I'm now looking at projects and "credibility" mainly focusing on these three aspects: whether GitHub is truly active (not just changing a README to fool people), whether the audit report can be opened to see the original text and how issues were fixed, and most importantly, who holds the upgrade permissions/multisig, what the threshold is, whether there's a timelock... In simple terms: who can change the rules with one click when something goes wrong. Recently, a bunch of new L1/L2 projects are offering incentives to attract TVL, and old users complain about "mining, dumping," which I can understand. Incentives are lively, but if the permission structure isn't stable, don’t get carried away. Someone said, "After an audit, it should be safe"... I can only say that an audit is just the passing line; how to upgrade afterward is the real daily risk.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments