AI-powered audit reports. We find what teams don't want you to find.
CA Audit Team looks at crypto projects the way a skeptical investor would — team background, tokenomics, technical credibility, red flags, and legal structure. Some of what we know, we give away for free. If you want a deep dive on a specific project, that's what our paid reports are for.
Plain-language explainers — what an audit actually is, how to read a whitepaper, what red flags to look for. No jargon, no sales pitch. If a guide is enough to answer your question, great — that's the point.
When you need a real answer about a specific project — not general knowledge — our reports do the actual work: scraping, reading whitepapers, scoring across 5 categories, or drafting a grant proposal in the exact format a program expects.
Pick a service below. Every report is delivered as a PDF to your email within 24 hours of payment confirmation.
Know the project name? We scrape their site and score it across 5 categories.
Give us the URL yourself — same 5-category scoring, your choice of site.
Upload the whitepaper PDF — we read it and score it, no need to find a website.
Pick a target grant program (Gitcoin, Optimism, Arbitrum, Ethereum Foundation ESP, Solana) — we draft a proposal in that program's actual format.
Ongoing watch on a DAO's Gnosis Safe treasury — balance, pending multisig transactions, and flagged anomalies, delivered by email and/or Telegram.
Short, plain-language explainers. Start here if you're new to crypto due diligence.
You give us a project name, we do the digging. Here's exactly what you get and why it saves you hours.
Same 5-category check, but you hand us the exact website. Here's when that matters.
For projects that only have a whitepaper PDF so far — no live site required.
Applying for Web3 grant funding? Here's what this service actually does for you.
No jargon — what an audit actually checks, and what it means for you if a project doesn't have one.
A due-diligence report is a snapshot. This is what watching continuously actually looks like, and who needs it.
Tokenomics, vesting, FDV, TGE — plain-English translations, and which sections actually matter.
Patterns that show up again and again before a project quietly fails or turns out to be a scam.
Neither, by itself. Here's how to actually read that fact instead of treating it as a verdict.
A short checklist you can run yourself before you buy, invest, or contribute — no report needed.
It's on every checklist, rarely explained. Here's what's actually being locked, and how to check it yourself.
Not automatically either way. Here's how to actually judge it instead of using it as a shortcut.
"Audited" gets treated as a safety guarantee. It isn't one — here's the real scope.
The most common way people lose money in crypto — and the signs that tend to show up first.
A trap coded into the token itself. Here's how it works, and how to check before you buy.
"Doxxed" isn't the same as "verified." How to actually check the people behind a project.
The alphabet soup of token sales in plain English — and which structure actually protects you.
Free tokens are the oldest bait for the most expensive mistakes. How to claim safely.
Fake copies of real tokens are everywhere. One habit protects you from almost all of them.
What it is, and when it's the right choice.
Get Report is the simplest way to have us check out a crypto project: you give us the name of the project, and we do the rest. We find their website ourselves, read through it, and score it across 5 things that actually matter — the team, the tokenomics, the technical setup, red flags in how they talk about themselves, and their legal structure.
You get back a PDF with a score out of 100, a plain-language summary, and the specific findings behind each score — not just "good" or "bad," but exactly what we found and why it matters.
How this helps you specifically: if you've heard about a project — from a friend, a tweet, a Telegram group — and want a second opinion before you put any money in, this is the fastest way to get one. You don't have to know how to read a smart contract or a whitepaper yourself. We did the reading. You get the conclusion.
When to use this one specifically (rather than Custom Audit or WPA): when you just know the project's name and nothing more technical — you haven't got a URL saved, and you don't have a whitepaper file. Just the name is enough for us to start.
Have a project in mind? Give us the name and we'll take it from there.
Same scoring as Get Report — you just hand us the exact site.
Custom Audit does exactly what Get Report does — same 5-category scoring, same PDF, same depth — with one difference: instead of us searching for the project's website ourselves, you give us the exact URL.
Why that difference matters: a lot of crypto projects have generic or copycat-sounding names. If you only give us a name, there's a real chance we find the wrong project, an unrelated blog post about it, or nothing at all. If you already have the site open in your browser right now, giving us that exact link removes any guesswork — we look at precisely the thing you're worried about, not our best guess at it.
How this helps you specifically: if you're already on a project's website deciding whether to trust it, this is the version built for that exact moment — copy the URL, paste it in, done.
When to use this one specifically (rather than Get Report or WPA): whenever you already have the actual website open or saved — especially for newer or smaller projects that don't show up easily in a search by name alone.
Got the site open right now? That's all we need.
For projects that don't have a live website yet — just a document.
Whitepaper Analysis is for a specific situation: you've got a whitepaper PDF — maybe shared in a Telegram group or Discord server — for a project that's still early. Maybe it doesn't have a real website yet, maybe it's still pre-launch, maybe you just want the actual document itself checked rather than the marketing site around it.
You upload the PDF, we read it in full, and we score it across the same 5 categories — team, tokenomics, technical credibility, red flags, and legal structure — but based on what the document itself actually says, not on a website's polished pitch.
How this helps you specifically: whitepapers are long, dense, and full of terms designed to sound impressive. Most people skim them and either trust the vibe or get intimidated and skip reading it at all. This gets you an honest read of what the document actually discloses — and, just as importantly, what it quietly leaves out (like exactly how many tokens the team keeps for themselves).
When to use this one specifically (rather than Get Report or Custom Audit): whenever a live website isn't the point — you have the document itself and that's what you want checked, typically for earlier-stage or pre-launch projects.
Have the PDF ready? Upload it and we'll do the rest.
This one's not about checking someone else's project — it's for your own.
Every other service on this site helps you evaluate someone else's crypto project. Grant Proposal Writer is the opposite: it's for you, if you're the one building something and want funding to keep going.
Programs like Gitcoin Grants, Optimism Retro Funding, Arbitrum Foundation Grants, Ethereum Foundation ESP, and Solana Foundation Grants all give away real money to Web3 projects — but each one wants a completely different kind of pitch. Gitcoin cares about community support. Optimism wants hard proof of past impact, with numbers. Arbitrum wants a concrete milestone-by-milestone execution plan. Ethereum Foundation wants an honest, ecosystem-focused narrative, not a form. Solana specifically wants you to justify why it has to be Solana.
How this helps you specifically: most builders don't know these unwritten differences and submit the same generic pitch everywhere, which reviewers can spot instantly. You tell us your project and which program you're targeting, and we write a draft in the shape and tone that program actually rewards — based on real research into what each one looks for, not a generic template.
What you get: a full draft proposal as a PDF, plus notes on where to actually submit it and what to double-check before you do. You should still review and adjust it — it's a strong starting point, not a substitute for you knowing your own project.
Building something and ready to apply for funding? Let's draft it.
A plain-language explainer — no finance background needed.
A crypto audit is someone independent checking a project's code and setup for problems before those problems cost people money. Think of it like a home inspection before you buy a house — the inspector doesn't build the house, they just tell you honestly what's wrong with it.
For a crypto project, that usually means checking things like:
Why it matters to you specifically: if you're holding a token or thinking about buying one, "no audit" doesn't automatically mean "scam" — plenty of small, honest projects simply haven't gotten to it yet. But it does mean nobody outside the team has checked whether the code does what they say it does. You're trusting their word alone. An audit doesn't guarantee a project is good — but no audit means you have no outside opinion at all.
The quickest thing you can check yourself: look at the project's website or GitHub for a section called "Audits" or "Security." If there's a named audit firm and a link to a real report, that's a good sign. If it just says "audited" with no link, or names a firm you've never heard of and can't verify, treat that the same as no audit at all.
Want someone to actually check a specific project for you, instead of guessing? That's what we do.
Saw one of our tweets about a specific project? Order the full audit report — team transparency, security gaps, tokenomics risks and more.
Have a project not in our list? Provide the website URL — we scrape, analyze and deliver a full due diligence report within 24 hours.
Enter the project's own website, not a news article or social media link.
Upload a crypto project's whitepaper PDF. Our AI reads the document and scores it across 5 dimensions — team, tokenomics, tech, red flags and legal structure.
Click to select or drag & drop PDF here
Max 20MB · Text-based PDF only
Give us your project docs and pick a target grant program — we draft a proposal tailored to that program's actual format and evaluation criteria (Gitcoin, Optimism Retro Funding, Arbitrum Foundation, Ethereum Foundation ESP, Solana Foundation).
Click to select or drag & drop PDF here
Max 20MB — or just describe the project below instead
Ongoing watch on a DAO's Gnosis Safe treasury: current holdings, the pending multisig queue, and flagged anomalies (a new pending transaction, an unusually large single outflow, or a transfer to a destination never seen before). Checked every few hours; a full digest email arrives weekly.
Independent, daily risk scoring of crypto launches on the primary market — launchpools, launchpads (IEO / IDO / presale) and airdrops. One question, answered honestly: will this dump, or is it a trap? Not hype, not signals. You get the picture a $100k desk would build before touching a launch — sized for a $100 ticket. Most days the verdict is “skip,” and that’s the point.
/start — it replies with your chat ID. Paste it below so your daily feed lands in your Telegram.
A payment bot, a paywall for a private channel, or a mini-app. Fixed price, 5–7 day turnaround, and a demo you can try in under a minute.
Still taking payment manually — "DM me for access"? Every person who doesn't wait around for a reply is money lost. A bot accepts payment, grants access, and renews subscriptions itself, 24/7, without you.
Accept USDT and Telegram Stars on your bot or site: CryptoBot, NOWPayments, or your own BTCPay. Automatic payment confirmation — no manually matching transfers in your DMs.
Payment → automatic access to a private channel → renewal reminder → auto-kick for non-payers → re-entry after payment. USDT and Stars out of the box.
A Telegram mini-app for your use case with native crypto payment — storefront, subscription, service. Scope discussed individually.
This isn't a slide deck. Every payment on this site runs through exactly this kind of setup: order → USDT payment → automatic delivery, no manual step anywhere. What we build for you, we use ourselves.
→ How our checkout worksOpen the bot, pay $1, get access to the channel, and watch the reminder, auto-kick, and re-entry-after-payment work with your own eyes. A live product, not a description.
Open @My_Pay_Gate_Bot1. Tell us what you need, pick a package.
2. Pay 50/50 in USDT.
3. In 5–7 days the bot is live — we hand over access and the code.
Not a demo built to look good — the same system every order on this site actually runs through.
Every product on kotick.site — including the one you're reading about right now — is paid for through the same checkout: a client submits a form, gets a payment link, pays in USDT through CryptoBot, and the order confirms itself automatically. No one has to notice a message and manually approve it. The confirmation, the report generation, and the email delivery all happen without a human in the loop.
What actually makes this reliable, not just functional:
Why this matters to you specifically: if you're paying us to build this exact kind of system for your own channel or bot, this is the proof — not a claim on a page, a working system you can try above for $1 and watch confirm itself in real time.
Every other service on this site is a one-time check. This one never stops looking.
A DAO treasury is a shared pool of crypto — often millions of dollars — controlled by a multisig wallet (usually Gnosis Safe), where a set number of people have to sign off before any transaction goes through. That's a good safety design on paper. In practice, almost nobody outside the core team actually watches it day to day. Most token holders and contributors only find out money moved when someone posts about it afterward, if they post about it at all.
Treasury Monitor is a standing watch on one specific Safe address. It checks in every few hours for three things: a new transaction sitting in the signing queue, a single transaction that moved an unusually large share of one holding, and a transfer to a destination the treasury has never sent to before. None of these automatically mean something's wrong — a big payment to a known contractor is normal. But they're exactly the kind of thing you'd want a human to at least glance at, and most people never do because checking a block explorer regularly isn't anyone's job.
How this helps you specifically: if you hold tokens in a DAO, contribute to one, or just want to know your money is being watched by more than the same three people who control it — this gives you (or your community) an independent, automatic second set of eyes, without anyone having to remember to check.
What you get: your choice of a weekly PDF digest by email, real-time Telegram alerts when something's flagged, or both. You pick a Gnosis Safe address and a chain, we do the watching.
Have a DAO treasury that could use a second set of eyes?
Most whitepapers are written to sound impressive, not to be understood. Here's how to cut through that.
You don't need to understand the math to get the important parts. You need to know what a handful of terms actually mean, because most whitepapers lean on them to sound more rigorous than they are:
Once you know those terms, read the whitepaper in this order: skip the introduction (it's marketing), go straight to the tokenomics/allocation table, then the team section, then the roadmap. If the allocation table is missing, vague ("TBD"), or the team section has no names you can actually search for — that tells you more than the rest of the document combined.
Why this matters to you specifically: the sections most people skim past (allocation percentages, unlock schedules) are usually the ones that determine whether early holders get diluted later. The exciting-sounding vision section rarely does.
Want someone to actually read the whole thing and score it for you?
None of these alone is proof of anything. Two or three together is worth taking seriously.
1. The team is anonymous with no track record. Anonymous doesn't automatically mean bad — some legitimate projects stay anonymous by philosophy. But anonymous plus no verifiable history anywhere (no past projects, no consistent online presence) means if something goes wrong, there's no one to hold accountable.
2. The roadmap stopped updating, but the marketing didn't. A project that's quietly stalled technically often keeps posting hype content on social media at the same pace, or even faster, to cover the gap. Compare the last real product update to the last tweet.
3. Large wallets move right before or after major news. If you can see (via a block explorer) that a handful of large wallets sold heavily right around a big announcement, that's worth noting — insiders trading on information the public just received isn't a good sign.
4. Criticism gets deleted or banned instead of answered. Legitimate teams answer hard questions, even badly. Teams that quietly remove critical comments or ban people who ask about the treasury or the audit are managing perception, not the product.
5. The price and the actual product have stopped being related. If the token is up a lot but nothing shipped recently, that's not automatically a scam — but it does mean the price is being driven by something other than progress, which can reverse just as fast.
Why this matters to you specifically: none of these five things are things a smart contract audit would catch — audits check code, not behavior. This is a different, faster kind of check you can do yourself in a few minutes of looking.
Want a full 5-category check instead of just these five signs?
By itself, neither. It's a fact that changes meaning depending on what else is true.
It's tempting to treat "backed by well-known VCs" as a stamp of approval, and "no VC backing" as a red flag (or, for some people, the opposite — "no VC" as proof a project is grassroots and honest). Both shortcuts are wrong on their own.
What VC backing actually tells you: professional investors did some due diligence before writing a check, which filters out some obviously broken projects. But it also usually means a chunk of the token supply is reserved for those investors at a low price, with a vesting schedule — and eventually, that supply unlocks and can be sold into the market. VC backing lowers the odds of an outright scam; it doesn't lower the odds of early holders getting diluted later.
What no VC backing actually tells you: it could mean a genuinely grassroots, community-funded project with no outside pressure to eventually cash out. It could also just mean no professional investor looked closely enough to write a check — which isn't the same as passing a check, it's the absence of one being done at all.
How to actually use this fact: don't treat VC presence or absence as a verdict by itself. Look at it together with the other signals — is there an audit? Is the team identifiable? Is the roadmap active? A project with no VC backing, an identifiable team, and a real audit can be a better bet than one with VC backing and nothing else checked.
Why this matters to you specifically: "no VC" and "no audit" often get lumped together as one red flag, but they're separate facts that need separate context — see the audit guide for why an old or narrow-scope audit isn't the same as no audit either.
Want the VC and audit picture checked together for a specific project?
Not a deep audit — just enough to catch the most obvious problems before you commit any money.
Run through these before you buy, invest, or contribute time to a new project. Each one takes under a minute:
Why this matters to you specifically: this checklist won't catch everything — a project can pass all five and still fail for reasons that only show up in the code or the tokenomics. But it takes five minutes and catches the most common, most obvious problems before you've spent any money finding out the hard way.
Passed the 5-minute check but want real certainty before committing?
It shows up on every checklist, including ours — rarely explained. Here's what's actually being locked.
Most new tokens trade on a decentralized exchange through a "liquidity pool" — a pair of the new token and something stable (ETH, USDC, BNB) that someone deposited so people have something to trade against. Whoever created that pool holds a claim on it, and technically, they can withdraw their share at any time — pulling out the stable side and leaving the token side worthless. That's the literal mechanism behind a "rug pull": it's not some hack, it's just the pool creator using a withdrawal button they always had.
"Liquidity locked" means the team sent that claim to a smart contract that holds it for a fixed period and won't release it early, no matter who asks — including them. Services like Team Finance or Unicrypt do exactly this: you can look up the token's liquidity pool address on either site and see whether it's locked, for how long, and who locked it.
Why this matters to you specifically: an unlocked pool doesn't mean the team will definitely rug — plenty of small, honest projects just haven't gotten around to locking, or lock later. But it does mean the mechanical ability to pull the rug exists right now, with nothing stopping it. A locked pool with a real, checkable expiry date removes that specific risk for as long as the lock lasts — check what happens when it expires, too, since a lock isn't the same as a promise.
One thing to watch for: a short lock (a few days) advertised loudly as "liquidity locked!" without mentioning the duration. Technically true, practically meaningless.
Want someone to check this along with everything else for a specific project?
Same shape of question as VC backing: the fact alone doesn't tell you much without context.
Crypto has a real tradition of anonymous or pseudonymous founders — Bitcoin's own creator never revealed their identity, and several well-established, still-running projects were built by teams who never put names to faces. Anonymity by itself isn't evidence of bad intent; for some founders it's a genuine philosophical stance, or protection against regulatory or personal risk in their home country.
What anonymity actually removes: accountability if something goes wrong. If a named team's project fails through negligence or fraud, there's at least a real person whose reputation is attached and who could, in theory, face consequences. An anonymous team that disappears after a failure faces none of that — there's no one to hold responsible, and no track record to check beforehand either.
How to actually judge it, instead of using it as a yes/no filter:
Why this matters to you specifically: treating "anonymous team" as an automatic disqualifier means missing legitimate projects with good reasons for it. Treating it as a non-issue means ignoring a real, meaningful gap in accountability. The useful question isn't "are they anonymous" — it's "what, if anything, stands in for the accountability that a named team would normally provide."
Want the team-transparency question checked alongside audit and tokenomics for a specific project?
"Audited" gets treated as a safety stamp. It's real, useful information — just narrower than most people assume.
A smart contract audit is a firm reading a project's code, by hand and with automated tools, looking for ways it could be exploited: reentrancy bugs, integer overflow, access-control mistakes, logic that lets someone drain funds or mint unlimited tokens. When it's done well, by a reputable firm, it's a genuinely valuable, technical check — this guide isn't arguing against audits.
What an audit does NOT tell you:
Why this matters to you specifically: "audited" is one real, positive signal — not a finish line. The useful habit is checking what firm did it (see our guide on red flags for how audit-firm reputation varies), what scope the audit actually covered, and whether the other categories (team, tokenomics, admin controls) got any independent look at all.
Want the code-audit signal checked together with the categories an audit doesn't cover?
The most common way people lose money in crypto — and the signs that tend to show up first.
A "rug pull" is when the people behind a project take the money and disappear, leaving a token that's suddenly worthless. The name comes from "pulling the rug out" — one moment there's a working-looking project with a rising price, the next the liquidity is gone and there's no one to sell to. It's not always a dramatic exit; sometimes it's slow, with the team quietly selling their own allocation into every bit of buying interest until nothing's left.
The signs that tend to show up first:
Why this matters to you specifically: almost every rug pull is visible before it happens, in the contract permissions and the holder distribution — not in the marketing. You don't need to predict intent; you need to check whether the mechanism to rug even exists. If it can't happen technically, it usually won't.
Want someone to check the contract permissions and holder spread for you?
A trap coded into the token itself. Here's how it works, and how to check before you buy.
A honeypot is a token designed so that you can buy it but not sell it. The price chart looks great — it only ever goes up, because the code silently blocks everyone except the creator from selling. You see your balance grow on paper, you feel clever for getting in early, and then when you try to take profit, the transaction just... fails. By the time you understand why, the creator has sold their own bag into all the money that flowed in.
How the trap is usually built:
How to check before you buy: free honeypot-checker tools (they simulate a buy and a sell on the contract and tell you if the sell fails) catch a large share of these. They're not perfect, and a "clean" result isn't a guarantee — but a "you can't sell this" result is a hard stop. Also read the token's fees and check whether an admin can change them after launch.
Why this matters to you specifically: a honeypot doesn't look risky — it looks like the best-performing token you've ever seen, which is exactly the point. The green chart is the bait. The one question that matters is whether a normal wallet can actually sell, and that's checkable before you spend anything.
Not sure how to read a contract? We check sell-ability and admin powers as part of every report.
"Doxxed" isn't the same as "verified." Here's how to actually check the people behind a project.
A project page with headshots, full names, and job titles feels reassuring — but a photo and a name cost nothing to invent. Stock images, AI-generated faces, and borrowed identities all show up regularly. "The team is public" only helps you if the public team is actually real and actually working on this project. That's a separate check, and it's not hard to do.
What actually verifies a team:
Why this matters to you specifically: a named team is only a positive signal if the names hold up. Treating "they're not anonymous" as reassurance — without spending five minutes confirming the people exist and are really involved — is exactly the gap that fake-team projects rely on.
Team verification is one of the five categories in every report we run.
The alphabet soup of token sales, in plain English — and which structure actually protects you more.
These are all ways a project sells its token to the public for the first time. They differ mostly in who stands between you and the team — and that's the part that affects your risk, so it's worth knowing which is which.
Where the risk hides: the earlier and less-gatekept the sale, the more the burden of checking falls entirely on you. None of these labels tells you the token is safe — an IEO on a serious exchange is a slightly stronger starting point than an anonymous presale, but every one of them still needs the same look at team, tokenomics, and contract permissions.
Why this matters to you specifically: knowing the sale type tells you how much has already been checked by someone other than you — which is usually "very little." That's not a reason to avoid them, just a reason to do the checking yourself before, not after.
Weighing a token sale? Get the team, tokenomics, and contract checked first.
Free tokens are the oldest bait for the most expensive mistakes. Here's how to claim safely.
An airdrop is free tokens sent to wallets, usually to bootstrap a community or reward early users. Real ones exist. But "you have an airdrop to claim" is also one of the most effective scam hooks there is, because the excitement of free money is exactly what makes people skip the checks they'd normally do.
The two ways airdrops actually cost you money:
How to claim safely:
Why this matters to you specifically: the danger in an airdrop is almost never the token — it's the transaction you're persuaded to sign to "get" it. Slow down at the approval step, and the vast majority of airdrop scams simply can't touch you.
Not sure if an airdrop or its project is legit? We can check it before you connect anything.
Fake copies of real tokens are everywhere. One habit protects you from almost all of them.
Anyone can create a token and call it whatever they like. There can be dozens of tokens named "Arbitrum" or "Pepe" or the name of whatever is trending — identical name, identical ticker, identical logo — and only one of them is the real one. What tells them apart is the contract address: the unique on-chain ID of that specific token. Buying by name instead of by address is how people end up holding a worthless clone of a real project.
The habit that protects you:
Why this matters to you specifically: a huge share of "I bought a scam" stories aren't sophisticated hacks — they're someone buying a same-named fake because they searched the name instead of confirming the address. Sourcing the contract address from the official channel is a ten-second habit that removes almost the entire category of risk.
Want the right contract confirmed and checked before you buy?