A midnight again reviewing GitHub and audit reports, basically giving beginners a rough sense of "trustworthiness": first check if they are still updating seriously recently, commits not just a lump from three months ago, then see if anyone mentions pitfalls in Issues, whether the team responds or not. Not responding is okay but don’t pretend to be dead. Don’t just look at the big logos on the cover of the audit report; focus on "what was found, how it was fixed, whether it was re-audited." Many projects say "fixed," but when you compare the code, they haven't actually addressed the real issues...



Also, I am now especially concerned about multi-signature upgrades, who can sign, how many people can sign, whether the logic can be changed arbitrarily. Cross-chain bridges that have been hacked many times, in the end, it’s not so much about technical mysticism but about permissions being too lax + upgrades being too fast. After oracle abnormal quotes, everyone is saying "wait for confirmation," and I agree. Taking it slow is not shameful, at least don’t rush in before figuring out who can upgrade with one click. That’s all for now, continuing to stay up late.
Ver original
Esta página puede contener contenido de terceros, que se proporciona únicamente con fines informativos (sin garantías ni declaraciones) y no debe considerarse como un respaldo por parte de Gate a las opiniones expresadas ni como asesoramiento financiero o profesional. Consulte el Descargo de responsabilidad para obtener más detalles.
  • Recompensa
  • Comentar
  • Republicar
  • Compartir
Comentar
Añadir un comentario
Añadir un comentario
Sin comentarios
  • Anclado