Verify identity and the official domain
Establish the canonical website, official social accounts, legal entity where disclosed and contact ownership. Check domain age and look-alike domains. A website check confirms an identity path; it does not validate every claim on the page.
Review team KYC in context
A KYC provider may verify identity and retain evidence under its own policy. It does not prove competence, financial health or future conduct. Check who was verified, when, what happens after an incident and whether the verification is still active.
Match the audit to the live contract
Open the original audit report, record scope, version, chain, contract address, findings and remediation status. Automated scans are useful signals but do not replace manual review. A past audit does not cover later upgrades or operational compromise.
Inspect tokenomics, vesting and control
Reconcile total supply, sale allocation, unlocks, treasury permissions, upgrade roles, mint authority and pause functions. Confirm who controls multisigs and whether changes are time-locked or publicly monitored.
Confirm liquidity and lock evidence
Verify lock addresses, ownership, duration, unlock conditions and the actual liquidity pair. A lock can reduce one risk while leaving pricing, concentration, contract and governance risks unresolved.
Monitor on-chain and community changes
Re-check ownership changes, contract upgrades, liquidity movements, large wallets, new domains and credible community reports. Verification is a dated snapshot and should be renewed when material evidence changes.