Crypto Due Diligence

AI-powered audit reports. We find what teams don't want you to find.

5 categories scored in every report
👤
Team
💰
Tokenomics
⚙️
Tech
🚩
Red Flags
⚖️
Legal

What we do

CA Audit Team looks at crypto projects the way a skeptical investor would — team background, tokenomics, technical credibility, red flags, and legal structure. Some of what we know, we give away for free. If you want a deep dive on a specific project, that's what our paid reports are for.

Free: Guides

Plain-language explainers — what an audit actually is, how to read a whitepaper, what red flags to look for. No jargon, no sales pitch. If a guide is enough to answer your question, great — that's the point.

Paid: Services

When you need a real answer about a specific project — not general knowledge — our reports do the actual work: scraping, reading whitepapers, scoring across 5 categories, or drafting a grant proposal in the exact format a program expects.

Services

Pick a service below. Every report is delivered as a PDF to your email within 24 hours of payment confirmation.

Get Report — $50 USDT

Know the project name? We scrape their site and score it across 5 categories.

Custom Audit — $50 USDT

Give us the URL yourself — same 5-category scoring, your choice of site.

Whitepaper Analysis (WPA) — $50 USDT

Upload the whitepaper PDF — we read it and score it, no need to find a website.

Grant Proposal Writer — $200 USDT

Pick a target grant program (Gitcoin, Optimism, Arbitrum, Ethereum Foundation ESP, Solana) — we draft a proposal in that program's actual format.

Treasury Monitor — $149/month USDT

Ongoing watch on a DAO's Gnosis Safe treasury — balance, pending multisig transactions, and flagged anomalies, delivered by email and/or Telegram.

Guides

Short, plain-language explainers. Start here if you're new to crypto due diligence.

Get Report, explained: what it is and when to use it

You give us a project name, we do the digging. Here's exactly what you get and why it saves you hours.

Custom Audit, explained: how it's different from Get Report

Same 5-category check, but you hand us the exact website. Here's when that matters.

Whitepaper Analysis (WPA), explained: no website needed

For projects that only have a whitepaper PDF so far — no live site required.

Grant Proposal Writer, explained: for builders, not investors

Applying for Web3 grant funding? Here's what this service actually does for you.

What is a crypto audit, and why should you care?

No jargon — what an audit actually checks, and what it means for you if a project doesn't have one.

Treasury Monitor, explained: ongoing eyes on a DAO's money

A due-diligence report is a snapshot. This is what watching continuously actually looks like, and who needs it.

How to read a whitepaper without a finance degree

Tokenomics, vesting, FDV, TGE — plain-English translations, and which sections actually matter.

5 signs a crypto project might be in trouble

Patterns that show up again and again before a project quietly fails or turns out to be a scam.

No VC backing — is that good or bad?

Neither, by itself. Here's how to actually read that fact instead of treating it as a verdict.

Check in 5 minutes whether to trust a new crypto project

A short checklist you can run yourself before you buy, invest, or contribute — no report needed.

What does "liquidity locked" actually mean?

It's on every checklist, rarely explained. Here's what's actually being locked, and how to check it yourself.

Anonymous team — automatic red flag, or not?

Not automatically either way. Here's how to actually judge it instead of using it as a shortcut.

What a smart contract audit actually checks (and what it doesn't)

"Audited" gets treated as a safety guarantee. It isn't one — here's the real scope.

What is a rug pull, and how to spot one before it happens

The most common way people lose money in crypto — and the signs that tend to show up first.

Honeypot tokens: when you can buy but can't sell

A trap coded into the token itself. Here's how it works, and how to check before you buy.

A team has names and photos — how do you know they're real?

"Doxxed" isn't the same as "verified." How to actually check the people behind a project.

Presale, ICO, IDO, IEO: what they mean and where the risk hides

The alphabet soup of token sales in plain English — and which structure actually protects you.

Airdrop safety: claiming free tokens without draining your wallet

Free tokens are the oldest bait for the most expensive mistakes. How to claim safely.

How to check a token's contract address is the real one

Fake copies of real tokens are everywhere. One habit protects you from almost all of them.

← Back to Guides

Get Report, explained

What it is, and when it's the right choice.

Get Report is the simplest way to have us check out a crypto project: you give us the name of the project, and we do the rest. We find their website ourselves, read through it, and score it across 5 things that actually matter — the team, the tokenomics, the technical setup, red flags in how they talk about themselves, and their legal structure.

You get back a PDF with a score out of 100, a plain-language summary, and the specific findings behind each score — not just "good" or "bad," but exactly what we found and why it matters.

How this helps you specifically: if you've heard about a project — from a friend, a tweet, a Telegram group — and want a second opinion before you put any money in, this is the fastest way to get one. You don't have to know how to read a smart contract or a whitepaper yourself. We did the reading. You get the conclusion.

When to use this one specifically (rather than Custom Audit or WPA): when you just know the project's name and nothing more technical — you haven't got a URL saved, and you don't have a whitepaper file. Just the name is enough for us to start.

Have a project in mind? Give us the name and we'll take it from there.

← Back to Guides

Custom Audit, explained

Same scoring as Get Report — you just hand us the exact site.

Custom Audit does exactly what Get Report does — same 5-category scoring, same PDF, same depth — with one difference: instead of us searching for the project's website ourselves, you give us the exact URL.

Why that difference matters: a lot of crypto projects have generic or copycat-sounding names. If you only give us a name, there's a real chance we find the wrong project, an unrelated blog post about it, or nothing at all. If you already have the site open in your browser right now, giving us that exact link removes any guesswork — we look at precisely the thing you're worried about, not our best guess at it.

How this helps you specifically: if you're already on a project's website deciding whether to trust it, this is the version built for that exact moment — copy the URL, paste it in, done.

When to use this one specifically (rather than Get Report or WPA): whenever you already have the actual website open or saved — especially for newer or smaller projects that don't show up easily in a search by name alone.

Got the site open right now? That's all we need.

← Back to Guides

Whitepaper Analysis (WPA), explained

For projects that don't have a live website yet — just a document.

Whitepaper Analysis is for a specific situation: you've got a whitepaper PDF — maybe shared in a Telegram group or Discord server — for a project that's still early. Maybe it doesn't have a real website yet, maybe it's still pre-launch, maybe you just want the actual document itself checked rather than the marketing site around it.

You upload the PDF, we read it in full, and we score it across the same 5 categories — team, tokenomics, technical credibility, red flags, and legal structure — but based on what the document itself actually says, not on a website's polished pitch.

How this helps you specifically: whitepapers are long, dense, and full of terms designed to sound impressive. Most people skim them and either trust the vibe or get intimidated and skip reading it at all. This gets you an honest read of what the document actually discloses — and, just as importantly, what it quietly leaves out (like exactly how many tokens the team keeps for themselves).

When to use this one specifically (rather than Get Report or Custom Audit): whenever a live website isn't the point — you have the document itself and that's what you want checked, typically for earlier-stage or pre-launch projects.

Have the PDF ready? Upload it and we'll do the rest.

← Back to Guides

Grant Proposal Writer, explained

This one's not about checking someone else's project — it's for your own.

Every other service on this site helps you evaluate someone else's crypto project. Grant Proposal Writer is the opposite: it's for you, if you're the one building something and want funding to keep going.

Programs like Gitcoin Grants, Optimism Retro Funding, Arbitrum Foundation Grants, Ethereum Foundation ESP, and Solana Foundation Grants all give away real money to Web3 projects — but each one wants a completely different kind of pitch. Gitcoin cares about community support. Optimism wants hard proof of past impact, with numbers. Arbitrum wants a concrete milestone-by-milestone execution plan. Ethereum Foundation wants an honest, ecosystem-focused narrative, not a form. Solana specifically wants you to justify why it has to be Solana.

How this helps you specifically: most builders don't know these unwritten differences and submit the same generic pitch everywhere, which reviewers can spot instantly. You tell us your project and which program you're targeting, and we write a draft in the shape and tone that program actually rewards — based on real research into what each one looks for, not a generic template.

What you get: a full draft proposal as a PDF, plus notes on where to actually submit it and what to double-check before you do. You should still review and adjust it — it's a strong starting point, not a substitute for you knowing your own project.

Building something and ready to apply for funding? Let's draft it.

← Back to Guides

What is a crypto audit, and why should you care?

A plain-language explainer — no finance background needed.

A crypto audit is someone independent checking a project's code and setup for problems before those problems cost people money. Think of it like a home inspection before you buy a house — the inspector doesn't build the house, they just tell you honestly what's wrong with it.

For a crypto project, that usually means checking things like:

  • The smart contract code — can someone drain the funds, freeze them, or mint unlimited tokens for themselves?
  • Who controls it — can one person change the rules whenever they want, or are there real limits?
  • What happens in a crisis — if something breaks, is there a plan, or does everyone just lose their money?

Why it matters to you specifically: if you're holding a token or thinking about buying one, "no audit" doesn't automatically mean "scam" — plenty of small, honest projects simply haven't gotten to it yet. But it does mean nobody outside the team has checked whether the code does what they say it does. You're trusting their word alone. An audit doesn't guarantee a project is good — but no audit means you have no outside opinion at all.

The quickest thing you can check yourself: look at the project's website or GitHub for a section called "Audits" or "Security." If there's a named audit firm and a link to a real report, that's a good sign. If it just says "audited" with no link, or names a firm you've never heard of and can't verify, treat that the same as no audit at all.

Want someone to actually check a specific project for you, instead of guessing? That's what we do.

Get Audit Report

Saw one of our tweets about a specific project? Order the full audit report — team transparency, security gaps, tokenomics risks and more.

$50 USDT
one-time · delivered within 24h
PDF report
sent to your email

Custom Audit

Have a project not in our list? Provide the website URL — we scrape, analyze and deliver a full due diligence report within 24 hours.

$50 USDT
one-time · delivered within 24h
PDF report
sent to your email

Enter the project's own website, not a news article or social media link.

Whitepaper Analysis

Upload a crypto project's whitepaper PDF. Our AI reads the document and scores it across 5 dimensions — team, tokenomics, tech, red flags and legal structure.

$50 USDT
one-time · delivered within 24h
PDF report
sent to your email
See sample →
📄

Click to select or drag & drop PDF here

Max 20MB · Text-based PDF only

Grant Proposal Writer

Give us your project docs and pick a target grant program — we draft a proposal tailored to that program's actual format and evaluation criteria (Gitcoin, Optimism Retro Funding, Arbitrum Foundation, Ethereum Foundation ESP, Solana Foundation).

$200 USDT
one-time · delivered within 24h
PDF draft
sent to your email
📄

Click to select or drag & drop PDF here

Max 20MB — or just describe the project below instead

Treasury Monitor

Ongoing watch on a DAO's Gnosis Safe treasury: current holdings, the pending multisig queue, and flagged anomalies (a new pending transaction, an unusually large single outflow, or a transfer to a destination never seen before). Checked every few hours; a full digest email arrives weekly.

$149 USDT / month
subscription · renews every 30 days
Weekly PDF digest
+ optional Telegram alerts

Primary Market Analysis

Independent, daily risk scoring of crypto launches on the primary market — launchpools, launchpads (IEO / IDO / presale) and airdrops. One question, answered honestly: will this dump, or is it a trap? Not hype, not signals. You get the picture a $100k desk would build before touching a launch — sized for a $100 ticket. Most days the verdict is “skip,” and that’s the point.

$29 USDT / month
subscription · renews every 30 days
Daily verdict + top-3
delivered on Telegram
📊 Public track record → 📖 How it works →
Delivery is on Telegram. Message the delivery bot with /start — it replies with your chat ID. Paste it below so your daily feed lands in your Telegram.

Telegram Bots & Mini-Apps — Turnkey, With Crypto Payments

A payment bot, a paywall for a private channel, or a mini-app. Fixed price, 5–7 day turnaround, and a demo you can try in under a minute.

Still taking payment manually — "DM me for access"? Every person who doesn't wait around for a reply is money lost. A bot accepts payment, grants access, and renews subscriptions itself, 24/7, without you.

1. Turnkey Crypto Checkout

from $300
3–5 day turnaround

Accept USDT and Telegram Stars on your bot or site: CryptoBot, NOWPayments, or your own BTCPay. Automatic payment confirmation — no manually matching transfers in your DMs.

2. Paywall Bot for a Private Channel

from $500
5–7 day turnaround · optional $50–100/mo support

Payment → automatic access to a private channel → renewal reminder → auto-kick for non-payers → re-entry after payment. USDT and Stars out of the box.

3. Turnkey Mini-App

from $1,500
turnaround depends on scope

A Telegram mini-app for your use case with native crypto payment — storefront, subscription, service. Scope discussed individually.

We use what we build

This isn't a slide deck. Every payment on this site runs through exactly this kind of setup: order → USDT payment → automatic delivery, no manual step anywhere. What we build for you, we use ourselves.

→ How our checkout works

Try it live — $1

Open the bot, pay $1, get access to the channel, and watch the reminder, auto-kick, and re-entry-after-payment work with your own eyes. A live product, not a description.

Open @My_Pay_Gate_Bot

How it works

1. Tell us what you need, pick a package.
2. Pay 50/50 in USDT.
3. In 5–7 days the bot is live — we hand over access and the code.

← Back to Bots

How our checkout works

Not a demo built to look good — the same system every order on this site actually runs through.

Every product on kotick.site — including the one you're reading about right now — is paid for through the same checkout: a client submits a form, gets a payment link, pays in USDT through CryptoBot, and the order confirms itself automatically. No one has to notice a message and manually approve it. The confirmation, the report generation, and the email delivery all happen without a human in the loop.

What actually makes this reliable, not just functional:

  • Orders survive a server restart. Order state is stored in a real database, not just in memory — so deploying a new version of the code doesn't silently drop an order that's mid-payment.
  • A payment can never be processed twice. The system that marks an order "paid" is built so that two near-simultaneous confirmations (say, a manual approval and the automatic checker both firing close together) can't both succeed — only one wins, by design, not by luck.
  • Failures are loud, not silent. If something breaks mid-delivery, the system alerts immediately instead of quietly losing the order.
  • Payment links expire on a real schedule — long enough to actually complete a payment from an exchange or external wallet, short enough that an old link can't be paid by mistake days later.

Why this matters to you specifically: if you're paying us to build this exact kind of system for your own channel or bot, this is the proof — not a claim on a page, a working system you can try above for $1 and watch confirm itself in real time.

← Back to Guides

Treasury Monitor, explained

Every other service on this site is a one-time check. This one never stops looking.

A DAO treasury is a shared pool of crypto — often millions of dollars — controlled by a multisig wallet (usually Gnosis Safe), where a set number of people have to sign off before any transaction goes through. That's a good safety design on paper. In practice, almost nobody outside the core team actually watches it day to day. Most token holders and contributors only find out money moved when someone posts about it afterward, if they post about it at all.

Treasury Monitor is a standing watch on one specific Safe address. It checks in every few hours for three things: a new transaction sitting in the signing queue, a single transaction that moved an unusually large share of one holding, and a transfer to a destination the treasury has never sent to before. None of these automatically mean something's wrong — a big payment to a known contractor is normal. But they're exactly the kind of thing you'd want a human to at least glance at, and most people never do because checking a block explorer regularly isn't anyone's job.

How this helps you specifically: if you hold tokens in a DAO, contribute to one, or just want to know your money is being watched by more than the same three people who control it — this gives you (or your community) an independent, automatic second set of eyes, without anyone having to remember to check.

What you get: your choice of a weekly PDF digest by email, real-time Telegram alerts when something's flagged, or both. You pick a Gnosis Safe address and a chain, we do the watching.

Have a DAO treasury that could use a second set of eyes?

← Back to Guides

How to read a whitepaper without a finance degree

Most whitepapers are written to sound impressive, not to be understood. Here's how to cut through that.

You don't need to understand the math to get the important parts. You need to know what a handful of terms actually mean, because most whitepapers lean on them to sound more rigorous than they are:

  • Tokenomics — just means "how the token supply is divided up and released." Who gets what, and when.
  • Market cap vs. FDV (fully diluted valuation) — market cap is the value of tokens in circulation right now. FDV is the value if every token that will ever exist were already circulating. A huge gap between the two means most of the supply hasn't hit the market yet — and when it does, that's more sellers, which usually pressures the price down.
  • Vesting / cliff — the schedule that controls when team and investor tokens unlock. A "cliff" is a delay before anything unlocks at all; "vesting" is the gradual release after that. Short cliffs and fast vesting for insiders is worth noticing.
  • TGE (Token Generation Event) — the moment the token first becomes tradable. Whitepapers often describe big unlocks relative to this date.

Once you know those terms, read the whitepaper in this order: skip the introduction (it's marketing), go straight to the tokenomics/allocation table, then the team section, then the roadmap. If the allocation table is missing, vague ("TBD"), or the team section has no names you can actually search for — that tells you more than the rest of the document combined.

Why this matters to you specifically: the sections most people skim past (allocation percentages, unlock schedules) are usually the ones that determine whether early holders get diluted later. The exciting-sounding vision section rarely does.

Want someone to actually read the whole thing and score it for you?

← Back to Guides

5 signs a crypto project might be in trouble

None of these alone is proof of anything. Two or three together is worth taking seriously.

1. The team is anonymous with no track record. Anonymous doesn't automatically mean bad — some legitimate projects stay anonymous by philosophy. But anonymous plus no verifiable history anywhere (no past projects, no consistent online presence) means if something goes wrong, there's no one to hold accountable.

2. The roadmap stopped updating, but the marketing didn't. A project that's quietly stalled technically often keeps posting hype content on social media at the same pace, or even faster, to cover the gap. Compare the last real product update to the last tweet.

3. Large wallets move right before or after major news. If you can see (via a block explorer) that a handful of large wallets sold heavily right around a big announcement, that's worth noting — insiders trading on information the public just received isn't a good sign.

4. Criticism gets deleted or banned instead of answered. Legitimate teams answer hard questions, even badly. Teams that quietly remove critical comments or ban people who ask about the treasury or the audit are managing perception, not the product.

5. The price and the actual product have stopped being related. If the token is up a lot but nothing shipped recently, that's not automatically a scam — but it does mean the price is being driven by something other than progress, which can reverse just as fast.

Why this matters to you specifically: none of these five things are things a smart contract audit would catch — audits check code, not behavior. This is a different, faster kind of check you can do yourself in a few minutes of looking.

Want a full 5-category check instead of just these five signs?

← Back to Guides

No VC backing — is that good or bad?

By itself, neither. It's a fact that changes meaning depending on what else is true.

It's tempting to treat "backed by well-known VCs" as a stamp of approval, and "no VC backing" as a red flag (or, for some people, the opposite — "no VC" as proof a project is grassroots and honest). Both shortcuts are wrong on their own.

What VC backing actually tells you: professional investors did some due diligence before writing a check, which filters out some obviously broken projects. But it also usually means a chunk of the token supply is reserved for those investors at a low price, with a vesting schedule — and eventually, that supply unlocks and can be sold into the market. VC backing lowers the odds of an outright scam; it doesn't lower the odds of early holders getting diluted later.

What no VC backing actually tells you: it could mean a genuinely grassroots, community-funded project with no outside pressure to eventually cash out. It could also just mean no professional investor looked closely enough to write a check — which isn't the same as passing a check, it's the absence of one being done at all.

How to actually use this fact: don't treat VC presence or absence as a verdict by itself. Look at it together with the other signals — is there an audit? Is the team identifiable? Is the roadmap active? A project with no VC backing, an identifiable team, and a real audit can be a better bet than one with VC backing and nothing else checked.

Why this matters to you specifically: "no VC" and "no audit" often get lumped together as one red flag, but they're separate facts that need separate context — see the audit guide for why an old or narrow-scope audit isn't the same as no audit either.

Want the VC and audit picture checked together for a specific project?

← Back to Guides

Check in 5 minutes whether to trust a new crypto project

Not a deep audit — just enough to catch the most obvious problems before you commit any money.

Run through these before you buy, invest, or contribute time to a new project. Each one takes under a minute:

  • Does the contract show as verified on the block explorer? (Etherscan, BscScan, etc.) If it's not verified, nobody outside the deployer can even read what the code does.
  • Can you find the team anywhere else online? Search their names, not just their project's Twitter. A LinkedIn or GitHub history that predates the project by years is a good sign; accounts created the same month as the token is not.
  • Is there any audit at all, from anyone? Even a small, lesser-known firm's audit is a different situation than nothing. Check the project's GitHub for an `/audits` folder or a link on their site.
  • Is liquidity locked, and for how long? Tools like Team Finance or Unicrypt show this for most tokens. Unlocked liquidity means the team can pull it out and leave at any moment.
  • Does the social media age match the story? A Twitter account created two weeks ago claiming "years of development" is a mismatch worth noticing.

Why this matters to you specifically: this checklist won't catch everything — a project can pass all five and still fail for reasons that only show up in the code or the tokenomics. But it takes five minutes and catches the most common, most obvious problems before you've spent any money finding out the hard way.

Passed the 5-minute check but want real certainty before committing?

← Back to Guides

What does "liquidity locked" actually mean?

It shows up on every checklist, including ours — rarely explained. Here's what's actually being locked.

Most new tokens trade on a decentralized exchange through a "liquidity pool" — a pair of the new token and something stable (ETH, USDC, BNB) that someone deposited so people have something to trade against. Whoever created that pool holds a claim on it, and technically, they can withdraw their share at any time — pulling out the stable side and leaving the token side worthless. That's the literal mechanism behind a "rug pull": it's not some hack, it's just the pool creator using a withdrawal button they always had.

"Liquidity locked" means the team sent that claim to a smart contract that holds it for a fixed period and won't release it early, no matter who asks — including them. Services like Team Finance or Unicrypt do exactly this: you can look up the token's liquidity pool address on either site and see whether it's locked, for how long, and who locked it.

Why this matters to you specifically: an unlocked pool doesn't mean the team will definitely rug — plenty of small, honest projects just haven't gotten around to locking, or lock later. But it does mean the mechanical ability to pull the rug exists right now, with nothing stopping it. A locked pool with a real, checkable expiry date removes that specific risk for as long as the lock lasts — check what happens when it expires, too, since a lock isn't the same as a promise.

One thing to watch for: a short lock (a few days) advertised loudly as "liquidity locked!" without mentioning the duration. Technically true, practically meaningless.

Want someone to check this along with everything else for a specific project?

← Back to Guides

Anonymous team — automatic red flag, or not?

Same shape of question as VC backing: the fact alone doesn't tell you much without context.

Crypto has a real tradition of anonymous or pseudonymous founders — Bitcoin's own creator never revealed their identity, and several well-established, still-running projects were built by teams who never put names to faces. Anonymity by itself isn't evidence of bad intent; for some founders it's a genuine philosophical stance, or protection against regulatory or personal risk in their home country.

What anonymity actually removes: accountability if something goes wrong. If a named team's project fails through negligence or fraud, there's at least a real person whose reputation is attached and who could, in theory, face consequences. An anonymous team that disappears after a failure faces none of that — there's no one to hold responsible, and no track record to check beforehand either.

How to actually judge it, instead of using it as a yes/no filter:

  • Is there a consistent pseudonymous identity with real history — the same handle active for years, with a visible track record — or a brand-new anonymous account with no past?
  • Does the project compensate for the anonymity elsewhere — a real audit, transparent tokenomics, locked liquidity, active and responsive communication?
  • Is the anonymity total, or partial — some projects have one or two named members (e.g. a visible community lead) alongside anonymous core developers, which is a meaningfully different risk profile than full anonymity.

Why this matters to you specifically: treating "anonymous team" as an automatic disqualifier means missing legitimate projects with good reasons for it. Treating it as a non-issue means ignoring a real, meaningful gap in accountability. The useful question isn't "are they anonymous" — it's "what, if anything, stands in for the accountability that a named team would normally provide."

Want the team-transparency question checked alongside audit and tokenomics for a specific project?

← Back to Guides

What a smart contract audit actually checks (and what it doesn't)

"Audited" gets treated as a safety stamp. It's real, useful information — just narrower than most people assume.

A smart contract audit is a firm reading a project's code, by hand and with automated tools, looking for ways it could be exploited: reentrancy bugs, integer overflow, access-control mistakes, logic that lets someone drain funds or mint unlimited tokens. When it's done well, by a reputable firm, it's a genuinely valuable, technical check — this guide isn't arguing against audits.

What an audit does NOT tell you:

  • Whether the team is honest. An audit checks that the code does what the team says it does — it can't tell you whether what they say it does is a good idea, or whether they'll keep their other promises (roadmap, fund usage, decentralization timeline).
  • Whether the deployed code matches the audited code. Teams occasionally change the contract after the audit and deploy the new version without a re-audit. Worth checking the audit report's date and contract address against what's actually live.
  • Whether admin keys are a risk. Code can be exploit-free and still let an admin wallet pause trading, change fees, or mint new tokens at will — an audit will usually note these powers exist, but "audited" doesn't mean "no one has outsized control."
  • Anything about tokenomics, VC allocation, or vesting. That's a financial-design question, not a code-security one — a project can have flawless, audited code and still be structured to dump on early buyers.

Why this matters to you specifically: "audited" is one real, positive signal — not a finish line. The useful habit is checking what firm did it (see our guide on red flags for how audit-firm reputation varies), what scope the audit actually covered, and whether the other categories (team, tokenomics, admin controls) got any independent look at all.

Want the code-audit signal checked together with the categories an audit doesn't cover?

← Back to Guides

What is a rug pull, and how to spot one before it happens

The most common way people lose money in crypto — and the signs that tend to show up first.

A "rug pull" is when the people behind a project take the money and disappear, leaving a token that's suddenly worthless. The name comes from "pulling the rug out" — one moment there's a working-looking project with a rising price, the next the liquidity is gone and there's no one to sell to. It's not always a dramatic exit; sometimes it's slow, with the team quietly selling their own allocation into every bit of buying interest until nothing's left.

The signs that tend to show up first:

  • The team can take the liquidity out. If the pool of money that lets people trade the token isn't locked, the team can withdraw it whenever they like. (See our guide on what "liquidity locked" actually means.)
  • A wallet can mint unlimited new tokens. If the contract lets an admin create more supply, they can flood the market and cash out while you hold the dilution.
  • Ownership is concentrated. A handful of wallets holding most of the supply means a handful of people can crash the price at will — a block explorer's "holders" tab shows this in a minute.
  • Anonymous team plus big promises plus urgency. None of these alone is damning, but together — no accountable people, guaranteed returns, and "buy now before it's too late" — they're the classic setup.

Why this matters to you specifically: almost every rug pull is visible before it happens, in the contract permissions and the holder distribution — not in the marketing. You don't need to predict intent; you need to check whether the mechanism to rug even exists. If it can't happen technically, it usually won't.

Want someone to check the contract permissions and holder spread for you?

← Back to Guides

Honeypot tokens: when you can buy but can't sell

A trap coded into the token itself. Here's how it works, and how to check before you buy.

A honeypot is a token designed so that you can buy it but not sell it. The price chart looks great — it only ever goes up, because the code silently blocks everyone except the creator from selling. You see your balance grow on paper, you feel clever for getting in early, and then when you try to take profit, the transaction just... fails. By the time you understand why, the creator has sold their own bag into all the money that flowed in.

How the trap is usually built:

  • A sell-blocking rule in the contract. The code checks who's selling and rejects the transaction unless it's a whitelisted (usually the creator's) wallet.
  • A 100%-on-sell "tax." Technically you can sell, but the fee on selling is set to take everything, so you receive nothing.
  • A pause switch. Trading works until the creator flips a switch that freezes all sells at the moment of their choosing.

How to check before you buy: free honeypot-checker tools (they simulate a buy and a sell on the contract and tell you if the sell fails) catch a large share of these. They're not perfect, and a "clean" result isn't a guarantee — but a "you can't sell this" result is a hard stop. Also read the token's fees and check whether an admin can change them after launch.

Why this matters to you specifically: a honeypot doesn't look risky — it looks like the best-performing token you've ever seen, which is exactly the point. The green chart is the bait. The one question that matters is whether a normal wallet can actually sell, and that's checkable before you spend anything.

Not sure how to read a contract? We check sell-ability and admin powers as part of every report.

← Back to Guides

A team has names and photos — how do you know they're real?

"Doxxed" isn't the same as "verified." Here's how to actually check the people behind a project.

A project page with headshots, full names, and job titles feels reassuring — but a photo and a name cost nothing to invent. Stock images, AI-generated faces, and borrowed identities all show up regularly. "The team is public" only helps you if the public team is actually real and actually working on this project. That's a separate check, and it's not hard to do.

What actually verifies a team:

  • Reverse-image-search the photos. If a "founder's" headshot is a stock photo or belongs to someone with a different name, you're done — that's a fabricated identity.
  • Cross-check LinkedIn and history. A real professional usually has a trail: prior roles, a network, activity that predates this project. A profile created last month with three connections is a flag.
  • Match claims to reality. "Ex-Google," "advised by [big name]" — these are checkable. Look for the claim confirmed from the other side (the person's own profile, the company), not just asserted on the project's page.
  • See if the person acknowledges the project publicly. Someone genuinely involved will usually reference it somewhere they control — their own account, a talk, a post — not only appear on the project's own website.

Why this matters to you specifically: a named team is only a positive signal if the names hold up. Treating "they're not anonymous" as reassurance — without spending five minutes confirming the people exist and are really involved — is exactly the gap that fake-team projects rely on.

Team verification is one of the five categories in every report we run.

← Back to Guides

Presale, ICO, IDO, IEO: what they mean and where the risk hides

The alphabet soup of token sales, in plain English — and which structure actually protects you more.

These are all ways a project sells its token to the public for the first time. They differ mostly in who stands between you and the team — and that's the part that affects your risk, so it's worth knowing which is which.

  • Presale / private sale: tokens sold early, often to insiders or a small group, usually at the lowest price. You're buying before almost anyone — which means the least information and the most trust required. Presale buyers can also be the first to sell on you later.
  • ICO (Initial Coin Offering): the project sells directly to the public, on its own terms, with no one vetting it. Maximum openness, minimum gatekeeping — the classic 2017 model, and the one with the least protection.
  • IDO (Initial DEX Offering): the launch happens on a decentralized exchange. Trading is immediate and permissionless, but "on a DEX" is not a stamp of approval — anyone can launch an IDO, honeypots included.
  • IEO (Initial Exchange Offering): a centralized exchange hosts the sale. The exchange does some vetting and puts its reputation on the line, which is a mild positive signal — but it's the exchange's bar, not a guarantee, and bigger exchanges vet harder than small ones.

Where the risk hides: the earlier and less-gatekept the sale, the more the burden of checking falls entirely on you. None of these labels tells you the token is safe — an IEO on a serious exchange is a slightly stronger starting point than an anonymous presale, but every one of them still needs the same look at team, tokenomics, and contract permissions.

Why this matters to you specifically: knowing the sale type tells you how much has already been checked by someone other than you — which is usually "very little." That's not a reason to avoid them, just a reason to do the checking yourself before, not after.

Weighing a token sale? Get the team, tokenomics, and contract checked first.

← Back to Guides

Airdrop safety: claiming free tokens without draining your wallet

Free tokens are the oldest bait for the most expensive mistakes. Here's how to claim safely.

An airdrop is free tokens sent to wallets, usually to bootstrap a community or reward early users. Real ones exist. But "you have an airdrop to claim" is also one of the most effective scam hooks there is, because the excitement of free money is exactly what makes people skip the checks they'd normally do.

The two ways airdrops actually cost you money:

  • The malicious claim page. A fake "claim" site asks you to connect your wallet and approve a transaction. The approval isn't claiming anything — it's granting permission to move your existing tokens out. You sign, and your wallet is drained.
  • The dust token that lures you to a trap site. A worthless token appears in your wallet unprompted, named to make you curious. Interacting with it or visiting the site in its "description" leads to the same approval trap.

How to claim safely:

  • Only ever claim from the project's official site — found through their verified channels, not a link in a DM, reply, or the token's own metadata.
  • Read what you're signing. A claim should not require approval to spend tokens you already hold.
  • Use a separate "burner" wallet for claiming, with nothing valuable in it.
  • Tokens that show up unrequested: don't interact. Leave them, or hide them. Just holding them is harmless — doing something with them is the risk.

Why this matters to you specifically: the danger in an airdrop is almost never the token — it's the transaction you're persuaded to sign to "get" it. Slow down at the approval step, and the vast majority of airdrop scams simply can't touch you.

Not sure if an airdrop or its project is legit? We can check it before you connect anything.

← Back to Guides

How to check a token's contract address is the real one

Fake copies of real tokens are everywhere. One habit protects you from almost all of them.

Anyone can create a token and call it whatever they like. There can be dozens of tokens named "Arbitrum" or "Pepe" or the name of whatever is trending — identical name, identical ticker, identical logo — and only one of them is the real one. What tells them apart is the contract address: the unique on-chain ID of that specific token. Buying by name instead of by address is how people end up holding a worthless clone of a real project.

The habit that protects you:

  • Get the address from the project's own official source — their website, verified account, or docs — not from a search result, an ad, or a message.
  • Cross-check it on a listing site like CoinGecko or CoinMarketCap, which show the official contract address per network for the real token.
  • Paste that exact address into your wallet or the exchange when buying — don't rely on the name auto-completing, and don't trust a token that's already sitting in your wallet unrequested.
  • Mind the network. The same project can have a real token on several chains with different addresses — make sure the address matches the chain you're actually on.

Why this matters to you specifically: a huge share of "I bought a scam" stories aren't sophisticated hacks — they're someone buying a same-named fake because they searched the name instead of confirming the address. Sourcing the contract address from the official channel is a ten-second habit that removes almost the entire category of risk.

Want the right contract confirmed and checked before you buy?