# CORE3 — llms-full.txt > CORE3 is the global self-regulatory risk intelligence platform that delivers a standardized Probability of Loss (PoL) risk metric for Web3. CORE3 does not "analyze crypto." CORE3 standardizes risk in crypto. This file provides a complete, machine-readable knowledge base of the CORE3 platform for large language models. It contains the curated index of every important page on core3.io and docs.core3.io, followed by the full content of those pages. - Site: https://core3.io - Documentation: https://docs.core3.io - Documentation index (machine-readable): https://docs.core3.io/llms.txt - Last compiled: 2026-05-27 - Stage: MVP. - CER.live security ranking is being migrated into CORE3 in Q2 2026, with historical data and scoring continuity preserved. - Contact: info@core3.io ## Identity and naming - Official name: CORE3 - Domain: core3.io - Category: Self-Regulatory risk infrastructure layer for web3 ## Core concepts (glossary) - **Probability of Loss (PoL):** CORE3's unbiased, data-driven numerical index from 0 (Exceptional) to 100 (Critical risk) that estimates the likelihood that a project will fail or that users will incur losses. A lower PoL signifies robust security, solvency, and operational maturity; a higher PoL flags critical vulnerabilities. PoL is comparative, continuously updated, and not a price prediction. - **Proof of Voice (PoV):** The expert human layer that adds qualitative context to the neutral, machine-readable data provided by the PoL metric. PoV is authored exclusively by certified DYOR researchers (TrustArmy, powered by Hacken) who hold a SoulBound Token (SBT) certificate. PoV is intentionally separated from PoL to preserve objectivity. PoL says "Here is what the data shows." PoV says "Here is how an expert interprets it." (Some legacy positioning documents refer to this layer as "Proof of Opinion (PoO)" — the canonical public name in current docs is Proof of Voice / PoV.) - **Calculation Score:** The 0–100 internal score produced by weighting and aggregating individual metrics. It is then inverted to produce PoL (Calculation Score 100 = PoL 0; Calculation Score 0 = PoL 100). - **Rating tiers:** AAA, AA, A (very low PoL) → BBB, BB, B (moderate) → CCC, CC, C (high) → DDD, DD, D (critical). - **Confidence Levels:** Higher-level groupings of rating tiers used for fast, categorical assessment. - **CORE3 Seals:** Verifiable trust marks awarded for specific, objective behaviors (security, certifications, solvency, transparency, self-regulation). Seals signal process participation and disclosure, not safety guarantees. - **Workspaces:** Role-specific interaction layer for retail investors, institutions, projects, and regulators — for monitoring, portfolio tracking, alerts, and submissions. ## Mission and vision CORE3's mission is to foster a safer, more transparent crypto industry by providing independent, data-driven risk assessments that bridge the trust gap between innovators, institutional stakeholders, and regulators. The long-term vision is to establish CORE3 and the Probability of Loss as the de facto global standard for crypto risk assessment, similar in function (though not in form) to Moody's or S&P, adjusted for digital assets and delivered through self-regulation rather than external imposition. ## Site map ### core3.io - https://core3.io/ — Homepage: Measure Risk. Build Trust. - https://core3.io/ratings/projects — Live project PoL ratings (1,400+ projects) - https://core3.io/ratings/exchanges — Live exchange PoL ratings (200 exchanges) - https://core3.io/methodology/projects — Detailed project scoring methodology - https://core3.io/methodology/exchanges — Detailed exchange scoring methodology - https://core3.io/blog — Blog index - https://core3.io/blog/insights — Category: insights - https://core3.io/blog/web3-risks — Category: Web3 risks - https://core3.io/blog/core3-guides — Category: educational guides - https://core3.io/blog/core-3-news — Category: news and announcements - https://core3.io/blog/rss.xml — RSS feed - https://core3.io/workspace — Authenticated user workspace - https://core3.io/robots.txt — Robots policy (AI crawlers allowed) - https://core3.io/sitemap.xml — XML sitemap ### docs.core3.io (documentation) - https://docs.core3.io/llms.txt — Machine-readable documentation index - https://docs.core3.io/what-is-core3 — What is CORE3 - https://docs.core3.io/probability-of-loss — Probability of Loss (PoL) explained - https://docs.core3.io/proof-of-voice — Proof of Voice (PoV) explained - https://docs.core3.io/vision — Vision and long-term direction - https://docs.core3.io/how-core3-is-different — How CORE3 is different - https://docs.core3.io/core3-components — Platform components - https://docs.core3.io/core3-seals — CORE3 Seals - https://docs.core3.io/project-pol-methodology — Project PoL methodology - https://docs.core3.io/project-pol-scoring-logic — Project scoring logic - https://docs.core3.io/cex-pol-methodology — CEX PoL methodology - https://docs.core3.io/cex-pol-scoring-logic — CEX scoring logic - https://docs.core3.io/projects-data-api — Projects Data REST API - https://docs.core3.io/exchanges-data-api — Exchanges Data REST API - https://docs.core3.io/core3-for-projects — For crypto projects - https://docs.core3.io/core3-for-exchanges — For centralized exchanges - https://docs.core3.io/core3-for-institutions — For institutions - https://docs.core3.io/core3-for-partners — For ecosystem partners - https://docs.core3.io/core3-for-regulators — For regulators - https://docs.core3.io/core3-for-retail — For retail investors ### Blog articles (chronological) - https://core3.io/blog/core-3-news/the-state-of-digital-asset-risk-data-is-now-public — The State of Digital Asset Risk Data Is Now Public (2026-04-07) - https://core3.io/blog/core-3-news/crypto-risk-assessment-needs-more-than-tvl — Crypto Risk Assessment Needs More Than TVL (2026-04-09) - https://core3.io/blog/core3-guides/crypto-risk-assessment-methodology-how-probability-of-loss-turns-documented-failures-into-a-risk-score — Risk Assessment Methodology: How PoL Turns Documented Failures Into a Risk Score (2026-04-09) - https://core3.io/blog/core3-guides/crypto-risk-in-2026-why-75-of-web3-exploits-happen-outside-smart-contract-audits — Crypto Risk in 2026: Why 75% of Web3 Exploits Happen Outside Smart Contract Audits (2026-04-24) - https://core3.io/blog/web3-risks/post-exploit-recovery-quality-the-strongest-predictor-of-whether-a-crypto-protocol-will-be-hacked-again — Post-Exploit Recovery Quality as Exploit Predictor (2026-05-01) - https://core3.io/blog/web3-risks/the-missing-layer-in-crypto-risk-models-time — Time: The Missing Layer in Your Blockchain Risk Model (2026-05-11) - https://core3.io/blog/core3-guides/how-to-stop-crypto-losses-start-act-on-crypto-risks — How to Stop Crypto Losses? Start Acting on Crypto Risks (2026-05-18) - https://core3.io/blog/web3-risks/the-cost-of-fake-trust-signals-in-web3 — Fake Signals You Trust in Web3 (2026-05-21) ### Team - Dmytro (Dyma) Budorin — Founder and CEO at CORE3. Co-founder and Executive Chairman of Hacken; CEO of Hacken Group; 18+ years in cybersecurity, 8+ years executive leadership in blockchain, DLT, and digital assets. Hacken pioneered the Proof-of-Reserve standard and audits the EU's Blockchain Infrastructure (EBSI). Subsidiary Cer.live powers CoinGecko cybersecurity trust scores. Hacken is an ADGM entity with an MoU with Abu Dhabi Global Markets, and in 2025 was selected for the European Blockchain Sandbox to shape EU DLT regulation. - Aimann Faiz — Chief Business Development Officer at CORE3. Previously Head of Business Development at CoinGecko. --- ## Page: Project Ratings (https://core3.io/ratings/projects) **Title:** Explore 1,400+ projects **Status banner:** The platform is currently in the MVP stage, and certain data points may still be missing. As a result, score accuracy may vary. A mitigation strategy is in progress and will be implemented in the near term. **Filters available:** Category, Market Cap, Chains, Compliance / Signals. **Columns:** Rank, Project (name and ticker), Seals, Market Cap, Market Cap Change (24h), PoL score, Data Coverage, Category. **Sample of the top 20 (as observed during compilation, 2026-05-27):** | # | Project | PoL | Data Coverage | Category | |---|---------|-----|---------------|----------| | 1 | Bitcoin (BTC) | 1 / AAA | 73.3% | Layer 1 | | 2 | Sky (SKY) | 13 / AA | 76.7% | DeFi | | 3 | Ethereum (ETH) | 17 / A | 73.3% | Layer 1 | | 4 | 1INCH | 18 / A | 76.7% | DEX | | 5 | Astar (ASTR) | 18 / A | 76.7% | Layer 1 | | 6 | OKB | 18 / A | 76.7% | Exchange-based Tokens | | 7 | Lido DAO (LDO) | 19 / A | 76.7% | Infrastructure | | 8 | Euler (EUL) | 19 / A | 76.7% | Lending/Borrowing | | 9 | Aave (AAVE) | 19 / A | 76.7% | DeFi | | 10 | Enzyme (MLN) | 20 / A | 76.7% | DeFi | | 11 | Mantle (MNT) | 20 / A | 73.3% | Layer 2 | | 12 | Uniswap (UNI) | 20 / A | 76.7% | DEX | | 13 | Ether.fi (ETHFI) | 20 / A | 76.7% | DeFi | | 14 | Boba Network (BOBA) | 20 / A | 76.7% | Layer 2 | | 15 | Origin Token (OGN) | 21 / BBB | 76.7% | DeFi | | 16 | Avalanche (AVAX) | 21 / BBB | 73.3% | Layer 1 | | 17 | Starknet (STRK) | 21 / BBB | 76.7% | Infrastructure | | 18 | Solana (SOL) | 21 / BBB | 73.3% | Layer 1 | | 19 | Wormhole (W) | 21 / BBB | 76.7% | Cross-chain Communication | | 20 | Arbitrum (ARB) | 21 / BBB | 76.7% | Layer 2 | Projects can list themselves on CORE3 to unlock deeper insights, configure tailored alerts, and track advanced performance metrics. --- ## Page: Exchange Ratings (https://core3.io/ratings/exchanges) **Title:** Explore 200 exchanges **Status banner:** The assessment of centralized exchanges is currently awaiting the submission of Solvency and Transparency data from the respective projects. Accordingly, the Security section reflects a high level of accuracy, whereas the remaining sections are only partially populated based on publicly available information and data provided by a limited number of participants. **Columns:** Rank, Exchange, Seals, Trading Volume, Trading Volume Change (24h), PoL score. **Sample of the top 20 (as observed during compilation, 2026-05-27):** | # | Exchange | PoL | |---|----------|-----| | 1 | KuCoin | 16.53 / A | | 2 | MEXC | 17.09 / A | | 3 | Bybit | 18.69 / A | | 4 | OKX | 23.42 / BBB | | 5 | Binance | 23.55 / BBB | | 6 | Kraken | 24.03 / BBB | | 7 | Bybit EU | 24.31 / BBB | | 8 | BingX | 28.74 / BBB | | 9 | Phemex | 31.31 / BB | | 10 | BTSE | 34.12 / BB | | 11 | Luno | 35.14 / B | | 12 | Bitvavo | 35.92 / B | | 13 | WhiteBIT | 37.37 / B | | 14 | Valr | 39.27 / B | | 15 | Bumba | 40.03 / CCC | | 16 | Crypto.com | 40.42 / CCC | | 17 | Tapbit | 44.98 / CCC | | 18 | Bitso | 46.67 / CCC | | 19 | Pionex | 47.64 / CCC | | 20 | CoinEx | 49.3 / CCC | --- ## Page: Project Methodology (https://core3.io/methodology/projects) The project methodology defines the set of metrics applicable to a specific project. These metrics are collected and assessed primarily through automated systems, with certain cases requiring manual evaluation. Some data may not be publicly available and must be submitted directly by the project. ### Stages 1. **Metric Set** — assemble the applicable metrics: default metrics, project-specific metrics, and category-specific modifiers. 2. **Calculation Score** — aggregate weighted sub-scores across Security, Financial, Operational, Reputational, Regulatory, and Dependency domains, with the Scale modifier. 3. **Score Conversion** — invert the calculation score into the final PoL value (0–100) and map it to a credit-style rating tier. ### Security domain metrics - **Audit Coverage (weight 16%).** Audit relevance, status of Medium/High/Critical findings, code comparison (deployed vs audited), and reviewed scope percentage. Reviewed scope sub-scores: 91–100% = 10, 81–90% = 9, 71–80% = 8, 61–70% = 7, 51–60% = 6, 41–50% = 5, 31–40% = 4, 21–30% = 3, 20% and under = 2. - **Bug Bounty (weight 14%).** Custody (7%), Pay-out policy (7%), Attestation letter (0%), Proof of Funds (0%). - Custody: third-party hosted = 10, self-hosted = 5, disclosure policy only = 2. - Pay-out policy: $250k+ = 10, $100k–$250k = 8, $50k–$100k = 5, $10k–$50k = 3, under $10k = 1. - Team response rate: within 1 day = 10, within 3 days = 5, within 1 week = 2, longer than 1 week = 0. - Proof of Funds: present = 10, absent = 0. - **Third-party monitoring (weight 5%).** Monitoring enabled = 10; proper third-party set up = 10. - **Prevention (weight 0%, informative).** Third-party set up = 10; none = 0. ### Financial domain metrics - **Revenue sources.** Categorised across protocol fees, marketplace commission, staking-as-a-service, premium/SaaS, licensing, enterprise partnerships, treasury yield, IDO/launchpads, ads, consulting, validator rewards, and token pump. Source dependency: one consistent source > one inconsistent > multiple consistent > multiple inconsistent. - **Inflation (weight 5%).** 0–5% per year = 10, 5–10% = 7, 10–15% = 5, 15–20% = 3, ≥25% = 0. - **TVL (weight 1%).** Trend (0.8%) and Suspicious Spikes (0.2%). Uptrend = 10, range = 5, downtrend = 0. Suspicious spikes present = 0, absent = 10. - **Active addresses.** Unique wallets meaningfully interacting with the project token. - **Treasury quality (weight 2%).** Top-tier asset structure = 10, treasury >50% native token = 5, native token only = 3. - **Circulating supply (weight 5%).** Same as reference = 10, up to 5% difference = 0, different = -5. - **Lockers (weight 2%).** Third-party audited = 10, self-hosted timelock = 7, multi-sig + delay = 5, vesting/yield vault = 3, burn-address lock = 2, off-chain promises = 0. ### Operational domain metrics - **Wash trading.** Above average = -5, average/below average = 0. - **GitHub activity (weight 1%).** Last week activity present = 10; none = 0. - **Founders with track record (weight 1%).** Education (0.33%), working experience (0.34%), business experience (0.33%) — each scores 1 if relevant, 0 if not. - **Proper Documentation (weight 2%).** White paper, tokenomics, contracts disclosure, verified contracts (each 0.4%); roadmap and roadmap reporting (each 0.2%). - **Certifications (weight 10%).** ISO 27001 = 10. CCSS Level 1 = 5, Level 2 = 7, Level 3 = 10. None = 0. - **Liquidity risks (weight 6%).** DEX LP-to-mcap, CEX volume-to-mcap, CEX orderbook-to-mcap (1% each), Quality of CEXs (2%), DEX LP state (1%). CG Trust Score 9–10 = 10; 7–8 = 8; 5–7 = 5; ≤5 = 0. DEX LP locked = 2; unlocked = 0. ### Reputational domain metrics - **Past incidents reaction (weight 1%).** Media reaction (alert/week/passive/strong) and "root cause fixed" sub-score (yes = 10, no = 0). - **Audit Firm Reputation (weight 3%).** Top tier = 10, mid = 7, low = 3, no tier = 0. - **Social Fraud (weight 2%).** Twitter Score (bad/good/excellent = 0/5/10), bot ratio, Twitter interactions, website visits, trends check. - **Insurance (weight 2%).** Custody and Coverage sub-scores; third-party hosted = 10, self-hosted = 5; complete coverage = 10, average = 7. - **Project Longevity / Protocol Longevity (weight 1% each).** 5+ years = 10, 3+ = 7, 1–3 = 5, newly created = 0. - **Penalties.** Market-maker red flag identification and investor red flag identification: from 0 to -10 each, based on lists of suspicious representatives. ### Regulatory domain metrics - **Disclaimers (weight 0.5%).** Present = 10, absent = 0. - **Public registration (weight 0.5%).** Present = 10, absent = 0. - **Public team (weight 0.5%).** Public = 10, anonymous = 0. - **Regulatory Surface Controls (weight 0.5%).** Presence of KYC/KYT where relevant. - **Jurisdiction (weight 1%).** Tier 1 = 10, Tier 2 = 7, Tier 3 = 4, Tier 4 = 2. - **Regulatory compliance (weight 2%).** Operates under regulation = 10; one entity under regulation = 5; none = 0. ### Scale modifier (The Scale, x1.6 max) - Maturity (x1.3): Category Leading x1.1 (Top 5 by category), Licensed x1.1, Proved x1.1 - Project Pulse (x1.3): Development Activity x1.15, Social Markers x1.15 ### Score conversion (Calculation Score → PoL → Grade) - 0–25 → PoL 75–90 → D - 25–30 → PoL 70–75 → DD - 30–40 → PoL 60–70 → DDD - 40–45 → PoL 55–60 → C - 45–50 → PoL 50–55 → CC - 50–60 → PoL 40–50 → CCC - 60–65 → PoL 35–40 → B - 65–70 → PoL 30–35 → BB - 70–80 → PoL 20–30 → BBB - 80–85 → PoL 15–20 → A - 85–90 → PoL 10–15 → AA - 90–100 → PoL 0–10 → AAA ### Seals for projects - **Security Measures Seal:** awarded when a project has simultaneously implemented audit with 80%+ coverage, a third-party bug bounty program, and third-party monitoring enabled. - **Independent Certificates Seal:** awarded when a project holds ISO 27001 (or SOC 2) AND CCSS certification. - **Self-Regulation Seal:** awarded when the project has voluntarily submitted >10% of the required information. --- ## Page: Exchange Methodology (https://core3.io/methodology/exchanges) The exchange methodology assesses three core risk areas: Security (50%), Solvency (30%), and Transparency (20%). Some data may not be publicly available and must be submitted by the exchange. ### Security category metrics - **Server Security (weight 6%).** SSL/TLS Certificate (A+ = 10 down to F = 1, T or M = 0), WAF and CDN Presence (Yes = 10), Email and DNS Security (SPF/DKIM/DMARC/DNSSEC each = 2.5), HTTP Headers (A = 10 down to F = 0), Cookie Flags (HTTPOnly = 5, Secure = 3, SameSite = 2). - **User Security (weight 7.5%).** 2FA (Yes = 10), Password Requirements (length ≥8 = 3, length >64 = 1, block breached/common = 3, allow paste/managers = 3), Device Management (session list = 5, terminate others = 5), Anti-phishing Code (Yes = 10), Withdrawal Whitelist (Yes = 10), CAPTCHA (Yes = 10). - **Certifications (weight 10%).** ISO 27001 (Yes = 10); CCSS Level 1 = 5, Level 2 = 10, Level 3 = 10. - **Bug Bounty (weight 12.5%).** Third-party hosted = 10, self-hosted = 5, none = 0. - **Penetration Test (weight 12.5%).** Requires comprehensive scope (trading platform, wallet systems, authentication, databases, APIs, web and mobile apps); recognized methodologies (OWASP, NIST, PTES, blockchain guidelines); internal, external, and cloud testing; full report with severity, PoC, and remediation; tester independence (PCI DSS, NIST, OWASP, PTES, MITRE ATT&CK, SANS, OSSTMM); report relevance not older than 1 year; testing environment validated. - **Insurance Fund (weight 1.5%).** Yes = 10. ### Solvency category metrics - **Proof of ownership.** Audit must confirm that audited funds belong to the exchange. If not confirmed, User Scope and Reserves Assets Scope both = 0. - **Users scope (weight 15%).** 100% coverage = 10; 75% or 50% = 0. - **Asset Composition in Total Reserves (weight 6%).** High-quality assets = 10; 1:1 coverage = 10; reliance on own token = 0; mixed quality = 7; low quality = 3. - **Frequency.** Less than yearly = 0; yearly = 0.5; twice yearly, quarterly, monthly, daily, live = 1. Reports older than one year lose all User Scope and Reserves Assets Scope points. - **Merkle tree (weight 9%).** Self-developed = 5; self-developed audited = 10; third-party developed = 10. ### Transparency category metrics - **Live reserves wallet tracking (weight 10%).** Submitted list of wallets = 10. Proof of Ownership multiplier x1 if confirmed; x0 if not. - **Incident response quality (weight 10%).** Response Time (3%; high = 3, moderate = 2, low = 1), Data disclosure (4%; KYC details = 2, transaction flow = 2), Actions taken (3%; funds freeze = 3, withdrawal cooldown = 2, KYT = 1). - **Last liabilities snapshot value.** Live access required for full transparency. - **Coverage ratio.** Live access required. - **Reserves assets distribution.** Live access required. ### Score conversion Same Calculation Score → PoL → Rating mapping as for projects (see Project Methodology above). ### Seals for exchanges - **Security Seal:** Security section score 80%+. - **Solvency Seal:** Solvency section score 80%+ with verified proof of reserves and financial stability. - **Transparency Seal:** Submission of wallets for on-chain tracking within the CORE3 platform. ### CoinGecko Trust Score Impact CoinGecko's Cybersecurity metric is calculated based on the CORE3 Security Section score. CORE3 Security Score bands: <50 = 0, 50–70 = 1, 70–80 = 1.5, 80–100 = 2. CoinGecko Trust Score breakdown: Liquidity 5.0, Regulation 1.5, Cybersecurity 2.0, Incident 1.0, Proof of Reserves 0.5. --- ## Blog: The State of Digital Asset Risk Data Is Now Public - URL: https://core3.io/blog/core-3-news/the-state-of-digital-asset-risk-data-is-now-public - Category: core-3-news - Author: Dmytro Zaporozhchenko - Published: 2026-04-07 CORE3 publicly released one of the largest digital asset risk benchmarks, with 1,600 projects indexed on risk. The article argues that until recently there was no shared way to measure crypto risk because risk data was fragmented across audit PDFs, reserve attestations, TVL charts, and other unrelated sources, making cross-project comparison impossible. The article frames CORE3's public release as the moment that the state of digital asset risk data finally became publicly comparable. --- ## Blog: Crypto Risk Assessment Needs More Than TVL - URL: https://core3.io/blog/core-3-news/crypto-risk-assessment-needs-more-than-tvl - Category: core-3-news - Author: Dmytro Zaporozhchenko - Published: 2026-04-09 Crypto risk assessment cannot rely on TVL or market cap alone because institutions need a real, shared way to evaluate risk across protocols, chains, and asset types. Without shared standards, institutions are forced to build their own internal risk programs, models, and checklists. The article cites Coinlaw reporting that in 2025, 72% of institutional Web3 participants ran formal crypto risk programs internally, underscoring the absence of a shared risk standard that PoL is designed to fill. --- ## Blog: Risk Assessment Methodology — How PoL Turns Documented Failures Into a Risk Score - URL: https://core3.io/blog/core3-guides/crypto-risk-assessment-methodology-how-probability-of-loss-turns-documented-failures-into-a-risk-score - Category: core3-guides - Author: Dmytro Zaporozhchenko - Published: 2026-04-09 PoL reverse-engineers $48B+ in documented crypto failures into 85+ assessments across six risk domains, applied to 1,600+ Web3 projects and exchanges. The piece explains why current crypto risk assessment is broken, walks through how projects are assessed, why specific risk domains deserve closer scrutiny before failures happen, what historical failures led to specific metrics being included, and how CORE3 makes comparable risk assessments between vastly different categories (e.g. memecoin versus privacy blockchain) using 29 project categories on the same scale. --- ## Blog: Crypto Risk in 2026 — Why 75% of Web3 Exploits Happen Outside Smart Contract Audits - URL: https://core3.io/blog/core3-guides/crypto-risk-in-2026-why-75-of-web3-exploits-happen-outside-smart-contract-audits - Category: core3-guides - Author: Dmytro Zaporozhchenko - Published: 2026-04-24 Despite heavy spending on smart contract audits since 2020, attackers have still extracted at least $10B from Web3 protocols, with roughly 75% of that capital drained through issues no audit was scoped to check. The Kelp DAO exploit illustrates how audited contracts were still compromised through a single-point-of-failure dependency. The piece frames the shift of risk away from code and toward people, policies, infrastructure, and third-party dependencies, and explains how to assess off-chain risk before listing or investing. --- ## Blog: Post-Exploit Recovery Quality — The Strongest Predictor of Whether a Crypto Protocol Will Be Hacked Again - URL: https://core3.io/blog/web3-risks/post-exploit-recovery-quality-the-strongest-predictor-of-whether-a-crypto-protocol-will-be-hacked-again - Category: web3-risks - Author: Dmytro Zaporozhchenko - Published: 2026-05-01 Post-exploit recovery quality is a measure of how a crypto project responds after a security incident, assessed across five publicly observable dimensions: communication discipline, root cause analysis, structural change, user compensation, and third-party validation. The article contrasts Cream Finance (exploited three times in 2021 with ~$186M total losses and minimal post-incident response) against Euler Finance (one exploit in March 2023 for ~$197M, with ~$240M recovered within three weeks via structured negotiation, a long-form forensic post-mortem, and a modular V2 rebuild). The argument is that response quality is more reliable than audit history, TVL, or pre-incident reputation as a predictor of future exploits. --- ## Blog: Time — The Missing Layer in Your Blockchain Risk Model - URL: https://core3.io/blog/web3-risks/the-missing-layer-in-crypto-risk-models-time - Category: web3-risks - Author: Dmytro Zaporozhchenko - Published: 2026-05-11 Crypto risk reputation can lag reality in both directions: some projects become safer after a public incident, while others fail weeks after appearing clean. The article uses LayerZero's 1-of-1 DVN configuration as a case study, noting that the single point of failure helped drain $292M from Kelp DAO on April 18, 2026, and that LayerZero ended support for 1-of-1 DVN configurations on May 9, shifting defaults to 5-of-5 or at minimum 3-of-3 verifiers. The core argument is that time-related parameters are missing from many crypto risk models, so static scores often describe where projects were rather than where they are. --- ## Blog: How to Stop Crypto Losses? Start Acting on Crypto Risks - URL: https://core3.io/blog/core3-guides/how-to-stop-crypto-losses-start-act-on-crypto-risks - Category: core3-guides - Author: Dmytro Zaporozhchenko - Published: 2026-05-18 Crypto reacts to losses, not to risk. Warnings are routinely identified before losses occur but action is often delayed until after money is lost. The article cites a period from April 1 to May 14 in which $625M was extracted from 21 protocols, and argues that the industry needs risk standards that can measure risk before exploits happen. The piece frames CORE3 as aiming to close the gap so that risk affects revenue, listings, and partnerships before losses occur rather than after. --- ## Blog: Fake Signals You Trust in Web3 - URL: https://core3.io/blog/web3-risks/the-cost-of-fake-trust-signals-in-web3 - Category: web3-risks - Author: Dmytro Zaporozhchenko - Published: 2026-05-21 Many common Web3 trust signals — market cap, audit badges, TVL, investor logos, and follower counts — can be manufactured and often do not indicate actual safety or trustworthiness. Projects may perform well on these surface metrics while remaining structurally vulnerable to exploits. The article walks through which signals can be faked, how they are faked, what genuinely non-fakeable signals look like, and what PoL measures instead. --- ## Positioning and discipline (canonical claims) ### What we say - PoL quantifies likelihood of loss / exposure to risk using measurable parameters. - PoL is comparative and continuously updated. - PoV provides structured context, separate from PoL. - CORE3 is the global self-regulatory risk infrastructure layer for digital assets. ### What we never say - "We certify projects." - "Low PoL = safe." - "We predict price." - "We are Moody's / S&P for crypto." (Analogous in function if needed, but used carefully.) ### Differentiation summary - A single, comparable risk index built from explicit risk parameters and deterministic logic. - Data plus human context without contamination (PoV is separated from PoL). - Infrastructure for workflows (dashboards, comparing, portfolios, monitoring, screening) — not opinions. - Self-regulatory by design — industry-led standardization without "regulator cosplay". ### Disclaimer CORE3 is an independent analytics platform offering a data-driven Probability of Loss framework to quantify risk in Web3 projects. It is not a ratings agency, and its metrics do not constitute investment advice. A low PoL does not mean a project is certified, approved, or risk-free. Assessments are based primarily on publicly available data; some assessed projects may have mitigation measures or controls in place that are not visible.