I just saw someone ask: “There are a lot of stars on GitHub, there are also audit reports, and the multi-sig upgrade has been made public—can you trust this then?” Actually, I’m not a technical expert either, so I’ll just share how I look at it. On GitHub, a high number of stars sometimes really doesn’t mean much. I’m more willing to go through the commit history and look for signs of long-term maintenance—like… kind of like… flipping through an old ledger book to see whether there are any alterations or missing pages. For audit reports, I usually first check the scope and the timeline. If it’s just a quick scan without clearly explaining the specific risk points, then basically it’s just going through the motions. The permission settings for the upgraded multi-sig are even more critical. A higher threshold doesn’t necessarily mean it’s safer; you still need to see who controls the keys and whether there is a timelock. Recently, the back-and-forth about NFT royalties—at the end of the day, it’s also a trust issue. Creators need to ensure their income, but the market liquidity is also watching every way to extract fees. Anyway, I’m not very convinced by those big promises. It’s better to look slowly and confirm slowly—nothing beats that.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned