Back to Tools
CHECKLIST10 min read2025-06-23

Blockchain Technical Due Diligence Checklist — For Investors and Acquirers

This checklist is for investors, acquirers, and enterprise partners evaluating a blockchain protocol or company's technical maturity.

Enterprise Ready

Built for production environments.

Fast Results

Save hours of manual planning.

Professional

Trusted by blockchain teams.

Blockchain Tool

Interactive planning, estimation, calculations and enterprise-grade blockchain utilities.

AI

Assisted

24/7

Available

Tool Assistance

Need Help with Technical Due Diligence?

Get expert guidance on evaluating blockchain protocols and companies.

Tool Workspace

Use, understand, and apply the results

Tool Overview

This checklist is for investors, acquirers, and enterprise partners evaluating a blockchain protocol or company's technical maturity.

Key Result

A technical due diligence checklist for evaluating blockchain protocols: Tier 1 Non-Negotiable (smart contract audit by named firm, zero unresolved Critical/High findings, multi-sig admin keys, timelocks ≥48 hours). Tier 2 Strong Signals (test coverage ≥95%, fuzz tests, invariant tests, clear upgrade path). Tier 3 Concerns (red flags: no audit, unlimited admin access, single-key admin, anonymous team, audit report not public). Technical interview questions: 'Walk me through responding to a 2am exploit,' 'What happens if oracle goes down for 30 minutes?', 'Who can pause the protocol?'

TIER 1: NON-NEGOTIABLE (Fail if absent)

Smart Contract Security:

01

All production contracts audited by named, reputable firm

02

Audit report publicly available (with findings and remediation status)

03

Zero unresolved Critical or High findings

04

Contracts verified on Etherscan (source code visible)

05

Bug bounty program active with material bounty ($50K+ Critical)

Key Management:

01

Admin keys held in multi-sig (3-of-N minimum)

02

No single-EOA admin keys for any production protocol

03

Upgrade timelocks ≥ 48 hours for any significant parameter change

04

Multisig signers are named individuals, not anonymous

Verifiable History:

01

Deployed contract addresses provided and match description

02

On-chain transaction history consistent with claimed launch date and usage

03

Named engineers with verifiable GitHub history

TIER 2: STRONG POSITIVE SIGNALS

Testing and Quality:

01

Test coverage ≥ 95% (evidence: coverage report)

02

Fuzz tests implemented for all critical math functions

03

Invariant tests passing

04

Fork tests against mainnet state

Architecture:

01

Clear and reasonable upgrade path (UUPS or Transparent Proxy)

02

Oracle design: dual-oracle with divergence threshold

03

No circular dependencies in token economics

04

Clear mechanism for emergency pause

Track Record:

01

Protocol has operated without incident for ≥ 90 days

02

No prior exploits (or prior exploits fully disclosed and resolved)

03

TVL trend: flat or growing (declining TVL = trust signal)

04

Protocol revenue covers operating costs at current scale

TIER 3: CONCERNS (Flag for further investigation)

Yellow flags:

01

Single audit by lesser-known firm

02

Admin timelock < 24 hours

03

Closed-source contracts

04

No bug bounty program

05

Anonymous team

06

Token emissions significantly exceeding protocol revenue

07

Recent large TVL decline without explanation

08

Governance controlled by <5 addresses

Red flags:

01

No audit at all for protocol handling funds

02

Unlimited admin access (no timelock, no multi-sig)

03

Team cannot explain their own codebase clearly

04

Prior exploit not disclosed

05

Audit report not publicly available

06

Admin keys held by single person

Technical Interview Questions for Protocol Team

01

"Walk me through how you would respond if your protocol were exploited at 2am UTC."

02

"What is the worst-case scenario if your oracle goes down for 30 minutes? Walk me through exactly what happens."

03

"If token price drops 70%, does your emission model still work? Show me the numbers."

04

"Who can pause the protocol? What is the exact process?"

05

"What is the most dangerous thing an insider could do with their current access?"

FAQ

Common Questions

1

Thorough technical DD for a DeFi protocol: 2–4 weeks. This includes: code review (1 week), audit report analysis (2–3 days), on-chain analytics (2–3 days), team interviews (3–5 hours), tokenomics modeling (1 week). For acquisitions or significant investments (>$5M): engage an independent technical advisor for the code review component.

Tool Assistance

Need Help with Technical Due Diligence?

Get expert guidance on evaluating blockchain protocols and companies.