Web3 products often explain what they can do before explaining what can go wrong. A user may see a feature list, a fee table, or a security claim, yet still be unsure who controls the assets, what happens during a service disruption, or how much a transaction may really cost.

That gap matters. Clear risk disclosure cannot remove market or technology risks, but it can help users understand what they are agreeing to before they deposit funds, connect a wallet, or sign a transaction.

“Decentralized” does not answer every important question

Web3 covers different kinds of products: self-custody wallets, decentralized finance protocols, and centralized platforms that offer digital-asset services. Their risks are not identical.

With a self-custody wallet, users generally control their own private keys. That gives them direct control, but also means losing access to those keys can mean losing access to their assets. A DeFi protocol may introduce additional risks, such as vulnerabilities in smart contracts or dependencies on other protocols. On a centralized platform, users may instead need to understand how the provider holds and records customer assets, and what rights users have if the provider faces financial or operational problems.

The Financial Stability Board’s recommendations for crypto-asset activities call for clear disclosure of providers’ governance, operations, risk profiles, financial conditions, products, and activities. These are recommendations to authorities, rather than a universal checklist already required of every product. Still, they point to a practical principle: users need enough information to understand who is responsible for each function and where risks may arise. FSB recommendations

Four questions users should be able to answer

1. Who controls the assets and the keys?
A product should explain whether the user or a service provider controls the private keys, how assets are held, and what happens if access is lost or withdrawals are paused. For a custodial service, users should also look for clear information about how customer assets are treated in relation to the provider’s own assets. The details can vary by product and jurisdiction, so broad phrases such as “secure custody” do not answer the full question.

2. What will the user actually pay?
A displayed transaction fee may not capture the full cost. Depending on the product, users may also face network fees, spreads, borrowing costs, funding payments, or withdrawal charges. Clear explanations should identify which costs apply, when they are charged, and whether they can change.

3. What could prevent a user from exiting?
A displayed price does not guarantee that a transaction will execute at that price. Low liquidity, congestion, slippage, withdrawal limits, or an interruption to a service may affect a user’s ability to act. Disclosures are more useful when they describe these conditions in concrete terms instead of relying on a general warning that “digital assets are risky.”

4. Who is accountable when something goes wrong?
Users should be able to find out who operates the product, which functions are performed by outside providers, and where incident notices or support information will appear. The International Organization of Securities Commissions (IOSCO) identifies custody and client-asset protection, conflicts of interest, operational and technological risk, and retail distribution among the areas its recommendations address for crypto-asset markets. Its DeFi recommendations also call for clear, accurate, and comprehensive disclosures. IOSCO recommendations · IOSCO DeFi recommendations

Disclosure needs to be usable, not merely available

A long legal document may contain important information while still being difficult for ordinary users to apply. Good disclosure puts the most decision-relevant facts where users need them: before they deposit, trade, borrow, or approve a transaction.

That means using plain language, explaining technical terms, and separating different types of risk. A smart-contract vulnerability is different from market volatility; a custody arrangement is different from a temporary service outage. When those risks are grouped into a single broad warning, readers may struggle to tell which ones apply to the product in front of them.

The U.S. Securities and Exchange Commission’s investor bulletin on custody discusses why custody arrangements matter and the safeguards relevant to investment assets held by investment advisers. Its scope is specific to that regulatory context, but it reinforces a wider lesson for readers: understand who holds the assets and what protections actually apply, rather than assuming the word “custody” means the same thing everywhere. SEC investor bulletin

A practical standard for trust

Before using a Web3 product, users can ask: Who controls my assets? What are the total costs? What could delay or prevent a transaction? Who is responsible for the service, and where can I verify its rules?

The same questions are useful when reviewing a centralized digital-asset platform such as BYDFi. A platform name or a list of features is not a substitute for checking the relevant product terms, fees, and risk disclosures. Users should read the current documentation for the specific service they plan to use and consider whether its risks fit their own circumstances.

Trust is not created by calling a product decentralized, innovative, or secure. It grows when users can understand how a product works, what they may pay, what could go wrong, and who is accountable. In Web3, clearer risk disclosure is part of the product experience—not a footnote added after the important decisions have already been made.

Disclosure: The author works with BYDFi. This article is for informational purposes and does not recommend any particular product.

Sources