Due Diligence Checklist for Kaspa Apps and Dapps

For individuals considering an untested project or token. A simple, DIY filter anyone in the community can use before putting in their $KAS.

Rug Pull Red Flags

  • Anonymous Team with No Track Record
  • High Token Allocation to Developers or Treasury (30%+)
  • No Lock-up or Vesting Periods
  • No Working Product or Demo
  • Fake Partnerships or Endorsements
  • Unverified Smart Contracts
  • “Too Good to Be True” Promises
  • Sudden Hype, No History

Basic Research

Project Website

  • Does it exist?
  • Is it professional, informative, and transparent?

Whitepaper or Litepaper

  • Is there one?
  • Does it clearly state the problem, solution, and token utility?

Team Information

  • Are team members named and verifiable?
  • LinkedIn, GitHub, past projects?

GitHub or Code Repository

  • Is it public?
  • Has there been recent activity?

Social Presence

  • Are their Telegram, X, Discord, etc. active?
  • Are followers real or botted?

Tokenomics

  • Is there a clear breakdown of supply, emissions, and allocation?
  • Any red flags in vesting or wallet control?

Kaspa Ecosystem Project Filter (WatchDAG Service) K-Guard? 🙂

A broader framework used by the Kaspa community to vet, monitor, and classify emerging projects.

Project Audit Framework (DIY, Transparent)

1. Identity & Transparency

  • Team Doxxed or Anonymous?
  • Country or jurisdiction of founding
  • Background check summary (crowd-sourced research)
  • Known affiliations or community endorsements

2. Technical Audit Lite

  • GitHub repo reviewed
  • Presence of tests, readme, docs
  • Flag whether contracts are open-source
  • Simple checklist:
    • Any owner functions?
    • Can liquidity be withdrawn?
    • Mint or burn functions?
    • Is the contract upgradeable?

3. Tokenomics Assessment

  • Total supply and issuance rate
  • Team and early investor allocations
  • Liquidity lock period
  • Emission schedule (fixed or inflationary)
  • Burn or redistribution mechanics

4. Use Case / Real Utility

  • Is the project solving a real problem?
  • Is Kaspa DLT actually necessary for this?
  • Who are the target users?

5. Community & Support

  • Real engagement vs. bot accounts
  • Public roadmap and dev logs
  • Issue responses and bug reports
  • Community transparency: weekly updates, AMAs, etc.
  1. Track Record & Delivery
  • Past milestones met or missed
  • Working demo or MVP?
  • Are devs building or just posting memes?

7. Security

  • Liquidity lock verified?
  • Multisig wallet used for treasury?
  • Admin key disclosure?
  • Contract interaction limits and permissions?

If anyone wants to build something like a Trust Score for Apps, here’s some ideas
Suggested Outputs of the “WatchDAG” Service:

  • Scoring System: Red/Yellow/Green light status
  • Community Comments Section (like product reviews)
  • Flag System for contract risks and key wallet movements
  • RSS feed or X posts for warnings and project updates
  • Add spots for source references
  • Form a Review Crew of Devs, technicians, researchers to offer their own rating