Crypto & Web3

How to Vet a Crypto Project: A Practical Checklist

How to Vet a Crypto Project: A Practical Checklist

The Ethereum diamond logo, representing on-chain crypto project verification

Every serious loss in crypto has the same autopsy. Not “the market crashed” — that is investing. The losses that hurt are the ones where the project was never real, the contract could be drained from day one, or the founders held the exit door open the whole time. Those are avoidable, and the tools to avoid them are free, public, and take about twenty minutes to use.

This is not investment advice about whether any coin will go up. It is a checklist for the prior question: is this project even legitimate enough to risk money on? Run it before you connect a wallet, not after.

1. Read the docs like you are being lied to

Start with the whitepaper, the documentation, and the website — and read them adversarially. You are looking for substance, not vibes. Does the project explain what it actually does and why it needs a blockchain to do it, or does it drown you in buzzwords, roadmaps full of emojis, and promises of guaranteed returns?

That last phrase is the single loudest alarm. As the Ethereum Foundation puts it plainly in its security and scam-prevention guide, the entire premise of decentralized networks is that “no one needs access to your private keys or personal information” and no legitimate party can promise to multiply your money. Any project guaranteeing fixed high yields, or leaning on artificial urgency (“limited time, act now”), is telling you what it is.

2. Verify the smart contract exists and is published

This is the step most people skip and most scammers rely on you skipping. A real project’s smart contract source code should be verified and published on a block explorer such as Etherscan (or the equivalent for whatever chain it lives on — Solscan, BscScan, and so on). Verified source means the human-readable code has been matched against the deployed bytecode, so what you read is what actually runs.

If a token’s contract is unverified, you are trusting a black box. If it is verified, spend a few minutes on it — or paste it into one of the free contract scanners that flag common danger functions: a mint function that lets the owner print unlimited new tokens, a blacklist or pause function that can freeze your ability to sell, or trading taxes that can be cranked to 100%. A contract you cannot sell out of is called a honeypot, and it is one of the most common ways liquidity gets trapped.

3. Follow the money: tokenomics and holder distribution

A block explorer does more than show you code. Open the token’s “Holders” tab and look at the distribution. If a handful of wallets — often the deployer and a few others — control the majority of the supply, you are one large sell order away from a collapse, and you would be buying the bags they intend to dump.

Ask the boring questions the marketing avoids: What is the total and circulating supply? How much is allocated to the team and early investors, and is it locked on a vesting schedule or free to sell tomorrow? Where is the trading liquidity, and is the liquidity pool locked or renounced so the founders cannot simply pull it? A “rug pull” in its most literal form is the team withdrawing the liquidity that backs the token, leaving holders with something they cannot trade. Locked liquidity is not a guarantee of honesty, but its absence is a genuine red flag.

4. Check whether anyone real is accountable

Anonymous teams are not automatically fraudulent — some of the most important projects in crypto history shipped pseudonymously. But anonymity removes the strongest deterrent to fraud, which is a reputation that can be destroyed. So weight it accordingly.

Look for a track record: have these builders shipped anything before? Are there independent security audits from recognized firms, and — crucially — did the project actually fix what the audit found, or just publish the report as a trophy? Is there a real, active community answering technical questions, or is every channel a wall of price cheerleading and moderators deleting hard questions? A project confident in itself can tolerate scrutiny. One that bans every skeptic is managing a mood, not building a product.

5. Learn the scam playbook so you recognize it live

Most scams are not creative; they are the same few scripts repeated. The Ethereum Foundation’s guide catalogs the classics, and they are worth memorizing because you will see them:

  • The giveaway / “2-for-1” scam. Send ETH to an address and receive double back. This is always a scam — always. It frequently masquerades as a “celebrity giveaway,” with scammers restreaming old interview footage of figures like Vitalik Buterin or Elon Musk on YouTube to fake a live endorsement.
  • Phishing via ads and fake support. Someone posing as a support agent offers to “recover” your lost funds in exchange for your recovery phrase. No legitimate service will ever ask for it.
  • Fake urgency and impersonation. A “limited window,” a lookalike domain, a Discord DM from a “team member” — all engineered to make you act before you think.

6. Protect yourself so a mistake is not fatal

Vetting reduces risk; it never eliminates it. So set up your defenses on the assumption that you will eventually interact with something malicious.

The non-negotiable rule, in the Ethereum Foundation’s words: never, for any reason, share your recovery phrase or private keys. That phrase is the master key to every asset in your wallet. Do not screenshot it — screenshots sync to the cloud, and cloud accounts get breached. For anything beyond small amounts, use a hardware wallet so your private keys stay offline and never touch an internet-connected machine, which massively reduces your exposure even if your computer is compromised.

One more habit worth building: use a separate “burner” wallet with only a little money in it for connecting to new or unproven dApps. If a contract you approve turns out to be malicious, it can only reach what that wallet holds — not your main savings.

The twenty-minute version

If you do nothing else: confirm the contract is verified on a block explorer, check that supply is not concentrated in a few wallets, confirm liquidity is locked, and treat any guaranteed return as a confession. Those four checks, plus a hardware wallet and a recovery phrase you never share, filter out the overwhelming majority of projects designed to take your money. The projects worth your time will pass them without complaint — and the ones that fail were doing you a favor by failing early.

We may earn commission from affiliate links at no extra cost to you. Last updated: Jul 24, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.