Recently, when reviewing projects, I first check GitHub and audit reports, but honestly, it's not about pretending to understand the code… I look for a few very "human" signals: whether the code is maintained long-term, if people are seriously tracking bugs in the issue tracker, whether the audit report clearly states high risks and whether those issues were actually fixed later. Upgrading multi-signature wallets is the same; don’t just look at "multi-signature = security," I care more about who the signers are, what the threshold is, whether it can be casually replaced, and ideally if there's a timelock, otherwise if you upgrade in the middle of the night, you might not have time to react.



Lately, hardware wallets are out of stock everywhere + phishing links are everywhere, and the more I look, the more I feel that security isn’t some kind of mysticism; it relies on these hard indicators as a safety net. I personally trust data more; intuition can easily be misled by narratives, and when your position gets too big, transparency goes out the window… Anyway, I still prefer to keep a light position and diversify gradually; I’d rather miss out than get swept away in a wave.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin