How does a VRA differ from a credit rating, and why does S&P stress the difference?
The release says plainly that a VRA “is not a credit rating and does not comment on yield levels.” A credit rating answers whether a borrower will default; a VRA addresses how likely it is that your position in a vault is impaired, relatively speaking. The subject is a structure that reallocates money on your behalf rather than a single borrower, which is why vault-specific dimensions such as the curator, withdrawal design, and governance permissions have to be included.
The release does not explain why the distinction is emphasized. A reasonable inference is that S&P wants to stop readers from treating a VRA score as principal protection or a default probability, and to keep it apart from its existing credit rating work, such as the Sky Protocol rating. That is our inference, not an S&P statement.
Does the 6.7x growth in vault deposits carry risk implications of its own?
Yes, but the two things should be separated. The figures come from S&P's own market estimates rather than an independently verified total, so $10 billion is best treated as an order of magnitude. Growth in itself does not mean risk has risen, but it does mean more money relies on a relatively young design: curators decide allocations, lending protocols supply liquidity, governance multisigs control parameters. At larger scale, a failure in any single link affects more funds.
The other implication is rising demand for evaluation. Traditional institutions typically need a third-party risk opinion before placing client money into a product, and the VRA is meant to fill that gap. That explains why the framework arrives first and scores come later: a shared vocabulary is established before vault-by-vault assessments begin.
Of the six factors, which is hardest for an outside institution to assess?
Curator risk is probably the hardest to standardize. Portfolio credit quality can draw on collateral and borrower data, and blockchain and protocol risk can lean on audits and incident history, but the curator is a judgment about people and process: how they pick markets, whether they change allocations under stress, and whether their own interests enter the decisions. Most of that information is not on-chain and not necessarily disclosed. This site's article on curators makes the point: a vault looks like a Smart Contract, but what you are actually trusting is a team you have probably never heard of.
This is also where to watch whether the VRA proves useful. If the first assessments give curator risk only a broad score with no stated basis, it will carry less information than the other five factors.
Before S&P publishes a first score, what can I do myself?
Rewrite the six factors into your own checklist. One: which markets does the vault actually lend into, and against what collateral. Two: is withdrawal instant, or is there a queue or a cap, and when was the last time withdrawals got stuck. Three: who is the curator, and is there a public allocation history. Four: which chain and which lending protocol sit underneath. Five: who holds admin permissions, and is there a timelock on parameter changes. Six: does the vault have public audits and an incident record.
The checklist is for comparison, not scoring. For two vaults yielding the same 8% a year, the bigger the gap in your answers, the more the difference lies in places you cannot see.
On October 4, 2026, S&P Global Ratings launched its Vault Risk Assessment (VRA), an analytical framework built specifically for digital asset lending vaults. In its press release, S&P defines a VRA as “a forward-looking opinion about the overall relative risk of impairment to an investor's position in a lending vault,” and states two things plainly: a VRA is not a credit rating, and it does not comment on yield levels. The same release puts the market at roughly $10 billion in vault deposits as of September 2026, up from about $1.5 billion two years earlier (September 2024) — roughly 6.7 times larger.
The release lists six analytical factors: portfolio credit quality risk, liquidity mismatch risk, curator risk, blockchain risk, protocol risk, and vault security and governance risk. Note that the release only names these six; it does not describe how each is scored, and it does not publish the scale — it mentions a “letter-based scale” and refers readers to S&P's website for details. More importantly, S&P says it will publish initial assessments in “future announcements,” gives no date, and names no vault. As of October 10, then, no vault has received a VRA score, and the only thing available to evaluate is the framework itself.
What follows is our plain-language reading of the six names, not S&P's official definitions. Portfolio credit quality is whether the borrowers the vault lends to can repay and whether collateral is sufficient. Liquidity mismatch is the gap between depositors being able to withdraw at any time and the vault's loans not being callable at the same speed. Curator risk is who decides where the vault allocates funds, and that person's judgment and incentives. Blockchain risk and protocol risk cover failure of the underlying chain and of the underlying lending protocol. Vault security and governance covers the control layer: admin permissions, multisig setups, and timelocks. Several past incidents on this site map onto one of these boxes: bad debt falls under credit quality and protocol risk, the Stream Finance case under curator risk, and the Term Labs governance exploit under vault security and governance.
S&P's stated angle is an information gap. The release says blockchains give point-in-time transparency into vault positions, but strategy and risk disclosures for vaults have typically been limited. S&P's head of global ratings services, James Wiemken, points to “a clear need for a standardized, independent risk perspective,” and S&P Global Ratings president Yann Le Pallec says demand for independent risk assessments that bridge traditional finance and decentralized innovation is “paramount.” According to media reports, S&P's recent digital asset activity also includes a credit rating for Sky Protocol (the rating level was not disclosed), Stablecoin stability assessments, and, in September, an agreement to acquire smart-contract security firm OpenZeppelin and a strategic investment in data provider Kaiko; whether the latter two feed into the VRA methodology has not been confirmed.
There is very little about this framework that can be tested today. The scale is undefined, no first assessments have been published, and the release does not say who commissions an assessment or how often it is updated. Those gaps determine how useful a VRA will be to readers: a score that is only valid on the day it is published has limited value for a vault that rebalances its allocations daily, and a score paid for by the vault's operator needs a separate look at conflicts of interest — a long-running debate in traditional ratings, though the release does not say whether S&P uses that payment model here.
If your money sits in a lending vault, the practical meaning of this news is that institutions have started examining the products you use every day through a fixed set of six questions. Until actual scores appear, you can ask those six questions yourself: who does this vault lend to, can I truly withdraw at any time, who decides the allocation, and who can change the parameters. The ones you can't answer are the risks you are carrying right now that nobody has priced for you.