# Do Your Own Research 101: Crypto Course

A Wealth of Opportunities in the Crypto World

The world of cryptocurrency is bursting with opportunities. The total market capitalization of all cryptocurrencies has surpassed $1 trillion. This figure is likely much higher now, showing the immense growth and potential of the industry.

The market isn't just about Bitcoin or Ethereum; it's teeming with various projects. From Decentralized Exchanges (DEXs), wallets, and blockchain games, to novel DeFi protocols and NFT platforms, there's a vast landscape to explore.

For traders who've had a rough ride, this diversity presents a second chance. Instead of focusing on a few high-profile cryptos, why not delve into the broader market?

There are countless lesser-known projects with solid fundamentals, impressive tech, and promising futures. These projects offer the potential for significant returns, but they also come with risks. To navigate these risks and identify the best opportunities, you need a comprehensive approach: Doing Your Own Research (DYOR).


# The Importance of DYOR

In the fast-paced, high-risk world of crypto, Doing Your Own Research (DYOR) isn't just a mantra, it's a necessity. While expert insights and community sentiment can be helpful, nothing beats firsthand knowledge. By researching and understanding the projects you invest in, you'll be better equipped to make informed decisions and weather the market's storms.

Over the course of this article series, we'll guide you through the ins and outs of DYOR.

### **Follow this checklist to become a DYOR expert:**

&#x20;         \[  ] Learn about DYOR opportunities (you are here)

### &#x20;    Become aware of DYOR challenges

&#x20;         \[  ] Navigate scams and frauds

&#x20;         \[  ] Learn about rug pulls and exit scams

&#x20;         \[  ] Understand market volatility

&#x20;         \[  ] Learn about regulatory challenges

### &#x20;    Identify worthy crypto projects

&#x20;         \[  ] Monitor market trends and indicators

&#x20;         \[  ] Look up projects

### &#x20;    Evaluate crypto projects

&#x20;         **Check Product Health**

&#x20;              \[  ] Research product potential

&#x20;              \[  ] Research product usage

&#x20;              \[  ] Research product monetization

&#x20;              \[  ] Research product roadmap

&#x20;         **Check Tokenomics Health**

&#x20;              \[  ] Research token utility

&#x20;              \[  ] Research inflationary mechanics

&#x20;              \[  ] Research deflationary mechanics

&#x20;              \[  ] Research tokenomics performance

&#x20;         **Check Community & DAO**

&#x20;              \[  ] Research сommunity engagement

&#x20;              \[  ] Research DAO performance

&#x20;         **Check Security**

&#x20;              \[  ] Research product security

&#x20;              \[  ] Research smart contracts security

&#x20;              \[  ] Research bug bounty

&#x20;              \[  ] Research incidents

&#x20;         **Check Team, Partners & Investors**

&#x20;              \[  ] Research team composition and experience

&#x20;              \[  ] Research partnerships

&#x20;              \[  ] Investors

&#x20;         **Check Legal Risks**

&#x20;              \[  ] Research incorporation

&#x20;              \[  ] Research UI decentralization

&#x20;              \[  ] Research DAO registration

### &#x20;    Become DYOR champion

&#x20;         \[  ] Compare projects in one category

&#x20;         \[  ] Tap into collective mind

&#x20;         \[  ] Monitor DYOR trends and new solutions

&#x20;         \[  ] Constant learning

Want to discuss? Join Hacken DYOR Community:  <https://discord.gg/draFdqzecP>


# How to Navigate DYOR Challenges in Crypto

In this chapter, you will learn how to navigate the challenges of conducting thorough research in the world of cryptocurrencies. The crypto landscape presents various obstacles, including scams and fraud, market volatility, rug pulls, exit scams, and regulatory complexities. By understanding these challenges, you will be better equipped to make informed decisions and protect your investments in the crypto space. Let's delve into each of these areas to develop a comprehensive understanding of how to safeguard your crypto ventures.


# Scams and Fraud

![](https://lh5.googleusercontent.com/mLtVbxQrH8PSuUZojSPlNHLxUCWUzOj2ghJ8Uu1camjfY4N0s8R9Ay60iVRTWYSqAVI5zx0TioxsNhqLMyMeIgafAFffWOiNfpIeeUxgCT12b_Ul2INr-j8BDsz4XIKzxT6hVWwsPqp-ZE4ozLkOPCo)

Scams and fraud have found a way to seep into the crypto market, preying on the excitement of investors and exploiting the Fear of Missing Out (FOMO).

One example of such a scam is the Ponzi scheme BitConnect, which promised high daily returns and lured unsuspecting investors into a trap. When BitConnect collapsed in 2018, those who had bought in were left with massive losses.

On the other hand, legitimate projects like Ethereum focus on creating real value. They have transparent, open-source blockchains and committed teams, providing a solid foundation for investors to trust.

Another fraudulent method found in the crypto world is phishing scams. These scams often disguise as trustworthy entities to trick you into revealing sensitive information.

A prime example of a phishing scam is the notorious Twitter Bitcoin scam of 2020. High-profile Twitter accounts were targeted to promote a Bitcoin scam, leaving many victims in its wake.

In contrast, genuine projects like Cardano prioritize transparency and peer-reviewed research. These qualities demonstrate the ethos of a trustworthy crypto project and provide investors with the confidence they need to invest.


# Market Volatility

![](https://lh4.googleusercontent.com/NGan2UrSurRyMvKzihgMAKYMTt17gexn0RQzhWHJMZTIIga4tu2BOhAu9tvUil5dn-o1QnHZC-D6tvLD3Q6jCrQTP6n1rL_Yu7MabJlDjBAIjTSQroG8g4g2049SGt-_Dyb7uNAOwB1yRciTtFnxB8c)

The crypto market is infamous for its extreme volatility, with prices shifting significantly within hours and catching investors off guard.

One example of this is Bitcoin's value soaring from around $5,000 to over $60,000 within a year, only to recede to around $30,000 in the following months.

Traditional markets like the stock market have measures to limit extreme fluctuations. With a disciplined investment strategy, investors can better navigate market volatility.

Market volatility isn't always negative; it can also present opportunities for high returns.

Those who purchased **Bitcoin** during its low in March 2020 and held on could have enjoyed significant gains by the end of the year. However, such opportunities require keen market understanding, patience, and a pinch of luck.

A cautious approach is often the best strategy, as market manipulation can contribute to the crypto market's volatility. Pump-and-dump schemes artificially inflate an asset's price, only to sell off at a higher price, leaving unsuspecting investors with losses.

Well-established cryptocurrencies like Bitcoin and Ethereum have more liquidity and market depth, making them less susceptible to market manipulation.


# Rug Pulls and Exit Scams

Rug pulls and exit scams are prominent risks in the crypto market. They occur when developers abandon a project after raising funds, causing the associated cryptocurrency's value to drop sharply.

SushiSwap is a prime example of such a situation. The project's anonymous creator sold off a significant portion of their tokens, which sent the price into a tailspin.

However, conducting thorough due diligence can help you steer clear of such risks. Before investing, it's essential to scrutinize the project's team, its code, and overall credibility.

Rug pulls and exit scams are often confused, but there are subtle differences between them. A rug pull is a more specific form of exit scam, wherein the liquidity is removed from a decentralized exchange, making it impossible for investors to sell their tokens.

In contrast, exit scams encompass a broader range of fraudulent activities, including when developers simply abandon the project after raising funds.

Understanding the project's roadmap and the team's past accomplishments can provide valuable insights. An important point to remember is that anonymity isn't always a sign of ill intent.

Bitcoin, the pioneer of cryptocurrencies, was created by the still anonymous entity, Satoshi Nakamoto. Despite this, Bitcoin has proven its resilience and legitimacy over time.


# Regulatory Challenges

Regulatory challenges pose a significant risk in the crypto market. The decentralized nature of cryptocurrencies is often at odds with traditional financial regulations, causing uncertainty and volatility.

For instance, various jurisdictions have different views on cryptocurrencies. Some countries like Japan and Switzerland have embraced them, while others like China and India have imposed stringent regulations or outright bans.

However, regulatory hurdles are not necessarily a death sentence for crypto projects. Some blockchain projects, such as Ripple, are actively working with regulators to ensure compliance and foster innovation.

Another major regulatory challenge in the crypto market is the possibility of securities regulations being applied to Initial Coin Offerings (ICOs) and token sales. This adds a layer of complexity and uncertainty for both project developers and investors.

A case in point is the SEC's lawsuit against Ripple Labs, alleging that its XRP token is a security and was sold illegally. This caused significant shockwaves in the crypto market and led to a steep drop in XRP's price.

On the other hand, Ethereum's ICO in 2014 was a game-changer for the crypto space, ushering in the era of ICOs. Ethereum has since been confirmed by the SEC not to be a security, paving the way for other projects to follow its path.

Lastly, the lack of a global regulatory framework for cryptocurrencies is a major challenge. This leads to a fragmented regulatory landscape, making it difficult for crypto businesses to operate across borders.

For example, Binance, one of the largest crypto exchanges in the world, has faced regulatory scrutiny in several countries, causing disruptions to its operations.

However, some crypto projects are proactively seeking regulatory clarity. They collaborate with regulators and lawmakers to contribute to the formulation of fair and comprehensive regulations. One such project is the Digital Chamber of Commerce, which advocates for blockchain technology at the policy level.

Continue your DYOR journey in the next article: How to identify worthy crypto projects.


# How to Identify Worthy Crypto Projects

In this chapter, you will learn how to identify worthy crypto projects by mastering the art of deciphering market trends and indicators.&#x20;

Understanding the pulse of the crypto market is the first crucial step toward making informed investment decisions. We will delve into key indicators, such as market sentiment and the Bitcoin dominance index, that can guide you in recognizing promising opportunities and avoiding potential pitfalls. Additionally, you will discover valuable resources and strategies for researching specific projects, helping you build a shortlist of cryptocurrencies that align with your investment goals. Let's embark on this journey to uncover the secrets of identifying crypto projects with the potential for success.


# Market Trends and Indicators

Understanding the pulse of the market is the first step towards identifying promising crypto projects. This involves staying updated with the market trends. One such significant trend to keep an eye on is the overall market sentiment. Positive sentiment is often a sign of a bullish market.

Consider the end of 2017, when the crypto market saw an influx of retail investors. This rush was driven by positive sentiment, pushing the prices of various tokens to new highs.

However, it's crucial to be aware that market sentiment can sometimes be misleading. During the euphoria phase of a market cycle, extreme optimism can lead to inflated asset prices. This was evident during the ICO boom of 2017-2018, where despite the overwhelmingly positive market sentiment, many projects failed to deliver, leading to losses for investors.

The second crucial trend indicator is the Bitcoin dominance index. A high Bitcoin dominance often points to a risk-off environment in the altcoin market. This is because during times of market uncertainty, investors tend to move their funds from altcoins to Bitcoin, leading to an increased Bitcoin dominance.

For instance, during periods of market uncertainty or bearish trends, investors often shift their funds from altcoins to Bitcoin. This shift results in increased Bitcoin dominance.

However, a high Bitcoin dominance doesn't always mean that altcoins are a bad investment. During the "alt season" of early 2021, Bitcoin dominance fell drastically as altcoins soared in value. Investors who solely relied on Bitcoin dominance as an indicator would have missed out on significant returns offered by the altcoin market.


# Looking up Projects

When you've identified potential market opportunities, the next step is to investigate specific projects. Here are some resources you can start off with:

* [https://www.coingecko.com](https://www.coingecko.com/)
* [https://coinmarketcap.com](https://coinmarketcap.com/)
* [https://www.cryptocompare.com](https://www.cryptocompare.com/)

Inside these project directories, you have to look for category pages like:

* cybersecurity projects
* meme tokens
* AI tokens

The idea is to narrow down into a specific submarket within all crypto projects. Once you’ve decided which market to research more thorough, you can start comparing project properties:

* market capitalization
* trading volume
* price performance
* community

Feel free to note down your shortlist in a spreadsheets or notes. Our top pick goes to:

* Notion
* Obsidian


# How to use the CAPED framework for surface DYOR

![](https://lh5.googleusercontent.com/pvg9NCM_0xJv7Sph3a4qZWU0_USo6qLUCCUgLQJPyrPr4uQoqCBxRVlx4lxs6gUdy8ixGWzmPY65MxY7IU8L_xgpB_vj526qVJL6dgp4lRxesqZMzmRMPhUPPrE8zK3KGUFL-edmq0bGhAyfgmSZGps)

To sort the researched projects by their potential for being alpha, use the CAPED approach. Analyze and score 4 factors:

1\. Capitalization of a project:

* 0 points: Under $1M
* 1 point: $1M - $10M
* 3 points: $10M - $100M
* 2 points: $100M - $1B
* 1 point: Over $1B

Small market cap projects have higher potential returns but also higher risk, hence the U-shaped scoring.

2\. Activity of traders:

* 0 points: Under $10K
* 1 point: $10K - $100K
* 3 points: $100K - $1M
* 2 points: $1M - $10M
* 1 point: Over $10M

Again, trading volume is U-shaped since both low and high volumes can be a sign of risk - low volume means potential illiquidity, while high volume could indicate pump-and-dump schemes.

3\. Price Performance:

* 0 points: Negative performance
* 2 points: 0% - 25%
* 3 points: 25% - 50%
* 4 points: 50% - 100%
* 1 point: Over 100% gain

A recent excessive price gain might indicate a recent pump, hence a lower score.

4\. Engagement inside the community (Twitter/Discord/Telegram users):

* 0 points: Under 1,000 users
* 2 points: 1,000 - 5,000 users
* 4 points: 5,000 - 10,000 users
* 3 points: 10,000 - 50,000 users
* 1 point: Over 50,000 users

A larger community might indicate a hype-driven project, hence the inverted U-shaped scoring.

5\. **Development** (Github commits in the last 30 days):

* 0 points: 0 commits
* 3 points: 1-10 commits
* 4 points: 11-50 commits
* 2 points: 51-100 commits
* 1 point: Over 100 commits

Continue your DYOR path in the next article: How to evaluate crypto projects.

<br>


# How to Evaluate Crypto Projects

In this chapter, you will learn how to evaluate crypto projects effectively. We'll guide you through the essential steps to assess both the product and token aspects, ensuring you can confidently evaluate their health and potential. Discover how to scrutinize product health by researching its potential, usage, monetization strategies, and roadmap. Additionally, gain insights into checking tokenomics health, covering key aspects like token transactions, supply, and project security. Unlock the knowledge to make informed decisions in the world of cryptocurrencies.


# How to Check Product Health - Article 1

#### How to research product potential

Product potential can be analyzed with 3 key factors:

* value proposition
* competitive advantage
* business model

For value proposition, try to understand what’s the key feature that provides the most value to users.

For competitive advantage, find the differences in similar products. This can be the novelty of an idea or a cheaper price.

For business model, research how the project is monetized, how do the revenue streams work. If this is not a public information, ask their community about it.

#### How to research product usage

Product usage can be analyzed with 5 key factors:

* brand demand
* trading volume
* total value locked
* token price
* unique active wallets

To research brand demand, you will need access to SEO tools like Ahrefs. The idea is to research product name as a keyword. High search volume per month indicates a top of the funnel demand.

To research trading volume and price you can use these services:

* [https://www.coingecko.com](https://www.coingecko.com/)
* <https://defipulse.com/> (good for TVL too)
* [https://coinmarketcap.com](https://coinmarketcap.com/)
* [https://www.cryptocompare.com](https://www.cryptocompare.com/)

Data on unique active wallets is harder to come by, use these services:

* [https://etherscan.io](https://etherscan.io/)
* [https://glassnode.com](https://glassnode.com/)
* <https://dune.com/>

#### How to research product monetization

Product monetization can be broken down into 4 key factors:

* Fees
* Revenue
* Treasury
* Price

To research fees, you should look into the blockchain transactions of the specific project. The charges applied for each transaction, whether in swapping, staking, or any other interaction with the blockchain, are a good indicator of how the project generates fees. Resources like [https://etherscan.io](https://etherscan.io/) provide insights into such transactions and the associated fees.

Revenue is a clear indicator of a project's financial health. This can be explored by understanding the project’s business model and how it earns income. This may be from transaction fees, services, or even yield farming rewards. Comprehensive details can often be found in the project's whitepaper, and aggregators like [https://www.coingecko.com](https://www.coingecko.com/) and [https://defipulse.com](https://defipulse.com/) often provide snapshots of revenue streams.

Treasury management is crucial in a crypto project's sustainability and growth. The treasury's size and management can be investigated through on-chain data and governance proposals. Services like [https://deepdao.io](https://deepdao.io/) and <https://etherscan.io/> can provide a window into a project's treasury.

Finally, price is an important but volatile metric. It should be analyzed in relation to the other factors mentioned to get a comprehensive view of the project's financial health. Crypto price tracking platforms like [https://coinmarketcap.com](https://coinmarketcap.com/)and <https://www.coingecko.com/> are great places to get accurate and up-to-date price data.

#### How to research product roadmap

Examining a crypto project's roadmap can be boiled down to 4 key elements:

* Clarity of Goals
* Milestone Achievements
* Timeline
* Technical Feasibility

To assess the clarity of goals, you need to dive deep into the project's whitepaper and official announcements. A clear, precise roadmap will include specific objectives and development plans. If these are vague or too broad, it could be a warning sign.

The milestone achievements refer to the completed objectives set out in the roadmap. It's essential to verify whether the team has successfully met their milestones. Websites like <https://coinmarketcal.com/> and <https://coincheckup.com/>can be handy in tracking these milestones.

Timeliness is crucial in a roadmap. Projects that consistently meet their deadlines reflect positively on the project's reliability. Again, using platforms like CoinMarketCal will help track whether a project is meeting its deadlines.

Analyzing technical feasibility involves some technical knowledge. It's crucial to ensure that the goals set out in the roadmap are technically possible within the stated timelines. Technical discussions on platforms like <https://github.com/> and Bitbucket <https://bitbucket.org/> can provide some insights into this aspect


# How to Check Tokenomics Health - Article 2

#### 1.1 Advanced description of tokens

![](https://lh6.googleusercontent.com/7qTSESBWtzlQeVAhbMdQT0t9DchCtSDxIKPS6oQoXfH9T_2KMtev_AQhMceLFpGTd0LIqKexCLbm9GWweNwRKQmnd9FCOsS2-_nzb3I2jnmPUjPnbFaFTicb-lMjweJ-q263GuoVseeFzbvpC7O1R1c)

Many concepts in the blockchain industry have profound implications. As we discussed, tokens represent some value within the ecosystem. They can be used to finance a company's operations, pay fees for transactions, and represent a stake in the project. Token holders and stakers can receive various benefits like airdrops, roles in their community, or governance rights.

But with rights, a burden of responsibility is attached to the issuers of tokens.

#### 1.2 How tokens can be used to create an economy

Bitcoin was created to be a global monetary system. Along the way, its purpose has evolved into a store of value, an inflation hedge, digital gold, or a scam - depending on whom to ask.

The same thing has happened to Ethereum - from being a humble funding mechanism and fee-paying token, it became a multipurpose juggernaut.

The key factor in the token's success is - is it being used? And for a token to be valuable, it has to solve some economic or governmental problems for a community of users. Hence, an issuer is pressured to establish an economic system that uses a token.

![](https://lh3.googleusercontent.com/qpfDlf7L15Hptm42v8szV4_sQF9nfGVElgjZsk1RF5vv_DK_Olm1vMcxTWGxK-CXgfen73TcyMy0jVMWQn_bKb7cSPWGDNXJ-JO0rTGn-QQd31x0iIOqNAHqv7EdUzx7pXkGktQ-N6O_RvZhU1STt7I)

#### 1.3 How projects describe their tokenomics

Whenever a project is planning to release a token, they have to create an explicit plan of its role in the ecosystem and who will be a beneficiary.

Having a detailed understanding of token use cases should give information to potential users on why they might need it, as well as how much they might need to spend to achieve their goals. Below we explore the evolution of Ribbon.Finance governance token.

<https://ribbonfinance.medium.com/ribbonomics-b070e269fbb3>

And disclosing all beneficiaries of the token mint is a standard practice in the financial world to prevent price manipulation. Here is the token allocation of a protocol described earlier:

![](https://lh5.googleusercontent.com/Wx6m6Y0-N3gqJt9bReCX_DowyF_RVaziaApL-IiPl92P1KFxO9xdtqMJJRriOXtxmkX03m0zUn3yQBCr3LikrCHAUkSky5QIQl6UZ8HpgmSb2sYQjRxDghgkTaX1EFuw2yuu_vcDOavCpqyn2q82FC4)

<https://docs.ribbon.finance/ribbon-dao/overview-and-rbn-distribution>

#### 2.1 How tokens are created with a help of smart contracts

Not all tokens are created the same way, but for one to be created on Ethereum network, an issuer must develop and deploy a smart contract. This contract should have "mint" and "transfer" functions, which would allow the developer to create and distribute tokens.

Let's continue exploring Ribbon.Finance and use their token as an example of typical mint-and-distribute action.

![](https://lh5.googleusercontent.com/drQ0v1aRgNwNbg8LQSSAdziBv0SRb4_tvFRGBRO6zGNqZx_hPcwfkDirRCoEQhWZu9qfSj3RO5w-DyQDBhFbOI5EcUqZ1noYLjpEqiG3yk2l8LxfUXOzT65hnDnYR_uJzJbck757YIxnwag_VCKUJ1Q)

<https://etherscan.io/tx/0x847230516f02021df2ae29d3c668b03b989d8e6097ab43297888073d32c33ba1>

In the "Token Transferred" field, we find that tokens have been minted out of "Null Address" and transferred to a multisig, a wallet controlled by multiple parties. Multisigs significantly increase the security of funds and are a common practice in the crypto industry.

#### 2.2 Token transfers after Token Generation Event

The next step of our analysis is to follow the initial transaction and see where coins went after the first transfer.

<https://etherscan.io/token/0x6123b0049f904d730db3c36a31167d9d4121fa6b?a=0xdaeada3d210d2f45874724beea03c7d4bbd41674>

Our goal is to see the first transactions in this multisig wallet. To do that, go to the last page of the list of transactions. The oldest transfer on the list is a Token Generation Event. But all following transactions represent the distribution of coins between various involved parties - 30m tokens went to the Airdrop Contract, 450m - to the Community Treasury, etc.

#### 3.1 Introduction to token allocation

We got a little bit familiar with the token allocation process in previous parts, but why do we care so much about it?

If there are 1,000,000 tokens minted, among which only 10% are available on the open market, the price per token will be significantly higher than if 100% of tokens are available. But if circulating supply\* would suddenly increase - the price would fall proportionally.

Therefore we need to understand which parties control which amounts of tokens and where they are allowed to dump them on the market.

#### 3.2 Team Allocation

As we know by now, there are multiple parties who usually receive token allocations. First and most common are the team members. Many programmers, business developers, and executives work for the percent of the total token supply.

In the example below, you will find a token allocation scheme of a JonesDAO, a community-driven project to create sophisticated investment strategies. Hacken does not advise you to invest in any projects, and all examples given are here for educational purposes only.

<https://docs.jonesdao.io/jones-dao/jones-token/tokenomics>

According to the scheme, we can expect that team members will receive 12% off 10,000,000 JONES tokens, vested for 18 months. And here they are - divided into 5 transactions.

![](https://lh5.googleusercontent.com/M6Q0R3tqYaIOLaEsX3R-EsP_JJnDOg18xLqiduLOk0qDzlYfgk6cpWn7iywAM0aA2PtusCRuENAUN5lZ-mC13I0CgOepjrdPUc3hPkSdj09kEzC03GGzZI0yGJEWJR-PdgaOwMtBU5PGEPRWxT_QrGU)

<https://arbiscan.io/tokentxns?a=0xc1d9682db60955d64f263025b282acbf8cda55b7&p=2>

#### 3.3 Investors/Advisors

Another, arguably more important group for our purposes are Investors and Advisors. These people and organizations help to fund and shape operations at the early stages of a project.

In the example of JonesDAO, investors are under the category of Private Sales and received 9.7% of the total allocation. To find it in blockchain explorer, we should look for an approximately similar sum, and here it is:

![](https://lh6.googleusercontent.com/EyLWmLnxVqVlznMgy0Yv1J-SFWYC7TFMtnORXjCKGXy87w-nZv1ZzBrQ_pgkT2yvEoBu1W5gbv2xWmPs-77HO_pRevGml72dSyEXtSD6NHIZTaUP5X5dowDyNmEyaXL1nAfqmvL4clwRFtdfMYiKyiw)

* \*<https://arbiscan.io/token/0x10393c20975cf177a3513071bc110f7962cd67da?a=0x4817ca4df701d554d78aa3d142b62c162c682ee1**>

<https://arbiscan.io/tx/0xda84531df6f6d9f73586029a9159354bddcaeaba7893ecf22424d998e280eea6>

Another part that falls under the "Investors" category is OlympusDAO, as they helped launch the project. We are looking for a transaction for approximately 330,000 tokens. There are two which may be valid:

<https://arbiscan.io/tx/0x00c229059f207fc798ff52ac011b9f8e005c49a35f1104f2e9b52b427b139e5e>

<https://arbiscan.io/tx/0xa75a8ae07511ca56459decbc08c7a5d380ea1ce3d691b4fbc168113c472a5abd>

We know, however, that the recipient of the first transaction is a contract called "Staking Rewards". So it's the second transaction that we need.

#### 3.4 Community distribution

Decentralized projects are incentivized to acquire as many token holders as possible. That is why they are creating multiple ways to distribute coins between people. Continuing to explore JonesDAO, we can see that they incorporated three distribution methods: Public Sales, Airdrop, and Platform Rewards.

<https://arbiscan.io/address/0x5a81abb52d96241d15d8b2bdcd76034e4119829b>

<https://arbiscan.io/address/0x5444c71cdd5ed85b6d51a297175bf71914e7944d>

Platform Rewards are distributed directly from the token smart contract, and can be identified by the “From” column - these transactions would be sent from the Null Address.

#### 3.5 Infrastructure

Last but not least, a group of addresses where tokens may go after they've been minted - to places where regular people can easily accumulate tokens. These are both centralized and decentralized exchanges, as well as bridges.

JonesDAO did not explicitly transfer coins to the infrastructure, but here is an example from our previous case study, Ribbon.Finance:

<https://etherscan.io/token/0x6123b0049f904d730db3c36a31167d9d4121fa6b?a=0x4e79d76173099469f982fc19df2c784d06465c98>

In this transaction, they transferred 1% of the token supply to Uniswap, the largest decentralized exchange.

#### 4.1 Introduction to distribution within the community (Airdrops, Farming)

In the previous chapter, we touched on a number of definitions that might puzzle some people.

What is an Airdrop? It is a method of sending tokens to the early participants in the protocol and is done to reward those who use protocols before they become big.

![](https://lh3.googleusercontent.com/1nAZRK0alYXjeVVAuzzbUT4POfypPjeZ4vFxWTA8BZKSOc1Inpthpk3_Vmoq7bH_8nD27dkcH066gPEJIjTVG8AhBQFY6zHED1skoShQqjB-h9SZ_EhnW12fPqWqEwSXqtIZjH40wacdwSKVm0thbiQ)

<https://optimistic.etherscan.io/address/0xfedfaf1a10335448b7fa0268f56d2b44dbd357de#tokentxns>

Community rewards or liquidity mining is a way to incentivize people to put their funds in a protocol and earn additional rewards. Sometimes tokens are given to another protocol to establish a collaboration and involve people from several communities. An example of that can be found on Aave, where you receive an Optimism Governance Token atop of the regular rewards. These programs are temporary in nature.

#### 4.2 Introduction to types of token allocation

![](https://lh3.googleusercontent.com/tm5KY9comHoECZlLChPgH9SbT-V2aLxVSDbWr9PDV6tN8-GjadzvbUylxl28BWyfbmbofAmIPMujI-7kwl_V95asLwHe3-I2HkPANRekUkBYeBAQceVyBx8fDaWqYjNvpmFNGIKoy0kp4piCytch8PU)

A typical way to allocate coins after the mint is to move them to a multisig that belongs to the team members or community treasury and then distribute it across investors, advisors, marketing, foundation, airdrop participants, and all the necessary smart contracts.

It is also common practice for teams and investors to lock up tokens for a period of time to show confidence in the project, as well as protect the public from token dumps.

#### 4.3 Vesting schedule

One way to lock up tokens is to have a vesting schedule - an algorithm that unlocks coins as time progresses. There are multiple ways to do vesting - from linear unlocks, where funds are released regularly each day/week/month/year, to continuous streaming of funds.

Since we now know how to interact with smart contracts through blockchain explorers, let's read a vesting schedule on Ribbon.Finance treasury:

[https://storage.googleapis.com/trusty-army-images/Task 3 {Analyzing Token Distribution}/Section 3.4.3-1.mp4](https://storage.googleapis.com/trusty-army-images/Task%203%20%7BAnalyzing%20Token%20Distribution%7D/Section%203.4.3-1.mp4)

<https://etherscan.io/address/0x42c1357aaa3243ea30c713cdfed115d09f10a71d#code>

<https://etherscan.io/address/0x42c1357aaa3243ea30c713cdfed115d09f10a71d#readContract>

Here we are interested in the starting and ending date of vesting, which can be read through the "start\_time" and "end\_time" methods. Note that the time you get from these methods has to be converted from UNIX to a human-readable format. You can do that through services like

<https://wtools.io/convert-unix-time-to-date-time>

#### 4.4 Cliff periods

Another interesting method in this contract is the "Cliff Period". If you click on it, you'll see that the cliff period of this vesting schedule is 0, meaning that the release of funds started from the "start\_time".

<https://etherscan.io/address/0x42c1357aaa3243ea30c713cdfed115d09f10a71d#readContract>

However, if it is larger than 0, it would mean that there is a period in the beginning when funds are not released. For example, if a vesting schedule is planned for 2 years with a cliff of 1 year, coins will start to be accessible only after 12 months.

#### 5.1 Tokenomics description as a part of whitepapers

![](https://lh4.googleusercontent.com/DZYFnUMoO2Bms74yMQnv8oVwlJSnZzRcNdSROKBguZUX5XwiIQQxmSvdIIPwHDfChuAJyoPdlty0L5anY972Jd6nw4Vy3mFDkI2-FMLfX0QXHe4s1jelQHuNkTThWcMBE0naDxGWMErzbvd96GTw41Y)

If you want to do your own research, it is of utmost importance to be able to find whitepapers that crypto companies provide. Not only do you become familiar with all risks and benefits of using this protocol through reading the whitepaper, but you also become acquainted with the token economy or tokenomics of a project.

We've already established the importance of token allocation and will now focus on where to search for tokenomics descriptions.

#### 5.2 Official website (find through CoinGecko)

First and foremost, our primary source of information about the token is the official website of a project. If you want to be sure that you are in the right place, use CoinGecko or similar aggregation tools to search for official web pages.

You will most likely find tokenomics under the "Token," "Whitepaper," or "Docs" parts of their website.

<https://docs.looksrare.org/about/looks-tokenomics>

[https://storage.googleapis.com/trusty-army-images/Task 3 {Analyzing Token Distribution}/Section 3.5.2-1.mp4](https://storage.googleapis.com/trusty-army-images/Task%203%20%7BAnalyzing%20Token%20Distribution%7D/Section%203.5.2-1.mp4)

#### 5.3 Gitbook

Many projects are using Gitbook as a way to create and maintain their documentation.

<https://gmxio.gitbook.io/gmx/tokenomics>

In the link above an exchange called GMX used Gitbook structure to construct the detailed documentation of their project. In there you can find all the necessary contract addresses, their staking proposal, token supply and much more.

#### 5.4 Github

Another great resource to find information about tokenomics is GitHub. It might be tricky for someone unfamiliar with code to navigate there, but we will do our best to help you search for original sources.

GitHub is a portal for developers to release and maintain their code. It also helps develop documentation for the code; therefore, some teams are moving their tokenomics design to this portal.

Here is an example of a crypto company having their token description on GitHub:

<https://github.com/BarnBridge/BarnBridge-Whitepaper>

To find it, you might want to search for it through Google or by clicking the GitHub link on the official page.

![](https://lh6.googleusercontent.com/Ccy-OgGe1BwEpExyACs7pcPfE2-Yh_2qQP7bp8-oKD5Z9Kd_EhrF-_Aoz670L2PgPAIVQK_FWvqzkv440XswdrjvblxtTefoYfG7dh0R8-yctT1bgHPKpcn_n0IlKvyiW7ZQBgXVDizUV5-2hlGtLsk)

5.5 Inconsistencies between what’s written and what’s on a blockchain

![](https://lh5.googleusercontent.com/u-jnuhVBdTz34YGXWhcepRJpodLSik67Rhb7_at9EAq_F97glYdtvntekaLjKOukczQIeJjJ09mOX9H0NGUrlydUwCE4MyFUIG-tC3gV4a32hmij1wgZizsUKrPECmt97cY7_qZMqCiR5DCxwwo2aq4)

By now, we've learned how to search for information provided by the team and what has actually happened on a blockchain. The reason why we make an emphasis on these two aspects is that companies do not always follow exactly what they say.

There might be multiple reasons for inconsistencies: it's hard to build an ecosystem; it's a living and breathing organism and can be subject to change. The purpose of token existence might change along the way. It's not always a malevolent reason that makes projects deviate from the plan.

But the crypto industry is full of shady behavior, and knowing how to get to the truth will bring you several steps ahead of other users!

<br>


# How to Check Token Transactions

#### 1.1 Crypto company as an organism

Blockchain development happens tremendously fast. One reason for that is its usefulness in many other industries like finance, art or supply chain. Another reason - crypto transactions have value behind it, and value attracts people. Third, but neither least, nor last reason - most of it is open source code. Whenever a project fails to deliver upon its promises, there is still some code left that can be reused. This gives an edge to any developer who likes to try their skills in solving real world problems.

These aspects resemble a living organism - it finds and fits to the ecosystem, absorbs available resources and creates offspring that lock in useful mutations.

Whenever you do the research of a crypto project, it might be useful to think of it as an evolving organism.

#### 1.2 TGE and its limitations

In previous lessons we’ve touched upon Token Generation Events and how important it is to know where tokens were allocated. However, there are a number of limitations to this approach:

* Tokens could be generated on one contract, but then migrated to another due to evolution of the project.
* There could be a hack that moved some of the unlocked tokens.
* Tokens could be generated gradually, along with user activity.
* And if a project is old enough, there are a lot of token movements which obfuscate the track.
* A number of tokens could be burned right after minting, increasing the percentage of tokens distributed to the participants

Still, the best way to investigate the project is to follow the money, i.e., tokens. One way to do that is to follow large transactions. To do that, you can go to a Token Tracker page, and then switch to Analytics tap. There you will be able to see the days where large amounts of tokens were moved, and search for these specific transactions.

![](https://lh5.googleusercontent.com/Z5JwUW8h7laqGu8pxYs6YKi20g4fmX4s0RRA5yhN8s3gzrzuJ_mNB-3pNgYwIntvF0ssDxa1Pl0MFZ8kkm7l8x5RNe4cyCC-alpUaiEliZRy2vGwTIEsXeXImyUc38S0M7ROfPe_d-EtCE0BYEy9PFo)

#### 1.3 Follow the money

The lifecycle of tokens may start with the Big Bang (TGE), or through a continuous minting process (inflation). Understanding the source of token creation is important to understand the current state of tokenomics.

Whenever tokens are minted in bulk, they often go to a smart contract deployer. In this case our job is to trace where the contract deployer sent tokens later.

Example:

![](https://lh6.googleusercontent.com/kXwd5P6iiTs25jCOGF-0FM5lTED6qnUbR5od2-iFZarvsUseLlTJi071CRPLJgIfXicSNXrb9LPFGy8iR9J-7812aN-TRTkrVfBGi7tfVAP1FLsvyNPqnxB33m1qUPJJw7UHL286IGdddnClNnCwOqQ)

#### 1.4 Breadcrumbs

In order to follow all transactions that have been done by the smart contract deployer, it can be beneficial to see them in another tool.

Go to <https://www.breadcrumbs.app/> , choose a type of token you would like to follow (in our case it’s UMA, an ERC20 token), enter its smart contract address, and then copy the address of a deployer into the Breadcrumbs app.

Here you will be able to visualize all transactions made by an address, and follow the path of UMA tokens to the current holders.

![](https://lh6.googleusercontent.com/cUEXN0bdOQZE0Nl-XNpROzPc0CsHlhtGI3McL0xLPSAa9Z1WaYaKgP9wuHZ2MdWCthUHock2R_GyBxMbfNCVx44NMLx4K_7xeYHIu8ZGlE1bYyD1w4Exz8HiG29aKcGPvgpxvdHcckYGDHYx_yZRyVg)

![](https://lh6.googleusercontent.com/f3mwCUF8nXXuI1IMclzzAY7v3KJjBtM07XU6HpnAezcbNORpxqMj8Ki86cOdpqROGg63-JwjkXYOiZmo1WuKdKTsCSpCTfpMFYNpwxMDAejmGHC7RyAeuI8aSnyuVKtkXYbsAnw5y_NcdmUFXws7bFg)

![](https://lh5.googleusercontent.com/UaEmrklNPPIQ99ZCyWAFjXm5FNjoFRkXiiImzqGOEGalp4PXZGFRzG7s34Yfq7_b1snIgWwG6Q76Rnfy7ppxXSkbqukqSmpDf7E9nSZrnEOLYtZ78Jh2TyA6mSJh-pdnCpvqb1AuxBLgauzdxQa9Sms)

![](https://lh4.googleusercontent.com/PrlgztcVXceJjZUa2cqWx98ewjBRax8wJ5qX5arNNH5aS8kWdHCcq9rOPWlFrItW3_T0M5_eoNzxoPt1FEM2eP5DfagBVKL8weK9a3Qp8DyZ6gwf4RJUUESF6CT1wufSmcBYB3DPY2n5G4jSQbXnIUY)

At this point, our goal is to follow the token to today’s top holders.

#### 2.1 Token holders and already existing labels

As you browse through the list of current token holders, you might notice that some of the addresses have already been labeled.

* <https://etherscan.io/token/0x6810e776880c02933d47db1b9fc05908e5386b96#balances> \* Example:

![](https://lh4.googleusercontent.com/gnBl7KwrafWsD66dKa1vOr49uq5XuZy_8KFoXDYL0TsOyGtUVPZK-8ooAhqvoK25S1zWIiJYr88n3tqGjgVCOq6aDE1tmHAvnBHQ50LBpNwGP4TJg4FgaKxU48RHzbP549mnJ4HL6NrWrisgZLY9xL4)

![](https://lh3.googleusercontent.com/lGFtN9ibzOQw10CXYDGNx7H-ki4P96_FGkaKbrvvCL0Z7CbgZP3JF8x8ptAk4fcLph92PjelS7tAaELqlTJNqJ2ZPjuXK8dMacTfPnuIz8Yw9YEnWktC6XXmOCZToU5dDRWXRkIfDA1BF6bvZ0neKOo)

Considering the vastness of data on blockchains and the expanding nature of crypto projects, labels make the lives of regular users much easier. However, it's done by the same regular users, and is an example of how people can bring public good into the industry.

Imagine how straightforward blockchain research could have been if all major token holders are labeled in the same manner. This is where your effort can really scale up and help millions of people.

#### 2.2 Principles of labeling

In the example above there is a pattern of which addresses are labeled, and which aren’t. Two of most commonly labeled types of addresses are those which belong to the team and exchanges. Usually these are the biggest token holders, and it is of utmost importance to know whom they belong to.

Another set of addresses that is labeled are exploiters. Whenever a hack happens, it is a priority to identify the wallet of an attacker and label it for further monitoring. Here are some examples:

![](https://lh6.googleusercontent.com/4sr26QTez32C1oKZ_ghyfbPpVp_BVRcD5CTOgQ5QLFqnXjuQ8i0pmRtNOJQFbIIss5ldQ1-uIjisHPefri4LprohqglfyHR5qKKV3UvbXe9AyBZCgiJ7uNDOSJ8M8EnC6Ldo66jV7pT3olgN7JriEGQ)

* \*<https://etherscan.io/address/0x07e02088d68229300ae503395c6536f09179dc3e> \*\*
* \*<https://etherscan.io/address/0xe74b28c2eae8679e3ccc3a94d5d0de83ccb84705> \*\*

The best thing is that now you can search for these exploiters in Breadcrumbs app as well.

![](https://lh3.googleusercontent.com/LPIWgpDNyZcu8nbz9BZ7-wJUE6Z7w7JAGeBn7iu9LxY-WS7hsaR3FEkgLqr9dHv6jG6QDHBvoxmadP-fcbv_PfV0TmE3holincFkZ3QDskJ74JQCm5OqwLJYQLc8kcY9QwNQfvJ1inQTtRGoBj86a4w)

#### 2.3 Label Word Cloud

So there are labels on some addresses. But how would one find other examples of these labels?

Etherscan has a page dedicated to all the labels you can find on a platform. From this page you can find, for example, all known Alameda Research wallets.

* \*<https://etherscan.io/labelcloud> \*\*

![](https://lh4.googleusercontent.com/ymeLfE2h_S6PrOD1yElK8siYGn_r64lc-Gk7mHnxQTeLfZ23F68E6EIuCZJvwJwINAG103T1QMYd8xv4l5dh0ZWW5Bsz8CvhO7-xW-zunFbH8p90RCIVSGpYNyffpyThSEreMHUIkXA8Lg1P21323Xc)

This page will also give you an idea on what categories there are that might help you in the future to label unknown wallets yourself.

#### 2.4 Making assumptions

Now, armed with the ability to track big token transfers from the deployer to the current holder, as well as some of the examples from the Label Word Cloud, you can start to make assumptions on who are the largest current token holders.

What are parameters you might take into consideration? If a large transaction has been made directly from smart contract deployer’s address, it is reasonable to assume that the end receiver is closely related to the team, advisory board or to early investors.

Investment wallets could also be spotted by looking at other tokens which these addresses hold. If it is a diverse set of tokens, and some of them were transferred to this account directly from the deployer - most likely it is an early stage investment entity.

#### 3.1 Reading a coherent story

In many cases it would be hard to give a definitive answer. Often enough entities are using the pseudonymous nature of a blockchain to hide their involvement in specific projects, especially if they are fraudulent. There is also a problem of assuming the intent of the transaction - in many cases it is almost impossible to do.

What a researcher can do is to gather some evidence and make an assumption based on them. This evidence can be found in many places, not only on-chain. Sometimes it can be beneficial to paste an address you are investigating into a search engine just to see if there are any mentions of it.

There is a thin line between assuming the identity of an address and making a wild guess. And by accumulating as much evidence as possible will improve your chances of identifying an entity correctly.

#### 3.2 Transaction parameters that can be useful (date, cumulative number of tokens)

Apart from the token holder addresses, pay a close attention to the details of large transactions. Look at the dates and check if they are made at the same time as funding rounds or around a Token Generation Event. That would decrease the number of possibilities for the label of a specific token holder.

Another important factor is that transactions can be divided into many smaller ones. Sometimes it is useful to look at the cluster of transactions to see that the amount of tokens transferred in them is equal to the number you are familiar with, for example, from a white paper.

An example of such behavior can be found in our earlier slides where we looked at Jones DAO and how they distributed Team tokens.

![](https://lh3.googleusercontent.com/oAQiKqIuMnRs5xkI69z3Eij10u5GzAaOYVEkiIm8AveTeynecCixCfVGLkohE6HdADhKaa2ryQiodTNpuKKEk6DUqlfXYBf8WEsVVfXJiNypEXNxl02Xcwb30RIYuFtbjYyXH7ghV_AhtPYeUQH9fHU)

#### Last but not least, always check the log of a transaction. It might give you an idea which methods have been called.

#### 3.3 Introduction in inconsistent behavior (differences between what’s written and reality)

The reason to do the research is to see if there are any red flags about a crypto project. There can be many examples of such flags. Some of them we’ve discussed previously, others we will touch in future slides. However, one of the most important parameters to look at is whether the team is consistent in what they are doing.

To see the pattern, we need to be acknowledged with their whitepaper and then look at the token transfers. Do they resemble what is written? If there are any changes, is the team clearly communicating about what those are? If there are sudden changes in team behavior and project direction, it should immediately be noticed.

An important part of any crypto project is their community. So sometimes it is beneficial to go to their Discord channel and to provoke some activity. Is the community capable of answering your questions? Can they provide clear and direct links to back their statements about the project?

#### 3.4 Additional red flags

If there are one or two issues with the token misuse, it is still not clear if the project is fraudulent. However, the more red flags you find, the closer attention you have to pay.

In addition to what was discussed above, here are some other red flags you might notice:

* Unverified smart contract (no green check mark next to a Contract tab on a Token Tracker Page)
* Ownership of a token smart contract is not renounced (you can check it in Blockchain Explorer under the Contract > Read Contract > owner. If there is anything else but zero address, the ownership is not renounced)
* Read the audit report and pay attention to its result. Check if the audited code is similar to the one deployed on a blockchain.

#### 4.1 Identification of address owners

The vast majority of crypto projects do not share their addresses. But a trained eye can see the history, connect the dots and make an educated guess. Sometimes the community of the project of choice can help out with your research.

By exploring a whitepaper, TGE, transfers of large amounts of tokens, as well as being able to trace how current holders acquired their positions will give you a detailed picture of the money trace.

Paying attention to the red flags can give you enough warning signs to assume some of the intentions behind transactions.

#### 4.2 Token status

Whenever you analyze a token holder, it is useful to pay attention to the status of tokens located on a wallet or smart contract. It is where all your previous lessons work together. Can tokens be moved? This can be found under the “Contract” > Read Contract” > vesting methods such as “locked”, “start\_time”, “end\_time” and “cliff\_length”.

If you see a “Null Address: 0x…” among token holders, this means that tokens located on it have been burned. If tokens are continuously entering the supply through vesting, mining, farming or staking contracts - these are vested tokens.

Funds that are located on multisigs should be considered as “unlocked” - the only thing that prevents them from leaving the wallet are the signatures of the multisig owners.

There are several ways you can reach information you need, and sometimes it is beneficial to compare the results. Stay vigilant!

#### 4.3 Tokens on other networks

And the last important thing to remember is that tokens may be located (and therefore burned) on several networks. If you feel like in your research you are missing some part of information, try to search for it on blockchains that are compatible with the primary network.

Sometimes teams can move their treasury to blockchains with smaller fees or more advanced instruments. Or a scammer can make a fake coin that mimics the original, and the only way to make the distinction is to see the origin of this token - which can be located on the other network.

<br>


# How to Check Token Supply

#### 1.1 Importance of Token Supply Research

In previous lessons we’ve touched on the importance of understanding Token Supply. However, due to many variables that should be included in its calculation, we must return and dive deep into this concept.

Considering that token is the lifeblood of a crypto project, it's hard to overestimate how important it is to have adequate and truthful values of what is available to purchase from the secondary market, what is locked and how many tokens are burned.

Investors should also have a clear understanding when a large amount of token **supply** is unlocked and ready to hit the market.

#### 1.2 Questions which has to be asked

Let's summarize the parameters we need to know in order to find Circulating Supply of a token.

First, we need to know the Maximum Total Supply if it is applicable. Is there a limit on how many coins can be minted? Is the token inflationary, deflationary or disinflationary by nature?

Second, how many tokens have been minted so far? Is it equal to the Maximum Total Supply? How many of them were burned? By answering these questions we can calculate the Total Supply of a token.

Third, how many tokens are locked in vesting contracts? How many tokens are lying dormant on addresses that belong to the team? Which addresses belong to the team anyway?

By combining answers to the questions above we can calculate the Circulating Supply of a token.

#### 1.3 Limitations of the research

Typical issues that arise while calculating the Circulating Supply come from not being able to spot all addresses that are controlled by the team. Another limitation appears when a token has a floating number of tokens, and it constantly changes.

Currently these limitations are dealt with by asking a crypto project to provide the API endpoint for these values. However, it is far from perfect as information uploaded to this endpoint can be forged.

By utilizing tools described in previous lessons you will be able to overcome some of the limitations. And in the further sections you will be able to see the full cycle of gathering all relevant data.

#### 2.1 Max Total Supply

In the best case scenario Max Total Supply is capped, and the mint functionality is disabled. An example of such a case can be the BarnBridge Governance token.

* \*<https://docs.barnbridge.com/bond/understanding-usdbond> \*\*
* \*<https://etherscan.io/token/0x0391D2021f89DC339F60Fff84546EA23E337750f> \*\*

![](https://lh6.googleusercontent.com/6_83FUlF-FLJaqwqI-fdn1SefzjCPZa_kR5hK2dBC8_YVCvvJyUFVOAMPUhJArV7gwMYlKcvEjsGnzuOS_JApFzdg2nRfnIhGYhEedWrYwVpCCiDny0Xu6XU2DW6iiaPRXu_6vpTgozE1P7Dm0Y2N7A)

![](https://lh3.googleusercontent.com/YREPf5IJNY63I4A6JD01zQlNmqGTGHhiofqf3e25Yw1-Tqbu7TsL5nAUTNbvHZ7wX_NoVXleTBY0EO6Bn7QAVKPVJoMguLgVHE9BT9rTceMrD4GzRcj5iAs5Z82hCD-IG5LjusRzWnRxcNDprC1bjGs)

But what if this parameter always changes? What if the token has a rebase function, and it changes its amount depending on various factors? In such a case the best we can do is to give the amount of tokens we get from calling “Contract” > Read Contract” > “totalSupply” method.

#### 2.2 Inflation - what it is and how to check it

Inflation in token supply means how many new tokens have been minted over a year. Inflation can be introduced in many ways - through gradual token minting, through releasing locked tokens or by rebasing the token.

Inflation can also change depending on tokenomics design. For example, UNI, a Uniswap Governance Token, has a 4 year cap on the amount of tokens. However, after 4 years the cap is removed, and a steady rate of inflation is implemented.

It’s not easy to collect inflation data, and for the purposes of this tutorial we just need to acknowledge if a token has inflation or not. However, if you want to calculate the rate of inflation, you can take Circulating Supply of a token a year ago (through Wayback Machine or CoinMarketCap’s “Historical Data”), and compare it to the current value. The formula is following: Inflation % Rate = (2023 Supply / 2022 Supply ) - 1

#### 2.3 Deflation - what are the mechanisms of it

The opposite process of token supply being gradually cut is called deflation. Most common way to do that is to burn tokens, either through destroying part of operational fees or manually moving tokens to an inaccessible contract.

In some cases inflation and deflation can walk hand in hand - and the main example is Ethereum. It has no maximum supply, but an update called EIP-1559 has introduced a mechanism to burn a part of each fee users pay.

![](https://lh4.googleusercontent.com/kQTCfeSY1rq_X1iyVSiosSycWttAJeD-m0Wb5pUqJUm--xzc0HkaV7iD6v78e3muJmvlpUS6r8-lhoViirrFdlf9EgJyluYxiPAchs8e3uUuuH96JT66ojK4XoyoCCAmcPqZRskBJ6AyaCQ62pBCNsk)

By having both forces in place, the protocol has dynamic supply that can increase or decrease the total amount of tokens depending on the market conditions and block space demand.

#### 2.4: Disinflation

The last term that you have to consider is disinflation. It is the rarer case, when a token has inflation, but it decreases over time. The most prominent example of such a mechanism is Bitcoin, which cuts inflation in half every 4 years. Many other forks of Bitcoin also use such an approach, hoping that the scarcity of an asset will increase faster than the cuts in inflation.

![](https://lh6.googleusercontent.com/yNDbeCFdueK89jLdWZwobLowwHVg-rMe3RWa-FW-98uAVFPWSfj0J1pZnCeYMang3zH63_PiSl5o-D2FXGaBLt-qj2oO3POZZYIMn6CUSybvzEacc8a6uCnmK9bNB3Shja6GSLVVd2uDmzolKAxC4do)

![](https://lh4.googleusercontent.com/J2qKU3nVpbO0eqld7cmPtVPd1_WO-by0y06q9ut6CJcUfdlCwB2Kf0zCckH55997Le9_O0mRwVBBvNT3vAlUbTzLLzR9986h_8MvksIIhCUKlKitBf84lyejrBaoJIgVAXc-Q-31fFHGz8JgcvqOj24)

#### 3.1 Total Supply and its limitations

As we discussed in lesson number 2, the standard definition of a Total supply is the amount of printed tokens minus all burned tokens. The goal of this metric is to see how many tokens are there in existence.

This should be a very straightforward metric, yet even at this stage there are issues with calculating it. The most common problem arises when a user tries to see Total Supply from blockchain explorer.

Lets see an example by opening a list of token holders of Ankr, a decentralized RPC protocol:

![](https://lh6.googleusercontent.com/PdlP_O2H7_UhxEFSCn-RONnhu_IobWjohpxJVZo6LH0hzVUTOSUuLCpuX3OkJDU_5t86yigX7PvXNH99_lgZwgQURfQZGngXbbhh0pClXDApR5Tf8uxMsyiKLws6xjcCVEdDACmD5hRk6F1PZKao39M)

![](https://lh6.googleusercontent.com/qrY4oJ-3ULVzw-bS2FdWHLfaiHgu7lMXc5BCVuuAFS0ZnJPzkXnD2opX_n42LdIogXzIMuVr-LepCM8uXfOnozrshKLm-pCZa1D1JxKNHZ9vMEVVKDePkXOSFUUbFrrRyKOqPJaJxvr_MglTl5cj1I8)

In the totalSupply method we see that there are 10 billion ANKR tokens in existence. However, by checking the list of holders we can notice that 2.4% of all of the tokens are located on Null Address, meaning they are burned. Therefore we can calculate that the Total Supply of ANKR is at most 9.76 billion.

#### 3.2 Collecting data from token holders

But what if there are multiple burn addresses for one token? How to collect them all? The problem with burn addresses is that they are almost infinite in number - and developers can choose any of them to send their tokens to.

However, you can search in blockchain explorer for “Null Address:” to see the most used addresses, or go through the smart contract “burn” method if there is one in the smart contract you are exploring.

With having a list of such addresses, now you can go through the token holders list and collect all tokens burned. Sometimes it is easier to do it by hand, and in other cases - by downloading the CSV file of all the holders and searching through it. But once again, be wary of the limits imposed by blockchain explorer on the amount of positions within this file.

#### 3.3 Using queries to collect data

If going through the file looks too cumbersome and you’re looking for more elegant ways to collect data from blockchain, there is a way to extract whatever you want using GraphQL queries through services like <https://graphql.bitquery.io/> .

After a quick registration you will be given an interface with a builder to construct custom queries. And though it is beneficial to know GraphQL to realize the full potential of such a tool, for the purpose of this course we will use only the simple queries. You may find an example of a script that would give you the sum of all the LooksRare tokens that were transferred on Ethereum network to the three most commonly used burn addresses.

{

ethereum(network: ethereum) {

burnt: transfers(

currency: {is: "0xf4d2888d29d722226fafa5d9b24f9164c092421e"}

receiver: {in: \["0x0000000000000000000000000000000000000000", "0x000000000000000000000000000000000000dEaD", "0x0000000000000000000000000000000000000001"]}

) {

amount

}

}

}

***

You can modify this script by changing “network: ethereum” to the blockchain you would like to explore; currency: {is: “0x…”} to the address of a token you are investigating, and add or remove potential burn addresses in the “receiver” line.

You can also use the “Explore” page in the upper part of the screen to see other queries that people are constructing, and adapt them to your liking.

#### 3.4 Combining the findings

Now we know that Total Supply should represent all the tokens minted minus all the tokens burned. We know that blockchain explorers often ignore the last part - and we have to take the matter of calculating the burned tokens in our own hands. And no matter the method you use, now you are prepared to make the best estimate possible.

The last, but not least thing to remember is that tokens can be burned on many chains. This means that if there are multiple networks that a project uses, you might need to go through all of them. Here is an example on why it is important:

<https://bscscan.com/token/0xf307910a4c7bbc79691fd374889b36d8531b08e3#balances>

![](https://lh6.googleusercontent.com/85vCh-PMukewZlXBoU-Ywmm0TzcgGKdnYF-YzTZ-o3XRKRRZ6AVbp-VcaZn-rhOA32i9F56yFd7u6H9X7ZWJQsweDmk03rPckX4YNqA9g2QOtOhfE7Te3DktC5hxgEv84LvxYLBD2Nw-LDE9bu-h3Xs)

Remember we looked at ANKR token holders on Ethereum and saw that about 240m tokens were sent to the burn address there. However, ANKR is represented on multiple networks, including Binance Smart Chain. And by checking BscScan, we can see that another 200m of tokens were burned there, totalling the number of ANKR moved out Total Supply to 440m.

#### 4.1 Issues with Circulating Supply

While understanding the Max Total Supply and Total Supply is not that hard, Circulating Supply is the most confusing term among three. The problem arises from the fact that all current methods of calculating Circulating Supply are rough approximations due to the pseudonymous nature of blockchains.

For example, CoinGecko defines Circulating Supply as Total Supply - Team tokens - Foundation tokens - Locked tokens. And though this is a viable way to approximate the supply in circulation, it is not always possible to identify all wallets that belong to the team, or identify all the tokens locked. Moreover, in situations where tokens are distributed through staking or mining, Circulating Supply will be roughly equal to the Total Supply.

To add insult to injury, tokens that belong to the team and foundation may not be locked - and therefore can (and do) enter the circulating supply at any point. So another method of calculating this metric is to focus only on truly locked tokens - those within smart contracts with cliffs or vesting schedules, or Liquidity Pools with no owners.

#### 4.2 Looking at the Example

To learn more about the process, let’s look at the Covalent token ([CQT](https://www.coingecko.com/en/coins/covalent)). In their Circulating Supply we see three three addresses extracted from the Total Supply.

![](https://lh3.googleusercontent.com/P5ydEYjxHEnwxlhNUzts3A8HUC8j26KEd6F83jdmYVeqoJEd5WTTCFdJ_1GQ9oE29RGeSWLZOfMeg2iZSDHxA6tBQ8zNz9FVIl3CGDTh3zS3qnk30nd33lPpOqMH05kUL0oqWG-PjP-rM7Ts7wX8G7o)

![](https://lh6.googleusercontent.com/o-1Noux0xQYJx8xg6svazAR4iR5nJfLVGvIPtd2POMZf8guXgyZbQ3KciyZLSZ5LTOB3YpWuhUv9T3ets2as-HAt6kIwC4enXZ02uI8-dccz0ZIoQXuOa2kJGgZezJzPzq2ghLaZjxlQBIwY4RwmrU4)

After checking all three contracts, we can conclude that two of them are multisig contracts with 2-of-2 signatures required to execute transactions. Both signatures are the same on both contracts. Details can be found in graphic interfaces of multisigs:

<https://app.safe.global/settings/setup?safe=eth:0x220B7eebD8974Aa9dcFF93371BC554e03236E57E>

<https://app.safe.global/settings/setup?safe=eth:0xBf7A6ED78f9399F4299A8d000a83DB84beafBcFd>

![](https://lh4.googleusercontent.com/ORd8vUO5e9APvsAyPKuvf_pWK9Nyj_HCGzNWfs8lqjqDowvkds_91V6f06txxKVtpjB5_qs_68wWI58MoANZoYTc3Gca7ndLNCn7c6NH5ybbORMPKzJPUVKMoxcTev-KUDUkxlSnQRZLWh-UMjg2RI4)

![](https://lh3.googleusercontent.com/8HKWPxNKOrStf5aLVe9jTb2x2NkiRQDCEPsw2PRLK4Y9XwFxkEusz4aUENXdJ_ZdwnogzrDvZGhdAM3jYAoOV2C9sSn4DOfNeoliwUhw459a1LlaYa6MTi5zRLoTebKq2qQoJpli_50oEvZFFIlWUec)

The third contract in the list is not verified and we can’t read the content of its code. However, we can look at the deployer of this contract, and see that the deployer is the same address that acts as an owner of the previous two multisigs.

![](https://lh5.googleusercontent.com/gJvRKTaVRGNHGoSZKif0Gc0tiK-SvpalRxId-ipk9SFxIs4_vnX0bB2jFQoTFhJfcB6cn5PeENjL5W3S_kFcb43k0wkXcaNcLtjPM0SDNzZdmg1-YijDlkmPTuycuFwKzJTtkrO1GsncFaWo07yA3CE)

<https://etherscan.io/tx/0xf403a9c09ee158defe431969249abfeeb80aa620fe20ad7315f6ad20a2579d63>

#### 4.3 Rechecking Circulating Supply

So far - so good. But are there any additions that could improve the number? Are these the only contracts where control of the tokens belong to the team?

First, we should check if there are any burned tokens. We can go through the list of token holders, and find any noticeable amount of tokens on the Null Addresses. We could also recheck it by querying the <https://graphql.bitquery.io/> as discussed earlier. And the result will show that there are no significant amounts of tokens that have been burned.

Another thing we need to check is whether CoinGecko has all of the addresses controlled by the Covalent team. To do that, we, once again, should check the contracts that are among the highest holders of CQT. None of them appear to be owned by the contract deployer, and even a multisig called Covalent: Delegator has different ownership by 2-of-3 signatures.

It is always useful to do a recheck of Circulating Supply metric as it is then used to create a Market Cap of a token - simply by multiplying the supply by the token’s price.

<br>


# How to Check Project Security

#### 1.1 Reasons for Being Paranoid About Security

When people dive into the digital world, the topic of security is often discussed as the afterthought. The utility of the app often prevails, and many people choose to use less secure products if they give them more streamlined user experience. As for the companies, many of them are ready to cut corners to reach high user accumulation, and often security is something that is discussed later in the development cycle.

This pattern of behavior leads to a situation where users are satisfied with their experience until they are not. It often happens abruptly, taking away all the positive aspects of using the app, as well as assets and information that should belong to the user.

In Web3, a hack of an application may lead to the loss of funds - either invested in the dApp, or even those which are located on the user's wallet. The database breach can take away user’s privacy and expose them to the possibility of being robbed in real life. It is happening all the time, and our goal is to be mindful about the possibilities of such attacks.

#### 1.2 How Sufficient Documentation Should Look Like

A Web3 researcher not necessarily should be the security expert - but they have to understand possible vectors of attack. By knowing the most common ways a dApp can fail, researchers can study the documentation of the project and see if the main security bases are covered or not.

The best place to start the analysis is by going through the documentation of a crypto project. In most cases you will be able to find the link to documentation on the crypto project’s website or on their Github. The absence of such documentation should be a bright red warning sign.

A sufficient crypto documentation should be comprehensive, well-organized, and addressing all crucial aspects such as project overview, list of smart contracts, tokenomics, community engagement, roadmap and team. By fostering transparency and maintaining active communication channels with the community, sufficient documentation can promote informed decision-making, facilitate adoption, and encourage a thriving ecosystem.

#### 1.3 Quality of Information Within Documentation

The company may have the required parts written in their documentation, but the true test comes from the actuality of information displayed there. The advantage of a blockchain is that if a company points out all the necessary information about the structure of their smart contracts, it can be then checked independently.

However, if a company hides the structure of their smart contracts, initial token distribution, or uses a lot of pretty words to describe what they are capable of without detailed explanation of the practical implication - that is a worrying sign.

Below you may find a link to the GameFi project that on the surface provides an explanation to what they are doing - but in reality it has no significant information neither about the token, nor about the smart contract structure.

<https://docs.metroverse.com/overview/met-token>

![](https://lh5.googleusercontent.com/XGs82mwQHQax3WnIheDsX3OdYcFZEtr3MoAtjCnPvGBHFKJYoERq9I2QNcLyGE0unpyuqdqPlhnAHtA587TRBSmPphxiCnSmNIe06Jk8Ob64P-OUT-e4A67dAvdd41owBf7XhZVRDgpBNxLkiE8UCD4)

This creates a misunderstanding when CoinMarketCap points to the token that Etherscan consider to be malignant:

* <https://coinmarketcap.com/currencies/metroverse/> \*

![](https://lh3.googleusercontent.com/VhlgvlnPA2O5yw0vN_o1pEyix2CYZd8TJIRFAGR9nfPgLK0GQU1GbcTjjEI_u7-AxgzcVYiaBhUvdUKutw2_faFCENz_nw_O8PqmmnReVUYP-x3XLn64OtWmLcMFnonK2Zvy5sABN00VCvxieZxop6Q)

* \*<https://etherscan.io/token/0x1ffe8a8177d3c261600a8bd8080d424d64b7fbc2> \*\*

![](https://lh5.googleusercontent.com/pX49Pwu5RH9kyFJC8mNU_yhZu7FuKuqfCcEBV0mvTn4nFhFn_coYVUlufas7CDc1veDxAcuRu1kd01BmwUcgUZ1o-wINcwAgk5ilZFINQDt1wbAXuJ9AJXZmQ68bZCZaMyYK5S4KBjUy7mJHpjefBF8)

#### 1.4 Finding Architecture Details

While there are many crypto projects with sub-par documentation, others are doing their best to write down the list of all smart contracts that constitutes every version of a project. An example of such effort may be Kyber Network that has several services, and all of them have a page that lays down the whole architecture including testnet:

<https://docs.kyberswap.com/liquidity-solutions/kyberswap-classic/contracts/classic-contract-addresses>

<https://docs.kyberswap.com/liquidity-solutions/kyberswap-elastic/contracts/elastic-contract-addresses>

![](https://lh6.googleusercontent.com/6mfwYaAmFOSlluvF9srcZLU_au_1-DPDgOvyrvlSNwZ5XroUSkjmmFwY7r8RoLQ0UZYT14XfViuxNUsmQ6ysUsQMFENCAPjDGqiUlTNUicCVKSlmGzGQ8eFrzKkxQEs66cuzd19mLQO9bxFtU5VOIsA)

![](https://lh3.googleusercontent.com/j5Ug4iHOaCiblQJrmfj-Kc1YDhAauwlwExvAayVaQL0YIkekHQtRLso5S_21n6-DYDB6Ki33Lc_XPNI6mk6VSPUkqSPW13fH2o_oo6H7t4DGwxvik4djEykM7_AfK0Zt7ukXH22kKRKLMTCpkHUraMM)

Same thing can be found in [Uniswap documentation](https://docs.uniswap.org/contracts/v3/overview) - they are very meticulous in describing all of their smart contracts for every version of the product they have.

#### 2.1: Audits - What are Those

Audits play a significant role in Web3 project security. They involve an independent third-party examining a project's code to find potential vulnerabilities. The goal is to ensure the system is secure and reliable, keeping users' assets and information safe. For instance, when researching a DeFi project like Aave, you should look for information about their most recent security audits.

<https://docs.aave.com/developers/deployed-contracts/security-and-audits>

![](https://lh6.googleusercontent.com/dZNou0Yi0fwEKVyUQi4HOg_KWwR3u_4wRY9qXkKNQ4fy2DuokooO0uPLEXjvLNHrCy0ltdUWiS4OMI887LRkmP9P02tY2kh9Nz5mNpLRRIo0UUAf_MhRipr68qBi-HoVHfu3n7DJHW0_kJuzuA7IEyw)

Audits are not foolproof, but they are an essential component of a project's security strategy. Regular audits can help identify and address vulnerabilities before they become a significant issue. As a researcher, you should be aware of the audit history and the reputation of the auditing firms involved to gauge a project's commitment to security.

But be mindful of projects that may boast they passed the audit without addressing the issues it brought to the spotlight!

#### 2.2: The Various Type of Audits

There are multiple types of audits a Web3 company may go through. The most common and necessary is the Smart Contract Audit - an investigation in functions, potential vulnerabilities and unintended functionality an smart contract might have.

Similarly important is the blockchain protocol audit - a check on the functionality of an architecture of an underlying protocol. If dApps are running as intended, but the underlying infrastructure is faulty - it’s still a huge risk factor to consider.

Speaking of dApps - an audit of a front-end of a dApp is another important part of a thorough security audit. If the user interface can be exploited - it can lead to large losses in funds as it has happened with [BadgerDAO](https://www.coindesk.com/business/2021/12/02/badger-dao-protocol-suffers-10m-exploit/).

There are also several other types of audits that a centralized Web3 company should go through - from Proof-of-Reserves and Proof-of-Liabilities, to an industry standard [CCSS Audit](https://cryptoconsortium.org/standards-2/).

#### 2.3: The Scope of Audit per Type

Now that we’re aware of the types of audits possible - let’s look at some limitations and scope of them. For example, when we talk about the Smart Contract Audit, we have to keep in mind that a crypto project often consists of many contracts. Pay attention to which contracts are audited - it can be core contracts of a business, or just a token contract.

While going through blockchain protocol audit, it’s important to note which parts of it are checked. What's the auditor's analysis of the code base, architecture, consensus mechanisms etc. Although you might not be able to adequately analyze the severity of issues found in the audit, you can notice whether the crypto project has addressed the problems and has fixed them.

Whenever there is a talk about proof-of-reserves, also notice if there is a proof-of-liabilities. First part of an audit is almost useless without the second part - a company has to be able to prove that they hold as much funds as they’ve been provided by the customers.

#### 2.4: Time Relevancy of an Audit

Another crucial aspect of an audit is the time when it was done. An audit done a year ago may already be outdated due to the new technological stack introduced to the blockchain network or vulnerabilities discovered during this year. An audit done two years ago is almost useless.

A [case study](https://blog.audius.co/article/audius-governance-takeover-post-mortem-7-23-22) of Audios hack may provide a glimpse of why it is important to keep the audits relevant. Smart contract was checked in 2020, then some other parts were checked in 2021. But the attack happened in the middle of 2022 - two years after the deployment.

New types of attacks are emerging all the time, and sometimes if a highly forked piece of open-source code is hacked, most of the copies of this code will be vulnerable and have to be upgraded as well.

#### 2.5: Things That Nullify the Audits

There are many reasons why a crypto company may be losing the validity of an audit. Some examples are:

* The code that has been audited was upgraded. Any upgrades to the code makes an audit obsolete
* Smart contracts that have been deployed are different from contracts that have been audited. Some companies are using the name of an auditor as a marketing strategy.
* Issues found in the audit weren’t addressed and patched.
* Enough time since the audit has passed (usually from 1 to 2 years)

Basically any change in the code after the check requires another round of audit.

#### 3.1: Bug Bounties

Bug bounties are essential tools for enhancing security in Web3 projects, as they incentivize developers and security researchers to find and report vulnerabilities in exchange for rewards. These programs help projects identify weaknesses in their codebase and address them before they can be exploited, contributing to a more robust and secure ecosystem.

Web3 projects with bug bounty programs demonstrate a proactive approach to security and a commitment to protecting their users' assets and data. By offering rewards for discovering vulnerabilities, projects can leverage the skills and knowledge of the wider community to bolster their defenses against attacks.

#### 3.2: Examples

If a crypto project is hacked or exploited, the attacker has a choice - to return the funds for a percent of the assets stolen, or take it all and deal with the consequences. And thoughtful companies prefer to launch bug bounty preemptively, so that white hat hackers know what reward they can expect in case they find vulnerability.

Bug bounties are loosely divided into two categories - self-held, and community based. The first category is hoping to rally the users of a platform to search for bugs in the program. An example of such bug bounty would be [The Graph](https://thegraph.com/security/). Some of these programs may have very lucrative rewards for finding critical issues, like the one held by [Ethereum](https://ethereum.org/en/bug-bounty/).

![](https://lh4.googleusercontent.com/l5yR8luE-yhOwXQmWI7O79GmhxbzNh7KqryCyGTPkT3hBY4uUqxIRv8LzRU3IA_9y5rCMn2If0hFF5gqW3vhQA51CD1yIxAXqPb7gkg0IMxhYhC1lrNUVBO3h3zLzZJOZyUy-pNtFhGNJOsvFLfapTY)

In other cases, a company would prefer to use the help of a community like [HackenProof](https://hackenproof.com/) or [Immunefi](https://immunefi.com/) - a group of advanced hackers can be more effective at finding the bugs than the regular platform users.

#### 3.3: How to Search for Them

In order to find out whether a crypto company has a bug bounty or not, the first thing you need to do is to check both documentation and the footer of their website. Most of the bug bounties are public, and if a crypto project has it - they are interested in promoting it as it gathers more attention of white-hat hackers.

Another option is to go through bug bounty communities like [HackenProof](https://hackenproof.com/) or [Immunefi](https://immunefi.com/) - if a company has the program with these communities, it will show you all the relevant details about it.

Last, but not least option is to just Google the name of a company you’re interested in with the “bug bounty” key word.

#### 4.1: Penetration Testing

Another activity that strengthens the overall security of a company is penetration testing. It is a process of simulated cyberattack on the system, trying to breach through security measures by utilizing sets of reconnaissance and exploitation tools, vulnerability scanners and other ways to get access to the system.

![](https://lh5.googleusercontent.com/sgF8o6-v6S7Cp2TAbyCjsRB81TMGUTCOapdPnla1gvSlShTST2IlAwP4mn_Pb4edXHSXA9P6_lwvoOfPFN-bS2otoErqMImMeWdtarqlVWpnBT_YE9-2EJmWzqL3FM2Fj6Bm-H8z1m32hJu2Fj_bXXU)

* \*<https://hacken.io/services/penetrationtesting/> \*\*

After the test, specialists who were executing it provide a report with description of all found vulnerabilities, as well as the methods of fixing it.

#### 4.2: How it is Done

The key difference between penetration testing and something like an audit is the multi-level approach to detecting security issues. Pentesting is usually done by simulating both internal and external environments of the project, then to find ways to disrupt the service from many angles.

There are three main approaches to pentesting, called Black Box, White Box and Grey Box. The first approach probes the running program without knowing any internal structure, while the White Box method looks at the source code and tries to detect vulnerabilities there. The Grey Box is a mixture of both.

This proactive testing is especially useful in assessing centralized Web3 companies as they can be most vulnerable to the security breach of their application and key management.

#### 4.3: Human Vector of Attack

Despite the whole plethora of security testing, the most common way of attacking a service is to target the human that controls it. By exploiting our trust, curiosity or lack of awareness, an attacker can do a significant amount of damage.

One of the most prominent examples of such an attack was the Ronin Bridge exploit, when a victim had access to the funds located on the Bridge. His machine was infected by a file masquerading as a CV - then only to compromise the access to the bridge.

![](https://lh4.googleusercontent.com/8fjYpo7Z8ZHwDJCulsMK6DErPrnZpv5wI7y33AftiH2H8yxdr8SSVbXYsTT2-3mbn3-Mz3-qwZyttAQj_tNCF-6U6KXA5ZzMgyjClDWXSvBLtrlHfSuJeGz_ivGbpZt7DU7_jCm725rsLsnMKUzQ8YY)

This is where true decentralization shines: by giving away the power to control funds unilaterally, a crypto project significantly decreases the chance of being exploited through social engineering methods.

<br>


