Lately, when checking if a project is reliable or not, I prefer to look at GitHub and audit reports first… But honestly, it's normal for beginners not to understand the code. My simple method is: whether the updates are continuous, whether they are just a bunch of "text revisions," whether anyone has raised security issues in the issues and been taken seriously, whether the audit report clearly states "which risks are not covered," and whether follow-up actions have been taken according to the suggestions. Also, regarding multi-signature upgrades, don’t just look at "multi-signature = security," consider who the signers are, how high the threshold is, whether the implementation contract can be changed at any time—being too flexible can actually be quite scary. Recently, NFT royalties have been a heated topic, and I care even more about whether the rules can be changed with a single click… Anyway, I don’t believe in any single metric; only if a few things line up do I dare to take a second look.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned