Coinbase Guide

How to Check if a Crypto Project Is Legit: A Practical Due Diligence Guide

The direct answer is that there is no single “legitimacy score,” but you can reliably vet a crypto project by triangulating four independent sources of truth: the team’s real-world identity, the token’s on-chain mechanics, the project’s community health, and its regulatory footprint. If a project fails on two or more of these checks, treat it as a probable scam regardless of how polished its website looks. This guide from ScamShield Weekly walks you through each layer, using the same framework we apply to every alert we publish.

1. Verify the Team and the "Anonymity Red Flag"

The first question is not "what does the whitepaper claim?" but "who is accountable?" Legitimate projects—even privacy-focused ones—usually have identifiable founders, advisors, or a registered legal entity. Scammers hide behind pseudonyms because accountability is their enemy.

What to look for in a team check

  • LinkedIn and GitHub history: Do the founders have a verifiable trail of past employment, education, or open-source contributions? A blank profile with a stock photo is a warning.
  • Video or live appearances: Have the founders spoken on a reputable podcast or conference? Text-only "AMAs" are easy to fake.
  • Registered company: Does the project list a physical address and registration number? Cross-check that address on a map—many scams use a random WeWork or a nonexistent office.

One major exception: some legitimate anonymous teams exist (e.g., early Bitcoin or certain privacy coins). But in those cases, the code itself must be exceptionally transparent and audited by third parties. If a team is anonymous and the code is closed-source, walk away.

2. Audit the Tokenomics and On-Chain Mechanics

A "legit" project can still be a bad investment, but a scam almost always has broken or deceptive tokenomics. You do not need to be a developer to check the basics. Read the smart contract on a block explorer like Etherscan or BscScan.

Three on-chain checks that expose most scams

  • Ownership and minting functions: Does the contract allow the owner to mint unlimited new tokens? If yes, they can dump on you at any time. Look for a "renounced" or time-locked ownership.
  • Liquidity lock: Is the liquidity pool (LP) locked? A project that can pull liquidity from a DEX is a classic rug pull. Check if the LP tokens are burned or locked in a smart contract vault.
  • Transaction fees and honeypots: Can you actually sell the token? Test with a tiny amount, or read if the contract blocks sales for certain wallets. A "honeypot" lets you buy but never sell.

If you are unsure how to read a contract, use a trusted tool like Token Sniffer or a professional auditor’s report—but never rely solely on the project’s own audit PDF. Scammers fake audit reports regularly.

3. Assess Community Health vs. Hype Metrics

Scammers buy bots and followers. A high Telegram count or Twitter following means nothing if the engagement is fake. Legitimate communities discuss technical details, ask hard questions, and tolerate criticism. Scam communities ban skeptics within minutes.

Signals of a healthy community

  • Question tolerance: Post a critical question in their Telegram or Discord. If you get banned or deleted instantly, that is a red flag. Legit teams answer or at least acknowledge.
  • Developer activity: Check the project’s GitHub or GitLab. Are there commits in the last 30 days? A dead repo with a live marketing push is a classic exit-scam setup.
  • Independent mentions: Does the project appear on reputable third-party review sites or in established media without being a paid press release? Search for the project name plus the word "scam" to see what comes up.

Be wary of "community" that only talks about price and never about utility. If 90% of the chat is "when moon?" and "to the moon," you are likely in a paid pump group, not a genuine project.

4. Check Regulatory and Exchange Status

Legitimacy is not the same as being listed on a major exchange, but exchange due diligence matters. Major regulated platforms like Coinbase perform their own legal and technical review before listing an asset. A listing on Coinbase or another top-tier exchange is not a guarantee of future success, but it does mean the project passed a baseline compliance check that most scams cannot pass.

How to use exchange and regulator data

CheckWhat it meansAction if failed
Listed on top-tier CEX (Coinbase, Kraken, etc.)Passed KYC and legal reviewNot fatal, but adds risk
Registered with a financial authority (e.g., FinCEN, FCA)Operates under legal frameworksHigh risk for large investments
Clear stance on securities statusProject states if token is a utility or securityVague answers = legal risk

Also, search for official warnings. Agencies like the SEC, CFTC, or the FCA publish lists of unregistered or fraudulent crypto firms. If the project name appears there, do not invest—no exceptions.

Final Checklist Before You Commit

You have read the four sections above. Now run a final 60-second test. Write down the project name and answer these five questions:

  1. Can I name one real human behind this project?
  2. Is the token contract audited by a third party I chose, not the project?
  3. Does the community tolerate my critical question?
  4. Is there a clear, non-hyped use case that works today?
  5. Is there any regulatory warning against this project?

If you answered "no" to any of the first three, or "yes" to the last one, treat the project as illegitimate. There are thousands of tokens; you only need to find one or two good ones. ScamShield Weekly publishes a new alert every Friday, but this framework will protect you daily.