I used to really think that "frequent GitHub updates + a bunch of audit reports = a super stable project," and when I saw multi-signature upgrades, I thought it was just going through the motions... Now I understand: GitHub needs to check if the core contracts are being modified, and whether there are a bunch of unresolved security issues; audit reports mainly focus on scope/known risks/whether there has been a re-review, don’t just look at "pass"; multi-signature upgrades are even more critical, look at who the signers are, what the threshold is, whether there's a timelock, otherwise it’s just "changing to a prettier keychain." Recently, on-chain large transfers and hot/cold wallets of exchanges get called smart money whenever they move, I get itchy too, but honestly, that’s more like an emotional amplifier. If you really want to go for it, first pull the liquidation line further away... Anyway, I stay cautious verbally, but my hands still tremble a bit.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned