guides

How to Write a Due Diligence Checklist for Launchpad Partnership Requests

A launchpad partnership request is sitting in your Telegram DMs right now. Here's the exact checklist to vet it before you reply.

Grow your business on Telegram

CRM, Outreach & Lead Research. Get started with 1-week free trial.

Grow your business on Telegram

CRM, Outreach & Lead Research. Get started with 1-week free trial.

Grow your business on Telegram

CRM, Outreach & Lead Research. Get started with 1-week free trial.

Sell on Telegram

CRM, Outreach & Lead Research. 1 week on us.

Someone just DMed your launchpad asking to list their token next week. They've got a slick deck, a "doxxed" team page, and a Telegram group with 40,000 members. Three of those things are probably fake, and you have maybe 48 hours before they start pressuring you to confirm a date publicly.

Launchpads that skip due diligence end up listing rug pulls, and the reputational damage lands on the platform, not just the project. One bad listing can undo a year of trust-building with your investor community. The fix isn't more gut instinct — it's a checklist you run every single time, no exceptions, no favors for "warm intros."

What should a launchpad due diligence checklist include?

A working launchpad due diligence checklist needs at minimum 7 core categories: team verification, legal/entity structure, smart contract audit status, tokenomics review, liquidity and vesting terms, community authenticity, and prior track record. Skipping any one of these is how launchpads end up listing projects that vanish within 90 days of TGE — which, by industry post-mortems, is where a large share of rug pulls and soft rugs happen.

Treat this as a gate, not a formality. If a project can't clear all seven categories with real evidence — not just a Notion doc — it doesn't go on the calendar.

How do you verify the team behind a launchpad partnership request?

Team verification is where most due diligence fails, because "doxxed" often just means a name and a LinkedIn link that was created two weeks ago. Real verification means confirming the humans behind the project actually exist, actually built what they claim, and can be found again if something goes wrong.

  • Cross-check LinkedIn history against claimed past projects — look for overlap in dates, not just company names listed

  • Request a live video call with at least two core team members, not just the founder or a hired spokesperson

  • Search wallet addresses tied to the team against known rug-pull or exploit wallets using a chain explorer

  • Check for prior projects that failed or rugged under a different name — reverse image search team photos

  • Confirm legal entity registration in the jurisdiction they claim, using a registry lookup rather than trusting a PDF they send you

That last point matters more than most teams realize. Founders regularly claim incorporation in Singapore, the UAE, or Estonia without ever registering anything. If you're vetting founders based outside your home region, a business registry provider can confirm whether the entity actually exists and is still active — the same way you'd check if a CIS company is still active before contacting it.

What legal and structural documents should you request?

Ask for the company's certificate of incorporation, a cap table showing team and advisor allocations, and any prior fundraising SAFT or token warrant agreements before you discuss listing terms. If a project stalls on producing these within 3-5 business days, that delay is itself a signal.

Don't accept a screenshot of a legal document as verification. Cross-reference the entity name against the registry directly — the same due diligence approach used when you cross-reference a company's website with its registry filing applies here just as much to a Web3 project claiming a legal wrapper.

How do you check smart contract and tokenomics risk?

The contract audit and the tokenomics table are where projects hide the mechanics that let insiders exit first. A completed audit from a recognized firm is the baseline — not "audit in progress" or "audit scheduled." Around 60-70% of rug pulls involve a contract function that was never flagged because no audit was actually completed before launch.

  • Confirm the audit report is publicly linked and matches the deployed contract address, not an earlier draft version

  • Check for mint functions, ownership renouncement status, and blacklist/whitelist functions that let the team block sells

  • Review the vesting schedule for team and advisor tokens — anything under a 6-month cliff is a red flag

  • Calculate initial circulating supply versus fully diluted valuation to spot inflated FDV marketing

  • Verify liquidity lock duration and the platform it's locked on (screenshot claims don't count — check the lock contract directly)

How do you tell if a launchpad partner's community is real?

A Telegram group with 40,000 members and 12 messages a day is not a community — it's a purchased member count. Real community health shows up in engagement ratio, not headline size: aim for at least 1-3% of total members active daily in a healthy project group.

This is also where scraping and comparing group activity at scale actually pays off. If you're vetting multiple launchpad requests per week, manually scrolling through each Telegram group doesn't scale. Extracting active members and message frequency from a project's group gives you a real engagement number instead of trusting the member count on the group header — the same lead research approach CRMChat uses to help Web3 companies find and vet Telegram communities at scale works just as well in reverse, to audit a partner's community before you commit a listing slot.

What red flags mean you should reject a partnership request outright?

Some signals are disqualifying on their own, regardless of how good the rest of the deck looks.

  • Pressure to skip standard timelines — "we need to launch in 72 hours" is a pressure tactic, not a real constraint

  • Refusal to do a live team call, or team members who can't answer basic technical questions about their own contract

  • No liquidity lock, or a lock under 3 months on a mainnet launch

  • Copy-pasted whitepaper sections from other known projects — run key paragraphs through a plagiarism checker

  • Anonymous team with no prior verifiable project history, combined with a high initial market cap ask

Any one of these alone might have an innocent explanation. Two or more together is a pass, no matter how good the marketing budget looks.

How do you track due diligence across dozens of partnership requests?

If your launchpad gets more than a handful of inbound requests a week, a checklist in a doc gets messy fast — you lose track of which project is on step 3 versus step 6, and who owns the follow-up. This is a pipeline problem, not just a checklist problem.

CRMChat lets you track each partnership request as a deal stage inside your Telegram-native CRM, so due diligence status, team call notes, and audit links live in one place instead of scattered across DMs and spreadsheets. It also automates outreach follow-ups to the project team when a document or clarification is still pending, so nothing slips through because someone forgot to nudge a founder for a missing audit link.

For teams managing high partnership volume — the same way VCs track deal pipelines in Notion or Airtable — CRMChat's approach keeps the entire vetting workflow inside Telegram, where the actual conversations with founders and their teams are already happening. Check the case studies for how other Web3 teams have structured similar pipelines.

Quick due diligence checklist recap

  1. Verify team identity via live call, LinkedIn cross-check, and wallet history

  2. Confirm legal entity registration through an independent registry search

  3. Require a completed, publicly linked smart contract audit matching the deployed address

  4. Review tokenomics: vesting cliffs, circulating supply, and FDV math

  5. Verify liquidity lock duration and contract directly, not screenshots

  6. Measure community engagement ratio, not member count

  7. Check for disqualifying red flags: rushed timelines, refused calls, copied whitepapers

Run every request through all seven steps before it touches your public calendar. The 20 minutes it takes to check a registry or scrape a group's real activity is nothing compared to the cleanup after a listing goes bad in front of your entire investor base.

Continue Reading

The latest handpicked blog articles