Just now I saw someone asking what to look for in a project’s GitHub, and how to judge whether an audit report is just “brushing.” Actually, it’s pretty simple—an audit report that has no audit for centralized upgrade multi-sig is basically a “white audit.”



To put it bluntly: before reading an audit report, I’ll definitely check whether the multi-sig address has publicly transparent thresholds and participating parties. If the upgrade authority is held by 1/1 or by two addresses, then it’s just a change in the way they cut the same deal. On GitHub, you should look at the time of the last commit and the update frequency—if it’s basically a stagnant pool, don’t touch it.

Lately, testnet incentives and points expectations have been flying around like crazy, and everyone is guessing whether tokens will be issued when the mainnet goes live. Actually, more than that, what I care about is whether the upgrade multi-sig includes ordinary users or people from industry organizations. If it does, at least when it’s running, there will be someone speaking up.

What I’m really afraid of “missing out” on isn’t the opportunity—it’s that nobody reminds me before they run away.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned