Recently, project teams have been posting a bunch of GitHub links, audit reports, and claims that "upgrades are controlled by multi-signature," which makes newcomers feel more at ease. But honestly, these three can also be faked. My simple approach: first, check if the GitHub is "alive," look at the submission frequency, whether issues get responses, and if key changes are just temporarily inserted; don't just look at the cover logo of the audit, review the conclusions and scope—many audits only cover a small part, and the upgrade logic isn't included; as for multi-signature, don't just listen
View Original