A DeFi risk-rating firm initially graded Valantis stHYPE at CCC+ in February 2026 based only on public info. The low grade reflected poor visibility: undisclosed multisig, no public monitoring docs, an unexplained admin key transfer, not weak engineering (three audits, no leverage).
Over four collaborative review rounds, the team closed the gaps: publishing monitoring and governance docs, then shipping irreversible on-chain changes: restructuring the multisig (3/5 → 4/6 with disclosed signers), adding a 48-hour timelock, and removing admin transfer controls. All ten High-Risk findings were resolved, lifting the grade to BB+.
Remaining gaps are structural: no bug bounty, 90-day lockups, small team, thin treasury, no live governance. Ceiling: AA+. The takeaway: iterative, adversarial review fits DeFi better than static credit ratings.
When we first rated Valantis stHYPE in February 2026, it received a CCC+ - a High-Risk grade that places a protocol in the venture-level risk category. Two months and four review rounds later, stHYPE holds a BB+ - an Elevated Grade that reflects a protocol with strong fundamentals and a credible improvement trajectory. This is the story of how that happened, and why we believe collaborative risk assessment is the right model for DeFi.
Capital allocators entering DeFi face a fundamental problem: there is no standardized way to assess risk. Every protocol claims to be secure, every team says they're transparent, and every set of docs says the right things. But when you're deciding whether to stake $50 million into a liquid staking token, "trust us" isn't an investment thesis.
Our DeFi rating framework was built to address this. It evaluates protocols across three dimensions - Security, Strategy, and Operations - using 86 questions with explicit criteria for Low, Mid, and High risk at each level. The framework is deterministic: if you know the facts, you can derive the score. There's no room for subjective "this feels safe" assessments. It produces letter grades from AAA to D, similar to credit ratings - but unlike traditional credit ratings, our process is designed to be iterative. DeFi protocols can ship changes in days. A rating process that doesn't account for that speed is broken by design.
Our first assessment was based entirely on publicly available information: documentation, on-chain data, audit reports, and block explorer analysis. No calls with the team, no private disclosures - just what any allocator could find on their own.
The engineering fundamentals were strong. Core contracts had been independently audited by three firms - Pashov, Three Sigma, and Guardian - with all findings remediated. Yield was sourced from native HYPE staking with no leverage. Validators were diversified across Europe and Asia. The exploit history was clean.
But the gaps were significant - not in engineering, but in visibility:
The overall CCC+ grade - ten High-Risk findings, seventeen Moderate-Risk - was accurate for what was publicly visible. The problem was that "publicly visible" was only a fraction of the actual story.
We shared the first review report with the Valantis team and scheduled calls to walk through the framework: how each question works, what the criteria require, and what concrete actions would change the assessment. This wasn't a negotiation over grades. It was a structured conversation: here is what we found, here is what the framework requires, and here is what we need to see as evidence.
The team's reaction set the tone for everything that followed. They focused on understanding the gaps. "What specifically would we need to publish for the monitoring finding to improve?" "Does the framework accept internal practices as evidence, or does it need to be public?" "If we ship a timelock, does a roadmap commitment count, or does it need to be on-chain?" The answers were consistent: the framework scores based on verifiable evidence, not intent. The team understood this and got to work.
The first response addressed 24 findings. Twelve saw score improvements - everyone driven by new documentation and transparency. The most transformative change was a comprehensive Monitoring and Incident Response page documenting automatic on-chain safety checks, a Safety Control Matrix, severity-based escalation, and timezone-distributed on-call coverage. Two of the highest-impact security findings moved from High-Risk to Low-Risk based on this disclosure alone.
The team also published a Roles and Controls Registry - a canonical source documenting every administrative role across all contracts, with a dated changelog linking to on-chain transactions. This resolved the undocumented admin key transfer that had raised transparency concerns. An incident response playbook covering key-compromise and signer-loss scenarios was published, and the team disclosed the protocol's financial self-sustainability with a comfortable operational runway.
But twelve questions saw no score change despite responses. When the team published a governance page confirming intent to implement timelocks, we explained the framework requires an actual on-chain timelock - not a roadmap. When they described internal incident rehearsals, we noted that Low-Risk requires public evidence of formal tabletop exercises. This round established the dynamic: documentation improvements counted when they met the evidentiary bar. Promises didn't.
The second round was smaller - five targeted follow-ups. Treasury reserves were disclosed, moving two financial resilience findings from High-Risk to Moderate-Risk. The team asked whether publishing the multisig threshold alone would help - we explained the framework requires both threshold AND independently verifiable signers. They took this feedback and came back with a full solution later.
The team also asked a broader question: "Is not having a treasury truly non-standard? Most LSTs aren't insurance-backed." Our framework evaluates against absolute criteria of adequate financial resilience for capital allocators, not industry norms. The absence of a backstop is a risk regardless of what peers do.
The third round addressed 22 findings, but changed character - the team pushed back on several scoring decisions. The most substantive refutation concerned CoreWriter. We had scored it as a bridging mechanism, but the team argued it's a native precompile in the Hyperliquid state machine - HyperCore and HyperEVM share a single unified state under the same consensus. We reviewed the architecture, agreed, and updated two findings: 0% of TVL relies on bridged assets, and no single infrastructure component outside the base chain can block withdrawals.
The team also published two stHYPE Health Reports covering stress events, meeting our criteria for demonstrated resilience. And they corrected our language on audit findings - no critical findings exist in any stHYPE audit, only two highs, both resolved. But this round produced only three score improvements out of 22 responses. That ratio matters: the process wasn't rubber-stamping. Most acknowledgments confirmed the current state was correctly scored and improvement required concrete action, not better arguments.
The final round was the most consequential. Instead of documentation, the team shipped code. On April 7, they overhauled the multisig: the threshold increased from 3/5 to 4/6, all six signer addresses were publicly disclosed, and two signers were rotated to a more secure setup. This resolved what had been one of the highest-impact gaps since day one.
Three days later, two protocol-level upgrades landed. First, all stHYPE proxy contracts were migrated to an OpenZeppelin TimelockController, which imposes a mandatory 48-hour on-chain delay on every contract change and has no bypass mechanism. Second, the setSelfDisableTransfer function was removed from stHYPE and wstHYPE, permanently eliminating admin-controlled address-level transfer restrictions.
These weren't cosmetic changes. They were irreversible on-chain commitments that any allocator can independently verify. And they happened because the team understood exactly which criteria they needed to meet and chose to invest engineering time to meet them.
Over two months and four review rounds, the Valantis team addressed 52 findings. Eighteen saw score improvements. All ten initially High-Risk findings were resolved. Three on-chain protocol changes were deployed - the multisig restructuring, the protocol-wide 48-hour timelock, and the removal of admin-controlled address transfer restrictions.
| Category | Initial Grade | Final Grade |
|---|---|---|
| Security | CCC | BBB |
| Strategy | BB | BBB |
| Operations | CCC- | B |
| Overall | CCC+ | BB+ |
The radar chart below visualizes the improvement across all twelve subcategories. The largest gains are in Key Management, Financial Resilience, Governance, and Documentation - areas where the initial score was depressed by missing disclosures rather than weak fundamentals. Subcategories like Protocol Mechanics and Market were already strong and remained flat throughout the process.
Security saw the largest improvement because the gaps were visibility failures, not engineering failures. The protocol already had good practices - they just weren't public. Strategy improved moderately, constrained by structural realities as non-standard stake accounts with 90-day lockups. Operations showed the broadest improvement but remains the weakest category due to limited financial backstop and opaque legal structure.

Not everything improved. Thirteen findings remain at Moderate-Risk, and some constraints are structural:
The honesty of the "no change" column is what makes the process credible. When the team acknowledged findings without improvement - and many April responses were simply "Acknowledged" - the scores remained unchanged.
stHYPE has a mapped path to investment-grade territory. The two highest-impact remaining improvements - bug bounty and tabletop exercises - are entirely within the team's control. Adding a formal backstop reserve and transitioning to on-chain governance would close the remaining gaps. The potential grade sits at AA+. The trajectory is clear, and the team has demonstrated the capability to close it.
Traditional credit ratings are point-in-time verdicts designed for entities that change slowly. DeFi protocols don't work that way - a team can deploy a timelock on a Tuesday, restructure their multisig on a Thursday, and remove an admin capability on a Friday. A rating process that can't incorporate that speed produces ratings that are stale before they're published.
Three factors made this work. A deterministic framework - the team could read it, identify gaps, and know exactly what was required. A team that shipped, not just talked - the biggest improvements came from irreversible on-chain changes, not promises. Structured disagreement - when the team brought evidence that our factual basis was wrong, we changed the score; when they didn't, we explained why it held.
The result is a risk report that institutional allocators can use with confidence - not because it's lenient, but because it reflects the protocol's verified current state after a thorough, adversarial review process. The CCC+ was accurate for February. The BB+ is accurate for today. We plan to offer this collaborative review process to every protocol we rate going forward.
Join 12,000 institutional allocators worldwide. No spam, unsubscribe anytime.
