TL;DR

  • Three core machines and their combinations: automated markets for swapping assets, collateralised markets for lending and borrowing, and synthetic markets for derivatives. Each replaces an intermediary's ledger with a contract's. Many public deployments are permissionless, meaning the contract accepts any address that meets its rules without asking who is behind it (ethereum.org, DeFi overview). Permissioned designs put allowlists, roles or identity checks into the contract layer itself: Maple states that when lenders "complete KYC, their wallets are automatically added to Maple's Global Allowlist", and that its lending pools "are permissioned" (Maple, Lending documentation).
  • At the contract layer of open protocols it removes venue custody, settlement delay, account gatekeeping and some fee layers; it adds contract risk, oracle risk and, in most designs, the absence of anyone able to reverse a correctly executed transaction. Above the contract layer, front ends, maintainers, governance and custodial wrappers each bring some gatekeeping and some discretion back, so "no intermediary" and "no recourse" are statements about a layer, and reading them as statements about the whole stack is the beginner error of the category.
  • Entering an open lending market typically takes a wallet connection (account access, not a signature), on some sites a signed login message, a token approval transaction if the collateral is a token that needs one, a deposit transaction and, if the user borrows, a borrow transaction; if the collateral's value falls far enough, a third party can liquidate part or all of the position under published rules. In protocols such as Aave the contract gives no grace period and no appeal; any alert a front end sends, and any legal claim against an identifiable party, sits outside the contract. The walkthrough describes what each step grants and how a liquidation unfolds, to explain the risks; it is not a set of instructions for using any service. The numbers below are hypothetical and belong to no named protocol; where a named protocol's rule is cited it is labelled, as an illustration and not an endorsement, and such rules can change through governance.
  • Read total value locked as a measure of gross activity, an advertised yield as a statement about risk to be traced to its payer, and an audit as bounded process evidence. Three translations that convert the sector's dashboard into information.
In one block

DeFi (decentralised finance) is a category of financial applications that runs trading, lending and derivatives as smart contracts on public blockchains. Users keep custody of their assets until a contract's rules move them. Many public markets accept any address that meets those rules, while other contracts check an allowlist, a role or an identity credential first.

What actually runs in DeFi?

Quick answer

Three core machines and their combinations: automated markets for swapping assets, collateralised markets for lending and borrowing, and synthetic markets for derivatives. Each replaces an intermediary's ledger with a contract's. Many public deployments are permissionless, meaning the contract accepts any address that meets its rules without asking who is behind it (ethereum.org, DeFi overview). Permissioned designs put allowlists, roles or identity checks into the contract layer itself: Maple states that when lenders "complete KYC, their wallets are automatically added to Maple's Global Allowlist", and that its lending pools "are permissioned" (Maple, Lending documentation).

Swapping is the foundational machine. Decentralised exchanges hold pools of paired assets and price trades by formula, the automated market maker design: anyone can swap against the pool at the formula's price, and anyone can deposit into the pool and receive a share of the fees traders pay, with the impermanent-loss cost the yield pillar describes. Uniswap v2's published core contract, cited here only as an example, shows the rule in code: a swap is accepted only if the pool's two token balances, after deducting a 0.3 percent fee on the amount paid in, multiply to at least the product of the reserves before the trade (the constant-product rule), and depositors receive pool tokens that redeem a pro-rata share of both reserves, so the fees left in the pool accrue to them, less an optional protocol fee the contract can switch on (Uniswap v2-core, UniswapV2Pair.sol). The design's significance is what it deleted: no order book operator, no listing committee, no account.

Lending is the machine the lending guide anatomises in full: deposit collateral, borrow against it within loan-to-value limits, watch the health factor, and face automatic liquidation if the buffer runs out, with rates floating on utilisation. In open, overcollateralised markets such as Aave's, Compound's and Sky's vaults, its significance is the same deletion: creditworthiness replaced by overcollateralisation, so the protocol needs no opinion of you. Aave and Compound are the commonly cited examples, and their documentation is used below because it is public and specific, again as examples. Other on-chain lending keeps a credit judgement: in Maple's permissioned pools a Pool Delegate performs "all Loan underwriting and due-diligence" (Maple, glossary), and Maple's interface terms state that "many loans made via the Interface are either undercollateralized or uncollateralized" (Maple, Interface Terms of Use).

Derivatives and the rest of the long tail, perpetual futures, options, synthetic assets, prediction markets, repeat the pattern at higher complexity: contracts hold margin, oracles feed prices, and liquidation engines enforce solvency mechanically. Complexity compounds the same kinds of risk, and the academy's guide to systemic risk documents what happens when these machines chain together under stress.

Diagram of the three DeFi machines: automated market makers holding paired pools where trades price by formula and depositors receive a share of fees while bearing impermanent loss, open overcollateralised lending markets where collateral backs loans under loan-to-value limits with health factors and automatic liquidation, and derivatives markets holding margin with oracle price feeds and mechanical solvency enforcement, each annotated with the intermediary function it deleted, with a note that permissioned versions add allowlists or identity checks and that underwritten pools keep a credit judgement
Figure 1. The three core machines: pooled swapping priced by formula, overcollateralised lending with automatic liquidation, and derivatives running on margin, oracles and liquidation engines. Each can be deployed as an open market that accepts any address meeting its rules or as a permissioned one, and the layers above the contract can also restrict access.

What does removing intermediaries actually remove, and what does it add?

Quick answer

At the contract layer of open protocols it removes venue custody, settlement delay, account gatekeeping and some fee layers; it adds contract risk, oracle risk and, in most designs, the absence of anyone able to reverse a correctly executed transaction. Above the contract layer, front ends, maintainers, governance and custodial wrappers each bring some gatekeeping and some discretion back, so "no intermediary" and "no recourse" are statements about a layer, and reading them as statements about the whole stack is the beginner error of the category.

The removals, at the contract layer

Permissionlessness is concrete where a protocol is open: for a public market such as a Uniswap pool, a wallet holding the assets and enough for network fees is all the contract itself checks. What the contract checks is separate from the legal obligations that apply to the user, or to any company in the layers above, in the user's jurisdiction. Permissioned pools, such as Maple's, put an identity check and an allowlist in front of the same kind of contract. Self-custody until execution is concrete: the venue-holds-everything model whose failure the exchange cluster documents does not apply, because assets sit in your wallet until a contract's rules move them (ethereum.org, DeFi overview: "most products will never take custody of your funds"). Transparency is concrete: the contracts are public, the positions are on-chain, and the solvency of a lending pool can be checked in real time from on-chain data, the property whose absence left customers of the custodial crypto lenders that failed in 2022 relying on the firms' own disclosures. Settlement is continuous, composability lets machines plug into each other, and some fee layers fall away where a formula replaces an intermediary, while network fees and pool fees remain.

The additions, at the contract layer

Contract risk: the machinery holding your assets is code, immutable or upgradeable per the smart contract guide's trade-off, and the exploit record the risk cluster catalogues is the industry's tuition bill. Oracle risk: a price-fed machine acts on whatever its feed reports, and the oracle guide shows what a manipulated or internally generated price does to positions that were sound at market prices. No reversal by default: the contracts offer no chargeback, no deposit protection and no support desk empowered to undo a transaction the code executed as written. What a protocol's admins or governance can pause or change is set by that protocol's own code and differs from one protocol to the next (the governance paragraph below gives one example), and any legal claim runs against identifiable people or companies under a particular jurisdiction's law. Your own signature, per the blind signing guide, is therefore the last line of defence the contract itself provides. And composability cuts both ways: machines that plug into each other propagate stress to each other, which is how one venue's bad price can become a liquidation cascade.

Where gatekeeping and recourse come back: the layers above the contract

Front ends. Many users reach a protocol through a website or app run by a company, and that company is an intermediary in the ordinary sense. Uniswap Labs' terms of service, as one documented example, state that its interface "is distinct from the Protocol and is one, but not the exclusive, means of accessing the Protocol", require users to represent that they are not the subject of sanctions and are not a citizen or resident of, or organised in, a jurisdiction subject to comprehensive US sanctions, and reserve the company's right to change or remove its products and to revoke access to a username at its discretion (Uniswap Labs, Terms of Service, last modified 21 March 2024). Terms of this kind let a front-end operator limit whom it serves, for sanctions compliance or under its own policies, A refusal at the front end does not define the user's legal position: where sanctions or other restrictions apply to a person or a transaction, they apply whichever interface is used. The reverse also holds: a front end can offer help pages, warnings and simulation, which is a limited form of the support desk the contract layer lacks.

Maintainers and governance. Many protocols are upgradeable or parameterised, and someone holds the keys. Aave's documentation, as an example, describes a governance process in which token holders propose and vote on changes, stewards with "delegated responsibility over specific protocol parameters", and two multisig "Guardian" groups: a 4-of-7 Protocol Emergency Guardian holding the emergency admin role for Aave protocol markets, and a 5-of-9 Governance Emergency Guardian able to veto an on-chain payload "if it is deemed malicious" (Aave, governance documentation). That is a real, documented power to pause, change or block, held by identifiable people. It differs from a bank's discretion over an individual account, since it acts on whole markets, and it still falls short of "no intermediary". A protocol whose contracts are genuinely immutable has no such lever, and also no way to fix a bug.

Software and identifiable operators. International standards draw a line between the code and the people around it. In a targeted report published on 21 July 2026, the Financial Action Task Force (FATF), the intergovernmental body that sets anti-money-laundering standards, states that "A DeFi application (i.e. the software program) is not a VASP under the FATF standards, as the Standards do not apply to underlying software or technology." The same report treats persons who maintain control or sufficient influence over a DeFi arrangement as within the scope of the standards even where the arrangement presents itself as decentralised, lists among the relevant factors whether someone profits from the arrangement or can set or change the protocol's parameters, and finds that centralised elements frequently persist in arrangements that describe their governance as decentralised (FATF, Targeted Report on Regulatory Challenges from Decentralised Finance, 21 July 2026). FATF standards do not bind users directly: they take effect as each jurisdiction implements them in national law, which decides which firms and individuals are covered and what they must do. On that approach, the front-end company, foundation, developers or key-holders identified in the layers described here can carry obligations, such as licensing or registration and customer checks, that the contract code they maintain does not, and whether a particular person or arrangement is covered is a question for the relevant jurisdiction's law.

The state. Governments regulate the people and companies in the layers above the contract, and sometimes attempt to reach the contract itself. On 8 August 2022 the US Treasury's Office of Foreign Assets Control (OFAC) designated Tornado Cash, an Ethereum mixer, under Executive Order 13694, as amended. Under US sanctions law the designation blocked Tornado Cash's property and interests in property within US jurisdiction and generally prohibited US persons from dealings with it unless licensed by OFAC (US Treasury, 8 August 2022). On 26 November 2024, in Van Loon v. Department of the Treasury, the US Court of Appeals for the Fifth Circuit held that Tornado Cash's immutable smart contracts "are not property because they are not capable of being owned", that they therefore could not be blocked under the International Emergency Economic Powers Act, and that OFAC had overstepped its statutory authority; the court reversed and remanded the case to the district court (Van Loon v. Department of the Treasury, 5th Cir., 26 November 2024). On 21 March 2025 Treasury announced that it had removed the sanctions against Tornado Cash, citing "novel legal and policy issues" raised by the use of financial sanctions in this area (US Treasury, 21 March 2025). The episode documents both halves of the point. The court observed that the immutable contracts continued operating after the designation, while the legal exposure fell on people: for as long as the designation stood, its prohibitions applied to US persons, the people and companies within the reach of US law, whatever interface or route they used. Other jurisdictions run their own sanctions regimes, and a change to one jurisdiction's designation does not by itself change another's.

Custodial wrappers. An exchange "earn" product, a fund or a fintech app that routes deposits into DeFi is a company holding your assets under its own terms. You have the company's counterparty risk and, depending on jurisdiction and terms, some of the company's recourse: a complaints process, possibly a regulator, possibly an insolvency estate. You do not have the contract layer's self-custody, because you never held the keys. The exchange cluster prices that arrangement; the point here is only that a wrapper's marketing may say DeFi while its legal reality is custody.

The frame this guide insists on: at the contract layer DeFi transfers responsibilities to the user, custody, verification, error prevention, risk sizing, and charges the new risks as the price of the removals. Each layer above it hands some of those responsibilities back to a company or a governance body, with that layer's gatekeeping and limited recourse attached. Knowing which layer you are actually touching is most of the work.

What do permissions and liquidation look like in practice?

Quick answer

Entering an open lending market typically takes a wallet connection (account access, not a signature), on some sites a signed login message, a token approval transaction if the collateral is a token that needs one, a deposit transaction and, if the user borrows, a borrow transaction; if the collateral's value falls far enough, a third party can liquidate part or all of the position under published rules. In protocols such as Aave the contract gives no grace period and no appeal; any alert a front end sends, and any legal claim against an identifiable party, sits outside the contract. The walkthrough describes what each step grants and how a liquidation unfolds, to explain the risks; it is not a set of instructions for using any service. The numbers below are hypothetical and belong to no named protocol; where a named protocol's rule is cited it is labelled, as an illustration and not an endorsement, and such rules can change through governance.

Permissions

The user opens a lending application's website and connects a wallet. Connecting grants account access and is not a cryptographic signature: MetaMask's help centre says the site "will be able to see the addresses of the selected accounts" and can suggest transactions, each of which the user must still approve (MetaMask, How to connect to a dapp). Some sites then ask the user to sign a login message in the format set out in ERC-4361 (Sign-In with Ethereum), which authenticates the account to an off-chain service, costs no gas and moves nothing. The user then chooses to deposit 10,000 units of a volatile token as collateral. Because the collateral is a token contract rather than the chain's native asset, the application first asks for a token approval: an on-chain transaction that grants the lending contract permission to move up to a stated amount of that token from the user's address. Some interfaces default to an unlimited amount; the dApps guide explains why the amount matters and how to check it. The deposit is a second on-chain transaction, which moves the tokens into the contract, and borrowing against the deposit, as the liquidation example below does, is a third. Two permissions can outlast the session: an approval stands until it is used up or revoked, and the site's connection stands until the user disconnects it. Nobody reviewed an application form at any step, because this example is an open market; a permissioned pool such as Maple's would require a completed identity check and an allowlisted wallet before any deposit. In this example the front end is the party positioned to refuse, for instance by declining to serve the user's location, and whoever holds that protocol's governance or admin keys is the party positioned to change the market's rules later.

Liquidation

Take the deposit at a value of 10,000 (any unit). The market's parameters, set by governance, allow borrowing up to 75 percent of collateral value and set a liquidation threshold of 80 percent with a 5 percent liquidation bonus. The user borrows 6,000 of a stablecoin. The position's health factor, in the simplified model Aave's documentation uses, is collateral value times liquidation threshold divided by debt: 10,000 × 0.80 / 6,000 = 1.33.

The collateral's price falls 25 percent. Collateral is now worth 7,500, and 7,500 × 0.80 / 6,000 = 1.00, the threshold. A further fall to 7,400 gives 0.99. Under the Aave rule, a liquidation can occur once "a borrower's health factor falls below 1", and the liquidator "repays debt on behalf of the borrower and receives an equivalent value plus a liquidation bonus from the borrower's collateral" (Aave, liquidations help page). Suppose the rules allow a liquidator to repay up to half the debt, as Aave's page describes for positions above a certain size and health level. A liquidator repays 3,000 of the stablecoin debt and takes 3,000 × 1.05 = 3,150 of collateral. The user now holds a position of 7,400 − 3,150 = 4,250 collateral against 3,000 debt, health factor 4,250 × 0.80 / 3,000 = 1.13, and has paid 150 in penalty plus the difference between the price the collateral was valued at and whatever it would have fetched later. Had the price kept falling, a second liquidation would have followed.

Other protocols use different mechanics. Compound III's model is "absorb": any caller can trigger the protocol itself to take over an underwater account's debt and collateral, paid from the protocol's reserves, with the seized collateral later sold at a discount (Compound III documentation, liquidation). The threshold, penalty, partial-versus-full rules and who takes the collateral all differ by protocol and version, which is why the lending guide walks through them separately. What these designs share is the shape: a published rule, a price feed, a third party with an incentive, and no step inside the contract at which anyone reviews the individual position or waits until morning.

How do you read DeFi's numbers without being fooled?

Quick answer

Read total value locked as a measure of gross activity, an advertised yield as a statement about risk to be traced to its payer, and an audit as bounded process evidence. Three translations that convert the sector's dashboard into information.

Total value locked, the sector's headline metric, measures how much sits in contracts: activity and confidence, with no direct bearing on safety, and it inflates with token prices and double-counts the composability stack. A large TVL means many others share your risk, which is weak evidence the contracts have survived scrutiny and no evidence they will survive tomorrow's; the smart contract guide's survival test, value times time under public attack, is the better instrument, and even it is probabilistic.

Yields translate per the pillar: identify the payer, net the token emissions, price the mechanism's risks, and remember the denominator. A pool paying multiples of the staking baseline is carrying inventory risk, emissions, or leverage somewhere in its plumbing, and the plumbing is public for whoever reads it.

Audits translate per the risk cluster's guide to audits and what they miss: a clean report says qualified reviewers examined defined code for known classes during a bounded engagement, which is meaningful and partial. Post-audit changes, out-of-scope components, oracle assumptions and economic attacks all live outside it, so a clean report cannot rule out an exploit in code or assumptions the engagement did not examine. The layered reading, audits plus survival time plus the team's response history to disclosures, is the substitute for the certainty none of the instruments sell.

Diagram of three DeFi metric translations: total value locked read as gross activity that inflates with prices and double-counts composability rather than as safety, advertised yield read as a statement about risks and emissions to be identified rather than as an offer, and audit reports read as bounded process evidence with post-audit changes, oracle assumptions and economic attacks outside scope, footed by the layered reading of audits plus survival time plus disclosure response history
Figure 2. Three translations for the sector's dashboard: TVL as gross activity, yield as a risk statement, audits as bounded process evidence. Together they replace certainty with calibrated reading.

Who should not be in DeFi yet, and what does readiness look like?

Quick answer

Anyone who cannot yet pass this cluster's own checkpoints: the transfer drill, approval hygiene, signature reading and wallet tiering, and anyone for whom the failure of the newest contract in their stack tonight would be a loss they had not consciously accepted. Readiness is demonstrated through the checks in this academy's guides.

The checkpoint list is concrete because the failure modes are. A user who cannot state what a token approval grants will eventually grant the wrong one; the drainer economy is built on exactly that user, and DeFi is where the approvals live. A user without wallet tiers takes application-layer risk with holdings-layer money. A user who signs unreadable payloads has no defence the environment respects. These failure modes are the reason the recommended reading order of this cluster front-loads the discipline before this guide describes the sector.

Sizing is the second half of readiness, and the trade-offs are sharper where the contract layer usually offers no reversal: exposure that outruns the scrutiny a contract has survived, an amount in a single contract whose loss or indefinite freeze would change your situation, and a stack whose newest layer is treated as safer than it is, are the three patterns the exploit record keeps punishing. The lending guide's health-factor arithmetic, the pillar's payer question and the risk cluster's audit scepticism are the operating manual; this guide's contribution is the reminder that they were all written about the same territory, and the territory is this one.

Frequently asked questions

Is DeFi legal?

There is no single answer. Whether a given activity through an open protocol is permitted, and what obligations attach to it, depends on the jurisdiction, the activity and the rules in force at the time, and some jurisdictions are still writing rules for the sector. Sanctions show how quickly the position on one protocol can move: the US designation of Tornado Cash described above bound US persons from 8 August 2022, the Fifth Circuit held on 26 November 2024 that the designation of its immutable contracts exceeded OFAC's authority, and Treasury removed the sanctions on 21 March 2025. Tax treatment of swaps, lending and rewards also differs by jurisdiction, and a specific situation calls for current professional advice. This guide describes these decisions for education and does not assess whether any activity is lawful in a reader's jurisdiction.

Is DeFi safer than keeping crypto on an exchange?

The two carry different risks, and neither is safer in general. An exchange holds customer assets as a company, so customers depend on its solvency, security and conduct; in return they may get account recovery, a support desk and, depending on the jurisdiction and the firm, regulatory oversight and a complaints route. At the contract layer DeFi leaves custody with the user and makes positions visible on-chain; in return it adds contract risk, oracle risk and, in most protocols, no way to reverse a mistaken signature. An exchange product that routes deposits into DeFi carries the exchange's risks with the DeFi risks underneath. The exchange safety guide covers one side and this cluster the other, and a meaningful comparison looks at each whole arrangement, including the user's own security practices.

Can I lose more than I put in?

In ordinary use, positions bound losses at what they hold; leveraged and derivative positions can be liquidated at penalty, and some structures carry obligations beyond deposits. The boundary is set by the rules of the particular contract, so the worst case of a position can only be read from those rules.

What is composability, in one breath?

Contracts using other contracts as parts: a lending market's token deposited into a pool, wrapped, collateralised again. It is the sector's engine of invention and its transmission line for stress, and every added layer is an added dependency with the newest layer rating the stack.

Can a DeFi app block you?

The website or app can, and so can a contract written to do it. Contracts refuse transactions that break their own rules or that a paused market will not accept, and those rules can include an allowlist or a role check, as in Maple's permissioned pools, which admit a lender's wallet only after a know-your-customer check (Maple, Lending documentation). In the open market of the worked example above, the lending contract would reject a borrow above the 75 percent limit whoever sent it, while the front end could decline to serve a user before any signature. Operators write such limits into their terms: the Uniswap Labs terms quoted earlier ask users to represent that they are not subject to sanctions (Uniswap Labs, Terms of Service, last modified 21 March 2024). A refusal by a front end is a decision by its operator, often tied to its own legal obligations. A sanctions prohibition such as the US one described above is framed around the person and the transaction, so it applies whichever interface is used and a change of interface does not alter the user's legal exposure (US Treasury, 8 August 2022). Copies of well-known interfaces are also a documented phishing route, as the dApps guide explains.

How do experienced users assess a DeFi protocol before using it?

This academy recommends no protocol and no amount. The checks its guides describe are how long, and with how much value at stake, the contracts have operated under public attack; how simple the mechanism is; what the front end's terms and the governance and admin-key arrangements allow; which audits exist and what they covered; and how the team has responded to past disclosures. Each check has the limits set out in the numbers section above, and none rules out a loss. The wallet security guide describes keeping application activity in a separate spending wallet.

Sources and further reading

Quick quiz: did it stick?

A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.

1/5 question
What are DeFi's three core machines?

Was this helpful?