Elevated risk — significant security history and radical architectural pivot to an unproven new system, combined with minimal ecosystem adoption after nearly a decade of development, create substantial uncertainty.
Risk Breakdown
Top Risks
Extensive history of security incidents — IOTA has experienced the Curl hash function vulnerability (2017), Trinity wallet attack ($2M stolen, 2020, required network shutdown via Coordinator), and replay attack vulnerabilities, demonstrating a pattern of critical security issues in earlier iterations
Radical architectural pivot — IOTA Rebased (May 2025) abandoned the original Tangle/Coordinator architecture entirely, switching to Move-based DPoS with Mysticeti consensus. While addressing centralization, this is effectively a new chain with less than 1 year of production history in its current form
Minimal DeFi ecosystem — combined TVL of approximately $10M across IOTA and IOTA EVM chains after nearly a decade of development, indicating limited developer and user adoption despite repeated architectural reinventions
The IOTA Foundation's pivot from crypto ecosystem to global trade infrastructure ($35T market) represents a strategic departure from the DeFi and L1 competition, creating uncertainty about the network's positioning and developer focus
Frequently Asked Questions
Is IOTA safe to use?
What are the main risks of using IOTA?
What is IOTA's risk score breakdown?
How does IOTA compare to other L1 protocols?
Has IOTA ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.