I’ve been seeing people recently say, “A large on-chain transfer happened—the smart money is coming in,” and then a bunch of people rush in after it. The truth is, big holders have plenty of reasons to make a transfer—moving funds between an exchange hot wallet and a cold wallet can be treated as a signal too, right? Anyway, I don’t really buy into it.



If you really want to judge whether a project is reliable, it’s better to spend ten minutes digging into its GitHub repository—see whether there’s been any code updates in the past three months, and whether the commit messages look like a bunch of sloppy “fix typo” kind of updates. To put it plainly, whether GitHub is active is like checking whether a restaurant’s kitchen is actually cutting vegetables. If the code hasn’t moved for half a year, don’t rush to trust an audit report just because it’s written beautifully.

Also, you need to read audit reports selectively. It’s not enough that they slap a CertiK or SlowMist logo on it and call it done. For beginners, you can first check whether the report lists “severe issues” and “medium issues.” If they’re all minor “informational” bugs, that’s still relatively conscientious. But if high-risk vulnerabilities aren’t explained clearly and they just get approved, then you should be more cautious. As for me, I’ll also glance at who the owner of the upgraded multisig is. If two out of three signatures are anonymous addresses, it’s not much different from putting the safe combination password on the door. That’s it for now. Even if after researching for a while you still don’t place an order, at least you’ll feel more at ease.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned