A couple of days ago, I almost got itchy to jump into a new project again, the promotion was over the top. I opened GitHub to check, the code updates are quite frequent, but the commits are mostly pushed by one or two people, and no one responds to issues, honestly it feels like a “self-hype repository.” Then I looked at the audit report, and on the conclusion page, there are a bunch of “fixed/pending confirmation,” so I went to see if there were clear re-testing records, but I didn’t see any, only a statement saying “We believe the team has handled it”… I stayed calm on the spot.



The more critical issue is permission upgrades: multi-signature exists, but who the signers are is not transparent, and the threshold is low, feeling like they could change the routing or fee structure at any time. Considering the recent heated debates over privacy coins and mixing compliance, if the project is forced to change strategies later, having permissions in the hands of a few people makes it even more risky.

In the end, I just said: if you don’t understand it, don’t touch it first. That time I held back from rushing in, and the next day someone on-chain complained about getting slippage due to parameter changes… It’s my luck, but it also means I finally learned to verify more carefully.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments