Key points
- Separate the protocol from the website interface.
- Understand approvals, contracts and the network you are using.
- Liquidity and oracle design can affect execution and risk.
- Decentralized branding does not remove operational dependencies.
Protocol, interface and control are separate layers
A DEX can include smart contracts, a web interface, governance, liquidity providers, oracles and third-party infrastructure. Research which parts can be changed, paused or upgraded and who has the relevant permissions.
The interface you visit may be only one way to interact with the protocol. Conversely, a protocol described as decentralized can still have important operational control points.
Understand the transaction you sign
Wallet approvals can grant a contract permission to move tokens. Check the contract address, network, token and approval scope before signing. A familiar interface does not make an incorrect network or malicious token safe.
Slippage settings, price impact and routing can materially change execution. For liquidity provision, impermanent loss and smart-contract risk are different from the risks of a simple spot swap.
Use evidence that matches the protocol version
Audits, documentation and governance parameters can become stale after upgrades. Record the version, deployment and date of the evidence you rely on. An audit is information about a scope and time period, not a guarantee against future failure.
For comparisons, publish only networks, features and controls that can be verified for the live product.
Primary reading
These official sources provide background for the risk and custody concepts used in this guide. Product-specific facts should still be checked against the relevant operator and jurisdiction.