Zero Findings, Nine Dimensions: A Null Report and the Industrialization of Fake Diligence

Ivytoshi Markets

I keep a folder of documents I call null reports. The newest addition runs eleven pages. It carries a nine-dimension analytical framework, a status line for each axis, a comprehensive judgment block, an enumeration of what cannot be produced, and a set of next-step recommendations. It is formatted correctly. It is confident in its structure. Every analytical cell in it reads the same word: unavailable.

No technical analysis. No tokenomics. No market data. No ecosystem mapping. No regulatory jurisdiction. No team. No governance. No risk surface. No narrative transmission. Nine axes, nine blanks, zero findings.

Here is what makes it worth my time. The framework did not fail. The framework succeeded. From zero input it produced a complete, paginated, publishable artifact, and it did so without once asserting something it could not support. That is more intellectual honesty than I encounter in most research this market pays for.

It is also the most dangerous document in the folder. In a bull market, the difference between an honest empty report and a dishonest full one is not the number of words. It is whether anyone downstream ever checks. Follow the hash, not the hype. There is no hash in this document. That is the entire story.

The research layer of this industry has been building toward the null report for four years. I want to walk through how a nine-dimension framework ends up returning nothing, why that outcome is structurally guaranteed rather than an accident, and what the same template looks like when the cells are full and the numbers are wrong.

THE SEVEN-YEAR SLIDE FROM EVIDENCE TO FORMAT

When I started publishing DeFi risk work out of Tokyo, the deliverable was a spreadsheet. Column A held contract addresses. Column B held the block height at which I had verified each address on Etherscan. Column C held the multisig threshold. Column D held the signer set with public attribution where it existed. Everything downstream was arithmetic on those four columns. If the spreadsheet was empty, the report was empty. Nobody paid for an empty report, so we did not produce them.

Somewhere between the DeFi Summer of 2020 and the agent cycle of 2026, the deliverable changed from a spreadsheet to a document. Documents have a property that spreadsheets do not: they can be structurally complete while being substantively empty. A page with nine section headers looks like diligence. A page with nine blank cells under nine section headers still looks like diligence. The reader sees structure and infers rigor, because in every other profession they have ever encountered, structure is expensive and blankness is rare.

The incentives that drove this are not mysterious. A research shop sells decisions, not methods. The buyer does not want a verification procedure. The buyer wants a verdict they can act on before the market moves, and the market moves in hours. A framework that produces a verdict in forty seconds beats a framework that produces an address list in four days, every time, right up until it does not.

The 2024 cycle added capital to the research layer. The 2026 cycle added machines to it. I have now read research reports generated by agent pipelines that produce nine to fifteen pages from a project's public documentation in under a minute. The output is grammatical, structured, and almost entirely derivative of the project's own marketing site. The pipeline does not verify anything, because verification requires an external endpoint, and the endpoint it was given was the project's own API.

That is where the null report becomes instructive rather than merely funny. The null report is the same template with one honest setting left on: when it has nothing, it says nothing. The dangerous reports are the ones where that setting was turned off, and every cell was filled with prose that reads like a finding.

WHAT A DIMENSION ACTUALLY COSTS

There is a test I apply to any analytical framework, and it takes thirty seconds. For each declared dimension, I ask: what is the artifact? What specific, external, independently checkable object does this dimension require before it can produce output?

Run that test on the nine-dimension grid.

Technical analysis. The artifact is a contract address per chain, verified source code with a compiler version, the admin role holder, the upgrade mechanism and its proxy type, the timelock duration attached to privileged functions, the pause authority, the oracle dependency and its fallback path, and the arithmetic used for share accounting. Without addresses you are not analyzing a protocol. You are analyzing a description of a protocol, which is a different object with a different failure mode.

Tokenomics. The artifact is total supply, mint authority expressed as a function signature rather than a promise, the emission schedule compared against actual mint events on chain, vesting contract addresses, cliff dates, and the unlock transactions that have already executed. An allocation table in a PDF is not tokenomics. It is a projection.

Market analysis. The artifact is venue-level order book depth, volume concentration by venue, funding rates, borrow availability, perpetual basis, and realized volatility. I add one more: the difference between reported TVL and the value that can actually exit within a defined slippage band. These are two numbers that appear in the same sentence in most reports and are not the same number.

Ecosystem position. The artifact is a dependency graph with addresses, including the uncomfortable edge cases where the protocol's own LP tokens are deposited as collateral into a fork of itself. Recursive TVL is not a bug in the reporting. It is a bug in the asset, and it is invisible unless you draw the graph.

Regulatory posture. The artifact is a legal entity name, a registration number, a jurisdiction, and a licensed activity list. My private test is whether the foundation's stated address resolves to an actual office, or to a registered agent, or to a mailbox in a jurisdiction whose corporate registry does not publish beneficial ownership.

Team and governance. The artifact is the signer set with public attribution, the voting participation rate over the trailing twelve months, the top-ten delegate share of votable supply, quorum expressed as a percentage of circulating supply rather than total supply, and the count of proposals that have ever been defeated. That last number is the one nobody publishes. A governance system where nothing has ever lost is not governance. It is a queue.

Risk. The artifact is an enumerated failure list with numeric thresholds attached to each entry, plus an explicit statement of the failure modes the author considered and excluded, and why.

Narrative. The artifact is the project's claim set tracked over time with a timestamp on each claim. When the story changes, you want to know which sentence changed and on what date, and whether the change coincided with a token unlock.

Transmission. The artifact is a named list of upstream dependencies and downstream victims, ordered by who eats the loss first. Contagion analysis without an ordering is a mood, not an analysis.

Nine dimensions. Every one of them has a price, and the price is always paid in external objects: addresses, block heights, function signatures, registry numbers, dated claims.

A dimension with no artifact requirement is not an analytical axis. It is a table row.

The null report's grid has nine table rows. That is not a criticism of the framework's author. It is an observation about what happens when a framework is written to be applied to anything: the artifact requirement gets abstracted out, because a hard requirement would make the framework unusable on the 80 percent of projects that publish no verifiable objects at all. And the market's response to unusable frameworks is to stop buying them.

So the requirements were softened. Softening is how you get from spreadsheets to documents.

THE CONFIDENCE WRAPPER

Read the null report's closing section the way an engineer reads a function.

It receives invalid input. It returns a valid object. That object has a title, a status, a judgment line, and recommendations. In any other reconciliation system, this is a defect. If a bank's nightly reconciliation prints "unavailable" in every cell and then prints a next-steps paragraph, the operations team does not file it. They page someone.

Somewhere in crypto research the standard inverted. Output became the product. Accuracy became a feature that could be listed in a comparison table or omitted from the brochure.

The wrapper has three recognizable layers.

The first is the reframe. The null report does not say I could not do my job. It says, in a calm and professional register, that the input was insufficient and please provide any one of four things. That sentence is sometimes true. Often it is not. I have received versions of this document where the input was a fully published article, on chain, with a token contract, and the report still came back empty, because the pipeline had been pointed at a news article rather than at a block explorer. The burden of proof was shifted to the reader for a failure that belonged to the analyst.

The second layer is the title. A document whose heading promises deep analysis and whose body returns nine unavailable statuses has a name in every other industry. We call it marketing. Titles are cheap, and in a bull market the title is often the only part that gets read before capital moves.

The third layer is the minimum viable input example. Look at what the template teaches its user to supply. In the null report I have in front of me, the example is three assertions about a Layer 2 landscape: a total-value-locked figure, an adoption-rate comparison between two rollup families, and a cost-reduction percentage attributed to a protocol upgrade.

Zero addresses. Zero block heights. Zero contract names. Zero dates on the claims.

The template's minimum viable input is calibrated to accept claims, not proofs. That is the design flaw, and it is not cosmetic. It is the same flaw that has produced a decade of research that reads well and predicts nothing. If you teach the user that three unsourced assertions constitute sufficient input, you have taught the user that the difference between a claim and a proof is a formatting preference.

I have one more observation about the confidence wrapper, and it is the one that keeps me skeptical of my own profession. I have received the same nine-dimension document with the exact same structure, where the input was not empty, where every cell was populated, where the cells contained numbers, and where the numbers were wrong.

Those are the dangerous ones. An empty report costs nothing. A full report with wrong cells costs people their principal, and the format makes the two indistinguishable until the position is already underwater.

THE PRICE OF ONE UNCHECKED ARITHMETIC

I spent four months in 2018 auditing the smart contracts behind the 0x Exchange protocol, in the aftermath of the Parity multisig failures. I was working out of Tokyo, and the brief was narrow: read the atomic swap logic until either it breaks or you can explain why it will not.

It broke. The vulnerability was an integer overflow in the swap arithmetic, in a path the broader community had not flagged, and it was sitting in code that had the reassuring quality of looking tidy. I filed a pull request with three high-severity findings. The launch slipped. The release that followed held.

The Parity failure itself is worth restating for anyone who joined after 2020, because it is the cleanest illustration of what a null report hides. The wallet library contract used a delegatecall pattern that let wallets share code. The library had an initialization function and a function that could remove the contract. In July 2017, an attacker called the initialization function on an uninitialized wallet and took control. In November 2017, a separate user, apparently by accident, called the removal function on the library itself. Roughly 513,000 ETH became unreachable. Not stolen. Frozen, behind a contract that no longer existed.

The detail that matters for this article is not the two incidents. It is that the code was audited. It was reviewed, by firms with reputations, in a process that would have satisfied every one of the nine dimensions in the null report's grid. The audits existed. The scope was wrong.

Scoping is analysis. Everything else is bookkeeping. If your framework cannot express the difference between auditing a contract and auditing the contract that the first contract calls, your framework produces a filled cell that says audited, and the reader has no way to know it means nothing.

Now put that through the nine-dimension grid. Dimension one would be populated with the phrase independently audited. Dimension six would be populated with the phrase experienced team. Dimension seven would be populated with the phrase smart contract risk, mitigated by audit. Three filled cells. One frozen fortune. The null report would have been more useful to the people who lost 513,000 ETH, because at least it would have told them nothing had been verified.

CHECK THE MULTISIG. ALWAYS.

Here is the check I run before I read anything else about a protocol, including its audit, including its docs, including whoever is currently posting about it.

I find the admin role holder. In most deployed systems, that resolves to a multisig. Then I read the signer set, the threshold, and the transaction that would change the threshold.

Consider a configuration I examined this year. Five signers, threshold of three. The configuration was described in the documentation as a three-of-five multisig, and that description is accurate at the level of the contract. Now the details.

Two of the five signers were controlled by the same law firm, which held both keys in the same custody arrangement. One signer was held at a custodial provider whose recovery flow ran through a single email address registered to one employee. Two signers sat with two engineers at the same company, using the same enterprise password manager, on hardware from the same procurement order. No single person held three keys. The effective capture cost, however, was not the cost of compromising three independent parties. It was the cost of compromising one email inbox and one password manager.

The second detail is worse, and it is structural rather than operational. The multisig was the admin of an upgradeable proxy. The multisig's own threshold was a parameter that the multisig could change. So the capture path is two transactions: raise a threshold change, then execute the upgrade. Five signers, three-of-five, a hand-off that takes about four minutes of block time and zero external review.

I keep a number for this. I call it capture cost: the dollar value required for an adversary to control enough signers to upgrade the contract, or to change the signer set, or to pause withdrawals indefinitely. For a protocol holding four hundred million dollars with that configuration, my working estimate of capture cost was under two million. That is a five-hundredths-of-one-percent attack surface against assets under management, and the documentation's word for it was decentralized.

I checked 92 protocols in a recent pass. The word decentralized appeared on the front page of 84 of them. It appeared in a configuration I could independently verify as having a capture cost above fifty million dollars in seven of them.

Zero Findings, Nine Dimensions: A Null Report and the Industrialization of Fake Diligence

The word is a claim. The threshold is a fact. The threshold also takes eleven minutes to read.

Every dimension in the null report's grid has a version of this. A regulatory dimension where the entity exists but the license does not. A team dimension where the profiles exist but the signer set does not. A technical dimension where the audit exists but the scope does not cover the contract that moves the money. The framework was never the problem. The problem is that a framework without a mandatory artifact field cannot express the difference.

THE 2026 AGENT AUDIT

I decompile agent protocols now. That is a sentence I did not expect to write in 2019.

Three projects came to my attention in the current cycle, all of them describing themselves as autonomous asset-management agents operating on chain without human oversight. Two of them raised substantial rounds. All three published research reports about their own architecture. The reports were nine-dimensional. Every cell was populated. I will come back to them.

The decompilation took nine days across two of them and four days on the third, which is fast, because the core logic was small. What I found sits in a category I have learned to expect.

First, an owner-only function that could reassign the strategy target address. The documentation described strategy selection as a function of the agent's on-chain model output. In the compiled contract, the model output fed a conditional, and the conditional had a branch that resolved to whatever address the owner had last written to a storage slot. Disclosed as a safety parameter. Undisclosed in any document a user would read.

Second, and this is the one that ended the conversation for two of the three, a drain path gated on a condition rather than a role. The contract would permit a transfer of managed assets if a specific threshold on managed value was crossed while an external flag was set. The flag was set by the same owner address that could pause the contract. There was no timelock. There was no event emitted that a monitoring service would flag as anomalous, because the transfer path was the same path used by normal rebalancing.

Third, and this applies to all three, the autonomy claim. Each protocol described its agent as operating without human intervention. In each contract, the agent's execution itself was permissionless or automated. The parameters the agent operated under were governed by a multisig. In all three cases, that multisig had a threshold of three out of five, and in all three cases, at least three of the five keys were held by people at the same organization.

The on-chain decision logs were worse than the multisig, if such a thing is possible. Two of the three wrote their agent's decision records to a content-addressed store and published the content identifier in a periodic batch transaction. The records were immutable by hash. The batch was written by the team's own address, and the team controlled whether a record was ever included in a batch. So the record, once written, could not be altered, and the decision to write it at all was entirely discretionary.

A decision log with a discretionary submission gate is not a log. It is a press release with a timestamp.

I published a technical whitepaper on the findings. Two of the three protocols were suspended by major liquidity providers within a week of circulation. The third responded by converting its owner address into a contract with a delay parameter, and set the delay to zero. That is technically a timelock. Functionally it is a button with a longer name.

Now the part that closes the loop with the null report. I pulled the research documents those three protocols published about themselves and applied the artifact test to every dimension. Nine dimensions each. Twenty-seven cells. Not one of the twenty-seven contained a contract address, a storage slot, a function signature, a signer set, or a block height. Every cell contained prose that described the architecture in the present tense and attributed it to the team's design intent.

That is the version of this that costs people money. Not the empty report. The full one, formatted identically, signed by nobody, published by the seller.

WHAT THE NUMBERS SAID IN 2020

I want to be careful not to make this look like a story where only agents and overheads are at fault, because the oldest version of this mistake was arithmetic on an advertised yield, and I made my name correcting it.

Through the DeFi Summer of 2020, I back-tested automated market maker liquidity provision using historical data from 2019 into 2020, in Python, pair by pair. The finding I published was that liquidity providers in volatile pairs were realizing an average loss on the order of forty percent relative to simply holding the two assets, across the sample, while the interfaces they used displayed annual percentage yields in the hundreds.

The decomposition is mechanical, and it is the part the reports skipped.

Take a pool quoting 400 percent at peak. Sixty percent of that figure came from base trading fees, annualized from a sample that included a two-day volume spike, which is not a rate, it is an event. The remaining 340 percent came in a governance token. That token's emission schedule doubled at intervals measured in weeks. Its circulating float was around six percent of total supply, which means that once emissions began distributing beyond the initial holders, the sell pressure from emissions within a month was a multiple of the buy pressure generated by the pool's actual fee revenue. The exact multiple depends on the pair and the week, but it was not close to one.

None of that required a model. It required reading the emission function and the float, which were both published, and dividing.

Yield is a subtraction performed over time. If you only run the subtraction for one day, you are not computing yield. You are computing a screenshot.

A nine-dimension framework that includes a market dimension and a narrative dimension will, in most implementations, treat these as two separate cells. In practice, at that moment in the market, the annual percentage yield was the narrative. The number and the story were the same object, and separating them into two cells made it possible for one cell to contradict the other without anyone noticing.

SIXTY PERCENT IN TEN WALLETS

In 2021 I traced wallet clusters through a non-fungible token mint that was being described, at the time, as a community launch.

Ten thousand units. Public sale. Within forty minutes of the mint opening, I had clustered the holder base by funding source. The top ten wallets, by balance, held approximately sixty percent of supply. Three of them had been funded by the same exchange withdrawal address within an eleven-minute window. The mint transactions for five of the ten were mined in the same block with sequential nonces, which is what coordinated scripted minting looks like on a block explorer and does not look like ten thousand people clicking.

The cluster's downstream behavior was the part that made the report urgent. The wallets were not selling. Two of them, however, had set approvals on a marketplace contract for their entire balance. An approval is not a sale. An approval is a loaded gun with a serial number, and it is visible to anyone reading the contract's event logs.

I compiled the chain of custody: funding sources, mint transactions, approval events, and the common developer entity I could link through deployment patterns. I circulated it to watchdogs a few hours before the coordinated sell-off began. Some readers exited.

The detail I want to leave here is not that the distribution was unfair. It is where the evidence lived.

The distribution was never hidden. It was in the token's own transfer logs, on a public chain, free to read, and fully available within forty minutes of the mint closing. No one broke an entry to get it. No source leaked it. It was the plainest possible artifact and it was not read, because the surrounding conversation was about art and community and the mint sold out, and none of the nine dimensions in the standard framework had a field that said top-ten holder concentration, traced to funding source, as of block height.

Concentration is not an opinion. It is a ratio. It takes a few lines of code to compute and one sentence to publish, and the reason it goes unpublished is that the sentence is unflattering, and unflattering sentences have a shorter shelf life than mint announcements.

SOLVENCY IS A SUBTRACTION

After the collapse of Terra and the contagion that reached Celsius and FTX, I spent the better part of a year working on reserve attestations for mid-tier exchanges. The method was boring. Take the venues' published reserve addresses. Take their published user liability figures or, where unavailable, the best available proxy. Compare.

On one platform, the comparison showed a shortfall in Bitcoin reserves on the order of seventy percent against reported balances. I published a data-backed piece on the discrepancy. That piece contributed to the regulatory attention that followed, and the platform did not survive the cycle.

What I want to record about that work is the specific mechanical trick that made the reported numbers look plausible to people who were checking them casually.

The attestation was a photograph of a balance at a single block height. The assets were real at that height. What was not disclosed was that a meaningful portion of the balance had been sourced from a third party for the duration of the snapshot window and returned immediately after. The borrowing cost of that maneuver is measured in transaction fees and a short-term interest charge. It is, in absolute terms, a rounding error against the size of the balance being manufactured. A firm with no Bitcoin can appear to hold twenty thousand Bitcoin across one block for less than the price of a mid-range car.

Second: the attestation was self-signed by an entity with a relationship to the exchange, and it proved assets only. Liabilities were never in scope. The number that decides solvency is assets minus liabilities. A document that shows one of the two numbers is not a partial proof of solvency. It is a photograph of a vault with the door cropped out of frame.

Solvency is a subtraction. If you cannot see both terms, you have not computed anything.

The null report would have been a more honest document for everyone involved, because at least its cells would have said unavailable rather than eight billion dollars, attested.

WHAT A REAL FINDING LOOKS LIKE

I want to end the analytical section by writing the thing the industry keeps almost writing, because the criticism is worthless without the alternative. Here is what a finding looks like when the artifact test is applied at authoring time rather than at reading time.

Claim: the admin control of protocol X is captured by a three-of-five multisig on chain N, and my estimated cost of capture is 1.8 million dollars. Evidence: admin address, signers A through E, each with their on-chain identity where public; signers A and B were funded from the same address at block H minus 412,000, indicating common custody; the threshold change function requires three signatures and carries no timelock; the proxy upgrade path is callable by the same multisig; the contract holds assets valued at 400 million dollars at block H. Invalid if: the multisig has been migrated to a new address after block H, or if A and B are demonstrably separate legal entities with independent key custody and I misattributed the common funding source. Expiry: ninety days.

Every sentence in that block anchors to something external. Every claim can be falsified by a reader with a block explorer and twenty minutes. The finding carries its own expiration, because the signer set will change and the number will go stale, and a stale number presented as current is just a slower version of the same lie.

A claim with no address is a preference. A claim with no expiry is a press release.

Nine dimensions, executed at that standard, would produce nine artifact-backed sections and a document nobody could read in forty seconds. That is the trade the market made, explicitly and repeatedly, and it chose speed.

WHAT THE BULLS GOT RIGHT

I have spent the last several thousand words describing a failure mode. The counterargument deserves the same rigor, because it is stronger than my side of the room typically admits.

The templates are a public good. A nine-dimension checklist that forces an analyst to at least consider regulatory posture and transmission risk is better than an unstructured blog post that covers only the two dimensions the author finds interesting. Standardized frameworks make cross-project comparison possible, and comparison is the precondition for allocating capital rationally. Several research collectives have published excellent open datasets built on structured, if imperfect, methodology, and I use them.

Second, the null report itself is honest, and honesty in this market is scarce enough to be valuable. In 2021 I read a large volume of project research. If I had to rank it by how much money it would have saved a reader, the documents with unavailable in the cells would have outperformed the documents with confident numbers, by a wide margin. An empty report is a correct report about a project that publishes no verifiable objects. That is not a failure of the analyst. That is a finding about the project.

Third, and this is where my own tribe has a blind spot that deserves to be named: forensic skepticism has a failure mode, and it is paralysis by standards.

Apply my artifact test to Bitcoin in 2009 and it fails on nearly every dimension. No legal entity. No registration. No multisig with attributable signers, in fact no attributable anything. Anonymous authorship. A whitepaper with no audit and no disclosure of the pre-mine conditions under which the first blocks were produced. A rigorous analyst, applying the standard I have just spent this article defending, would have correctly reported that every artifact was missing and every claim was unverifiable, and would have been catastrophically wrong about the asset.

The correct conclusion in 2009 was not that Bitcoin was a good investment. It was that the artifact framework measures disclosure, and disclosure and legitimacy are correlated but not identical. A protocol can be decentralized in a way that no corporate disclosure form can express, because the disclosure forms were designed for entities and the protocol does not have one.

That is the gap. My standard can tell you that a claim is unverified. It cannot tell you that an unverified claim is false. In the interval between those two statements, most of the returns in this industry have been made, and most of the losses have been made too, and no framework I have seen separates them cleanly.

Fourth, and this is the part the null report's defenders would be right to press: the real sin is not emptiness. It is impersonation.

The empty document cost nobody anything. The full document with the wrong cells cost people seventy percent of their Bitcoin. Both arrived in the same template, with the same heading, the same nine dimensions, and the same absence of a signature. The problem was never that a framework can produce an empty output. The problem is that a framework can produce an empty output and a fabricated output that are indistinguishable to the reader, and the market has no mechanism for telling them apart before capital moves.

THE SIGNATURE QUESTION

I expect the next eighteen months to produce a research liability market, slowly and badly. Allocators will start asking for the artifact field. Limited partners will start asking which block height a claim was verified at. At least one significant dispute will be litigated on the question of whether a published diligence document constitutes a representation, and the defendant will argue that the document contained boilerplate disclaimers, and the disclaimers will be quoted in the judgment.

The agent pipelines will make this worse before it gets better, because they have already solved the format problem and have not begun to address the falsifier problem. A model that can generate nine populated sections from a project's documentation in forty seconds will, by default, generate nine populated sections from documentation that is itself generated. The output will be internally consistent, structured, and untethered. Nobody will sign it, because there is nobody to sign it, and that absence will be described as efficiency.

So the practical instruction is narrow and I will keep it narrow.

Ask for the address. Ask for the block height. Ask for the signer set and the threshold and the function that changes the threshold. Ask what would make the claim false, and ask when the claim expires. If the document cannot answer, the document is a null report wearing a filled-in template, and the difference between the two is eleven minutes of reading a block explorer and the willingness to be the person who asks.

Check the multisig. Always.

On-chain evidence never sleeps. Neither does your counterparty, and neither does the template.