I look at GitHub and audit reports mainly to find a few "signals": whether the project has been maintained continuously, whether issues raised have been taken seriously and responded to, and whether fixes match the upgrade records. I’m also not very superstitious about the conclusion page of audit reports; instead, I check whether it clearly states "what's out of scope," whether similar risks keep recurring, and after reading, I get a general sense of the situation.



Upgrade multi-signature is more straightforward: I look at how much permissions can be changed, whether the signers are a consistent group, and if there are delays or announcement periods. Basically, I’m worried about "things being fine today, but tomorrow a one-click upgrade turns it into something else." Recently, we also discussed how some regions are increasing taxes, tightening or relaxing compliance, and how deposit and withdrawal expectations are changing, making everyone more eager to move funds… I actually prefer to slow down a bit, even if it costs more, just don’t do reckless moves.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned