I nearly scared myself to death just now—my thumb slipped and I copied the wrong address, and a transfer almost went down the drain. Luckily it finally got stuck, so it was all a close call. But this incident suddenly made me want to talk about GitHub, audit reports, and upgradeable multisigs—how do beginners actually judge “trustworthiness”?



Honestly, I can barely understand those code repositories, and the number of stars on GitHub doesn’t mean security. My clumsy method is: first, check whether the project team has published the audit report, but don’t just look at the cover—scroll to the “risk disclosure” section and see if they themselves admit to any issues. Then there’s upgrading the multisig—if the project team controls a few wallets and can change the contract, then no matter how good the audit is, it’s basically pointless.

Lately I keep seeing terms like “social mining” and “fan tokens”—it gives off the vibe that attention is the real thing being mined. But honestly, many projects use on-chain governance like it’s just a game just to attract eyeballs, and upgradeable multisigs can change the rules in minutes. This kind of “trustworthiness” is still worse than going to check whether, on their GitHub, anyone has been doing work in the last three months.

Anyway, my experience right now is: don’t trust whitepapers, don’t trust KOLs. Just skim the repository’s update timing and the number of multisig signatures, and you can filter out most of the fluff.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned