I just went back through some older notes and saw a retrospective on that “audited” project from 2017 that later ran off with the funds… Now every time I open a new project’s GitHub, I’ll first take a quick look at the commit frequency and the quality of the issue discussions, instead of only checking the star count. Honestly, audit reports are like that too now—many newcomers just look at the conclusion lines like “no critical vulnerabilities found” and rush in, but the real horror stories are in the main text: the assumptions, the test coverage, and the places marked “n/a.” As for upgrading the multisig, don’t even mention it—whether the signer list contains a few well-known KOLs or anonymous addresses makes a huge difference.



Recently, those projects that are re-staking and sharing security have been arguing a lot, saying that the compounded returns are like “matryoshka dolls.” I think if the underlying assets aren’t transparent to begin with, then no matter how many layers you stack, it’s still a castle in the air. After looking around, it’s basically that trust isn’t built by shouting “we audited it”—it’s built by being willing to lay open every single GitHub commit and every footnote in every audit report for people to see.

What I’m most afraid of missing isn’t a certain 100x opportunity—it’s that I’ll clearly have seen a warning in the code, yet still stubbornly convince myself it’s a “low-probability event.”
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned