I just checked another project team’s GitHub again, and when I clicked in, my first instinct was still to look at the commit frequency and the date of the audit report. Honestly, after reading that pile of audit report jargon for so long, it’s basically the same—what matters is how many people actually hold the multisig addresses being upgraded, and whether the most recent code updates are about fixing urgent vulnerabilities. In plain terms, many rug-pull cases happen because the multisig threshold is set too low, or they go straight to single-sig; then once one person’s wallet leaks, everything collapses.



Recently, the on-chain data labeling system has been exposed a lot too—things like DeFi security tags and audit certifications. In reality, the team can just buy it themselves or boost a few website ratings. Anyway, my current habit is: after setting transaction alerts and limits, I’ll take another look at the upgrade multisig owners to see whether there are familiar institution addresses or third-party audit firms involved. If it’s all anonymous addresses, I’ll hold off for now.

Seriously, every time I set the limits, those few minutes afterward are the hardest—I always feel like I might miss something. But a few times, it turned out I just happened to dodge the downturn. Forget it—take it slow.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned