In May 2025, a federal jury found SafeMoon CEO Braden Karony guilty of fraud after prosecutors showed that he and his co-conspirators secretly retained access to SafeMoon’s liquidity pools, despite telling investors those funds were locked.
They diverted millions of dollars for personal purchases, including luxury cars and real estate. On February 10, 2026, Karony was sentenced to 100 months in prison and ordered to forfeit about $7.5 million.
That case captures why crypto due diligence matters: verify claims before you invest, not after you lose money. With the crypto market now worth about $2.76 trillion, the risks remain significant.
In addition, Chainalysis estimates that scams and fraud cost victims $17 billion in 2025, with the average scam payment reaching $2,764.
First things first,
What Is Crypto Due Diligence?
Crypto due diligence is the process of checking a project’s claims, risks, and fundamentals before you put money into it.
It borrows from how professional investors vet traditional companies, but it’s adapted for crypto’s specific dangers: teams that can hide behind fake names, code that runs itself once deployed, and rules that vary wildly from one country to the next.
Traditional investing has decades of paperwork, disclosure laws, and regulators standing between you and a scam. However, crypto often has none of that.
A person can write some code, launch a token, and take your money in an afternoon. That’s why the checking has to come from you.
What Poor Due Diligence Actually Costs
- The pattern shows up again and again. According to Chainalysis, major illicit crypto loss and activity categories include losses into four buckets: sanctions evasion ($104 billion), scams and fraud (about $17 billion), stolen funds from hacks (about $3.4 billion), and ransomware (roughly $820 million).
- FTX (2022): A close, undisclosed relationship between the exchange and its trading arm, Alameda Research, hid a multibillion-dollar balance sheet hole. Basic questions about where customer funds actually sat would have surfaced the problem.
- Terra/LUNA (2022): An algorithmic stablecoin that promised to hold its dollar peg through a token-swap mechanism instead of real reserves. Anyone who modeled what happens under stress would have seen the death spiral coming.
- SafeMoon (2021-2026): A “locked” liquidity pool that was never actually locked, as described above. The court filings, once public, showed exactly what an audit or an on-chain check would have flagged years earlier.
Which Investments Need the Deepest Checking
Not every crypto asset needs the same level of scrutiny. Match your effort to the risk:
- Bitcoin and Ethereum: Lighter checking. Focus on market cycles and network health rather than team background.
- New Layer-1 blockchains: Deep technical review, since you’re betting on infrastructure that doesn’t exist yet at scale.
- DeFi protocols: Smart contract audits, how much money is locked in the protocol, and how the token’s economics actually work.
- New tokens and altcoins: Run the full 12-category checklist below, no shortcuts.
- NFT projects: Community strength, real utility, and whether the team ships what it promises.
- Meme coins: Treat as pure speculation. Understand you could lose everything, and size your position accordingly.
- ICOs, IDOs, and new launches: Maximum scrutiny. This is where rug pulls concentrate.
The 12-Category Due Diligence Framework
A useful crypto due diligence checklist covers twelve areas. Miss one, and you’ve left a door open for something to go wrong.
1. Whitepaper and Documentation Analysis
A whitepaper is the project’s blueprint. Bitcoin’s original whitepaper, published by Satoshi Nakamoto in 2008, is nine pages long and still readable today. That’s the bar for clarity, not the bar for length.
What to check:
- Does the document state a clear problem, and does it explain why a blockchain (not a regular database) is the right tool?
- Is the proposed solution technically believable, with real detail instead of buzzwords?
- Is token distribution laid out plainly: how much goes to the team, investors, the public, and the treasury?
- Are vesting schedules (the timeline for when team and investor tokens unlock) spelled out?
- Is the roadmap realistic? Be wary of “mainnet in one month” type promises.
- Is the writing professional, with sources cited for any statistics used?
Immediate red flags: no whitepaper at all, plagiarized content lifted from another project, guaranteed-return language, and vague claims like infinite scalability or solves the blockchain trilemma.
If a whitepaper reads like it was built for the marketing team instead of engineers, that’s the point.
2. Team and Leadership Verification
Technology, tokenomics, and marketing can all be improved after launch. A dishonest or incompetent team cannot be fixed. This is the single biggest factor in whether a project survives.
How to verify a team, step by step:
- LinkedIn. Look for a complete profile, real work history, and genuine connections, not a sparse page created the same week as the token.
- GitHub. Check account age, commit history, and whether the person has contributed to other real projects.
- Social media. An account created the same month as the launch, with no history of prior crypto discussion, is a warning sign.
- Video. Watch interviews or conference talks. Does the person on video match the photo on the website?
- Reverse image search. Run team photos through Google Images to check they aren’t stock photos or stolen identities.
Anonymous teams aren’t automatically disqualifying; some privacy-focused projects have legitimate reasons to stay pseudonymous. But outside that specific case, an anonymous team with no verifiable identity is a serious risk, because there’s no one to hold accountable if things go wrong.
Red flags: stock photos used as team headshots, LinkedIn profiles with almost no connections, team members previously tied to failed or fraudulent projects, and founders who hold no tokens themselves, meaning they have nothing at stake if the project fails.
3. Technology and Innovation Assessment
You don’t need to read code to judge a project’s technology. You need to know what to look for.
Checks that don’t require a computer science degree:
- GitHub activity. Frequent commits from multiple contributors signal real, ongoing work. A repository that’s been quiet for 60+ days is a concern.
- A public testnet. If the project claims high performance, a working testnet with visible data backs that up. A claim with no testnet is just a claim.
- Third-party builders. Are other developers actually building on top of this protocol?
- Plain claims. Be skeptical of fastest blockchain ever or infinite scalability language. Every blockchain trades off between security, speed, and decentralization. Therefore, a project that claims to have solved this completely, without independent verification, is overselling.
Closed-source code that the team promises to open up “after launch” is one of the more common excuses used to hide problems until it’s too late to matter.
4. Smart Contract Security and Audits
Smart contracts are close to permanent once deployed. A bug isn’t a bug you patch quietly; it’s a vulnerability sitting in public, waiting for someone to find it.
DeFi losses show why this matters: according to Chainanalysis, since the first half of 2026, at least $36.7 million has been stolen from protocols whose source code was never publicly verified.
What a real audit looks like:
- The full report should be public, not just a summary graphic on Twitter. Names like ConsenSys Diligence, Trail of Bits, OpenZeppelin, and Certik carry weight; a firm nobody has heard of does not.
- It comes from a recognized firm. Confirm the report is hosted on the auditing firm’s own official website, not just linked from the project’s page.
- The full report is public, not just a summary graphic on Twitter.
- It lists severity levels (Critical, High, Medium, Low) and shows which issues were actually fixed, not just acknowledged.
- The audited code version matches what’s actually deployed. Projects sometimes patch code after the audit and never get it re-checked.
A bug bounty is a good sign, not a nice-to-have. A program with rewards of $10,000 or more for critical bugs, hosted on a platform like Immunefi, shows the team is confident enough in its code to invite scrutiny.
Red flags: no audit before launch, an audit from an unverifiable firm, unresolved Critical findings and closed-source contracts that the public can’t review at all.
5. Tokenomics and Economic Model
Tokenomics is the economic design behind a token: who holds it, how it’s unlocked, and what it’s actually for.Bad tokenomics has killed technically solid projects more than once.
Even the best product falls apart if the token is designed to reward insiders at the expense of everyone else.
The core questions to answer:
- How is the supply split? A team and VC allocation above 50% of total supply is a serious concern. Anything above roughly 35% deserves close attention, and it should come with long vesting.
- What’s the vesting schedule? Team tokens should unlock gradually over 2-4 years, ideally after a 6-12 month cliff (a period with no unlocks at all).
- If team tokens can be sold the day after launch, there’s little holding the team to the project’s long-term success.
- What does the token actually do? Governance voting, fee payment, staking, or revenue sharing are all real utilities. “It’s a governance token” with no functioning governance is not.
- Is supply inflationary or deflationary? High annual inflation (think 20%+) with no burn mechanism dilutes every holder over time.
- Is liquidity locked? SafeMoon’s entire fraud case rested on a false claim about locked liquidity. Verify this yourself on a blockchain explorer rather than trusting the website copy.
A quick way to read vesting schedules: if a project shows you a chart with a big cliff where 20%+ of supply unlocks all at once, expect heavy sell pressure around that date. A steady, linear unlock over years is far less disruptive to the price.
6. Community and Social Presence
A real community argues, asks hard questions, and sometimes disagrees with the team in public.
A manufactured community repeats the same phrases, like great project and to the moon, and bans anyone who asks something uncomfortable.
What to look for:
- Are team members answering tough questions directly or hiding behind DYOR (do your own research) and wait for the announcement?
- Is the Discord or Telegram full of genuine discussion, or just price talk and hype?
- Do new members get DMed immediately by support agents? That’s almost always a scam attempt, not a feature.
- Are Twitter/X followers real, or is the account followed mostly by bots? Free tools like Twitter Audit can give you a rough read.
Tools worth using: LunarCrush for social analytics, Social Blade to track growth patterns over time, and a simple Twitter Audit check for fake followers.
7. Market and Competition Analysis
No project exists in a vacuum. Before investing, understand what it’s actually competing against and whether it has a real edge.
Questions to work through:
- How big is the actual market this project is targeting, and does the project need a small or unrealistic slice of it to succeed?
- Who are the direct competitors, and what does this project do differently that actually matters to users?
- How does its valuation compare to similar projects with similar usage numbers?
If a project claims to be the first in a space that clearly already has established competitors or dismisses everyone else as legacy without addressing why users would switch, treat that as a marketing tactic rather than an analysis.
8. Partnerships and Backers
Investor quality is a real signal. Funds like a16z crypto, Paradigm, Polychain Capital, and Coinbase Ventures do their own due diligence before writing a check, and their involvement means someone else has already looked closely at the project.
How to check a claimed partnership
Go to the partner’s own official channels. If Chainlink, Binance, or any other named partner has never mentioned the relationship anywhere on their own website or social media, the partnership probably amounts to a logo on a slide deck, not a real collaboration.
Verify investors, too.
A funding round should be traceable; check the project’s own announcements against reporting from outlets like The Block or research from Messari, rather than taking a backed by top VCs claim at face value.
9. Regulatory and Legal Compliance
Regulation moved fast in 2026, and it changes what safe looks like depending on where you live.
In the EU, MiCA (Markets in Crypto-Assets Regulation) is already law.
Its transitional period for existing crypto-asset service providers ended on July 1, 2026This means any platform serving EU customers now needs full MiCA authorization to keep operating. You can read the framework directly through the ESMA MiCA documentation.
In the US, the picture is still forming. The CLARITY ActWhile it passed the House in July 2025 and cleared the Senate Banking Committee in May 2026, it has not received a full Senate floor vote as of early August 2026.
In March 2026, the SEC and CFTC jointly classified 16 cryptocurrencies, including Bitcoin, Ethereum, and XRP, as digital commodities, a meaningful step toward clarity, even without the full law in place.
You can track official guidance directly at the SEC’s crypto assets page.
What to check on any project:
- Is there a real legal entity behind it, and where is it registered?
- Are US or other restricted investors actually blocked, or is it just a checkbox disclaimer nobody enforces?
- Does the project use language like guaranteed returns or investment that would normally trigger securities rules? That’s often a sign the team hasn’t taken compliance seriously.
10. Exchange Listings and Liquidity
Liquidity is what lets you actually sell without crashing the price yourself. A token can look valuable on paper and still be nearly impossible to exit.
A simple test: could you sell $10,000 worth of this token right now without moving the price more than a percent or two? If the honest answer is no, that’s your answer about how liquid it really is.
What to check:
- Which exchanges list it? A listing on Binance, Coinbase, or Kraken means the exchange has already run its own compliance and security review. A listing only on small, unknown exchanges means no one else has vetted it.
- Is daily trading volume real, or is it wash trading (fake volume designed to look like activity)? Compare centralized exchange volume against decentralized exchange volume for consistency.
- Is liquidity on decentralized exchanges locked, and for how long? Unlocked liquidity is exactly what let SafeMoon’s team quietly divert funds while telling investors it was safe.
You can check liquidity pool locks yourself on a blockchain explorer like Etherscan or BscScan and cross-check trading data on CoinGecko or DeFiLlama.
11. Roadmap and Development Progress
Ideas are cheap; shipping is everything. A project’s history of hitting or missing its own deadlines is one of the most honest signals you can find.
What to check:
- Compare the original roadmap against what’s actually been delivered. Delays happen to good projects too, but a pattern of missed milestones with vague excuses is different from an occasional honest delay.
- Look at GitHub commit frequency over the last 30-90 days. A project that claims to be actively building but hasn’t committed code in two months is not actively building.
- Is there a working product you can use right now, or is it still “coming soon” a year after launch?
A roadmap that keeps growing more ambitious over time, without ever actually shipping the earlier, smaller promises, is a pattern worth taking seriously.
12. Red Flags and Warning Signs
This category pulls together the deal-breakers from everything above. Treat these as a final gut check before you commit money.
Stop immediately if you see:
- A fully anonymous team with no verifiable identity, outside of a genuine privacy-focused project
- No security audit at all, or an audit from a firm no one can verify
- Team and insider wallets holding more than 70% of total supply
- No whitepaper, or one that’s clearly copied from another project
- Guaranteed or “risk-free” return promises
- No code repository, or one with no real development activity
Proceed with real caution if you see multiple of these together:
- Heavy team or VC token allocation (40-60%) with short vesting
- A community that reacts to any criticism with hostility instead of answers
- Constant pivoting or rebranding with no clear explanation
- Team wallets that are steadily selling into the market
Common Scam Patterns to Recognize
- The classic rug pull: anonymous team, no vesting, heavy hype, then the team drains liquidity and disappears.
- The slow rug: the team stays visible but stops building, delays the roadmap repeatedly, and quietly sells down its holdings over months.
- The honeypot: the smart contract lets you buy but blocks you from selling. This is exactly how the Squid Game Token scam worked in 2021, where the price spiked before investors discovered they couldn’t sell at all.
- The unsustainable yield: returns advertised well above 100% APY that are actually paid from new deposits rather than real revenue. When new money slows down, the whole thing collapses.
Practical Crypto Due Diligence Workflow
Phase 1: Initial Screening (30 Minutes)
Start with a quick assessment to eliminate obvious red flags before spending hours on deeper research.
Check:
- Team: Are founders and key contributors publicly identifiable with verifiable backgrounds?
- Documentation: Does the project have a credible website, whitepaper, technical documentation, and roadmap?
- Security: Are independent smart-contract audits available? Check what was audited, when, and whether identified issues were resolved. An audit is useful evidence, but it does not guarantee that a protocol is safe.
- Reputation: Search for recent scam allegations, exploits, regulatory actions, or misleading claims.
- Development: Review GitHub activity and recent product updates.
- Market presence: Check token listings, liquidity, trading activity, and community engagement.
Decision: If you uncover multiple serious red flags, stop. If the project passes the initial screen, move to Phase 2.
Phase 2: Deep-Dive Analysis (3–5 Hours)
For projects that survive the initial screen, investigate the fundamentals in detail.
1. Documentation & Tokenomics
- Read the whitepaper and technical documentation.
- Analyze token supply, allocation, utility, vesting, and unlock schedules.
- Compare the project’s valuation with similar protocols.
- Check whether its roadmap matches what the team has actually delivered.
2. Team & Track Record
- Verify team identities and professional histories.
- Review LinkedIn profiles, GitHub contributions, interviews, and AMAs.
- Investigate previous projects, successes, failures, and controversies.
3. Technology & Security
- Review the codebase and development activity.
- Examine smart contracts on a blockchain explorer.
- Read audit reports and verify remediation of critical findings.
- Test the product where possible and compare its technology with competitors.
4. Community & Market Health
- Observe Discord, Telegram, and other community channels rather than relying only on follower counts.
- Assess whether engagement appears genuine.
- Monitor sentiment for excessive hype, unrealistic promises, censorship, or coordinated promotion.
- Check liquidity, exchange depth, whale concentration, and major wallet movements.
5. Financial & Regulatory Risk
- Model potential dilution from future token unlocks.
- Assess liquidity and valuation against comparable projects.
- Calculate your potential risk/reward rather than relying on price predictions.
- Check the project’s regulatory exposure in relevant jurisdictions. In the U.S., for example, the SEC’s 2026 guidance clarified how securities laws can apply to certain crypto assets and transactions.
Finally, score the project against your due diligence checklist and make a clear go, watch, or avoid decision.
Phase 3: Ongoing Monitoring
Due diligence does not end after you invest. Reassess the project regularly.
Weekly
- Monitor GitHub development and product releases.
- Track token price, liquidity, and major wallet activity.
- Watch team announcements and security alerts.
- Monitor community sentiment.
Monthly
- Review roadmap progress and partnerships.
- Reassess token unlocks and supply changes.
- Check for new listings, regulatory developments, or security incidents.
- Revisit your original investment thesis.
Know Your Exit Triggers
Consider reducing or exiting your position when:
- A critical security vulnerability or exploit emerges.
- Key team members leave unexpectedly.
- Major roadmap milestones are repeatedly missed.
- Regulatory action materially changes the project’s outlook.
- Token unlocks create unsustainable selling pressure.
- Community confidence and project fundamentals deteriorate.
- A stronger opportunity offers a better risk/reward profile.
Tools & Resources for Crypto Due Diligence
1. Blockchain & On-Chain Analysis
Start with blockchain explorers to independently verify transactions, contract addresses, token holders, and team-wallet activity.
- Etherscan – Ethereum transactions, contracts, and token holders.
- BscScan – BNB Chain activity and contracts.
- Solscan – Solana wallets, tokens, and transactions.
- PolygonScan – Polygon on-chain activity.
- DeFiLlama – TVL, protocol and chain-level DeFi data.
- Dune – Custom dashboards and blockchain data queries.
- Nansen – Wallet labels, smart money tracking, and multi-chain analytics.
2. Token & Smart-Contract Security
Security tools can expose common contract risks, suspicious token behavior, and concentration problems before you invest.
- TokenSniffer – Automated token and contract risk checks.
- CertiK Skynet – Security scores, audits, and project risk information.
- Tenderly – Smart contract simulation, debugging, and monitoring.
- Bubblemaps – Visualizes token-holder relationships and wallet concentration.
- DEXTools – DEX liquidity, trading activity, and token analytics.
Use several tools together rather than treating any automated security score as proof that a project is safe.
3. Development & Community Signals
A project’s activity can reveal whether its development claims match reality.
- GitHub – Review repositories, commits, contributors, and development history.
- CryptoMiso – Compare crypto-project development activity.
- Electric Capital Developer Report – Industry-level developer trends.
- LunarCrush – Social engagement and sentiment data.
4. Research, Audits & Regulation
Cross-check claims against independent research and primary regulatory sources.
- SEC EDGAR – U.S. company and securities filings.
- FCA Register – Verify UK-regulated firms. The FCA’s new cryptoasset regime is scheduled to take effect on October 25, 2027, with the authorization application period opening in September 2026.
- ESMA – EU crypto-asset regulatory information and MiCA resources.
- Messari, CoinDesk, and The Block – Market research, industry news, and project intelligence.
Once you’re comfortable running this checklist manually, our crypto investment tip guide and crypto security best practices go deeper on protecting the assets you do decide to buy.
Common Due Diligence Mistakes to Avoid
| Due Diligence Failure | Key Risk / Impact | Mitigation Strategy |
| 1. Hype-Driven Investing | Falling for scams/rug pulls (e.g., Squid Game token collapse). | Use social media only for discovery; perform independent technical research. |
| 2. Ignoring Red Flags | Overlooking weak fundamentals during market rallies. | Treat anon teams, unaudited code, and high concentration as firm warning signs. |
| 3. Unverified Team Claims | Fake identities, inflated resumes, or copied bios. | Cross-check founders via GitHub, past projects, official channels, and conferences. |
| 4. Skipping Audit Details | Deployment mismatches or unaddressed high-severity bugs. | Read the actual report; check critical/high findings, scope, and remediation status. |
| 5. Ignoring Tokenomics & Unlocks | Massive price dilution from upcoming token unlocks. | Evaluate supply, insider allocations, vesting schedules, and emissions data. |
| 6. Over-relying on One Factor | Masking fatal flaws (e.g., strong team with broken tokenomics). | Score projects holistically across tech, security, liquidity, and regulations. |
| 7. Fake / Exaggerated Partnerships | Misleading credibility claims to pump token price. | Verify all partnership claims on the partner’s official website or channels. |
| 8. Neglecting Exit Liquidity | High paper gains that are impossible to sell without massive slippage. | Check DEX depth, trading volume, holder concentration, and liquidity locks. |
| 9. Trusting “Insider Information” | Getting dumped on by early holders exploiting artificially generated FOMO. | Treat all private tips, Discord, and Telegram leaks as unverified until proven. |
| 10. Poor Risk & Position Sizing | Total portfolio wipeout on a single speculative project failure. | Define maximum position size, stop-loss thresholds, and exit strategy in advance. |
Behavioral Biases to Guard Against
| Bias | Summary Trap |
| Confirmation Bias | Only seeking info that validates an investment you already want to make. |
| Recency Bias | Weighting recent price surges or hype heavier than long-term fundamentals. |
| Authority Bias | Assuming big VCs, exchanges, or influencers did thorough diligence for you. |
| Anchoring | Fixating on past all-time highs, ICO prices, or arbitrary target valuations. |
| Sunk-Cost Fallacy | Refusing to cut losses because you already invested significant time or capital. |
| FOMO | Buying impulsively due to rapid price appreciation or community hype. |
Conclusion
Crypto doesn’t come with a refund policy. There’s no regulator to call, no fraud department to dispute the charge, and no one to reverse the transaction once the money moves.
What you have instead is information, publicly available, on-chain, verifiable and the discipline to actually use it before you invest rather than after you lose.
The 12-category framework in this guide isn’t a guarantee. SafeMoon still fooled millions of people who thought they’d done their research. What it is, is a system for making it significantly harder to be fooled.
Every red flag you catch in a whitepaper, every unresolved audit finding you notice, every anonymous team you walk away from is a decision that compounds quietly, invisibly into a portfolio that’s still standing when the next market cycle cleans out the people who skipped the checklist.
Crypto due diligence isn’t the most exciting part of investing. It’s just the part that determines whether the exciting parts were worth anything.












