I'm currently looking at the project "Trustworthy or Not," not focusing on the K-line for now, just turning off Twitter... and checking GitHub and audit reports. To be honest, GitHub isn't about being greener or stronger; the key is whether there are ongoing people fixing bugs, responding to issues, and whether version updates are not just quick fixes to core logic. Don't rely solely on audit reports as a get-out-of-jail-free card; the most useful parts are the lines in the conclusion that say "Repaired/Unrepaired/Accepted Risks," especially regarding permissions. Upgrading multi-signature is more practical: who are the signers, can they be replaced, is there a delay? The more "upgradable at any time," the more I see it as something that can be passively tampered with at any moment. Recently, AI Agents and automated trading are being hyped up, but the more automated on-chain interactions are, the easier it is to treat security as a default option... Anyway, I’d rather be slower than have "automation" pay my tuition fees.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments