Services
Crypto Team KYC Verification: Read the Badge Before Trusting It
A team badge records a provider's identity checks; it does not guarantee honest behavior or safe code. Crypto team KYC verification is useful only when its scope and current project binding are clear.

Key facts
- Archive folders
- 842 folders contain 1,612 KYC-named files
- Multiplicity
- 750 of 842 folders hold multiple files
- Scope
- Identity evidence is separate from code review
- Status
- Current verification was not checked
- Prices
- Compare billable participants, not badge images
Verification scope: documents, custody and disclosure
A crypto team KYC verification checks information about the people presented as a project's team.
The resulting badge is an assertion by its issuer about a defined process. It does not transfer control of the treasury to the issuer or establish what a token contract can do. Read the verification record as evidence about identity, then inspect the code and control structure separately.
Start with the subject.
A founder who completed an identity check might not hold an upgrade key. An engineer who controls deployments might work through a company the badge never names. Ask the provider or project to identify the covered roles without requesting private identity documents. Matching responsibilities to authority is more useful than collecting passport copies that an investor cannot authenticate or safely retain.
| Field | Evidence to request | Unresolved question |
|---|---|---|
| Identity documents | Provider confirmation of the completed checks | Was the document tied to the person participating? |
| Covered roles | Roles and count of verified participants | Does coverage reach the people controlling funds? |
| Record custody | Applicable storage and access policy | Who can obtain evidence after an incident? |
| Disclosure conditions | Provider's published terms and incident channel | What process permits release to investigators? |
| Project binding | Official record naming the relevant project | Does a rebrand or replacement team remain covered? |
Custody and disclosure are separate promises.
A statement that information is encrypted describes handling, while a promise to cooperate with authorities describes a possible use. Neither specifies how quickly an investigation will progress. Treat an unanswered field as unknown. A glossy badge cannot fill it.
Our archive census: files are not verified teams
We counted KYC-named artifacts in SolidProof's public GitHub archive to test whether file counts could reasonably stand in for team counts. They cannot: 1,612 matching files belong to 842 exact parent folders, and 750 folders contain multiple matching files. Even a folder count is not a deduplicated identity register.
Method
- Source
- solidproof/projects at the measured revision
- Retrieved
- Population and selection
- All tracked blobs whose basename contains the whole token KYC, grouped by exact parent directory. Case-insensitive basename token. No OCR or identity checks. A directory is an archive folder, not a deduplicated team.
- All repository files
- 11645
- Non kyc named files
- 10033
- Included files
- 1612
- Revision
e4764a6c42e1382a7fd829a2f2efad3870c578b0
Results
| Observation | Count | Denominator |
|---|---|---|
| KYC-named files | 1612 | 11,645 repository files |
| Exact parent folders | 842 | 1,612 matching files |
| Folders with multiple matching files | 750 | 842 folders |
| PNG files | 1537 | 1,612 matching files |
| Other file formats | 75 | 1,612 matching files |
Limits
- We read filenames and the complete repository tree, not private documents. No identity was reverified and no image was analyzed with optical character recognition.
- Folders can contain revisions or refer to the same team under different names. A folder is not a unique company or a currently verified project.
- The archive is one provider's public artifact collection, not its entire client register. It cannot measure fraud rates, service quality or present badge validity.
- All 842 folders have unknown current verification status in this census. No missing status was converted into a clean result.
The reproducible script is seo/research/kyc-artifact-survey.py; the fixed evidence is seo/research/kyc-artifact-survey-2026-09-05.json.
Both are kept in the repository and are not published as downloads. The output retains request statuses and raw evidence so a later review can distinguish a source change from a counting error.
What a KYC badge does not prove
Identity verification can make an investigation more informative without preventing the transaction that causes a loss.
A verified person can make a mistake, lose a signing device or deliberately misuse a privilege. The badge issuer may hold records but have no ability to pause the protocol. Confusing these roles turns evidence for accountability into an unsupported promise of prevention.
Keep these assurance questions in separate rows when reviewing a KYC verified crypto project.
A team may have convincing evidence in one row and no evidence in another. Combining them into a single trust score hides the gap instead of resolving it.
| Question | Relevant artifact | Badge limitation |
|---|---|---|
| Who was checked? | Verification record and covered roles | Coverage can exclude other contributors |
| What code was reviewed? | Audit report with scope and revision | Identity checking does not inspect code |
| Who can move funds? | Current role and signer configuration | People and keys may change |
| Are assets available? | Relevant balances and custody evidence | Identity is not a reserve statement |
| Can users exit? | Withdrawal behavior under adverse conditions | A badge does not supply liquidity |
A KYC audit badge is also different from an independent smart contract audit. Marketing sometimes places both symbols in one image. Open each original record and compare its issuer, subject and date. Our guide to a fake audit report explains the provenance checks that also help when a project copies a badge from another site.
Do not infer regulatory approval from a private team check. Exchange customer onboarding, a project's identity badge and an assessment of a business's legal obligations solve different problems. The provider should describe the actual service in its contract. If a launchpad requires a particular certificate, ask the launchpad which evidence it accepts before buying a package with a similar name.
- Official record
- Locate the issuer-controlled record before relying on the image.
- Covered roles
- Establish which responsibilities the verification covered.
- Current control
- Compare those roles with current operational authority.
- Bounded conclusion
- Limit the conclusion to the evidence that survives every check.
Member-firm KYC packages compared
Provider descriptions differ in ways that matter after a problem occurs. SolidProof's service page describes automated checks combined with manual authentication and identifies Veriff as a supporting provider. Its storage description refers to an offline encrypted disk. Those are published service claims, not an independent inspection of its systems.
Cyberscope describes confidential verification of founders and core contributors, with document workflows and internal review. Its page specifies Verification of 2 or more project team members
. That minimum is a package statement; it does not establish that every person with a sensitive role at any particular project was checked.
| Provider | Published scope | Buyer follow-up |
|---|---|---|
| SolidProof | Automated and manual authentication | Which project roles and records are covered? |
| Cyberscope | Confidential checks of core participants | How does the participant minimum affect billing? |
| CertiK | Identity and project-role review with an official badge record | Which team changes trigger another review? |
CertiK's process explanation describes private identity review and a publicly verifiable result. Its privacy discussion says personal information is not publicly disclosed and describes cooperation with law enforcement in suspected fraud cases. A public verification result should therefore not be mistaken for a public directory of the team's legal identities.
SolidProof's published terms describe conditions under which it may share collected data with authorities and injured third parties. That wording differs from a general promise of confidentiality. Read the applicable terms for the actual engagement and ask the provider to resolve any conflict with shorter marketing copy; do not assume every provider follows the same disclosure procedure.
Use the security provider directory to identify candidates, then verify their current offers directly. The SolidProof company analysis provides directory context. Membership, a profile or a commercial package is not evidence that a specific client's badge is current. That check belongs on the issuer's own record.
Separate a provider's verification service from a launchpad's use of its result. A launchpad may accept a badge as one entry requirement while making no promise about the project. Ask the project to show the original provider record rather than relying on a launchpad icon that abbreviates several checks. If the icon links only to a promotional page, the underlying verification remains unresolved.
Also distinguish a project record from a record about one person. A contractor can have a valid identity check without having authority to represent a project or control its funds. The useful question is whether the provider established the person's claimed role during the process. Where that role evidence is unavailable to investors, describe the gap explicitly instead of assuming a badge covers the whole organization.
Public prices and the unit being sold
On the retrieved Cyberscope pricing page, the KYC block displays $450
per user alongside a crossed-out price of $900. The same block describes verification of core team members. A buyer should confirm the billable participant count in writing instead of treating the visible price as the total cost for an entire team.
Record a displayed offer as an observation on . It is not a binding quotation or an industry average. The SolidProof and CertiK service pages opened for this comparison did not provide a comparable fixed team price, so their total cost remains quote required in this comparison. Absence from these pages does not prove that no other public offer exists.
- Participants
- Name the covered roles and ask how added people are charged.
- Rechecks
- Confirm the trigger and price for a replacement founder or signer.
- Incident support
- Ask whether document preservation and investigative assistance are included.
- Certificate maintenance
- Specify the record that remains available if the project changes its domain.
Buying the cheapest badge can be expensive if it verifies someone who no longer controls the project. Conversely, a higher price is not proof of a stronger process. Compare the same requested coverage and get exclusions stated clearly. Refuse a quote whose practical deliverable is only an image that cannot be verified independently.
Ask for an example of the public result before purchasing. It should be possible to understand the subject and find the issuer's record without receiving anyone's private documents. Clarify what happens if the provider retires a product or changes its record format. A durable redirect or an issuer-confirmed replacement record can preserve provenance; an old image stored by the project cannot establish current status by itself.
Do not compare team verification with the advertised cost of checking a retail exchange customer. A team engagement may include role review and follow-up, while a document-check transaction can have a narrower scope. The shared abbreviation KYC does not make those products equivalent. The quotation should identify the work being purchased so that a finance team can compare like-for-like coverage.
A rug after KYC: the Zoro Inu case
CertiK's own Zoro Inu account, published on , describes a project that completed its KYC process before an alleged exit scam. This is a provider's report about its client and response. It is not a court finding, and the retrieved source does not establish an investor recovery amount.
| Time | Provider's account | What it supports |
|---|---|---|
| Core team completed KYC | A check preceded the alleged misconduct | |
| Investigation found evidence of an exit scam | Verification did not prevent this reported event | |
| Report says identities and findings were submitted to the FBI | Stored information supported an investigative response |
The useful distinction is between identification and enforcement. A provider can supply information to investigators while users still lack a way to recover funds. An identity check does not create a technical withdrawal restriction or guarantee that the identified person has reachable assets. Do not convert the provider's report of cooperation into a claim of prosecution, conviction or restitution.
For a current incident, preserve the official badge record alongside transaction hashes and the project's public claims. Send material through the provider's verified incident channel. Publishing personal identity documents in a community chat is not a substitute for evidence preservation and can expose unrelated people. Our crypto incident response guide covers operational coordination and evidence handling.
How investors should read the badge
A useful review ends with a short statement of what is known, what remains uncertain and which decision the evidence can support. Avoid reducing that statement to verified or unverified. A valid historical check with unclear current role coverage deserves a different conclusion from a forged certificate.
- Open the issuer's own site independently. Find the project record there and save its URL, retrieval date and displayed status.
- Match the project identity. Check the official domain and any contract identifiers supplied by the record. Resolve rebrands before assuming a name match is enough.
- Request covered roles without collecting private documents. Compare those roles with the people or entities that control upgrades and treasury operations.
- Read the custody and disclosure terms. Save the incident contact while the provider's site is available.
- Combine identity evidence with the scoped audit and current control configuration. Record the gaps separately so another reviewer can reproduce the conclusion.
If the badge link is unavailable, mark the result unverified pending issuer confirmation. Do not call it fraudulent merely because a page is down. If the issuer explicitly denies the certificate, preserve that response and remove reliance on the badge. These outcomes require different actions and should never share the same spreadsheet cell.
Teams can make this review easier by maintaining a public assurance register: the issuer's record, the covered roles, the audit revision and a contact for changes. Keep private documents with the party responsible for verification. A register gives readers an evidence trail while avoiding an unnecessary collection of personal data.
Consider a disagreement between the project and issuer. The project may call the team fully verified while the issuer confirms only a subset of participants. Record both claims with their dates, then use the narrower confirmed scope until the discrepancy is resolved. This is a documentation problem to investigate, not proof that either party committed fraud. The investor's immediate task is to avoid relying on an assurance that the issuer does not support.
A chain migration creates another binding question. Identity documents do not change merely because a token moves, but a new deployment may introduce different administrators and contributors. Ask whether the issuer's project record was updated and review the new control graph separately. Copying the original badge into a new website is not enough to establish that relationship.
Keep a concise reviewer note with the final evidence packet: the official URL, the covered subject, the date checked and the unanswered questions. Another reviewer should be able to reconstruct the conclusion from those fields. If the provider later changes status, retain the prior observation as history and update the current conclusion rather than rewriting the earlier record.
Frequently asked questions
The founder refuses to publish their legal name. Does that invalidate KYC?
No. A provider can perform private identity checks and publish a verification result without publishing personal documents. Ask for the official record and covered roles, then assess the separate evidence about current operational control.
Can a replacement signer inherit a previous team badge?
Do not assume so. Ask the issuer whether the new person or role is covered and whether the change requires another verification. Preserve the old record as historical evidence rather than silently updating its meaning.
Can an investor purchase the team's identity documents from a badge provider?
The badge does not grant that right. Use the provider's incident or lawful disclosure process. Requesting a public scope confirmation usually answers the verification question without transferring private documents.