You're about to put real money on-chain, and you know you need a security review. So you go looking — and the market is bewildering. A firm quotes you $30,000 and a six-week wait. A Fiverr gig offers "full audit, 24h delivery" for $60. How are you supposed to tell what's real?

I do these reviews for a living, so let me hand you the checklist I'd use if I were the one buying. Five questions. Ask every auditor.

1. "Can I see a sample report — and does it include things that were fine?"

A report that's all red flags is a red flag. A real review says "the access control is correct, here's why; the staking math is sound, here's the invariant I checked." A clean bill on what checks out is a finding — it's the auditor telling you where they looked and found nothing, which is exactly what you need to know before you ship.

If every sample report is a wall of "criticals," you're looking at a scanner's raw output, not an audit.