In March 2024, I received a two-hundred-page blockchain analysis report from a mid-tier investment fund. The document contained nine analytical dimensions, color-coded risk matrices, and a proprietary scoring algorithm. The cover page listed six analysts' names with CFA and CPA credentials. The executive summary concluded that the target protocol showed "moderate promise with identifiable risk factors." When I asked which protocol they had analyzed, the lead analyst admitted they had reviewed a document that mentioned no specific project name, team members, or technical architecture.
The entire exercise had consumed forty billable hours and produced output that could be generated by a script feeding random data into a template.
This is the state of due diligence in crypto: elaborate frameworks that function perfectly in the absence of information.
The document followed a standard format that has become industry convention across crypto research firms, family offices, and exchange listing committees. Nine dimensions, each subdivided into categories, each category populated with assessment criteria. The visual design suggests rigor. The methodology section cites academic papers on portfolio theory and stochastic modeling. The conclusion employs probabilistic language—"high confidence," "moderate probability," "elevated risk"—that sounds analytical without committing to anything falsifiable.
I recognized the template immediately because I helped design an early version of it in 2019, when I was consulting for a DeFi aggregator that needed "institutional-grade" evaluation criteria for the protocols they would integrate. The framework was meant to impose structure on messy, ambiguous data. It was never meant to operate without data.
The core insight is elementary: a scoring system applied to nothing produces nothing, and that nothing can be dressed in the language of expertise.
Consider what happens when the "technical analysis" dimension receives no input. The template still requires an assessment. The analyst marks "N/A - information insufficient" and moves to the next section. The document still has a "technical analysis" section. It occupies space. It creates the impression that technical factors were evaluated when, in fact, they were not. A reader who scans the table of contents sees nine dimensions addressed. They do not see that seven of those dimensions contain only placeholder text.
This is not a formatting issue. This is a fundamental epistemological failure disguised as methodological rigor.
The proof is in the logic, not the promise.
The nine-dimension framework, like its cousin the "tokenomics scorecard," operates on a category error. It conflates comprehensiveness with thoroughness. Listing more categories does not compensate for shallow evaluation within categories. A protocol can score perfectly on "governance decentralization" while having its entire voting power concentrated in three multisig wallets controlled by the founding team—but the framework will catch this only if the analyst actually examines the on-chain governance data, not if they mark the field N/A and proceed.
In 2020, I reviewed a Yearn Finance vault strategy document that had received a "security: low risk" rating from an external auditor. The auditor had checked the mathematical logic of the yield optimization algorithm and confirmed it was sound. They had not modeled what happens when the algorithm encounters the liquidity conditions that actually exist in DeFi markets. The theoretical optimum and the practical outcome diverged by forty percent under realistic slippage assumptions. The framework had evaluated "security" as a property of the code, not as a property of the code operating in adversarial market conditions.
Yields are just risk wearing a tuxedo. The same principle applies to analysis frameworks. Elaborate structure is risk (of intellectual laziness) wearing a three-piece suit.
The bull market has accelerated this pathology. When prices are rising, limited due diligence still generates returns. The opportunity cost of thorough research becomes apparent only when alpha dissipates and the protocols that survived only on momentum reveal their structural weaknesses. The funds that performed due diligence by checking boxes during the 2021 cycle are mostly inactive now. The protocols they evaluated—many of which scored highly on the nine-dimension framework—are largely irrelevant.
The current cycle presents a more insidious version of the same failure mode. Teams have learned to optimize for the frameworks. They produce documentation that addresses each dimension explicitly. They include governance proposals that look decentralized. They publish tokenomics models with plausible emission schedules. The framework evaluates what is presented rather than what is hidden. Complexity is the camouflage for incompetence—or, in this case, for the absence of substance.
A protocol that genuinely requires no due diligence will have simple, boring documentation. The team will be identifiable and answerable. The smart contract code will be boring. The token distribution will show no mysterious wallets with early-round allocations that mysteriously appear at launch. The governance will involve actual token holders making actual decisions.
A protocol that has been optimized for due diligence frameworks will have the opposite characteristics. The documentation will be comprehensive. The governance model will be elaborate. The tokenomics will include hedging mechanisms and dynamic emission adjustments. The team will be pseudonymous but backed by a legal opinion from a respected firm.
Assume malice, verify everything, trust neither.
I do not claim that all protocols optimized for frameworks are fraudulent. Some teams simply understand that institutional capital requires institutional-grade documentation. But the correlation between framework-optimized presentation and underlying substance is weak enough that treating them as proxies for each other is a category error.
The contrarian angle here is uncomfortable: the frameworks themselves are not wrong. Nine dimensions are appropriate. Tokenomics scoring is useful. Risk matrices are necessary. The failure is not in the structure but in the execution. The frameworks assume that analysts will exercise judgment within each dimension—will notice when the governance data suggests concentration rather than decentralization, will flag when the token distribution shows insiders accumulating ahead of public launch, will question why the "mysterious wallet with early allocation" pattern appears in so many protocols that score highly on decentralization metrics.
Static analysis reveals what marketing hides. The frameworks were designed to standardize the application of judgment, not to replace it. A template that produces output regardless of input is not a template; it is a generator of noise.
What would actual due diligence look like? It would start with identifying the specific question the analysis is meant to answer. Is this a security audit? A tokenomics review? A market positioning assessment? Different questions require different data. A single framework cannot answer all questions simultaneously without answering none of them well.
It would require the analyst to state explicitly what information they used and where it came from. Not citations of "project documentation" but specific document names, specific commit hashes, specific on-chain data queries with timestamps. It would require the analyst to acknowledge uncertainty rather than dress it in probabilistic language.
Most importantly, it would require the analyst to say "I don't know" when they don't know. Not fill the space with N/A and proceed. Not produce twenty pages of template output. Simply state that the information required for the assessment is not available and that any conclusion reached without that information is invalid.
This is a radical proposal in an industry where showing up with a report—even an empty one—creates the appearance of diligence. Where the cost of producing a bad report is lower than the cost of producing no report. Where the incentive structure rewards comprehensiveness over accuracy.
The solution is not better frameworks. The solution is better incentives for analysts to say what they actually know.
Until that shift occurs, the nine-dimension framework will continue to produce elegant documents that tell readers nothing. The bull market will continue to reward limited diligence. The protocols optimized for frameworks will continue to attract capital while the protocols that actually work—who have boring documentation and named teams and transparent token distributions—will struggle to raise.
I have no expectation that this dynamic changes. The fundamental incentives are structural. But for the individual analyst or investor who reads these words, the takeaway is operational: when you encounter a framework output, ask first what information went into it. If the answer is "not much," then the output is decorative, not analytical. The three-hundred-page report is a costume, not a contribution. And the protocol it evaluates is still an unknown quantity, regardless of how many dimensions it ostensibly addressed.
The next time a due diligence report crosses your desk, check the methodology section for data sources before the executive summary for conclusions. If the data sources section is vague, the conclusions are too. This is not a heuristic. It is a proof.