Recently, I saw the project "upgraded multi-signature again and added an audit," and a bunch of people in the group started automatically adding trust scores.


My own simple method is: first check GitHub to see if the commits are maintained by someone long-term, not those who haven't touched it for half a year and only rush to update the README right before the exam;
then look at the audit report, focusing not on how fancy the cover page is, but whether the issue list has follow-ups marked as "fixed/unfixed," preferably matching the code changes.
Don't just look at "3/5 is very safe" for multi-signature; check who the signers are, whether they are the same group of people using different accounts, because in truth, opaque multi-signature setups are only slightly more respectable than single signatures.
Recently, hardware wallets are out of stock, and phishing links are everywhere.
It's during times like these that it becomes clear: everyone talks about security seriously, but in practice, people are quite casual about it...
I'll first review all authorizations and bookmarks to avoid waking up later and having to patch up.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin