Credora brings DeFi risk ratings to Tydro v2
BACK TO BLOG
August 25, 2026·9 min read

Credora brings DeFi risk ratings to Tydro v2

Credora is coming to Tydro. The protocol’s v2, already in active development, will feature Credora’s ratings on the UI for select assets and markets, enabling the users, including institutional allocators, to make more informed decisions with the help of independent estimates.

What stays beyond the white label

Tydro and Aave

Tydro is a decentralized non-custodial liquidity and lending protocol built on Ink, Kraken’s Ethereum Layer-2 network. With a TVL of $61M+ at the time of writing, it accounts for almost half of its native chain’s overall DeFi TVL and acts as the native credit and lending layer for the Ink blockchain ecosystem.

Architecturally, Tydro is running a white-label deployment of Aave v3, a battle-tested platform that is widely used around DeFi. The terms are as follows: Aave DAO licenses the code making up the core of Tydro’s onchain backend. In exchange, as the same Aave Request for Comment (ARFC) establishes, it gets “a share of all revenue generated by the platform. This should be greater than or equal to the equivalent of a Reserve Factor of 5% based on borrow volume in all pools.”

Looking at the familiar smart contracts, it may be tempting to presume that supporting those is the same risk apparatus. That is not the case. Aave DAO holds no votes on Tydro listings, as “the instance will initially be centrally governed without a governance token.” BGD Labs, Aave’s core dev team, echoes this: “the decision to include/not to assess in the listings set is of the friendly fork manager, not ours.” Should Tydro markets accumulate bad debt, Aave Umbrella would not cover it: “This instance will not be covered by the DAO-operated Umbrella.” 

Aave Risk Stewards are also beyond the scope of the white-label relationship. These mechanisms enable trusted entities to adjust risk guardrails on specific markets without a governance vote, enabling emergency responses, but Tydro’s deployment does not carry over that mechanism. The code is there, the risk management infrastructure around it isn’t.

None of that is unusual. Neither is it immediately obvious to an asset allocator considering capital deployments on Tydro. Credora is joining it as a risk intelligence engine for select markets to close that gap.

Credora on Tydro v2: A DeFi risk rating engine 

As part of the partnership with Tydro, Credora will be providing A+ to D risk ratings to all assets and markets with exposure to $kBTC and $USDC, will be open for any users to check via the Tydro interface or the Credora app. For markets, the ratings will be based on Probability of Significant Loss (PSL), which refers to the annualised probability of losing more than 1% of principal over a one-year horizon. For assets, the ratings will be based on the Probability of Default (PD), the annualised probability of a default event.

The PSL or PD estimates for a specific market or asset respectively are based on onchain data-driven simulations as well as additional risk factor simulations. A PSL estimate begins with 100,000 Monte Carlo simulations of price movements, liquidity conditions, and correlated market shocks for the market’s collateral. The proportion of cases where losses go over 1% on a one-year time horizon makes up the PSL. Five additional risk factors (smart contract risk, liquidity risk, oracle risk, counterparty risk, collateral quality) are simulated independently, adjusting the final rating up or down. 

A PD estimate, for its part, is based on a specific asset type, including direct rating for reserves comprising rated tokens, agency-published cumulative default rates for assets like T-Bills, and Monte Carlo simulations for crypto-native reserves. Similarly to PSL, PD can also go up or down based on additional modifiers. In both cases, the outcome is converted into a letter-based rating varying from A+ to D; you can learn more about the methodology in Credora’s documentation.      

For an asset allocator on Tydro, the Credora rating is an independent read on the downside that Aave’s apparatus would otherwise be assessing on their behalf. It will give them a point of reference that’s immediately familiar to anyone well-versed in the TradFi risk language, with Credora’s letter-based ratings reading similarly to the industry’s conventions. For instance, a Credora A rating corresponds to a PSL of roughly 0.1%-0.4% annually, comparable to an investment-grade BBB rating in traditional credit markets. Even more importantly, the rating will be delivered by an independent entity based on a well-documented methodology that the decision-maker can inspect and run against the internal policies. 

As a result, capital allocators on Tydro v2 will be able to compare the risk profile of the rated markets both within the platform and across the other vaults rated by Credora, all on the same axis. The comparability is the benefit, and more effective decisions that are easier to defend before an internal risk committee are its outputs.

Tydro strategy: Don’t inherit, build

While it may not be immediately obvious why a DeFi platform may want risk ratings right at a launch, an incident Tydro was forced to withstand earlier this year puts this into perspective, revealing the protocol’s underlying strategy. 

On May 4th, Chaos Labs, the sole price data provider powering all markets on Tydro from the get-go informed the platform about a suspected nation-stale level attack on its infrastructure, recommending a temporary operational halt. Tydro heeded the advice.

Further investigation revealed that the incident was limited to Chaos Labs’s operational wallets for routine onchain activities, with no manipulated prices reaching Tydro at any point during the crisis and no user positions affected. The price data provider gave Tydro a green light to go back online.

Nevertheless, Tydro chose to extend the halt and migrate the price feeds, with Chainlink as the primary provider and RedStone as the redundancy layer. As the markets reopened on May 10th, it unveiled a short grace period with liquidations halted and LTV temporarily set to 0, giving borrowers a time window to protect their positions if needed before the operations resumed as usual. 

Later in the year, it announced a failsafe two-oracle structure coming up in Tydro v2, with the strategic redundancy deepened across all markets to ensure continuous operations even if one provider is compromised. It also implemented Hypernative’s Transaction Guard to simulate and screen multisig transactions in real time across Ethereum, Optimism, and Ink, automatically blocking actions that violate security policies before they execute.  

When facing a crisis, Tydro halted the markets and decided against a green light from another party in favor of a more complicated migration and a restart that protected the borrowers. This behavior reveals the same logic that now drives the Credora integration: instead of relying on inherited risk mechanisms, it builds its own one. 

A look beyond the scope

While Credora’s ratings make for a useful decision-making and comparison tool, it’s important to be clear-eyed about what they mean. The ratings price the downside on the rated collateral or market. They do not amount to an end-to-end assessment of any given protocol, network, or asset, or a claim that a specific investment product is risk-free. 

By the same account, while the Credora methodology clearly delineated the main risk surfaces it accounts for, anything beyond those is similarly beyond its scope. For instance, Credora does factor a protocol’s security track record into its ratings, but does not conduct in-depth audits of its entire code base. The explicitly limited scope of the ratings is part of the value they bring to the table.

Tydro’s risk intelligence engine

With the launch of Tydro v2, Credora will work as part of its DeFi risk intelligence layer, covering  all assets and markets with exposure to kBTC and USDC. It will rate the markets and their collateral assets on an A+ to D grade scale, against the same methodology it uses for dozens of others, enabling capital allocators to make more informed decisions.

Frequently asked questions

What’s the difference between Probability of Significant Loss (PSL) and Probability of Default (PD)?

Probability of Significant Loss (PSL) is the annualised probability that a market or vault loses more than 1% of principal over a one-year horizon, and it’s the metric Credora uses for markets and vaults on Tydro. Probability of Default (PD) is the annualised probability of a default event, and it’s the metric used for individual assets like kBTC and USDC. Both are converted onto the same A+ to D letter scale, so they can be compared side by side even though they measure different things, and confusing the two is one of the most common mistakes when discussing Credora ratings.

Does a Credora A+ to D rating mean a Tydro market or asset is safe?

No. A Credora rating prices the downside on a specific rated market or asset based on a defined set of risk factors, and it isn’t an end-to-end audit of the underlying protocol, network, or asset, nor a claim that any investment product is risk-free. Credora’s methodology, for example, factors a protocol’s security track record into its ratings but doesn’t independently audit its full codebase. Allocators should treat the rating as one input for comparison, not a substitute for their own due diligence.

Tydro already runs on Aave v3, so why does it need Credora’s ratings on top of that?

Running Aave’s contracts doesn’t come with Aave’s risk-management apparatus: Tydro is centrally governed, so Aave DAO doesn’t vote on its listings or parameters, and Tydro’s markets aren’t covered by Aave’s DAO-operated Umbrella backstop. After a May 2026 oracle incident forced Tydro to halt its markets, the protocol opted to build its own risk infrastructure for v2 rather than rely on inherited safeguards, and Credora’s ratings are part of that buildout. In short, the smart contracts are shared with Aave, but the risk oversight around them on Tydro is Tydro’s own.