (validator-based, light client-based, others), historical security incidents, specific transfer mechanisms.
NFT Markets
What they actually do:
Provide marketplaces for non-fungible tokens (NFTs).
Handle bid and listing transactions through smart contracts.
Charge specific transaction fees.
Major examples: OpenSea, Blur, others.
What they don't do: validate NFT artistic or commercial value, eliminate counterfeiting concerns, provide IP protection automatically.
What to evaluate: fee structures, royalty enforcement, specific market dynamics, fraud prevention.
Specific risk patterns across DeFi
Common risk categories across DeFi:
Smart contract risk: bugs in code can cause loss of funds. Audits reduce but don't eliminate this risk.
Oracle risk: price feeds and other external data sources can fail or be manipulated.
Governance risk: decentralized governance can produce specific harmful decisions.
Liquidity risk: insufficient liquidity can prevent execution at expected prices.
Regulatory risk: specific jurisdictional regulations can affect protocol operations.
Composability risk: protocols built on other protocols inherit their risks.
Front-end risk: compromised user interfaces can drain funds even when underlying protocols are secure.
User error risk: mistakes in transactions, addresses, or signatures can cause irreversible loss.
Understanding risk categories applies broadly across specific protocols.
Specific patterns that suggest caution
Patterns suggesting elevated risk in specific protocols:
Anonymous teams with no documented history.
Unaudited or recently audited code with limited history.
Yields substantially exceeding market norms (typically indicates elevated risk).
Heavy reliance on token incentives rather than sustainable economics.
Limited liquidity making exits difficult.
Specific governance patterns suggesting centralization or capture risks.
Marketing focus on price appreciation rather than actual utility.
Recognition of patterns supports better risk assessment.
What to do before using any specific DeFi protocol
Practical due diligence steps:
Read the protocol documentation thoroughly.
Review audit reports if available.
Check governance and team transparency.
Assess liquidity for your specific use case.
Start with small amounts before larger commitments.
Understand specific risks of your specific use case.
Verify you're using official URLs (phishing is substantial risk).
Use hardware wallet for substantial holdings.
Substantive due diligence substantially reduces avoidable losses.
What this cheat sheet doesn't cover
Specific things this cheat sheet doesn't address:
Specific token recommendations or price predictions.
Specific yield farming strategies optimizing returns.
Trading strategies or technical analysis.
Specific operator recommendations.
The omissions are deliberate. The site doesn't produce that content.
For substantive understanding, the omitted material isn't generally what matters most.
The honest takeaway
DeFi protocols do specific things mechanically. Understanding what each category actually does provides substantive foundation for evaluating any specific protocol.
Specific risk patterns recur across DeFi categories. Recognition supports better decisions.
Substantial substantive due diligence substantially reduces avoidable losses.
For substantive engagement: understand what protocols actually do beyond marketing.
For risk management: recognize patterns that suggest caution.
For sustainable participation: substantive understanding produces better long-term outcomes.
The space continues to evolve. Continued substantive engagement supports continued informed participation.
That's the cheat-sheet level overview. Specific protocols warrant deeper individual analysis when you're considering substantive engagement.