Crypto Due Diligence: A Framework for Evaluating Web3 Projects
Most crypto losses are not bad luck — they are diligence that was never done. This is the framework we use to decide whether a Web3 project is worth investing in, partnering with, or building on.
Due diligence in Web3 is not a checklist you tick before wiring funds. It is a structured attempt to find the reasons not to proceed, across every dimension where risk can hide, before the market finds them for you. A project can have a brilliant team and fatal tokenomics, an audited contract and a captured treasury, real users and a legal structure that unravels under the first regulator's letter. Risk lives across all of these at once, and a strength in one rarely compensates for a failure in another.
The mistake we see most often is treating diligence as trivia collection — gathering facts that feel thorough but never resolve into a decision. The point is the opposite. Every dimension below should move you toward a single output: a defensible go or no-go. This is the same discipline we apply in Web3 due diligence engagements, compressed into the dimensions that actually decide outcomes.
Team: track record beats pedigree
People ship protocols, and people drain them. Start with who is behind the project and what they have actually done. A doxxed team with a verifiable history is not a guarantee, but it changes the cost of misbehaviour. An anonymous team is not disqualifying — many serious builders stay pseudonymous — but it raises the bar for everything else, because there is no reputation to forfeit.
Read the on-chain history before the pitch deck. Wallets tell a less flattering and more reliable story than a website. Look for prior launches, how they ended, and whether the founders held through or exited at the first unlock. A clean LinkedIn and a trail of abandoned contracts is a contradiction worth resolving before you commit.
Technology and smart contracts: where the money actually sits
The contract is the product. An audit is a signal, not a clearance — read who performed it, what scope it covered, when it was conducted, and whether the findings were actually remediated. A single audit from an unknown firm on a codebase that has shipped three times since means very little. Unaudited code handling user funds is a position, not an investment.
- Upgradeability — can the contract be changed after deployment, and if so, by whom? A proxy pattern is not inherently bad, but it means today's audited code is not necessarily tomorrow's.
- Admin keys — what can a privileged address do? Pause withdrawals, mint supply, drain a pool? Map every privileged function and assume it will eventually be used.
- Multisig and timelocks — who holds the keys, what is the signing threshold, and is there a timelock that gives users a window to exit before a change takes effect?
- Dependencies and oracles — external price feeds, bridges, and libraries are attack surface. A protocol is only as safe as the weakest contract it trusts.
Tokenomics and unlocks: the supply you cannot see
A token that looks cheap on circulating market cap can be wildly overvalued on fully diluted valuation. The gap between the two is the supply waiting to hit the market, and it is where most retail entries quietly go to die. Map the FDV, the vesting schedule, and the cliffs — then weigh every unlock against realistic daily volume and ask whether the market can absorb it without collapsing the price.
Vesting overhang is the slow risk; the absence of sinks is the structural one. If every mechanism distributes tokens and nothing locks or burns them, supply only grows. We apply the same supply-and-sink lens here that underpins our tokenomics framework — a design where insiders unlock faster than the network creates demand is a countdown, regardless of how good the narrative sounds today.
Market and traction: separate real users from rented activity
Traction is the easiest metric to fake and the most expensive to misjudge. Total value locked can be a single whale that leaves the day the incentives stop. Daily active users can be a script. Volume can be wash trading between wallets the team controls. Before you trust a number, ask what behaviour would produce it if the project were not paying for it.
Go to the chain. On-chain data is harder to dress up than a dashboard: unique paying addresses, retention after incentives taper, the ratio of fees earned to emissions spent. A protocol that pays more in token incentives than it earns in fees is buying its traction, and that traction leaves with the subsidy. Real demand survives the moment the rewards are switched off.
Governance and treasury: who actually controls the protocol
Decentralisation is frequently asserted and rarely true. Read the governance distribution, not the governance forum. If a handful of insider wallets can pass any proposal, token holders are voting on a stage, not in a parliament. Ask what a hostile actor accomplishes with 5%, 20%, and 51% of voting power, and whether quorum rules make capture easier or harder.
The treasury is the project's runway and its largest attack surface. Find out what it holds, who can move it, and whether it is denominated in its own token — because a treasury that is mostly native token is correlated to the very risk it is meant to insure against. A multisig with a credible signer set and on-chain transparency is the minimum; sole-signer control is a red flag dressed as efficiency.
Legal and regulatory exposure: the risk that arrives late
Regulatory risk rarely shows up in week one, which is exactly why it is underpriced. Where is the entity domiciled, and does that jurisdiction match the activity? Is the token plausibly a security under the regimes that matter to its users? Are there licensing obligations — for custody, exchange, or transfer — that the project is simply ignoring? A token that cannot survive its own classification is a liability with a countdown, and we treat token compliance as a first-order diligence dimension, not a footnote for later.
Red flags: patterns that end the conversation
Some findings warrant a discount. Others end the diligence. The signals below are not merely concerning in isolation — they are the recurring shapes of projects that did not last.
- Mercenary liquidity — capital that only arrived for the incentives and will leave the instant a higher yield appears elsewhere. It inflates every metric and defends nothing.
- Governance capture — insider wallets that can unilaterally pass proposals, paired with a community vote that exists for optics.
- Fabricated volume — wash trading and self-dealing engineered to manufacture the appearance of demand. If the volume does not reconcile with unique addresses, it is theatre.
- Opaque control — unverified contracts, undocumented admin keys, or a treasury that moves without explanation. What cannot be inspected should be assumed hostile.
The market eventually prices every risk you chose not to look at. Diligence is simply paying that cost upfront, while you can still walk away.
From findings to a decision
A pile of observations is not diligence; a decision is. Once the dimensions are mapped, weigh them as a system and force the output. The goal is not a perfect project — none exist — but an honest map of where the risk concentrates and whether the upside is paid for taking it. When the contracts are sound, the unlocks are survivable, the traction is real, and control is genuinely distributed, you have a case to proceed. When risk clusters in even one load-bearing dimension, the answer is no, and no narrative should be allowed to overrule it.
Frequently asked questions
- What is crypto due diligence?
- Crypto due diligence is the structured evaluation of a Web3 project before you invest, partner, or build — assessing the team, smart contracts, tokenomics, traction, governance, and legal exposure to reach a defensible go or no-go decision rather than collecting reassuring facts.
- How do you evaluate a Web3 project before investing?
- Work through every dimension where risk hides: the team's on-chain track record, the security and upgradeability of the contracts, the fully diluted valuation and unlock schedule, whether traction reflects real users or paid activity, who controls governance and the treasury, and the regulatory exposure — then weigh them together as one decision.
- What are the biggest red flags in a crypto project?
- The clearest red flags are mercenary liquidity that defends nothing, governance capture by insider wallets, fabricated or wash-traded volume, opaque admin keys and unverifiable contracts, and a fully diluted valuation dominated by insider unlocks that the market cannot absorb.
Related reading
Let's build something durable.
Tell us about your project. We reply within two business days.
