A fund associate forwarded me a thirty-one-page due diligence report last month. It contained twenty-two tables, four risk matrices, a Howey test, a competitive landscape grid, and a governance health scorecard. Every substantive cell โ every one โ read N/A. Team background: N/A. Unlock schedule: N/A. Contract permissions: N/A. The author had written a footer explaining that information was insufficient to evaluate, then delivered the document anyway, because the document was the deliverable.
I have read a lot of bad research. This was the first time I read a report that was honest about being empty and still passed it upstream. What unsettled me was not the blankness. It was the template. Someone had designed a structure rigorous enough to look like diligence regardless of what was poured into it, and the structure worked exactly as designed.
Due diligence in crypto was once an improvised craft. In 2017 I spent three months auditing the whitepapers of forty-two failed ICOs and interviewing twelve founders who had burned out. There was no standard format then, which meant every report was a small act of original reasoning. Eighty-five percent of those projects lacked a value proposition that survived contact with a spreadsheet, and I could only discover that by reading the code and the cap table myself.
Nine years later, diligence has become a product. Research shops sell it by the page. Funds generate it internally with language models that summarize a deck, a website, and a Telegram announcement, then format the output into institutional furniture. In a bull market, when a hundred million dollars closes in a week and the memo is due Friday, the incentive is not to know. The incentive is to have a document that demonstrates you tried to know.
This is the quiet corruption of a good institution. Templates were invented to prevent omission โ to force an analyst to ask about unlock cliffs and admin keys before writing a check. They now function as a substitute for asking. A field labeled Token Distribution with N/A beneath it performs the same visual labor as a field with real numbers. The reader's eye registers completeness, not content. Nobody reads the N/A. They register that the box was addressed.
Here is how I test a research document now. I invert it. Instead of asking what the report contains, I ask what the report would look like if the analyst had actually found something.
A real token unlock table has a cliff date and a wallet cluster. It tells you that fourteen percent of supply vests in month twelve, and that the three addresses holding it were funded from the same exchange hot wallet in 2023. That is not a suspicion; that is a fact you can verify on-chain in an afternoon. When that table says N/A, the analyst is telling you the project has published nothing checkable โ or has not been read carefully. The distinction matters enormously, and the template collapses it into a single character string.
Contract permissions are the same. Who can mint? Who can pause transfers? Is the proxy upgradeable, and who holds the admin key? These are not philosophical questions. They are five function signatures. I have never seen a project hide them successfully; I have seen many analysts never look. An empty permission field is not a neutral observation. It is an unforced error dressed as restraint.
The Howey test deserves particular contempt in its template form. Four checkboxes and a comprehensive determination cell is a legal ritual, not a legal analysis. The actual inquiry is whether buyers are relying on identifiable managerial effort. You cannot answer that from a whitepaper. You answer it by reading how the foundation talks to its community, who controls the treasury, and whether the roadmap behaves like a product plan or a marketing calendar.
What actually predicted survival in my 2017 sample was not the quality of the token model section. It was whether founders had shipped anything before the token existed. That single fact outperformed every structured metric I collected. Structure is what we measure when we cannot measure substance.
I built a version of this test during the Ethical Oracles pilot I ran in 2026 with ten AI researchers, designing contracts meant to enforce human-centric constraints on autonomous transactions. The hardest problem was never encoding a value. It was detecting its absence. A smart contract that verifies nothing returns true. A due diligence report that checks nothing returns a document. Both fail open, and failure that looks like success is the most expensive kind there is.
Zero-knowledge proofs taught me something adjacent to this. A ZK proof is powerful precisely because it proves a specific claim without revealing the underlying data. It is sparse and it is complete. An N/A report is sparse and proves nothing about anything. The two look similar on a page. Only one of them is cryptographic.
There is a version of this argument that sounds like defensiveness โ the analyst blaming the project for publishing nothing. That is not my point. My point is that a blank field is a discovery, and treating it as a gap in the analyst's work rather than a finding about the subject inverts the entire purpose of the exercise. A blank field is not an oversight. It is a finding. If a project carrying a nine-figure valuation cannot produce a documented unlock schedule, that absence is the most important sentence in the report. It deserves three pages, not a cell.
Don't confuse liquidity with loyalty. A token can trade a billion dollars a day while its governance has twelve voters, six of them related to each other. Volume measures who is passing through a market. It says nothing about who is staying, and it says nothing about who can pause the contract while they stay.
So the associate's report was, in one narrow sense, correct. If the project published nothing auditable, the honest output is a stack of blanks. I would rather read that than read a document where every cell is filled with the analyst's guesses, formatted to resemble evidence. Fabricated diligence is worse than absent diligence, because it launders ignorance into institutional confidence and then attaches a number to it.
The failure is upstream and downstream at once. Upstream, in a market where a hundred-million-dollar round closes on narrative alone, projects have no reason to publish the uncomfortable tables โ the vesting chart, the treasury wallet, the audit scope letter. Downstream, funds measure research capacity by turnaround time, and a blank report delivered in forty-eight hours beats a real one delivered in six weeks.
When I spent two months in 2024 drafting a values-based investment framework with five traditional finance academics, we found that seventy percent of institutional hesitation traced to cultural unfamiliarity rather than analytical gaps. They already had frameworks. What they lacked was a reason to trust the culture underneath. Handing them a document full of N/A did not build that trust. It built distance, politely formatted, and it made the next conversation harder.
Code never lies, but it rarely volunteers. Someone has to stand in front of it and ask a specific question, in a specific block, about a specific address. In a bull market, very few people are asking, and the templates have become remarkably skilled at making the resulting silence look like an answer.
The next time a report lands on your desk with every cell filled, ask what it would have said if the project had published nothing. Then open a block explorer and check the one thing the report never touched. If the answer is still N/A, you have your finding. You did not need thirty-one pages to reach it.