My phone just popped up a red dot saying "Protocol upgrade has been executed."


My first reaction wasn't whether to upgrade or not, but: who actually has the final say on this...
Newbies want to see credibility, but I think don't be fooled by the words "Audited."
First, check GitHub: Are there continuous commits? Is it just a bunch of forks with the main repo empty?
Are there any critical changes reviewed by someone (even if you can't understand the code, you can tell if "someone is working on it").
Don't just look at the audit report cover logo; focus on the conclusion pages:
Are high-risk issues fixed?
Has verification of fixes been done?
Does the audit scope exclude the most sensitive upgrades/permissions?
Then there's multi-signature for upgrades:
Is the number of signatures sufficient and decentralized?
Is the threshold high?
Is there a timelock (giving you reaction time before you can run away)?
Recently, privacy coins/mixing compliance debates have been tearing apart, but it's actually the same logic:
The more centralized the authority, the more heated the narrative, and the more you should treat "control" as a risk.
Anyway, now when I see a popup, I first check permissions, or I feel uneasy.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin