Nine Sections, Zero Findings: What an Empty Diligence Report Reveals About Crypto Research in 2026
There is a document open on my second monitor as I write this, and it is beautiful in the way an empty building is beautiful. Nine sections. Forty-one assessment rows. A risk matrix with six categories, each with a probability column and an impact column. The typography is immaculate. The table borders align. And every single field in it says the same three words, over and over, in slightly different fonts: information insufficient.
The technology row: no description extracted. The supply row: no unlock schedule available. The team row: no names provided. The regulatory row: jurisdiction unknown. The final judgement, which in a working document would carry a star rating, carries nothing, because nothing is the honest number when the input was nothing.
I have been reading crypto documents for twelve years and writing them for nearly as long. I have produced fifteen plain-language whitepaper breakdowns for students who had never opened a block explorer, and I have spent more nights than I care to admit cross-referencing unlock tables against on-chain balances by hand. I know what a real diligence pass feels like from the inside. It is loud, it is argumentative, and it almost always ends with a list of things nobody could confirm.
But I have never seen a document this clean that knew this little. And that is worth writing about, because it is not an isolated artifact. It is a symptom with a name, and the name is not laziness.
Let me set the scene properly. The document is a template produced by an analytical framework of the kind that became standard in crypto research somewhere between 2023 and 2026. Nine dimensions. Technical. Token economics. Market. Ecosystem position. Regulatory. Team and governance. Risk. Narrative. Supply chain transmission. Each dimension has sub-tables. Each sub-table has a scoring column. It is a serious apparatus, and in the abstract it is a good one. I have used versions of it myself, and I have defended it in rooms where people wanted to skip straight from ticker to target price.
The framework did what frameworks do. It ran. It produced a structure. It filled every structural slot with the only truthful value available, which was a marker for absence. And then it published.
What makes this interesting is the timing. We are in a bull market. The price of everything has gone up, which means the price of appearing to know has gone up too, which means the volume of research-shaped documents has gone up faster than the volume of research. In 2017, a project needed a forum post and a promise. In 2021, it needed a whitepaper and a Discord server. In 2026, it needs coverage โ a rating, a matrix, a thread, a chart with a labelled axis. The apparatus expanded. The evidence base did not.
Here is the mechanism that makes the gap structural rather than accidental. Between 2023 and 2026, the marginal cost of producing a framework collapsed. A large model will generate a nine-dimensional diligence template in about eight seconds, complete with column headers and a scoring rubric. What did not collapse is the marginal cost of producing a finding. Finding things still requires reading bytecode, messaging founders, sitting through town halls, reconciling documentation against a deployed contract, and admitting when the answer is that you cannot tell. That cost is roughly where it was in 2017.
When containers are free and contents are expensive, you get a market that is overwhelmingly container. Most of those containers are not empty, and that is the worse version of the problem. They are full of inference dressed as evidence โ ranges presented without sources, comparisons presented without metrics, risks presented without triggers and without probabilities. The empty document I am describing is simply the case where the inference did not survive the formatting pass.
I want to be fair to whoever produced it. Publishing blank fields is the least rewarding thing you can do in this industry. There is no distribution for it. There is no applause. If those nine sections had been filled with plausible material โ a team section assembled from professional networking profiles, a tokenomics section assembled from a blog post, a risk matrix populated by pattern-matching against other projects โ the document would have travelled further. It would have been quoted. It might have been screenshot into a thread with forty thousand impressions. The blank version travels nowhere.
Which means the blanks are not a formatting failure. They are an economic event. And the economy that produced them is the thing I want to take apart, because I have spent most of my working life on the other side of this exact problem โ helping people who could not read Solidity figure out which parts of a claim were checkable and which parts were atmosphere.
Before we get to what should have filled those fields, it is worth being precise about what a blank actually means, because there are three distinct states and most frameworks collapse them into one.
The first is unknown. The information exists in the world; you have not found it yet. A protocol's deployment addresses are on-chain. Its audit lives on a website. Its multisig signers may be public after ten minutes of searching. Unknown is a temporary condition and a solvable one.
The second is unknowable. The information does not exist yet, and it cannot, because the thing it describes does not exist yet. A pre-launch protocol has no live governance participation rate, no retention curve, no realised revenue. If a framework demands a number for a quantity that cannot yet have a number, the framework is broken, not the analyst.
The third is unexamined. The information exists, it is findable, and nobody looked. This is the interesting one, and it is almost always what a blank field actually encodes.
Why does the distinction matter? Because a blank in the first category is a task. A blank in the second category is a status. A blank in the third category is a claim โ it is somebody telling you that the diligence was not done โ and it gets filed under the same generic marker as the other two, where it reads as neutral.
When a field is blank in a diligence document, the blank is not neutral. It is a finding that has not been written down.
I learned this the blunt way in 2017, during the ICO boom, when I was a sophomore with more curiosity than capital. I was not trading. I was running what I called Blockchain Literacy Circles out of the campus library in Hangzhou, and the deal was simple: I would take a whitepaper and turn it into something a non-technical friend could read in twenty minutes. Fifteen of them across two semesters. Alongside that, I manually audited the tokenomics of five projects I genuinely found interesting โ not because I intended to buy, but because I wanted to understand what the numbers were doing.
The lesson out of those five audits is the one I have never unlearned. The documents a team does not publish tell you more than the documents it does. A team that publishes a forty-page token paper but will not publish the threshold on its treasury multisig is telling you exactly which part of the system it wants you to look at. A team that publishes a governance charter with no quorum figure is telling you that quorum has never been the binding constraint. A team that publishes an emission graph to the year but not the allocation buckets is telling you where the unlocks land. The absence is the signal. It is simply harder to read than a number, so most readers skip it.
If blanks are informative, why are they so rare in published research? Because the market for research does not price them.
Consider what happens when an analyst publishes a filled report versus an empty one. The filled report gets a title, a summary, a star rating, and distribution. The empty report gets, at best, a shrug, and at worst an accusation that the analyst did not do the work. The incentive is one-directional and it is not subtle.
Over time, that incentive produces a specific pathology, and I have watched it happen in real time. Year one, analysts write what they know and mark the rest as unknown. Year two, under pressure to fill the page, they write what can be plausibly inferred and mark it as an estimate. Year three, they write what the pattern suggests and stop marking it at all. By year four, the inference has been cited enough times to feel like a fact, and the next analyst uses it as an input. Nobody in that chain lied. Every individual step was a reasonable accommodation of a real constraint. The output is a document that reads like evidence and traces back to nothing.
Every layer of unverified inference you add to a report increases the distance between the reader and the risk.
I spent 2022 living on the other side of that gap. When the market broke, I was a junior professional watching people I knew lose real money, and what struck me was not the size of the losses. It was how many people had decided on the basis of things that had never been checked. They had read a summary of a report that summarised a thread that summarised a claim. They had never seen the contract. They had never seen the multisig. They had never asked whether withdrawals could be paused by anyone.
So I started a weekly series called DeFi for Humans. More than two hundred students came through it. The structure was not lecture-then-questions. It was: bring a position, and we will walk through what is verifiable and what is assumed. The sessions that mattered โ the ones that helped more than fifty people recover funds from broken or hostile contracts โ were not the ones where I explained a mechanism. They were the ones where we sat with a block explorer open and separated two lists. Here is what the code does. Here is what the documentation claims. Here is the intersection. Here is the part with nothing in it.
That last list is the one nobody wants to publish. It is also the only one that ever saved anyone money.
So if the blank document is a symptom, what would a filled one contain? Let me be concrete, because abstraction is how this industry hides.
It starts with the contract, and the first question is not what it does. It is whether you are reading the code that is running. On an explorer, that means verified source matching deployed bytecode โ not a link to a repository, which may or may not correspond to what was actually deployed. Unverified contracts are not automatically malicious. But an unverified contract inside a system that custodies deposits is a blank field wearing a helmet.
Then the proxy question. Is the contract upgradeable? If yes, who holds the admin key? If the admin key is an externally owned account โ one private key on one laptop โ then the protocol has a single point of failure that has nothing to do with its cryptography. If the admin key sits behind a multisig, what is the threshold? Three-of-five is not seven-of-eleven, and a three-of-five where three signers share an employer is a single signer with extra steps. If there is a timelock, what is the delay? Two days and seven days are different products. Two days is a window. Seven days is a negotiation.
Then the pause function, where I have seen the most confusion. Who can freeze transfers, and what exactly gets frozen? A pause that stops deposits but leaves withdrawals open is a circuit breaker. A pause that stops everything is a custodial switch. Documentation describes both with the same word. They are not the same risk.
Then the asset layer, and here I have to be direct about something the industry prefers to keep at arm's length. The largest compliance-oriented stablecoin issuers can freeze an address, and they say so in their own published terms. That is not a rumour. It is a documented capability with a support process attached. What follows is not that stablecoins are bad. What follows is that any protocol whose collateral, liquidity, or settlement leg is denominated in a freezable asset inherits the freezer. A lending market built on a freezable asset is a lending market that can be pushed toward insolvency by a compliance decision made elsewhere, on a timeline the market cannot observe. That dependency does not appear in a total value locked chart. It does not appear in a risk matrix that was never filled in.
A protocol is only as decentralised as its least decentralised dependency.
Then, for anything on a rollup: who sequences the transactions, and can a user force inclusion if the sequencer declines to include them? How long does the escape hatch take, and does it require cooperation from the same party you might be escaping? Where does the data actually go โ to the base layer, or to a committee that promises to publish it? These are not edge cases. They are load-bearing questions, and each one has an answer that is either published or not published.
Then the token. Cliff length. Unlock cadence. Bucket sizes. Not the headline percentage, the schedule. What fraction of circulating supply is genuinely liquid, versus circulating-but-locked inside a vesting contract the chain can see and the chart does not reflect. Treasury composition: is the runway denominated in the protocol's own token, in which case it is a bet, or in a stable asset, in which case it is a runway.
Then governance. Quorum as a percentage of total supply, and quorum as a percentage of active delegation. The gap between those two numbers is where real power lives. A quorum of four percent means a single well-funded holder can move anything through a sleepy voter base, and it will look legitimate, because the mechanism functioned exactly as designed.
I could keep going. That is the point. There are nine sections in that template, and every one of them has a list like this behind it. None of it is possible without the inputs. The document on my second monitor is not a failure of rigour. It is a failure of supply.
Here is an arithmetic worth doing slowly. Take a single unverified claim โ say, a circulating supply figure that came from a blog post rather than a contract read. It enters a summary. The summary enters a comparison table. The comparison table enters a screen. The screen enters a decision. Four hops, four handoffs, zero verifications. If each hop has even a moderate chance of preserving the claim rather than checking it, and in practice the probability of checking approaches zero because checking is expensive and citing is free, then the compound probability that the final decision rests on anything verified is functionally nil. Nobody in the chain behaved irresponsibly. The chain itself is the risk.
This is why I keep returning to the format question. My own primary format is short: one finding, a fast deduction, a conclusion that has to fit in a few hundred words. Short-form is not a lesser form of analysis. It is a discipline that forces honesty, because there is no room to hide an unexamined claim behind nine sections of scaffolding. If you have one paragraph, you spend it on what you actually know. Long-form gives you somewhere to put the things you do not.
Governance deserves its own pass, because it is the section where empty analysis does the most damage.
In 2025, after the ETF approvals changed who was sitting at the table, I led a cross-functional team drafting a community governance proposal for a major open-source protocol. Fifteen town halls. Developers on one side, institutional holders on the other, and a mandate that institutional capital would not be allowed to outvote the people who built the thing. My job was not to pick a winner. It was to build a structure in which the disagreement could stay productive.
What I learned is that consensus is not agreement. Consensus is the machinery that lets disagreement continue without breaking the system. And that machinery is almost entirely numeric. The two camps wanted different vesting schedules โ three-year escrow for ecosystem grants on one side, eighteen-month cliffs for everything on the other. The compromise did not live in the vesting table. It lived in the quorum design, the delegation rules, and the review cadence, because those determine who actually decides.
So when I see a governance section with three empty rows โ participation rate, holder concentration, proposal quality โ I do not see a missing table. I see the difference between a token that does something and a token that does not.
A governance token with no participation data is not a governance token. It is a lottery ticket with a voting interface.
The participation number matters because it tells you whether a vote is a decision or a formality. The concentration number matters because it tells you who has to be convinced. The proposal-quality number is the one people skip, and it is the one I care about most: how many proposals reached execution, how many were withdrawn, and how many passed and were never implemented. A governance system that passes proposals nobody executes is not governing. It is publishing.
This is where I have a strong view, and I would rather express it through an example than a slogan. Public goods funding in crypto has two live models. One is the committee: appointed reviewers allocate a treasury according to criteria described at a high level and rarely documented at the level of individual decisions. The other is the retrospective round: funding is allocated after the work is done, by reviewers whose identities and weights are visible, against a published rubric, with results reconstructable by anyone holding the data.
The difference is not generosity. It is auditability. In the retrospective model you can, months later, take the results and ask why a given project landed where it did. You can disagree with the outcome and still trace it. In the committee model you observe only outcomes, and outcomes lag โ by the time you can tell whether a funding decision was sound, the people who made it have moved on.
I have watched both from close enough to touch the spreadsheets. The retrospective mechanism is not perfect. It is the only one I have seen where an outsider can reconstruct how the money moved.
I want to name three specific things I keep testing, because they are where the industry's rhetoric and its mechanics diverge most sharply, and because all three are places where an empty document hides the gap.
The first is identity. In 2021 I worked with a digital-art collective in Hangzhou to build an on-chain reputation system โ ten workshops, thirty documented collaborations between traditional artists and crypto-native builders. The pitch was straightforward: put reputation on-chain and let it accrue. What actually got used, out of everything we shipped, was the membership gating. The reputation score sat there. The reason is not technical. The primitive is trivially simple โ a non-transferable token, an issuer registry, a revocation function. The reason is social. A permanent, globally readable record of your memberships and contributions is attractive right up until you need to leave something. Reputation you cannot walk away from is a liability. Reputation you can walk away from is not reputation. That tension has now survived three years of conference panels, and the panels keep describing it as a user-experience problem.
The second is the stablecoin dependency I raised earlier, and I want to sharpen it. The freeze capability is not a flaw in the design; it is the design. What follows is a set of dependencies most protocols do not disclose and most frameworks do not ask about. If your collateral can be frozen, your liquidation engine has an external input. If your settlement asset can be frozen, your payment flow has an external input. Naming that input is not an attack on anyone. It is the minimum standard for using the word decentralised in a sentence about your own product.
The third is the funding mechanism, which I already gave away. It is the cleanest available test of whether a community governs itself or merely markets itself as doing so, and the test is one question: can someone who is not on the inside reconstruct the decision?
Three tests, three blanks, one document. That is not a coincidence. Those are precisely the questions a framework leaves empty when nobody forces them to be answered, because the answers are expensive and the readers are in a hurry.
There is a fourth thing, and it is the reason this document exists in 2026 rather than 2021.
Earlier this year I wrote a series on AI agents and blockchain identity. Ten interviews with researchers working on alignment and machine ethics, twenty with developers building agent infrastructure, three essays, roughly fifty thousand readers across them. The technical findings were less interesting than the structural one. Agents need three things from a settlement layer: a way to hold value, a way to be permissioned, and a way to be identified. Blockchains provide the first two convincingly. The third they provide badly, for exactly the reason the identity debate has been stuck: identity systems that are useful are the ones people can escape from, and identity systems people can escape from do not prevent Sybil behaviour.
But the finding that keeps returning to me is about the research process itself. An agent can now produce a nine-section diligence document in eight seconds. It will produce it in flawless prose, with correct structure, with a scoring rubric and a risk matrix, and it will never once write the words insufficient information. Not because it is dishonest, but because it was not built to be honest. It was built to be complete. Completeness is the objective function, and a complete document that admits it knows nothing is, by that objective function, a failure.
If you cannot find the human who signed off on a claim, you do not have research. You have a rumour with formatting.
The counterweight is not to ban the tools. It is to build the verification layer and make it the scarce, visible, expensive part of the process. A research artefact worth trusting should carry a named attestation, a dated snapshot of the data that was read, and an explicit list of what could not be verified. That record should be checkable by anyone, and it should survive the researcher changing employers, changing opinions, or leaving the space entirely.
Which is, somewhat ironically, the one use of non-transferable credentials I think actually holds up โ not your credit history on a public ledger, but a researcher's track record of claims made and claims retracted, verifiable and portable. Not identity as surveillance. Identity as accountability.
We don't audit because we expect to find fraud. We audit so that we can say, with evidence, what we actually know. That sentence is the whole discipline, and it is the sentence a completeness-optimised system cannot produce.
Now the uncomfortable part, because everything above makes the empty document look like a small act of integrity, and I do not think that is quite right either.
The blank report is the most honest document in this quarter's market, and it is completely useless, and those two facts are connected. Honesty is only cheap when the truth is boring. Here the truth is that nobody knows anything, which is never what a reader paid for, and so the honest artefact gets no distribution while the confident artefact gets cited. The system does not punish dishonesty. It punishes friction.
Second, and this is the part that actually worries me: the document still got produced. Nine sections. Forty-one rows. Six risk categories. The framework ran to completion on an empty input, and that is not a quirk of one tool โ it is the genre. A machine that generates the visual grammar of diligence whether or not diligence happened is more dangerous than no machine at all, because at a glance the output is indistinguishable from work.
A framework that renders ignorance in the same visual language as safety is worse than no framework at all.
And that leads to the third point, the one I keep circling. Show a reader a risk matrix with six categories and no red entries, and almost nobody concludes unexamined. They conclude clean. Absence reads as safety, particularly in a bull market, particularly when the surrounding document looks rigorous. The blank is not a neutral placeholder. It is a green light with nothing behind it, and the more professional the formatting, the greener it looks.
So the contrarian reading of my beautiful empty document is not that honesty is rare and therefore admirable. It is that we built a genre in which the honest version and the dangerous version are typographically identical, and then let a market decide which one gets read. The market does not select on truth. It selects on completeness, because completeness is what scans in three seconds.
Trust isn't compiled, verified, and shared the way bytecode is. It has to be assembled by people willing to publish the list of things they could not find out.
So what should the document have looked like, given that the inputs did not exist?
It should have been short. It should have listed the nine sections and, for each, the specific input that was missing and the party responsible for supplying it. It should have carried a date and the name of the person who signed it. It should have ended not with a rating but with a question, because a rating is a conclusion and there was nothing to conclude from.
That is a boring artefact. It will never trend. But it is the only kind that survives a drawdown, and drawdowns are how this industry does its accounting.
The forward-looking version of this: over the next two years we will see more research published than in the previous ten combined, most of it generated faster than it can be read, most of it structurally complete and evidentially hollow. The protocols that come out the other side will be the ones whose claims survive a blank-field audit โ the ones where somebody, at some point, asked who holds the admin key, what the timelock is, who can pause what, and whether the thing called collateral can be switched off from an office in another jurisdiction. Those questions have answers. They are simply not the answers the framework was built to generate.
Bridges aren't maintained by optimism. They are maintained by people who walk out and check the cables.
Code is only as strong as the trust it protects.