Checking a whitepaper
Most warning signs sit right in the document, or are conspicuously missing from it. Anonymous founders, missing technical substance, and yield promises are the three biggest.
A whitepaper is supposed to explain what problem gets solved and how. If you can't say what the project does in one sentence after reading it, that's already your answer.
Three warning signs are especially reliable. First, anonymous or fabricated founders, often checkable in minutes via a reverse image search of their profile photos. Second, yield promises with no identifiable source. Third, text made up mostly of market size and future vision instead of engineering.
Further points: is there working code you can actually look at? Was it independently audited? Who holds most of the tokens? How fast do they unlock?
And the simplest test of all: if a fixed return is promised and nobody can explain who's actually generating that return, then it's coming from the next round of depositors. There's a name for that, and it's over a hundred years old.
Verifiable traits sort into four groups: identity and traceability of the team, technical substance and availability of open-source code, independent audit reports on the contracts, and the token's distribution and unlock structure. Missing several of these groups entirely means the project can't be evaluated, regardless of the document's content.
Smart-contract audit reports are helpful but of limited scope. They apply to a specific code version and a defined scope of review, which can include exclusions. An existing report is therefore not proof of safety, it's merely the basis for asking what was checked, and what explicitly wasn't.
Economically, every yield promise should be judged by its source. Traceable sources include trading fees, interest from actual lending, or income from collateral services. Where the source can't be named, or consists of newly issued tokens, this is a redistribution from later participants to earlier ones.
Summary
- Anonymous founders, missing engineering, yield promises with no source.
- An audit report only says what was checked, not that it's safe.
- Yield with no nameable source comes from the next round of depositors.
Did you get it?
What four areas should you check?
Team and identity, technical substance and code, independent audit reports, token distribution and unlock schedule.
What does a smart-contract audit report actually tell you?
Only what was examined, for a specific code version and scope, not that the project is safe.
How do you judge a yield promise?
By its nameable source. Without one, the return comes from later depositors.
Related
- TokenomicsStage 3
- Rug pullFraud Protection
- DeFi: staking, lending, liquidity poolsStage 4