Lately, when looking at projects "trustworthy or not," I’ve actually stopped focusing on APY first and instead started reviewing GitHub, audit reports, and multi-signature upgrade processes. Beginners shouldn’t be scared; honestly, just focus on a few points: Is GitHub maintained consistently (not those that go silent for half a year and then suddenly update a bunch at once), do the audit reports clearly outline risks and whether they’ve been fixed or not (I deduct points if they only post a logo), are the upgrade permissions multi-sig, who are the signers, and is there a timelock, at least giving you some reaction time.



Recently, hardware wallets are out of stock everywhere, and there are a lot of phishing links. People’s security awareness has improved, but there’s really too much information, which makes people a bit anxious… My current filtering method is pretty crude: first look at the “permission structure + upgrade path.” If it doesn’t pass this test, I put aside the lively community activities for now and take it slow. After all, compound interest isn’t something you can rush in one night.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments