Education only. Crypto assets can lose value, become illiquid, or fail to deliver. This is educational information, not an offer or a recommendation. Country eligibility must be assessed separately.
1. Match the exact network and address
Start with the chain name, network environment and exact contract address. Compare the address character by character across the issuer's English security policy, the relevant block explorer and any independent technical record. Do not accept a ticker, logo, shortened link or wallet label as identity proof. Record the explorer URL and the time of the check. Confirm that the deployed contract is on the intended network, that the page is not silently switching networks, and that a proxy address is not being confused with an implementation address. A mismatch is a stop signal, not a small formatting issue.
2. Record audit date, scope and deployed bytecode
An audit is evidence about a defined scope at a defined time. Read the report's date, commit or bytecode reference, included contracts, exclusions, severity definitions and remediation status. Match the deployed bytecode or verified source where the report permits it; an audit of source code that is not the deployed code does not answer the same question. For a proxy, identify the implementation and examine the proxy admin, upgrade authority, pause authority, mint authority and other privileged limits. Ask whether those controls are timelocked, multisigned, renounced, documented or simply asserted. “Audited” is not the same as safe, certified or free of future change risk.
3. Separate allocation, vesting and liquidity claims
Treat token allocation, vesting schedules and liquidity as three separate evidence tracks. Look for a dated allocation table, a contract or distribution mechanism, and a clear explanation of who can change the schedule. Check whether vesting is enforced on-chain or described only in marketing copy. Liquidity should be evidenced by the actual venue, pair or pool, lock terms, unlock date, depth and control of the relevant assets; “liquidity planned” is not liquidity proven. If the evidence is incomplete, write “unproven” rather than filling the gap with an assumption. Loss, dilution, illiquidity and contract-control risk remain possible even when documents are consistent.
4. Keep standards claims precise
FIPS 203 is a NIST standard specifying ML-KEM, a key-encapsulation mechanism. It is not a product certificate, a smart-contract audit, a token endorsement or proof that an issuer's implementation meets every requirement. Read the primary NIST publication directly and keep the distinction visible: a standard describes a technical scheme; product conformance requires separate evidence. Do not turn a named algorithm, a roadmap statement or a partner logo into a certification claim. This page uses standards language only as a reading aid and makes no certification claim about BMIC Research or any product. NIST FIPS 203 primary publication.
5. Protect the wallet and transaction trail
Never disclose a seed phrase, private key or recovery code to a website, support account or reviewer. Confirm the network, destination contract, chain ID, token allowance and transaction details in the wallet before signing. If a transaction is pending, inspect the explorer and nonce before retrying; do not follow instructions to repeat actions automatically or send again because a page says it failed. Treat urgent messages, copied addresses, fake verification pages and wallet-connect prompts as phishing risks. Keep a local record of the transaction hash and the exact page and date used for the check, without publishing personal wallet identity.
6. Check jurisdiction separately
Local eligibility must not be assumed from language, residence, an available webpage or a successful wallet connection. The Japan Financial Services Agency explains that classification and registration questions for crypto-asset offerings can depend on the facts and applicable framework; consult the primary materials and qualified local advice for the reader's situation. This page does not determine whether BMIC Research, a token or an offering is eligible in Japan or elsewhere. This is educational information, not an offer or a recommendation. Country eligibility must be assessed separately. Japan FSA primary material.
7. Publish an evidence log, not a verdict
For each check, record the source URL, access date, exact claim, observed result, limitation and follow-up question. Mark facts as current, historical, unavailable or unproven. Preserve contradictory evidence instead of selecting the most flattering version. A useful conclusion may be “the address matched, the audit scope was limited, vesting and liquidity remain unproven, and local eligibility requires independent advice.” That is more useful than a star rating or a claim that a project is safe. Published by BMIC Research, which is associated with the BMIC issuer; not independent investment research. This is educational information, not an offer or a recommendation. Country eligibility must be assessed separately.