Recently, I’ve seen a lot of people using audit reports like a talisman—yet this stuff runs pretty deep. For those projects on GitHub, just looking at how many stars they have is useless; you need to check the recent commit history, especially anything related to smart contracts. Some projects finish an audit and then quietly push a few more versions of code afterward—tweaking parameters or even changing permission logic. In that case, the earlier audit is basically rendered useless.



Updating the multisig address and the signer list is now commonly disclosed, but have you actually verified it one by one on Etherscan? Anyway, every time I compare what’s on-chain with what’s written in the docs, if they don’t match, my heart drops.

Also, the kind of recent public opinion that forcefully links ETF fund flows to price movements is a bit lazy in its thinking. Funds do reflect the market’s direction, but compared with actual on-chain behavior (for example, trade depth and changes in slippage), sometimes it’s better to trust the latter. For beginners trying to judge a project’s “credibility,” instead of just following others shouting “bullish” or “bearish,” it’s better to first dig into the diffs in GitHub issues and audit reports, then look at the multisig address to see whether there have been any abnormal large transfers recently. Personally, I’d rather make less money and not get tricked into a trap blindly.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned