The questions to ask before you touch anything
I found an unlimited approval eleven months after I stopped using the wallet it was sitting on. Live, pointed at a contract I had never read, granted on the first day because the interface asked for it and I was in a hurry.
Nothing came of it. The protocol is still running, I got my money out long before, and as a story it goes nowhere.
What bothered me was that the result had nothing to do with any decision I made. Somebody I trust had recommended it, and the trust did all the work that checking was supposed to do.
So here is the list I built afterwards. Six questions, then two that almost nobody asks.
Safe is not a question anybody can answer
People ask me if something is safe maybe once a fortnight. I have never been able to answer, and eventually I worked out why.
Safe is a claim about the future. Nobody has access to that, including the team, the auditors, and whoever is telling you it will be fine.
What is answerable is exposure. If this goes badly, what leaves, and can I stop it. None of the questions below is a prediction.
I am also not naming anything here as good or as a scam. By the end that should read as a position rather than as caution.
Is there anybody to hold responsible
A good answer has names in it. Prior work that existed before this project did, a company registered somewhere you can look up, people whose faces are attached and who would lose something if this went badly.
A bad answer is a team page of first names and cartoon avatars, or no team page.
The middle case is common and worth being fair about. A pseudonymous founder with four years of public work behind the handle has continuity, which is most of what identity buys you here. A handle created in January has none.
Notice what the question does not settle. Identified people with registered companies have walked off with money, and anonymous teams have run things carefully for years. All you find out is whether somebody could be held responsible, and how much they would lose by being the reason it fell apart.
Has anybody independent read the code
The good version is a full report, published, from a firm whose other reports you can read, dated recently enough to cover what is deployed, with findings and fixes both visible.
The bad versions are everywhere. An audit badge on the homepage that links to the auditor’s site rather than to a report. A report covering a version from eighteen months and one migration ago. A one page summary of a report you cannot see.
Read the scope. Every real report lists the files it examined, and that list is where the information is. I have read one where the audited contract was not the contract holding the money, stated plainly on page two, where nobody goes.
An audit is a record of work done, and it is worth having. Protocols have still been drained a few weeks after a clean report, because the reviewer found what they found in the time they were paid for.
The balance is the bounty
Whatever is sitting in those contracts is a standing offer to anybody who can break them. Four hundred million dollars is an enormous amount to leave on a table in public, and every capable person in this field has been staring at that table for years. It is still standing. Call that what it is: a long run of failed attempts.
A contract holding two hundred thousand has been looked at by roughly nobody, because the payoff does not justify the week of work.
So the number reads both ways. Large and old means heavily tested, and worth somebody’s continued attention. Small and new means untested, and a smaller prize.
The conclusion you cannot draw is that small equals safe. It usually means nobody has bothered yet.
The transaction is the document
Here is the question where the answer is already on your screen.
Can you read what you are signing. A good answer is that you recognise the contract being called, the amount matches what you intended, and the wallet’s simulation shows the tokens landing where you expect.
A bad answer is that you cannot tell. That is still an answer, and the correct response to it is to close the tab.
Approvals are where this does the most damage. An unlimited approval is standing permission for a contract to move that token out of your wallet at any future moment, without asking again. Plenty of interfaces request one by default, because it saves you a fee the second time. The one I found eleven months later had been granted exactly that way.
Signatures are the half that feels harmless. A signature costs no gas and never lands on chain, so nothing appears to happen, and it can still authorise somebody to take your tokens. The absence of a fee is doing a lot of work in convincing you it was nothing.
The exit that does not need their cooperation
This is the one I weight above the rest.
If the team disappeared this afternoon, could you get your money back out.
The good answer is yes, by calling the contract directly, with no website involved and nobody’s permission required. That path genuinely exists on some protocols, by design.
The bad answer is that withdrawals go through their interface, and their interface runs on their server, which can vanish over a hosting bill or a court order.
The specifics are narrow enough to check quickly. Whether the contract can be upgraded, and by whom. Whether there is a pause function, and who is allowed to call it. Whether the keys are one signature or a multisig, and how many people hold it.
Upgradeability is not sinister on its own, since upgrade paths are how real bugs get fixed. It does mean the audit you just read describes one version of the code, and versions change.
My position: I will not use something whose withdrawal path runs through the operators, whatever the yield. That rules out things a lot of people are perfectly happy with, and I am fine being wrong about some of them.
Time is the only input that cannot be bought
Everything above can be produced. A team page can be produced. A report can be commissioned. A balance can be seeded.
Eighteen months of holding real money without an incident cannot be manufactured at any price. That is the whole reason the question is on the list.
A good answer is that it has carried real value through at least one genuinely bad week in the market and at least one upgrade, and nothing went missing.
A bad answer is three weeks old with a large amount already parked in it. That is the square on the grid I now walk away from. Not as proof of anything. It is the point where the number of untested things is at its highest.
Are you even on the real site
Now the two that get skipped, and this is the one that actually empties wallets.
A convincing copy of an interface costs almost nothing. The front end code is public and so is the design, so an afternoon of work produces something you cannot tell apart.
The traffic to it is purchasable too. The slot at the top of a search page is an advertisement sold to whoever pays. The same goes for a reply under an announcement, a top comment, a message from a helpful account in a group chat.
A good answer is that you arrived from a bookmark you created yourself on a calm day. A bad answer is that you clicked a link.
The detail worth keeping is that the fake site works. It loads, it connects your wallet, it looks exactly right. The only thing that differs is the transaction it eventually asks you to sign, which is the part you had already decided to skim.
Somebody else’s clock
The last question is who started the deadline.
Manufactured urgency is the oldest tool available for stopping a person thinking, and far older than any of this. A window closing tonight, a counter on the page, a claim that expires, a mint ending in nine minutes.
A good answer is that the deadline was published in advance by the source, and you found it yourself rather than hearing it from whoever is selling you the opportunity.
I do not make decisions inside somebody else’s timer. If a thing cannot survive one night of sleep, losing it costs me nothing I can measure. That rule has made me miss a few things that turned out fine. It has also kept me away from every drainer that ever came near me.
What the answers are worth
None of these questions tell you it will work out. You can get a clean answer to all eight and lose everything anyway, because the failure that gets you is usually the one nobody thought of yet.
They tell you what you are exposed to, and that is smaller than most people want it to be.
Exposure is also the only part you control. How much goes in. Whether the approval is unlimited or exact. Whether the wallet holding this position also holds everything else you own. Whether you can leave without asking.
The eight answers exist today and take about twenty minutes to gather, which makes them the cheapest thing in this hobby.
None of this is financial advice, I am not going to tell you what any token will be worth, and I have no idea. The people who sound most certain about that are usually charging for the certainty.
The rest of how I run this side of things is on the home page.
Get new guides and videos first — join the Telegram channel.